You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
ActorTemplate: replace on_pause/on_commit/on_resume with capture_scope and minimum_scope #2102
Every actor must be bootable from its OCI image + its volumes alone; anything not reconstructible that way must live on a volume. This is the invariant that demotes memory and rootfs snapshots to accelerators. Applications that cannot meet this contract must declare a minimumResumeFidelity floor - the worst resume they can survive - and pay for a stricter floor in scheduling freedom and blocked upgrade automation.
Today's SnapshotConfig can't express that floor.
Proposal
1. Updated SnapshotConfig
messageSnapshotConfig {
stringstorage_location=1;
// capture_scope defines the scope captured when taking a snapshot on suspend.// Defaults to SNAPSHOT_SCOPE_MEMORY when unset.SnapshotScopecapture_scope=2;
// minimum_scope defines the lowest state layer required for the actor// to resume safely. The system attempts to resume at capture_scope, but may// be unable to (e.g. the sandbox config changed, or the target hardware// can't restore the snapshot) and fall back to a lower scope. If the scope// it can resume at is below minimum_resume_scope, the actor enters CRASHED.// Must be <= capture_scope.// Defaults to SNAPSHOT_SCOPE_VOLUMES when unset.SnapshotScopeminimum_scope=3;
}
SnapshotScope is an ordered enum of state layers, lowest to highest (it replaces SnapshotContentScope):
enumSnapshotScope {
SNAPSHOT_SCOPE_UNSPECIFIED=0;
// Durable volumes only; the actor cold boots from its OCI image.SNAPSHOT_SCOPE_VOLUMES=1;
// Volumes plus root filesystem changes.SNAPSHOT_SCOPE_ROOTFS=2;
// Volumes, root filesystem changes, and process memory.SNAPSHOT_SCOPE_MEMORY=3;
}
Also ResumeActorResponse needs to tell user what was actually used.
messageResumeActorResponse {
Actoractor=1;
boolresumed=2;
// The scope that we actually resumed.SnapshotScopescope=3;
}
2. Remove the old per-operation fields
Remove on_pause, on_commit, on_resume / OnResumeConfig and ResumeSource.
changed the title [-]ActorTemplate: replace on_pause/on_commit/on_resume with capture_scope and minimum_resume_scope[/-][+]ActorTemplate: replace on_pause/on_commit/on_resume with capture_scope and minimum_scope[/+]on Oct 6, 2026
Motivation
Part of actor lifecycle v2. The contract we want is
Today's
SnapshotConfigcan't express that floor.Proposal
1. Updated
SnapshotConfigSnapshotScopeis an ordered enum of state layers, lowest to highest (it replacesSnapshotContentScope):Also ResumeActorResponse needs to tell user what was actually used.
2. Remove the old per-operation fields
on_pause,on_commit,on_resume/OnResumeConfigandResumeSource.capture_scope. Pause vs suspend distinction is being removed separately in Opt-in durability instead of Pause vs Suspend API #798.capture_scope.cc: Julian Gutierrez Oschmann (@juli4n) Dmitry Berkovich (@dberkov) Jaana Dogan (@rakyll)