Ingot writes every object body to a local spool before uploading it and never removes a blob once it is committed, so local disk grows with every byte ever written: deletes free nothing locally, and a multipart upload holds the whole object on disk. At sustained multi-GB/s ingest of large blobs the disk fills in hours, and a full disk fails every write.
Bound the spool by configuration: free a deleted blob's local copy when its release runs, drop multipart parts once the provider holds them, and add a byte budget with an eviction sweeper (reads of evicted blobs already fall back to the network), plus an optional write-through mode and spool metrics. Done when spool usage stays within the configured budget under sustained ingest, deletes free local disk, and evicted objects read back byte-exact. The design, work items, safety rules and tests are in the attached document "Bounding ingot's local spool: design and work plan"; its one open decision, whether a deleted object's encrypted copy must stay on local disk, needs sign-off from the encryption design's owner.
See also fil-forge/piri#44
Ingot writes every object body to a local spool before uploading it and never removes a blob once it is committed, so local disk grows with every byte ever written: deletes free nothing locally, and a multipart upload holds the whole object on disk. At sustained multi-GB/s ingest of large blobs the disk fills in hours, and a full disk fails every write.
Bound the spool by configuration: free a deleted blob's local copy when its release runs, drop multipart parts once the provider holds them, and add a byte budget with an eviction sweeper (reads of evicted blobs already fall back to the network), plus an optional write-through mode and spool metrics. Done when spool usage stays within the configured budget under sustained ingest, deletes free local disk, and evicted objects read back byte-exact. The design, work items, safety rules and tests are in the attached document "Bounding ingot's local spool: design and work plan"; its one open decision, whether a deleted object's encrypted copy must stay on local disk, needs sign-off from the encryption design's owner.
See also fil-forge/piri#44