Taking a database server out of service starts with its connection pool, and until this release pausing a pool was abrupt: new work was refused, and a connection still in use was closed after about two seconds, whatever it was doing. For a long report or a batch posting that means a failed transaction and a retry. This release makes the pause graceful, while still guaranteeing that it completes.
A pause that waits for work in flight
- New work refused at once. As soon as a pool is quiesced it hands out no further connections, so the load on the server starts falling immediately.
- Running work allowed to finish. Connections already in use are left alone until they are returned, and a pool with nothing left in use completes its pause at once rather than waiting out the window.
- A bounded window. A connection that has not been returned when the window expires is closed, so a pool with one abandoned connection still pauses. The window is five minutes by default, can be set for the whole platform, and can be given per operation.
- Forced closes named as such. A connection closed because the window expired is logged with its own reason, distinct from a shutdown, so an operator can tell which work was cut short and why.
Three verbs, not four
- Online, quiesce, close. An operator starts a pool, pauses it gracefully or closes it for good. A separate drain action was built and then folded into quiesce, because two actions that leave a pool in the same state are one decision presented twice.
- Resumable. A quiesced pool returns to service with the same online action as before, with its caches and statistics reset.
Nothing changes for applications: a pool is quiesced only by an operator, and the change is in how considerately that pause treats the work already running.