Block, drop, or spill — when_full=block paired with a synchronous logger
When the backend stalls, the agent's in-memory queue fills and it must block, drop, or spill to disk — and when_full=block paired with a synchronous logger is the single most common way a logging-pipeline outage takes the application down with it.
The agent ships at-least-once over a pipe — but ships them WHERE? The backend at the far end can stall, and when it does the agent has exactly three choices, only one of which keeps the application alive.
Scene 03
Block, drop, or spill
- Watch
- Try it
- Predict
- Capture
Backend healthy. Lines arrive at the buffer, fill climbs, a batch ships, fill drains — and the cycle repeats. The app's thread-pool meter is calm; the disk-spill overlay on the right is dim, unused. Get a feel for the steady state before we break the backend.
Highlighted lines are the ones running in the diagram right now.
def write_log(line):# request-handler thread is the callerif sync_logger:agent.enqueue(line) # blocks if queue fullreturn# async logger: hand to in-process queue, return nowinproc_queue.put_nowait(line)
def enqueue(line):if len(queue.mem) < queue.mem.capacity:queue.mem.append(line) # 3200 events defaultreturn# buffer is full — backend is not draining fast enoughif when_full == 'block':wait_until_room() # caller's thread parkselif when_full == 'drop':metrics.lines_lost += 1 # silently discardedelif when_full == 'spill':spill_to_disk(line) # queue.disk / WAL
def spill_to_disk(line):# queue.disk = 10 GB on Filebeat, storage.type=filesystem# on Fluent Bit, WAL on Promtail, disk buffer on Vectordisk_buffer.append(line)def replay_loop(): # runs when backend recoverswhile disk_buffer and backend.healthy():batch = disk_buffer.read_batch()backend.send(batch) # at-least-oncedisk_buffer.advance(batch)
Where this sits in Build a distributed logging stack (ELK / Loki)
Scene 03 of 12. When the backend stalls, the agent must block, drop, or spill to disk — and `when_full=block` plus a synchronous logger is how a logging outage takes the application down with it.
Up next. The agent survived the backend outage by spilling to disk — but every line it spilled was still just a string. Before we ask the backend to index this stuff, we have to decide whether a log line is text or a typed record.
All 12 scenes in Build a distributed logging stack (ELK / Loki) · Every curriculum