Availability
Start with Availability modes to configure none or dc. The binary also
accepts ha, but the current release has no network layout that reaches both its public peer routes and private Raft
routes through the one address each roster member carries. Treat HA procedures as design material until that peer plane
has one deployable endpoint model.
Release status
| Operation | Status in this release | Scope or deployment gap |
|---|---|---|
Local operation with mode = "none" | Shipped | No distributed routes, listener, workers, or ownership state |
| Primary-to-replica metadata and blob replication | Shipped | dc uses the public server named by each member address |
| Same-datacenter placement receipts | Shipped with limits | Responses do not bind the serving node; object stores use node receipts; filesystem parent-directory sync failures are ignored |
| Replica heartbeat, liveness, and group readiness | Shipped | These report the static DC roster; they do not elect or promote a writer |
| Derived-view read frontier | Shipped | Replica page application advances the registered view frontiers before reads pass them |
| Filesystem copy, placement reconciliation, and reclamation | HA components ship | Their jobs require a nonzero ownership term; DC supplies zero and HA has no supported peer layout |
| Public topology, placement, operation, analytics, health, and readiness views | Shipped | The generated OpenAPI document lists public distributed operations |
| Private listener status | Shipped | dc can expose status; ha requires the listener for Raft |
Private listener commands and transfers in dc | Unavailable by design | DC runs no ownership consensus, so mutations return 503 Service Unavailable |
| Voting membership, home assignment, and planned transfer | HA components ship | The handlers and consensus code exist, but the split peer planes prevent a supported multi-node HA deployment |
| Automatic failed-home selection and transfer | Design | No runtime worker calls the failover policy or submits the transfer after liveness marks a member dead |
| PyPI ingress records and local publication | Shipped | Uploads publish at the local or assigned HA home; no transport sends an admitted intent from another datacenter to that home |
| PyPI write acknowledgements | Shipped with limits | The request path checks DC receipts; the crash-recovery finalizer can record published from local placement without calling the acknowledgement resolver |
| OCI write acknowledgements | Not integrated | OCI mutation paths do not call the distributed acknowledgement resolver |
| Visibility projection replication | Design | The minter, envelope, projection, and snapshot types have no production caller |
| Version negotiation and rollout preflight | Design | The policy functions have no startup, command, or HTTP integration |
Private control and peer-replication routes do not appear in peryx openapi or /api-docs/openapi.json; those schemas
describe the public server. Each page below labels a procedure that depends on design-only wiring.
-
Availability contracts
Shipped durability evidence and the remaining HA contract gaps.
-
Availability deployment and sizing
Deploy none and dc modes and inspect the HA peer-plane gap.
-
Availability modes
Configure none and dc modes and inspect the HA component boundary.
-
Node liveness
Track datacenter replica health from bounded heartbeats while leaving the configured roster unchanged.
-
Authority transfer and drain
Separate automatic-failover design from the shipped HA transfer and drain components.
-
Derived-view frontiers
Gate replica reads until each required view reflects the applied metadata serial.
-
Finalizing admitted content
Distinguish local PyPI finalization from the cross-datacenter design.
-
Home assignment on first publish
Describe the HA first-home component and its deployment boundary.
-
Availability control listener
Configure the private availability control socket.
-
Filesystem placement reconciliation
Describe the HA placement workers and their deployment boundary.
-
Planned authority transfer
Describe the HA planned-transfer component and its deployment boundary.
-
Blob reclamation
Describe the HA reclamation component and its deployment boundary.
-
Managing voting membership
Describe HA membership commands and their deployment boundary.
-
Observe availability health
Inspect topology, placement, operations, readiness, and replica frontiers.
-
Rolling upgrade and rollback
Record the design for HA upgrade preflight and rollback.
-
Upgrade and roll back an availability cluster
Separate shipped DC replacement from the HA upgrade design.
-
Version compatibility and rolling upgrades
Record the design for mixed-version negotiation and rollback limits.
-
Failover and recovery
Classify availability failures, recover the selected mode, and verify service before restoring traffic.
-
Client behavior across availability modes
Shipped retry behavior and HA fencing design across availability modes.
-
Visibility replication
Record the design for replicated visibility transitions and tombstones.