Repository navigation
Conversation
Persist aggregation completion state and defer month-boundary snapshots for one recovery cycle after long gaps. Replace snapshots transactionally and propagate snapshot generations to quota readers. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## master #3298 +/- ##
=============================================
- Coverage 64.24% 50.63% -13.61%
+ Complexity 10398 8736 -1662
=============================================
Files 840 942 +102
Lines 71755 81222 +9467
Branches 8611 9811 +1200
=============================================
- Hits 46099 41128 -4971
- Misses 23004 36668 +13664
- Partials 2652 3426 +774 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes AMBRY-14502.
During the Aug 2026 prod-lva1 incident, account 1085's monthly
STORAGE_IN_GBbaseline was about 18 TB below peer fabrics. Once current aggregation caught up, the apparent monthly delta jumped from about 13 TB to 31.5 TB and uploads received 429s.The task writes
AggregatedAccountReportsbefore handling the monthly baseline.AggregatedAccountReports.updatedAtis therefore always fresh after the write and cannot identify a pre-write gap. Row timestamps also cannot prove that a host report is complete because unchanged rows are not rewritten and report upserts/deletes span multiple transactions.This change adds durable completion state and gates baseline recovery on measurable report coverage:
HostAccountReportsStatein progress before changingAccountReports, then complete only after all upserts and deletes succeed;The recovery reset can slightly under-report usage for the remainder of that month because the corrected baseline starts near zero. That is intentional: avoiding customer-facing 429s from a stale baseline is the higher-priority failure mode.
Schema, deployment, and rollback
The required schema counterpart is AmbryLI#4141. It adds the three backward-compatible
AggregatedAccountReportsMonthstate columns plusHostAccountReportsState. No backfill is required or safe: monthly state retainsNULL/NULL/0, and each host state row is created by its next successful report publication.Required rollout order:
HostAccountReportsStateexist;monthlyBaselineRecoveryMonthclears andsnapshotVersionadvances if recovery is armed;This mechanism is intentionally non-retroactive when
lastAggregationTimeMsis initially null, so rollout cannot silently infer or repair a baseline corrupted before initialization. For rollback, roll back readers first and aggregators/publishers second; retain the additive columns and table. Old binaries ignore them, and retaining state avoids destructive rollback and supports redeploy.Durability risk
This does not change blob write/delete paths or client success callbacks. It changes quota/account-report metadata only. A failed host publication remains marked incomplete and is excluded from recovery; the next successful publication supersedes it. Monthly snapshot replacement and state/version advancement are transactional, so SQL failures cannot expose an empty or partially replaced monthly table. Current aggregation writes are never suppressed by an unready recovery gate.
Testing Done
JAVA_HOME=$(/usr/libexec/java_home -v 17) ./gradlew :ambry-mysql:test --tests com.github.ambry.accountstats.HostAccountReportsStateDaoTest :ambry-mysql:compileIntTestJava :ambry-clustermap:test --tests com.github.ambry.clustermap.MySqlReportAggregatorTaskTest --quietJAVA_HOME=$(/usr/libexec/java_home -v 17) ./gradlew :ambry-mysql:test --quietJAVA_HOME=$(/usr/libexec/java_home -v 17) ./gradlew :ambry-clustermap:test --quietambry-api,ambry-mysql, andambry-clustermapsource setsgit diff --checkambry_container_storage_statsMySQL service is available; integration test sources compile and CI provides the database-backed run.