Skip to content

[1/4 messagequeue] RFC: per-tenant sharding for the MySQL message queue - #693

Merged
behinddwalls merged 3 commits into
mainfrom
preetam/mq-tenant-rfc
Sep 10, 2026
Merged

[1/4 messagequeue] RFC: per-tenant sharding for the MySQL message queue#693
behinddwalls merged 3 commits into
mainfrom
preetam/mq-tenant-rfc

Conversation

@behinddwalls

@behinddwalls behinddwalls commented Sep 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

Why?

Vitess is the product, not the contract. The RFC should talk about sharded MySQL and a tenant shard key so the design does not read as Vitess-specific.

What?

  • Drop the RFC metadata table.
  • Rename the RFC to per-tenant sharding for the MySQL message queue and replace vindex/Vitess wording with shard key and sharded MySQL.

Test Plan

Issues

Stack

  1. @ [1/4 messagequeue] RFC: per-tenant sharding for the MySQL message queue #693
  2. [1/3 messagequeue] Shard MySQL queues by tenant identity #694
  3. [1/2 messagequeue] Wire MQ_TENANTS through services and tests #695
  4. [2/2 messagequeue] Add Vitess vschema and two-shard vtcombo suite #696

## Summary

### Why?

Vitess needs a stable vindex that is not the Kafka-style partition key. SubmitQueue already uses partition_key for ordering, so hashing it would scatter one queue across shards and mix tenants.

### What?

- Add the per-tenant MQ sharding RFC: tenant column as the vindex, queueName mapped at wiring, partition_key remaining the in-tenant ordering unit.
- Link the RFC from the index and note the consumer-gate interaction.

## Test Plan

Docs only. Review the RFC against the follow-up implementation PRs.

Co-authored-by: Cursor <cursoragent@cursor.com>
@behinddwalls behinddwalls changed the title [1/4 messagequeue] RFC: per-tenant Vitess sharding [1/4 messagequeue] RFC: per-tenant MySQL sharding Sep 8, 2026
## Summary

### Why?

Vitess is the product, not the contract. The RFC should talk about sharded MySQL and a tenant shard key so the design does not read as Vitess-specific.

### What?

- Drop the RFC metadata table.
- Rename the RFC to per-tenant sharding for the MySQL message queue and replace vindex/Vitess wording with shard key and sharded MySQL.

Co-authored-by: Cursor <cursoragent@cursor.com>
@behinddwalls behinddwalls changed the title [1/4 messagequeue] RFC: per-tenant MySQL sharding [1/4 messagequeue] RFC: per-tenant sharding for the MySQL message queue Sep 8, 2026
## Summary

### Why?

VARCHAR(255) is not a single byte budget. Reviewers need to know why operational IDs are ascii_bin and partition keys are utf8mb4_bin, including the 255-byte vs 255-character distinction and InnoDB's 3072-byte key cap.

### What?

- Explain CHARACTER SET ascii COLLATE ascii_bin vs utf8mb4/utf8mb4_bin, NOT NULL, and the per-column limits in the tenant-sharding RFC.

Co-authored-by: Cursor <cursoragent@cursor.com>
@behinddwalls
behinddwalls marked this pull request as ready for review September 8, 2026 06:11
@behinddwalls
behinddwalls requested review from a team and sbalabanov as code owners September 8, 2026 06:11
@behinddwalls
behinddwalls added this pull request to the merge queue Sep 10, 2026
Merged via the queue into main with commit 7f194e0 Sep 10, 2026
27 checks passed
@behinddwalls
behinddwalls deleted the preetam/mq-tenant-rfc branch September 10, 2026 16:40
behinddwalls added a commit that referenced this pull request Sep 10, 2026
## Summary

### Why?

Vitess needs a stable vindex that is not the Kafka-style partition key.
Isolation has to be an explicit tenant column, with identity carried on
publish and consume so two tenants sharing a partition key cannot
collide.

### What?

- Prefix every queue table and store query with tenant; set
queue_offsets PK to (tenant, topic, partition_key, consumer_group).
- Use typed (tenant, partitionKey) identities in consumers, gates, and
MySQL workers; stop workers when lease discovery cannot confirm
ownership.
- Require tenant on publish.Message and validate payload queue against
message tenant in pipeline controllers (the publish signature change is
not compilable without those call sites).
- Add ParseRequiredTenants and wire Stovepipe ingest to the configured
tenant list so NewIngestController still builds.
- Require tenant xor all-tenants on MQ admin list commands; message
inspect/delete/requeue take the full (tenant, topic, partition, id)
identity.
- Comment ascii/ascii_bin vs utf8mb4/utf8mb4_bin on every queue table,
with the full encoding note on queue_messages.

## Test Plan

✅ `go test` on mysql, publish, consumer, messagequeue identity,
service/messagequeue, and start controller

Rebased onto current `main` after RFC #693 merged.

## Stack

- ~~[#693](#693) RFC: per-tenant
sharding for the MySQL message queue~~ (merged)
- [#694](#694) Shard MySQL
queues by tenant identity
- [#695](#695) Wire MQ_TENANTS
through services and tests
- [#696](#696) Add Vitess
vschema and two-shard vtcombo suite

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
behinddwalls added a commit that referenced this pull request Sep 10, 2026
## Summary

### Why?

The MySQL subscriber only discovers partitions for configured tenants.
Service processes and compose stacks must pass the same list they
already use as queue names, or Subscribe fails at startup and tests talk
to an unsharded process.

### What?

- Parse MQ_TENANTS in gateway, orchestrator, and runway wiring and
reject configs whose queue names do not match.
- Set MQ_TENANTS in service compose files, e2e harnesses, and
SubmitQueue integration suites.

## Test Plan

✅ `go test` TestValidateConfiguredQueueTenants,
TestValidateProfileQueueTenants, TestValidateMergeQueueTenants, and
service/messagequeue

Rebased onto current `main` after #694 merged.

## Stack

- ~~[#693](#693) RFC: per-tenant
sharding for the MySQL message queue~~ (merged)
- ~~[#694](#694) Shard MySQL
queues by tenant identity~~ (merged)
- [#695](#695) Wire MQ_TENANTS
through services and tests
- [#696](#696) Add Vitess
vschema and two-shard vtcombo suite

Co-authored-by: Cursor <cursoragent@cursor.com>
behinddwalls added a commit that referenced this pull request Sep 10, 2026
## Summary

### Why?

The MySQL subscriber only discovers partitions for configured tenants.
Service processes and compose stacks must pass the same list they
already use as queue names, or Subscribe fails at startup and tests talk
to an unsharded process.

### What?

- Parse MQ_TENANTS in gateway, orchestrator, and runway wiring and
reject configs whose queue names do not match.
- Set MQ_TENANTS in service compose files, e2e harnesses, and
SubmitQueue integration suites.

## Test Plan

✅ `go test` TestValidateConfiguredQueueTenants,
TestValidateProfileQueueTenants, TestValidateMergeQueueTenants, and
service/messagequeue

Rebased onto current `main` after #694 merged.

## Stack

- ~~[#693](#693) RFC: per-tenant
sharding for the MySQL message queue~~ (merged)
- ~~[#694](#694) Shard MySQL
queues by tenant identity~~ (merged)
- [#695](#695) Wire MQ_TENANTS
through services and tests
- [#696](#696) Add Vitess
vschema and two-shard vtcombo suite

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants