swuferhong opened a new pull request, #3340:
URL: https://github.com/apache/fluss/pull/3340
<!--
*Thank you very much for contributing to Fluss - we are happy that you want
to help us improve Fluss. To help the community review your contribution in the
best possible way, please go through the checklist below, which will get the
contribution into a shape in which it can be best reviewed.*
## Contribution Checklist
- Make sure that the pull request corresponds to a [GitHub
issue](https://github.com/apache/fluss/issues). Exceptions are made for typos
in JavaDoc or documentation files, which need no issue.
- Name the pull request in the format "[component] Title of the pull
request", where *[component]* should be replaced by the name of the component
being changed. Typically, this corresponds to the component label assigned to
the issue (e.g., [kv], [log], [client], [flink]). Skip *[component]* if you are
unsure about which is the best component.
- Fill out the template below to describe the changes contributed by the
pull request. That will give reviewers the context they need to do the review.
- Make sure that the change passes the automated tests, i.e., `mvn clean
verify` passes.
- Each pull request should address only one issue, not mix up code from
multiple issues.
- **Generative AI disclosure:** Indicate whether generative AI tools were
used in authoring this PR. If yes, specify the tool below.
- [ ] No generative AI tools used
- [ ] Yes (please specify the tool below)
**(The sections below can be removed for hotfixes or typos)**
-->
<!--
Generated-by: [Tool Name and Version] following [the
guidelines](https://github.com/apache/fluss/blob/main/AGENTS.md)
-->
### Purpose
<!-- Linking this pull request to the issue -->
Linked issue: close #3338
<!-- What is the purpose of the change -->
Introduce a periodic disk-usage monitoring mechanism that proactively
rejects client writes when the TabletServer's data disk usage exceeds a
configurable high-water-mark ratio, preventing ENOSPC errors and potential data
corruption.
Key design decisions:
- Hysteresis state machine with a fixed 10% recovery gap to avoid rapid
lock/unlock oscillation (lock at limit, unlock at limit-0.10)
- Max-per-disk strategy: report the highest usage across all distinct
FileStores so a single full disk is never masked by other low-usage disks in
multi-disk deployments
- Only client-driven writes (appendLog/putKv) are rejected with a retriable
DiskWriteLockedException; follower replication is not blocked to preserve
replica consistency
- write-limit-ratio supports runtime dynamic reconfiguration via
ServerReconfigurable, with an immediate re-check on change
- Setting ratio to 1.0 completely disables the protection
New configuration:
- server.data-disk.write-limit-ratio (default 0.85, dynamic)
- server.data-disk.check-interval (default 30s)
New metrics:
- diskUsageRatio: current disk usage ratio [0.0, 1.0]
- diskWriteLocked: 1 when writes are being rejected, 0 otherwise
### Brief change log
<!-- Please describe the changes made in this pull request and explain how
they address the issue -->
### Tests
<!-- List UT and IT cases to verify this change -->
### API and Format
<!-- Does this change affect API or storage format -->
### Documentation
<!-- Does this change introduce a new feature -->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]