43425497

By: Michael Lynch <git@mtlynch.io>

Document the shutdown budget contract in DESIGN.md

Adds the shutdown budget contract to the Fly.io hosting rationale:
kill_timeout must exceed drain-timeout plus shutdown-sync-timeout, and
the app must exit 0 on every signal path, or Litestream skips its final
sync and discards unreplicated writes. This constraint now lives in the
design doc rather than only in commit messages and code comments, per
the project's convention of not burying critical maintenance
constraints where they'll be missed.

Depends on split/litestream-shutdown-budget (raises shutdown-sync-timeout
and kill_timeout) and split/litestream-graceful-shutdown (makes exit 0 on
every signal path true) both landing on master first -- this paragraph
describes their combined behavior and is not accurate before either
lands.

Co-Authored-By: Claude <noreply@anthropic.com>

Suite timing

Time to Start Worker time Duration Time to finish Idle
Config 34s 4s 4s 38s 34s
Eval 1m48s 1m34s 1m34s 3m22s 1m09s
Build 3m13s 8m05s 6m27s 9m41s 4m02s
Suite 34s 9m44s 9m06s 9m41s 5m46s

Timeline

0s2m2m20s2m40s3m3m20s7m20s7m40s8m8m20s8m40s9m9m40s