Skip to content

Commit b640a9d

Browse files
committed
dc-dr: pin-standby help says role pin, not data freeze
The help promised that a held DC's coordinator refuses destructive cross-DC rewinds or re-seeds of the data it holds. That is no longer true: standby-hold pins the role and the cross-DC loss budget protects the data, the same budget that protects every other data center. Leaving the old wording would be worse than the old behaviour, since an operator would believe in a freeze that no longer exists. Signed-off-by: Tamal Saha <tamal@appscode.com>
1 parent 0787f60 commit b640a9d

1 file changed

Lines changed: 12 additions & 6 deletions

File tree

‎pkg/dcdr/pin.go‎

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -130,7 +130,7 @@ func NewCmdPin(f cmdutil.Factory, kind pinKind) *cobra.Command {
130130
if remove {
131131
_, _ = fmt.Fprintf(out, "The standby-hold is cleared. NOTE: this DC resumes contending on the NEXT Lease event; if the Lease is idle, a pending handoff may take until the agent's informer resync. Touching the Lease (for example dc-dr handoff --to <dc>) makes it immediate.\n")
132132
} else {
133-
_, _ = fmt.Fprintf(out, "This data center is now HELD as a standby for scope %s: it never contends for the Lease, never promotes, and refuses destructive cross-DC rewinds of its data.\n", lease)
133+
_, _ = fmt.Fprintf(out, "This data center is now HELD as a standby for scope %s: it never contends for the Lease and never promotes. Its data is still repaired normally if it needs a rewind or re-seed to stay a standby, bounded by the cross-DC loss budget.\n", lease)
134134
_, _ = fmt.Fprintf(out, " It is ignored while this DC is the ACTIVE one (demoting the active DC without a quiesce is unsafe): move the primary away with a switchover first.\n")
135135
_, _ = fmt.Fprintf(out, " Remove with: kubectl dba dc-dr pin-standby --scope %s --remove --yes\n", lease)
136136
}
@@ -184,11 +184,17 @@ func pinStandbyTexts() (use, short, long, example string) {
184184
coordination namespace of the CURRENT cluster, which must be the data
185185
center you are holding down.
186186
187-
While it exists that DC never contends for the scope's primary-DC Lease,
188-
never promotes (it refuses even an explicit handoff naming it), and its
189-
coordinator refuses destructive cross-DC rewinds or re-seeds of the data
190-
it holds. It fails CLOSED: if the ConfigMap cannot be read the hold is
191-
assumed, so a flaky apiserver never silently drops the protection.
187+
While it exists that DC never contends for the scope's primary-DC Lease
188+
and never promotes: it refuses even an explicit handoff naming it. It
189+
fails CLOSED, so if the ConfigMap cannot be read the hold is assumed and
190+
a flaky apiserver never silently drops it.
191+
192+
This pins the ROLE, not the disk. A held DC is still repaired normally:
193+
if it needs a rewind or a re-seed in order to BE a standby, that happens,
194+
bounded by the same cross-DC loss budget that protects every other data
195+
center. It is refused only when this DC holds more WAL than the budget
196+
allows, or when that distance cannot be measured. Use it to say "this DC
197+
must never become primary", not "never touch this DC's data".
192198
193199
It is deliberately ignored on the data center that is currently ACTIVE,
194200
because demoting the active DC without a quiesce is unsafe; move the

0 commit comments

Comments
 (0)