Skip to main content

Data Model: YU11-aeron-replication

Input message (InputEventMessage, 64 bytes)​

The message contains the standard 8-byte SBE header followed by a fixed 56-byte root block. All multi-byte fields use little-endian encoding.

SBE header​

OffsetFieldTypeValue
0blockLengthuint1656
2templateIduint16schema-assigned input template ID
4schemaIduint16YU11 replication schema ID
6versionuint16encoded schema version

Root block​

Root offsetFieldTypeMeaning
0inputSequint64Contiguous logical sequence within the leader epoch.
8eventTimeMillisint64Sequenced event time.
16limitPxint64Existing fixed-point limit-price slot.
24priceTicksint64Existing fixed-point market-price/client-key slot.
32orderRefuint32Internal order reference.
36accountIduint32Trading account ID.
40securityIduint32Symbol-table ID.
44qtyint32Signed quantity.
48leaderEpochuint32Witness/Lease transition epoch.
52commandTypeuint8 enumExisting InputEvent.type.
53sideuint8 enumExisting buy/sell value.
54flagsuint16 setDefined compatible fixed flags; unknown required bits reject.

Logical identity is (clusterId,leaderEpoch,inputSeq). Aeron session/stream/position values are transport coordinates and do not replace that identity.

Durable ACK (DurableAckMessage, 32-byte root)​

OffsetFieldTypeMeaning
0leaderEpochuint32Epoch of the accepted data stream.
4flagsuint32ON_RING, JOURNALED, APPLIED, REPLAYING, DEGRADED.
8inputSequint64Highest contiguous sequence covered by the flags.
16recordingPositionint64Follower Archive position associated with the ACK.
24journalForceNanosuint64Monotonic force-completion time for latency accounting.

The primary accepts an ACK only for its current epoch and only when inputSeq is monotonic. Durable mode requires JOURNALED; promotion readiness separately requires APPLIED.

Session hello/challenge​

The control handshake binds:

FieldMeaning
clusterIdDeployment identity shared by both replicas.
podUidKubernetes pod UID.
ordinalStatefulSet ordinal (0 or 1).
leaderEpochCurrent Lease/witness epoch.
transportNATS or AERON.
schemaChecksumSHA-256 of the committed SBE schema and generated codec metadata.
dataSessionId / ackSessionIdAccepted Aeron session identifiers.
nonceFresh challenge nonce.
hmacHMAC-SHA256 over all preceding fields with the replication Secret.

The handshake state is DISCONNECTED -> CHALLENGED -> AUTHENTICATED -> CATCHING_UP -> LIVE. Any identity/schema/epoch mismatch transitions to REJECTED and readiness remains false.

Snapshot/Archive checkpoint​

(leaderEpoch, inputSeq, recordingId, recordingPosition, sbeSchemaVersion)

The checkpoint is persisted with the application snapshot and is valid only when all fields match one complete snapshot manifest.

Snapshot manifest​

FieldMeaning
bundleIdUnique immutable bundle identifier.
leaderEpoch / inputSeqLogical snapshot boundary.
recordingId / recordingPositionReplay start coordinate.
schemaVersion / schemaChecksumDecoder contract.
snapshotLength / symbolsLengthExpected file sizes.
snapshotSha256 / symbolsSha256Content checksums.
chunkCountComplete chunk count for atomic install.

Bundle installation writes temporary files, verifies lengths/checksums/schema, fsyncs, and atomically renames both files before journal/Archive replay starts.

Shadow comparison record​

Shadow mode tracks a fixed rolling window keyed by (leaderEpoch,inputSeq):

FieldMeaning
natsChecksum64-bit checksum of the authoritative NATS-decoded payload.
aeronChecksum64-bit checksum of the Aeron-decoded payload.
natsSeen / aeronSeenPresence bits.
deadlineNanosBounded comparison deadline.

Matched entries are cleared; mismatches, gaps, duplicate-different payloads, and expired one-sided entries increment the shadow-failure counter and block a successful shadow result.

Fast witness record​

The TRADERX_BLP_FAST_WITNESS KV value contains:

FieldMeaning
clusterIdDeployment identity.
holderIdentityPod identity allowed to open admission.
leaderEpochMonotonic epoch assigned by a successful compare-and-set.
previousRevisionKV revision the contender observed before its claim.
claimedAtMillisWitness-server-observed claim time.
expiresAtMillisBounded fast-witness term.
schemaChecksumServing pair's schema identity.

The KV revision is part of the in-process admission fence. A contender opens admission only for the exact revision returned by its successful atomic claim.

Runtime state model​

Transport state:

DISABLED | NATS_LIVE | AERON_SHADOW | AERON_CATCHING_UP | AERON_LIVE | DEGRADED_SOLO | STRICT_REFUSING

Watermarks:

  • offeredSeq: highest primary sequence offered to the selected transport;
  • recordedPosition: primary Archive recorded position;
  • followerReceivedSeq: highest contiguous decoded follower sequence;
  • followerJournaledSeq: mapped primary sequence covered by follower journal force;
  • followerAppliedSeq: mapped primary sequence applied by the follower BLP;
  • acknowledgedSeq: highest accepted peer ACK for the active mode;
  • shadowComparedSeq: highest contiguous payload-equal shadow sequence.

Readiness requires a legal state/mode combination and no gap. Promotion eligibility additionally requires followerJournaledSeq and followerAppliedSeq at the observed live high watermark.