External Storage Integration: Lazy resolving references, general refactoring - #3016
External Storage Integration: Lazy resolving references, general refactoring#3016cconstable wants to merge 12 commits into
Conversation
3fe47fb to
831c284
Compare
| private boolean allowActivityHeartbeatDuringShutdown; | ||
| private String workerControlTaskQueue; | ||
| private PreferredVersionProvider preferredVersionProvider; | ||
| private @Nullable ExternalStorage externalStorage; |
There was a problem hiding this comment.
This doesn't have any callers in this PR but three of the PRs that build off this will use it. Included it here since those PRs are being up together.
831c284 to
460bfbf
Compare
| } | ||
|
|
||
| if (ExternalStorageReferences.isReference(payload)) { | ||
| throw new ExternalStorageNotConfiguredException(); |
There was a problem hiding this comment.
IIUC, this looks to be a DataConverter, which means it runs within the workflow code context. This means that this exception is handleable by user code. I think we need to move this to somewhere before the workflow code executes so we can fail the workflow task without allowing the user code to compensate.
There was a problem hiding this comment.
The context here is that if we missed integrating external storage into some piece of the SDK or a new feature was added that forgot to integrate external storage, this would catch it and throw a not configured error. It's purely a defensive fallback to make sure that SDK bugs don't appear as "your payloads can't be decoded/transformed" errors.
I do think ExternalStorageNotConfiguredException is probably the wrong error to be throwing here because it's likely that it was configured right and the sdk just isn't using external storage. Should this be a "some feature you are using has not integrated external storage. please file a bug report" type thing?
There was a problem hiding this comment.
I added a new ExternalStorageUnhandledReferenceException for when a reference payload makes it to fromPayload without being retrieved. This is a guard against SDK features that fail or fail to correctly integrate external storage. Normal misconfiguration errors should be caught at a level above fromPayload and are done so in the PRs that build off this.
| /** | ||
| * A {@link DataConverter} that resolves external storage reference payloads before deserialization. | ||
| */ | ||
| public final class ExternalStorageResolvingDataConverter implements DataConverter { |
There was a problem hiding this comment.
There was a problem hiding this comment.
Removed this entirely in favor of just doing the lazy retrieving in the few spots we needed explicitly. After chatting this felt like too much abstraction.
| @@ -84,10 +98,21 @@ public Builder setPayloadSizeThreshold(int payloadSizeThreshold) { | |||
| return this; | |||
| } | |||
|
|
|||
| /** | |||
| * Maximum number of payload lists visited concurrently while offloading or restoring the | |||
| * payloads of a single message. Must be at least 1. Defaults to 3. | |||
There was a problem hiding this comment.
Not sure a user is going to understand what is meant by "a single message". And "a single message" isn't quite the right scope from a implementation perspective. Maybe should describe this in terms of client operations and worker tasks.
There was a problem hiding this comment.
I think this will get cleaned up in the concurrency pass. I believe (technically) a single message is correct but I agree it's not a helpful way to describe it.
| } | ||
| } | ||
|
|
||
| <T extends Message> CompletableFuture<T> store( |
There was a problem hiding this comment.
Are there legitimate places where we need to visit on the fully constructed message instead of the build (the next overload)? I presume that the caller already created a builder, constructed the message, then this would effective recreate another builder, and reconstruct the message again. Might be perf issues. I would check to see if we can drop the message overloads and only use the builder overloads to force callers into the better performing algorithm.
| } | ||
| } | ||
|
|
||
| <T extends Message> CompletableFuture<T> store( |
There was a problem hiding this comment.
This will not work for workflow task completions because the nested commands need to change the the context when they are encountered. Having an outer visitor doing that determination and then calling this method is probably okay.
There was a problem hiding this comment.
Correct but workflow task completions are routed through a different store overload that includes the MessageVisitor so that the context can be changed (it's the one earlier in the file).
public <T extends Message> T storeBlocking(
T message,
@Nullable StorageDriverTargetInfo target,
@Nullable MessageVisitor<StorageDriverTargetInfo> targetVisitor) { ... }Regardless, it is confusing that there are so many overloads. I'll take a pass at consolidating them. I think we could just have one or two public ones. Some of the overloads above organically grew during the refactors and can be removed.
| /** | ||
| * A {@link DataConverter} that resolves external storage reference payloads before deserialization. | ||
| */ | ||
| public final class ExternalStorageResolvingDataConverter implements DataConverter { |
There was a problem hiding this comment.
Maybe add a comment that this is used in non-workflow contexts.
…former to ExternalStorage, create a lazy extstore resolving data converter.
460bfbf to
b3804da
Compare
|
Pushed a few updates:
|
…e to match other sdks.
b3804da to
ca09b50
Compare
…h to workers. we've got the dataconverter already so we can just derive it where its needed.
…for configuring external storage.
…ce payload makes it to fromPayload without being retrieved. This is a guard against SDK features that fail or fail to correctly integrate external storage. Normal misconfiguration errors should be caught at a level above fromPayload.
| */ | ||
| @Experimental | ||
| @Nullable | ||
| default ExternalStorage getExternalStorage() { |
There was a problem hiding this comment.
External storage should not be on DataConverter but instead on WorkflowClientOptions. The IDataConverter instance is accessible from within the workflow context, where we do not want external storage be accessible, let alone executable.
There was a problem hiding this comment.
We already have externalStorage on the data converter in both the Python and TS implementations. Also WorkflowClientOptions wouldn't be sufficient. I think we would need to independently configure ActivityClientOptions, NexusClientOptions, etc. I also don't think there is anything preventing a user from just doing S3Client().getObject(...) inside a "workflow".
There was a problem hiding this comment.
After chatting: will move to WorkflowClientOptions, ActivityClientOptions, NexusClientOptions, ScheduleClientOptions.
| return (T) new RawValue(payload); | ||
| } | ||
|
|
||
| if (ExternalStorageReferences.isReference(payload)) { |
There was a problem hiding this comment.
I'm not really convinced this is necessary. If we forget to plumb through retrieval somewhere, then it should likely fail at deserialization time explaining that the ExternalStorageReference message couldn't be deserialized into the target type. I also don't think we should give customers something that they can handle and attempt to compensate for in their executions.
There was a problem hiding this comment.
will chat with @Quinn-With-Two-Ns or @maciejdudko
There was a problem hiding this comment.
Potential directions:
- wrap the final data converter with a "reference payload checking" data converter. ensure it fails the workflow task.
- remove check entirely
…flow client options
… make sure users don't see a misleading error is nice it could also cause some nondeterminism if we fix the error and came with its own set of problems. maybe in the future we can find a better way to catch missing external storage integration in a better way.
jmaeagle99
left a comment
There was a problem hiding this comment.
Most are nits except the ExternalStorageDataConverter decorator should implement all methods and some more test coverage. I also pointed out some naming inconsistencies, but please do take a pass over them.
| * <p>Defaults to null. | ||
| */ | ||
| @Experimental | ||
| public Builder setExternalStorage(@Nullable ExternalStorage externalStorage) { |
There was a problem hiding this comment.
nit: Is there a way we could possibly mark this hidden from API / doc generation for now and adjust the comment to effectively say this is no-op at this time? I know we have the other PRs as follow ups to enable it, but just in case we need to pause and release Java in between. Obviously remove all of that when it does actually get attached in some usable manner.
| import javax.annotation.Nullable; | ||
|
|
||
| final class ExternalStorageReferences { | ||
| public final class ExternalStorageReferences { |
There was a problem hiding this comment.
This can be non-public again, correct?
| } | ||
|
|
||
| /** | ||
| * External storage configuration uses to store/retrieve large payloads. |
There was a problem hiding this comment.
| * External storage configuration uses to store/retrieve large payloads. | |
| * External storage configuration used to store/retrieve large payloads. |
| * <p>This This is an internal class that is not exposed to users or workflow code. The intent is to | ||
| * use this data converter to consolidate extstore usage within the SDK. | ||
| */ | ||
| public final class ExternalStorageDataConverter implements DataConverter { |
There was a problem hiding this comment.
Need to implement Object[] fromPayloads(Optional<Payloads> content, Class<?>[] parameterTypes, Type[] genericParameterTypes).
|
|
||
| private Payloads store(Payloads payloads) { | ||
| Payloads.Builder builder = payloads.toBuilder(); | ||
| externalStorage.store(builder, storageTarget, null, CancellationToken.none()); |
There was a problem hiding this comment.
nit: I think this needs to be lifted to be an instance field so that the owner of the data converter can cancel in flight operations, or maybe provided via something like a thread local so each call site can cancel. Then again, not sure if there is anything on any of the clients that would enable cancellation. Take this as a todo rather than fixing unless others object.
| private final boolean allowActivityHeartbeatDuringShutdown; | ||
| private final String workerControlTaskQueue; | ||
| private final PreferredVersionProvider preferredVersionProvider; | ||
| private final @Nullable ExternalStorageRunner externalStorage; |
There was a problem hiding this comment.
nit: storageRunner or externalStorageRunner
| HeartbeatManager getHeartbeatManager(); | ||
|
|
||
| @Nullable | ||
| ExternalStorageRunner getExternalStorage(); |
There was a problem hiding this comment.
getStorageRunner or getExternalStorageRunner
| import java.util.concurrent.CompletableFuture; | ||
| import org.junit.Test; | ||
|
|
||
| public class ExternalStorageDataConverterTest { |
There was a problem hiding this comment.
When you do implement the array form of fromPayloads, please add a test.
| import java.util.concurrent.CompletableFuture; | ||
| import org.junit.Test; | ||
|
|
||
| public class ExternalStorageDataConverterTest { |
There was a problem hiding this comment.
This we could add a test that wraps CodecDataConverter with a basic "encrypting/decrypting" codec to validate that drivers receive "encrypted" payloads?
| } | ||
|
|
||
| @Test | ||
| public void throwIfContainsReferenceThrowsOnReference() throws Exception { |
There was a problem hiding this comment.
While this is a worthwhile test, I think there should be a test that does the same thing but for a non-Payload/Payloads message type. Maybe a WFT completion with a start activity task command that has a storage reference input.
What was changed
ExternalStorageMessageTransformertoExternalStorage.ExternalStorageDataConverter: an internal data converter used consolidating extstore usage.Why?
These changes support the following PRs:
Checklist