Skip to content

Add composite MySQL safety checks and stable recovery - #196

Open
pradeepkintali wants to merge 5 commits into
masterfrom
pkintali/a1-freno-primary-protection
Open

pradeepkintali wants to merge 5 commits into
masterfrom
pkintali/a1-freno-primary-protection

Conversation

@pradeepkintali

@pradeepkintali pradeepkintali commented Sep 23, 2026 •

Copy link
Copy Markdown

Summary

  • compose replica lag with required primary-load and ProxySQL-capacity safety metrics
  • fail closed when configured probes have no eligible hosts or required runtime metrics are unavailable
  • keep throttling active until recovery thresholds and continuous cooling periods are satisfied
  • require a complete healthy recovery window after process or leader startup
  • include the blocking metric name in composite check responses and publish recovery-latch metrics
  • support explicit MASTER/PRIMARY Vitess tablet discovery while preserving REPLICA as the default
  • validate required-cluster references, dependency cycles, and Vitess tablet types at configuration load time
  • document the configuration model and scope boundaries

Configuration model

A normal replica-lag cluster can list primary-load, connection-capacity, or other scalar safety metrics in RequiredClusters. Each required metric is sampled centrally by the Freno leader and may opt into:

  • FailOnNoHosts
  • RecoveryThreshold
  • RecoveryDurationMillis
  • an explicit Vitess tablet type where applicable

All settings are opt-in, preserving existing behavior for current clusters.

Validation

  • go test -count=1 ./...
  • go vet ./pkg/base ./pkg/config ./pkg/throttle ./pkg/http ./pkg/mysql ./pkg/proxysql ./pkg/vitess

Full-repository go vet ./... still reports pre-existing testing.T.Fatalf calls from non-test goroutines in internal/raft tests.

Scope boundaries

This PR provides reusable admission checks and recovery behavior. Deployment-specific metrics, thresholds, host discovery, operational alerting, and application concurrency or fallback controls remain the responsibility of each deployment.

Allow replica-lag checks to require cached primary and ProxySQL safety metrics, fail closed for configured probes, and hold recovery until a cooling period completes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0fbc396f-32f9-449a-8537-6264e8665c31
Require a full healthy window after process or leader startup, expose the blocking metric in check responses, and publish recovery latch state.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0fbc396f-32f9-449a-8537-6264e8665c31
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0fbc396f-32f9-449a-8537-6264e8665c31
@pradeepkintali pradeepkintali changed the title Add composite MySQL safety checks Add composite MySQL safety checks and stable recovery Sep 24, 2026
@pradeepkintali
pradeepkintali marked this pull request as ready for review September 28, 2026 19:03
Copilot AI balanced review requested due to automatic review settings September 28, 2026 19:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Recovery semantics and direct-memcache behavior can bypass or inconsistently apply the new safety gates.

Review effort: Balanced
Findings: 1 High severity · 3 Medium severity

Open (4)
What changed in this PR

Adds composite MySQL safety checks, recovery hysteresis, and configurable Vitess tablet discovery.

Changes:

  • Composes replica checks with required primary and ProxySQL metrics.
  • Adds fail-closed behavior, recovery thresholds, cooling periods, and metrics.
  • Supports validated REPLICA, MASTER, and PRIMARY Vitess tablet configuration.
File Description
pkg/​base/​throttle_metric.go Adds recovery-state metric errors.
pkg/​config/​config_test.go Tests new configuration validation.
pkg/​config/​mysql_config.go Adds composite and recovery settings.
pkg/​config/​vitess_config.go Validates tablet types.
pkg/​throttle/​check.go Evaluates required clusters.
pkg/​throttle/​check_result.go Reports the blocking metric.
pkg/​throttle/​throttler.go Implements recovery latching.
pkg/​throttle/​throttler_test.go Tests composition and recovery.
pkg/​vitess/​api_client.go Filters configured tablet types.
pkg/​vitess/​api_client_test.go Tests primary discovery.
doc/​mysql.md Documents configuration and rollout scope.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/vitess/api_client.go
Comment thread pkg/throttle/check.go
Comment thread pkg/throttle/throttler.go
Comment thread pkg/throttle/throttler.go
Preserve the replica validation API, apply read overrides consistently, reset recovery state on leadership regain, and enforce required clusters for direct memcache consumers.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0fbc396f-32f9-449a-8537-6264e8665c31
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0fbc396f-32f9-449a-8537-6264e8665c31

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants