Every cell has one current owner and an ownership epoch. Recovery advances the epoch, rebuilds state from durable records and refuses writes from a stale owner.
Lose a node, keep every cell
When a node stops renewing its lease, a live peer can claim its cells at a new ownership epoch. State is recovered from replicated records, while writes from the stale epoch are refused. Try it.
node-alease live
node-blease live
node-clease live
cellre-homed at next epochreleased by expired lease
$peren status fleet.toml
t+0ready3 nodes · 46 cells · bucket reachable
waitpress SIGKILL node-b to inject the fault
pending–duplicate writes
pending–corrupted databases
pending–cells recovered within the lease TTL
Illustrates the chaos-harness scenario: SIGKILL a live owner, then watch recovery within the lease TTL.
Ownership checks
Tests cover ownership, fencing, release and recovery paths so a stale owner cannot keep writing after handoff.
The same rules are documented in the durability and recovery guides.
Runtime conformance
Runtime globals, modules, bindings and unsupported behaviours are exercised against the documented contract.
The compatibility matrix names the APIs Peren intends applications to rely on.
Example verification
The example suite validates each fleet file, starts the Worker and checks that the public socket answers.
External-provider variants are validated separately from local runnable examples.
The invariants
No two nodes ever own the same cell at the same epoch.
A node that has lost ownership can never write to that cell.
A cell whose owner is gone becomes claimable once the lease TTL passes.
A taken-over cell contains every write that was durably confirmed.
What the harness reports
Recovery runs report request and error counts, timing data and PRAGMA integrity_check results for the resulting database files. The docs keep operational limits separate from behaviours that applications can depend on.