Summary
graceful_period is already part of the Clio configuration, while the example config still notes that graceful shutdown is not fully implemented.
It would be useful to make this setting define the actual upper bound for an orderly Clio shutdown.
Motivation
As Clio deployments become more automated, predictable shutdown behavior becomes important for rolling upgrades, instance replacement, and container orchestration.
Operators should be able to coordinate Clio's internal shutdown window with systemd, Docker, Kubernetes, or other process supervisors without relying on an oversized external timeout.
More importantly, a process receiving SIGTERM should have a clear contract: stop taking new work, allow in-flight work to drain, then exit within a known amount of time.
That makes deployments safer and avoids turning routine restarts into abrupt connection or request termination.
Solution
Use graceful_period as the shutdown deadline.
When shutdown starts, Clio should stop accepting new work and begin draining active requests and background activity. It can exit as soon as everything is drained, or continue waiting until graceful_period expires.
Once the deadline is reached, shutdown should proceed rather than waiting indefinitely.
This would give operators a simple and predictable contract:
SIGTERM -> stop accepting new work -> drain existing work -> exit when drained or graceful_period expires
Paths Not Taken
This can be handled partially by configuring a large timeout in systemd or the container runtime, but an external timeout only controls when the process is killed. It does not define how Clio should behave during that window.
A fixed internal shutdown timeout would also solve part of the problem, but graceful_period already exists and is the natural operator-facing control for this behavior.
Summary
graceful_periodis already part of the Clio configuration, while the example config still notes that graceful shutdown is not fully implemented.It would be useful to make this setting define the actual upper bound for an orderly Clio shutdown.
Motivation
As Clio deployments become more automated, predictable shutdown behavior becomes important for rolling upgrades, instance replacement, and container orchestration.
Operators should be able to coordinate Clio's internal shutdown window with systemd, Docker, Kubernetes, or other process supervisors without relying on an oversized external timeout.
More importantly, a process receiving
SIGTERMshould have a clear contract: stop taking new work, allow in-flight work to drain, then exit within a known amount of time.That makes deployments safer and avoids turning routine restarts into abrupt connection or request termination.
Solution
Use graceful_period as the shutdown deadline.
When shutdown starts, Clio should stop accepting new work and begin draining active requests and background activity. It can exit as soon as everything is drained, or continue waiting until graceful_period expires.
Once the deadline is reached, shutdown should proceed rather than waiting indefinitely.
This would give operators a simple and predictable contract:
SIGTERM -> stop accepting new work -> drain existing work -> exit when drained or graceful_period expiresPaths Not Taken
This can be handled partially by configuring a large timeout in systemd or the container runtime, but an external timeout only controls when the process is killed. It does not define how Clio should behave during that window.
A fixed internal shutdown timeout would also solve part of the problem, but
graceful_periodalready exists and is the natural operator-facing control for this behavior.