Skip to content

Status

Watchdog is on version 0.0.0. Until 1.0, a minor release can change the public API, so pin the version you test against.

Every failure is a WatchdogError with a closed cause:

  • store_unavailable: the store threw, or an ingest replay conflicted with the stored job.
  • store_invalid: part of the closed set. The engine reports store faults as store_unavailable.
  • claim_unavailable: a claim could not be taken or renewed.
  • execution_failed: your Promise executor threw. tick() does not reject. The job settles as failed with this code as its failureReason.
  • settlement_rejected: the claim was replaced or expired before settlement.
  • wake_unavailable: wake.recompute() threw.
  • liveness_unavailable: isAlive threw.

underlying keeps the original thrown value for server-side diagnosis. Do not send it to clients.

Limits and guarantees:

  • One tick runs at most one job. Call tick() again, or from your wake, to drain a queue.
  • Concurrency is per runtime. Open one SQLite runtime per owner. The D1 and PostgreSQL runtimes use leases so more than one worker can share a database.
  • Delivery is at-least-once. A job recovered after a crash runs again, so make executor side effects idempotent.
  • outcome_unknown is a terminal outcome. Watchdog does not retry it.
  • IDs, queue names and lanes are 1 to 256 characters. failureReason is 1 to 200 characters and should be a short code, never provider text.

Watchdog is MIT licensed. See LICENSE.