Current state: Approved
Discussion thread: https://lists.apache.org/thread/mb98kw1qjq2hb0ksj14d3thz3g50x9ck
Vote thread: https://lists.apache.org/thread/2vlxrnq0ojytw590fhs98f3g2hrwybbl
JIRA:
Please keep the discussion on the mailing list rather than commenting on the wiki (wiki discussions get unwieldy fast).
KIP-853: KRaft Controller Membership Changes added support for bootstrapping the KRaft state while added support for bootstrapping the metadata state. In other words, the zero checkpoint (00000000000000000000-0000000000.checkpoint) contains the starting state for KRaft while bootstrap.checkpoint contains the starting state for the cluster metadata.
This KIP unifies these two checkpoints by moving the starting metadata from bootstrap.checkpoint to the zero checkpoint. The main advantage of using the zero checkpoint is that it integrates with the rest of the checkpoint mechanisms like checkpoint loading (RaftClient.Listener#handleLoadSnapshot) and checkpoint deletion introduced in KIP-630: Kafka Raft Snapshot. For example, not deleting the bootstrap.checkpoint has cause issues with Kafka startup logic as documented in .
Currently, these two checkpoints that handle bootstrapping metadata can be viewed as "logically separate," and this KIP seeks to unify them under the zero checkpoint in KRaft.
SnapshotHeaderRecord and SnapshotFooterRecord are not a concept in the bootstrap.checkpoint). Other KRaft control records include the kraft.version level and the starting voter set. QuorumController when it becomes leader. The active QuorumController attempts to write the bootstrap metadata records in a transaction if transactions are supported, or in a single atomic batch. From the perspective of KRaft, the contents of the bootstrap.checkpoint are "data" records, not control records. The bootstrap.checkpoint file is created by the kafka-storage tool. The kafka-storage tool will not create this file any more and will instead write metadata record to the zero checkpoint in the cluster metadata partition.
The Kafka node will delete the bootstrap checkpoint if it is not needed. The checkpoint is not needed if the bootstrapping metadata has been committed to the cluster metadata partition. One implementation is for the node to delete the bootstrap checkpoint if it has loaded a non-empty checkpoint from the cluster metadata partition.
Pre-KIP-1170, both brokers and controllers would create this file during formatting. Post-KIP-1170, this file will no longer be written during formatting.
This checkpoint file is created by the kafka-storage tool in the __cluster-metadata-0 directory. Now, it will also contain the data that used to be contained in the bootstrap.checkpoint file. It is important to note that the bootstrap records must be less than 8MB of total size if transactions are not supported, since that is the maximum batch size in bytes supported by KRaft.
Pre-KIP-1170, this file was created by KIP-853-enabled controllers who formatted with either --standalone or --initial-controllers . Post-KIP-1170, this file is created during formatting by controllers. Brokers will not write this file because they cannot write its contents to the metadata log.
There are two fields in the ApiVersionsResponse that are used to describe the finalized feature version of the cluster. There is an existing issue where ApiVersionsResponse reports finalized feature versions even if the state of the cluster metadata partition is not known. Those two fields are documented as follow:
FinalizedFeaturesEpoch - The monotonically increasing epoch for the finalized features information. Valid values are >= 0. A value of -1 is special and represents unknown epoch.
FinalizedFeatures - List of cluster-wide finalized features. The information is valid only if FinalizedFeaturesEpoch >= 0.
The semantic of FinalizedFeatures will be changed slightly to not include any finalized feature version if the FinalizedFeaturesEpoch is -1.
When the controller handles RaftClient.Listener#handleLoadSnapshot if the checkpoint id has an epoch of 0 and a base offset of 0, the controller will consider these records as the bootstrapping records. The controller will rewrite bootstrap records to the log if they haven't been successfully written in the past. If the controller doesn't load a checkpoint at epoch 0 and offset 0, the controller will load the bootstrap.checkpoint and rewrite the bootstrapping record to the cluster metadata partition if they haven't been successfully written in the past.
Both the Kafka broker and controller nodes will delete the bootstrap.checkpoint file from the metadata log dir if the node has been asked to load a snapshot that contains at least one metadata record.
The kafka-storage format command is responsible for creating the zero checkpoint (00000000000000000000-0000000000.checkpoint). The metadata that is currently written to the bootstrap.checkpoint will instead be written to the zero checkpoint.
Formatting will fail if the metadata log directory already contains the bootstrap.checkpoint or the zero checkpoint. Formatting will be skip if the metadata log dir already contains the bootstrap.checkpoint or the zero checkpoint, and the --ignore-formatted flag is provided.
To be compatible with previous bootstrapping of Kafka, at controller activation the controller can be in the following states:
This feature will be tested using Java JUnit tests and system tests.
Not applicable.