You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Docker image: the background join has no server role, so a standalone replication server or a directory server without one needs the deprecated one-shot types #1178
Since #1086 (#1115) the image joins its replication topology in the background, on every start, with OPENDJ_REPLICATION_TYPE=simple, and the README declares the one-shot types srs, sdsr and rg deprecated in favour of it (README.md:182-189). But simple builds one kind of topology only: every server is a directory server and a replication server at once. The two other roles dsreplication enable offers - a replication server that holds no data (--onlyReplicationServerN) and a directory server that connects to replication servers elsewhere (--noReplicationServerN) - are reachable through the deprecated types alone. The deprecation leaves no supported way to run them.
That layout is the one of #534 (four directory servers without a replication server, two standalone replication servers - the topology that piled up missing changes under load), the one #1090 wants to test, and the usual production one, where the replication servers are kept off the servers that take the client load.
What simple does
One enable, both sides combined. The join runs a single dsreplication enable (join.sh:442-449) with --replicationPort1 and --replicationPort2 and neither role flag. Without them the tool configures both a replication server and a replication domain on each side (ReplicationCliArgumentParser.java:100-108).
The peer's role is not this server's to choose, and the enable chooses it anyway. A server without a replication server that is passed through without --noReplicationServer1 is given one: !serverDesc.isReplicationServer() && enableServer.configureReplicationServer() runs configureAsReplicationServer() (ReplicationCliMain.java:5087-5097). A role variable for the joining server alone is therefore not enough: as the call stands, every directory server without a replication server that a new member joins through silently becomes a combined one. Likewise, a replication-server-only peer passed without --onlyReplicationServer1 is asked to configure a domain for BASE_DN (ReplicationCliMain.java:5059-5060).
Membership means holding the data. A member holds the replication domain of BASE_DN and is registered in cn=admin data (replicates_base_dn(), join.sh:302-309). A replication server without data never has that domain, so the join cannot recognise one as a member.
Health waits for the data. A volume bootstrapped with simple carries INITIALIZE_PENDING until the join has initialized it from the topology (run.sh:192-194), and the health marker waits for the join (run.sh:156, run.sh:229-236). A replication server has no BASE_DN data to initialize.
The seed is a data holder. The first peer of REPLICATION_PEERS seeds a topology nobody else holds with its own data. A replication server has none to seed with.
The bootstrap always creates the data backend.setup.sh creates userRoot for BASE_DN on every server (setup.sh:86-88), and with ADD_BASE_ENTRY / SAMPLE_DATA fills it (:90-104). On a replication server that would be data nothing replicates, served to any client that reaches it.
srs enables this server as a directory server without a replication server (--noReplicationServer1) and MASTER_SERVER as a replication server only (--onlyReplicationServer2), then runs initialize-all. The role of the master is set by whichever replica enables first, not by the master. Every replica pairs with the one MASTER_SERVER, so nothing connects a second replication server: the two standalone replication servers of Missing Changes count is piling up during peak load testing with OpenDJ 4.9.4 #534 cannot be built this way.
sdsr enables this server as a directory server without a replication server next to a combined master, and initializes it from that master.
A server role for simple, say REPLICATION_ROLE (the name is open):
Value
Server
dsreplication enable flag for this server
combined (default)
directory server and replication server, as today
--replicationPortN
directory
directory server without a replication server
--noReplicationServerN
replication
replication server only, no data
--onlyReplicationServerN + --replicationPortN
Both sides of every enable get their actual role. This server's comes from its environment. The peer's is read from the peer - whether its configuration holds a replication server and a domain for BASE_DN - and never assumed, so a peer without a replication server keeps having none.
Membership by role. A replication member has its replication server and is registered in cn=admin data (which the enable replicates to a replication-server-only server as well, ReplicationCliMain.java:5059-5060). A directory member has its BASE_DN domain, is registered, and its domain lists at least one replication server.
Bootstrap by role.replication creates no userRoot and ignores ADD_BASE_ENTRY / SAMPLE_DATA, never carries INITIALIZE_PENDING, never seeds and is never initialized. Its health follows its membership.
Seeding. Only a server that holds data (combined or directory) seeds. A topology needs at least one replication server: a directory server whose peers hold none does not join, and says so rather than retrying for ever.
Docs. README: the roles, the Kubernetes layout (one StatefulSet per role, REPLICATION_PEERS listing the members of both), and how srs / sdsr map onto simple with roles, so that their deprecation has a replacement.
Tests in docker-test-replication.sh: two replication + two directory servers, a change on each directory server reaches the other; a restart of each; a new member joined through a directory peer leaves that peer without a replication server; a replication server holds no BASE_DN backend; a directory server with no replication server among its peers does not turn healthy.
Out of scope
rg (replication groups, OPENDJ_REPLICATION_GROUP_ID) has the same gap - deprecated with no simple counterpart - but is a separate setting.
(line numbers on
master, 3f4deb9)Problem
Since #1086 (#1115) the image joins its replication topology in the background, on every start, with
OPENDJ_REPLICATION_TYPE=simple, and the README declares the one-shot typessrs,sdsrandrgdeprecated in favour of it (README.md:182-189). Butsimplebuilds one kind of topology only: every server is a directory server and a replication server at once. The two other rolesdsreplication enableoffers - a replication server that holds no data (--onlyReplicationServerN) and a directory server that connects to replication servers elsewhere (--noReplicationServerN) - are reachable through the deprecated types alone. The deprecation leaves no supported way to run them.That layout is the one of #534 (four directory servers without a replication server, two standalone replication servers - the topology that piled up missing changes under load), the one #1090 wants to test, and the usual production one, where the replication servers are kept off the servers that take the client load.
What
simpledoesdsreplication enable(join.sh:442-449) with--replicationPort1and--replicationPort2and neither role flag. Without them the tool configures both a replication server and a replication domain on each side (ReplicationCliArgumentParser.java:100-108).--noReplicationServer1is given one:!serverDesc.isReplicationServer() && enableServer.configureReplicationServer()runsconfigureAsReplicationServer()(ReplicationCliMain.java:5087-5097). A role variable for the joining server alone is therefore not enough: as the call stands, every directory server without a replication server that a new member joins through silently becomes a combined one. Likewise, a replication-server-only peer passed without--onlyReplicationServer1is asked to configure a domain forBASE_DN(ReplicationCliMain.java:5059-5060).BASE_DNand is registered incn=admin data(replicates_base_dn(), join.sh:302-309). A replication server without data never has that domain, so the join cannot recognise one as a member.simplecarriesINITIALIZE_PENDINGuntil the join has initialized it from the topology (run.sh:192-194), and the health marker waits for the join (run.sh:156, run.sh:229-236). A replication server has noBASE_DNdata to initialize.REPLICATION_PEERSseeds a topology nobody else holds with its own data. A replication server has none to seed with.setup.shcreatesuserRootforBASE_DNon every server (setup.sh:86-88), and withADD_BASE_ENTRY/SAMPLE_DATAfills it (:90-104). On a replication server that would be data nothing replicates, served to any client that reaches it.What the deprecated types do
replicate.sh:87-150:
srsenables this server as a directory server without a replication server (--noReplicationServer1) andMASTER_SERVERas a replication server only (--onlyReplicationServer2), then runsinitialize-all. The role of the master is set by whichever replica enables first, not by the master. Every replica pairs with the oneMASTER_SERVER, so nothing connects a second replication server: the two standalone replication servers of Missing Changes count is piling up during peak load testing with OpenDJ 4.9.4 #534 cannot be built this way.sdsrenables this server as a directory server without a replication server next to a combined master, and initializes it from that master.MASTER_SERVER, with none of the retries, membership repair and health gating Docker image: joining replication is one-shot, fixed-master and unchecked, which a StatefulSet cannot rely on #1086 brought tosimple.sdsr(docker-test-replication.sh:617-618);srsandrgare run by no test.Proposal
A server role for
simple, sayREPLICATION_ROLE(the name is open):dsreplication enableflag for this servercombined(default)--replicationPortNdirectory--noReplicationServerNreplication--onlyReplicationServerN+--replicationPortNBASE_DN- and never assumed, so a peer without a replication server keeps having none.replicationmember has its replication server and is registered incn=admin data(which the enable replicates to a replication-server-only server as well, ReplicationCliMain.java:5059-5060). Adirectorymember has itsBASE_DNdomain, is registered, and its domain lists at least one replication server.replicationcreates nouserRootand ignoresADD_BASE_ENTRY/SAMPLE_DATA, never carriesINITIALIZE_PENDING, never seeds and is never initialized. Its health follows its membership.combinedordirectory) seeds. A topology needs at least one replication server: adirectoryserver whose peers hold none does not join, and says so rather than retrying for ever.REPLICATION_PEERSlisting the members of both), and howsrs/sdsrmap ontosimplewith roles, so that their deprecation has a replacement.docker-test-replication.sh: tworeplication+ twodirectoryservers, a change on each directory server reaches the other; a restart of each; a new member joined through adirectorypeer leaves that peer without a replication server; areplicationserver holds noBASE_DNbackend; adirectoryserver with no replication server among its peers does not turn healthy.Out of scope
rg(replication groups,OPENDJ_REPLICATION_GROUP_ID) has the same gap - deprecated with nosimplecounterpart - but is a separate setting.Related
dsreplication enable --noReplicationServerN / --onlyReplicationServerNthroughdocker exec, on containers started withoutOPENDJ_REPLICATION_TYPE.OPENDJ_REPLICATION_TYPE,OPENDJ_MASTER_SERVER) predatesimple.