Replicationmedium0-2 years

Replication factor 3, `acks=all`. A team wants writes to survive one broker failing with no data loss and no downtime. What else has to be set, and why does `acks=all` alone not guarantee it?

acks=all means the leader waits for every replica currently in the in-sync replica set (ISR) to have the record before acknowledging it — but the ISR can shrink to just the leader itself if followers fall behind, and at that point acks=all is acknowledging a write that only lives on one broker. min.insync.replicas is the floor: set to 2 on a replication-factor-3 topic, a write only succeeds if the leader plus at least one follower have it, so the topic keeps accepting writes with one broker down, and a leader failure can never lose an acknowledged record. acks=all without min.insync.replicas=2 can still silently degrade to single-broker durability.

The lesson behind it →