Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents

Status

Current state: Under DiscussionAccepted

Discussion thread: https://lists.apache.org/thread/kc87jkgyvf9x7nwmgwrhx6fs6w0tqymj

Vote thread: https://lists.apache.org/thread/rdpjmmqdxzog2m555r2wrncfn40zjf54

JIRA:

Jira
serverASF JIRA
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyKAFKA-20395

...

However, there is currently no way to unregister a controller, like there is for brokers via UnregisterBrokerRequest and UnregisterBrokerRecord. This means stale controller registrations can block feature upgrades. This KIP proposes adding support for operators to manually unregister controllers like they can with brokers.

The main One important use cases for unregistering a controller are for dynamic quorum clusters case for this KIP is to remove controller registrations from KRaft observers (i.e. clusters with KIP-853 enabled), since controller processes can now become observers of the KRaft log (i.e. they replicate the log but do not nodes that replicate the log but do not participate in leader election or committing data) and persist a controller registration to from the metadata log. However, there is a static quorum edge case where modifications to controller.quorum.voters can allow for a stale ControllerRegistrationRecord  to end up in the log. In either quorum mode, this KIP allows for operators to remove those controller registrations from the metadata log.This means operators can remove these stale registrations to unblock feature upgrades on their cluster.

Public Interfaces

New RPC 

...

Code Block
{
  "apiKey": 93,
  "type": "request",
  "listeners": ["broker", "controller"],
  "name": "UnregisterControllerRequest",
  "validVersions": "0",
  "flexibleVersions": "0+",
  "fields": [
    { "name": "ControllerId", "type": "int32", "versions": "0+",
      "about": "The controller ID to unregister." }
  ]
} "The controller ID to unregister." }
  ]
}

This request can return the following errors:

  • an UNSUPPORTED_VERSION  error if the cluster's MetadataVersion does not support UnregisterControllerRecord 
  • a CONTROLLER_ID_NOT_REGISTERED  error if no registration exists for the requested controller ID. This is similar to the BROKER_ID_NOT_REGISTERED error in the case of brokers.
  • a NOT_CONTROLLER  error if the request does not arrive at the active controller
  • an INVALID_REQUEST error if the request arrives at the active controller. This is known to be a "mistaken" request, as it is expected controllers are not running when they are unregistered. See the User Experience for more details.

UnregisterControllerResponse

...

Code Block
kafka-cluster unregister-controller --controller-id 99901

When the user executes this command to unregister controller 99901:

  1. UnregisterControllerRequest is sent to the active controller
  2. The active controller writes an UnregisterControllerRecord to the metadata log
  3. When this record is committed, return a response to the user for unregistering the controller
  4. The active controller's state machine removes the registration for controller 99901, meaning feature upgrades no longer consider node 99901's supported features
  5. The registration from controller 9990 1 is removed from the metadata image

...

Code Block
kafka-metadata-quorum remove-controller --controller-id 99901 --controller-directory-id EXAMPLE_UUID --unregister

When the user executes this command, kafka tries to remove 9990 1 as a voter AND unregister it:

  1. RemoveRaftVoterRequest  is sent to the active controller
  2. The KRaft leader writes a VotersRecord without voter 9990 1 to the metadata log
  3. When this record is committed, return a response to the user for removing the voter
  4. UnregisterControllerRequest is sent to the active controller if steps 1-3 were successful
    1. If steps 1-3 were not successful, return the error and direct the user to use kafka-cluster unregister-controller instead.
  5. The active controller writes an UnregisterControllerRecord to the metadata log
  6. When this record is committed, return a response to the user for unregistering the controller
  7. The active controller's state machine removes the registration for controller 99901, meaning feature upgrades no longer consider node 99901's supported features
  8. The registration from controller 9990 1 is removed from the metadata image

The main use case for this command is to remove a node from the voter set in a dynamic KRaft quorum, AND unregister it from the cluster all within the same CLI command. Since this is a common usage pattern, running this command with --unregister can be thought of as a "built-in" script that provides a smooth UX for decommissioning voters in a dynamic quorum. Running the command with --unregister will still fail when the cluster does not support dynamic quorum to be consistent with the behavior of the command when --unregister is not set.

User Experience

There are three The main use cases for the above of these CLI tools , with the recommended steps, are listed below. In any caseWhen trying to unregister a controller, it is assumed that the operator has stopped a node before unregistering it and does not intend to bring that node back in the near future. This is because after unregistering a node, the active controller no longer checks its supported feature levels when validating a feature upgrade. 

Remove and unregister a KRaft voter in a dynamic quorum

...

  1. Stop the voter
  2. Run kafka-metadata-quorum remove-controller with the --unregister flag

Remove a KRaft voter in a dynamic quorum and keep it registered as an observer controller

  1. Run kafka-metadata-quorum remove-controller with without the --unregister flag

Unregister an observer controller in a static or dynamic quorum

...

  1. Stop the voter who was mistakenly put in controller.quorum.voters 
  2. Run kafka-cluster unregister-controller
  3. Ensure the stopped voter is not part of controller.quorum.voters on every Kafka nodesnode

Proposed Changes

Controller Changes

...

Because this KIP is introducing a new metadata record alongside a new MetadataVersion, it means that existing clusters who have a stale controller registration will not be able to unregister it, and unblock feature upgrades thereafter. The main reason for not supporting this in existing clusters is that in many environments, operators can simply bring up another controller node with the same node ID to "refresh" its registration. Additionally, the interest of keeping this design simple, some of the potential workarounds for existing clusters have been moved to the Rejected Alternatives section.

...

This approach would be one way existing clusters could support unregistering stale controller registrations without updating the MV. However, the main issue with this approach is that it is unsafe. A user who unregisters a controller before updating the software versions on all controllers to support this feature would crash the controllers with an older software version.

Additionally, combined mode deployments where the broker and controller use the same ID make reusing the same metadata record for unregistering both brokers and controller too complex compared to introducing a new record for unregistering controllers.

Non-durably unregister controllers

...