Specify scheduler lease state with a separate authority epoch
The scheduler table stores only owner name and expiry, so an old owner can appear identical to a later process with the same name.
- Focused work estimate
- 1h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Lease modeling · Identity
Estimated field mix
- Distributed systems100%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional document service runs periodic retention planning on multiple application instances. Paused instances resume after lease expiry and can overlap newer schedulers.
Setup prerequisites
- Create a synthetic maintenance queue and two independent scheduler clients.
- Use fake time where possible and no destructive real retention actions.
Preceding work
No earlier ticket is required. Complete the project setup above.
Acceptance criteria
- Include lease identity, holder instance, expiry and monotonic epoch.
- Define active and expired semantics at the exact boundary.
- Keep display names outside authority checks.
Implementation constraints
- Use opaque process-instance identities.
Verification to include
- Represent two successive owners with distinct epochs.
- Reuse a display name and verify it cannot impersonate the previous instance.
Deliverables
- Lease schema and authority contract
Rollout and recovery
Review the schema before scheduler writes; leave coordination disabled until epoch checks exist.
Value of the work
For the engineer: Practice lease assumptions, fencing and stale-owner rejection.
For the team: Review safe coordination that remains explainable under pauses and recovery.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.