A pass for one service
For each service, the reconciler keeps the correct containers, starts new ones and removes the others.
Lock. The reconciler takes the service lock and does not wait. It skips a busy service until the next pass.
A service is busy when a deploy starts its instances, or during a scale or a suspend. See The service lock.
The reconciler then works on the containers of the live deploy only.
The routes change before a removal. Thus traffic never goes to an instance that stops next.
Kept or removed
| Result | Containers |
|---|---|
| Kept | Containers of the live deploy in the state running or restarting, up to the wanted instance count. Those in the state running come first. |
| Removed | Containers that exited, are dead or never started. Containers of each other deploy. Instances above the wanted count. |
The reconciler always uses the snapshot of the live deploy: the image, the resolved environment, the command, the port, the disk and the resource limits. The engine saved them when that deploy went live. If the snapshot has no limits, the server defaults apply.
It never uses the current settings. If the image does not exist, the reconciler logs a warning and starts nothing. Deploy again.
- Stale containers of deploys that never went live (failed, canceled, interrupted): immediately.
- The others get 10 seconds to stop. Examples: the containers of a previous deploy, or the instances above the count after a scale down.
The order is the opposite. The service has one instance at most. The reconciler removes the stale container before it starts a new one, because two containers cannot share the volume safely.