pnclPULSEGet API access

DROP ALERT NOTES

One stream, one reader: designing a standby that takes over

A second connection with the same key closes the first, so redundancy means failover, not parallel readers. A standby design that actually works.

The first instinct for a reliable alert pipeline is to run two readers, and on this stream that instinct backfires: each account holds one connection per stream, and a second live connection with the same key closes the first, as the SSE setup guide documents, checked 2026-10-06. Two readers do not double your reliability; they hand you a fight over the socket. The working design is a primary and a standby that takes over.

Primary and standby, not primary and rival

The shape is active-passive. One process holds the stream and works. The standby runs warm: same code, same configuration, no connection. It watches the primary's heartbeat, and when the heartbeat stops for longer than your tolerance, it opens the stream and becomes the primary. The old process, if it ever wakes up, finds its connection closed by the takeover and exits.

This is where the one-connection rule becomes a feature: the takeover needs no negotiation protocol, because the stream itself evicts the stale reader.

The takeover needs shared state

A standby that takes over cold re-alerts everything the primary already handled. The dedupe store and the last-processed alert time must live somewhere both processes can read, a small shared database or file mount, written by whichever process currently owns the stream. The dedupe guide covers a store that survives restarts; the failover version of the same advice is that it must survive a change of owner too.

Gaps during the switch are still gaps. The documentation promises no resume point, so anything that fell while neither process was connected is missed, and the recovery path is the REST drops endpoint's recent-drops window, per the setup guide.

How fast should the standby take over

The takeover delay is a trade between false switches and missed alerts. Too short, and a slow garbage-collection pause flaps ownership back and forth. Too long, and every real failure costs minutes of silence. Start with three missed heartbeats, and let the setup guide's habits, the health endpoint and the silence check, tell the standby the difference between a dead primary and a quiet market.

One connection, one owner, one warm standby. The stream enforces the single reader; your heartbeat decides who it is.