0Pricing
Elixir & Phoenix: Scalable Backend Development · 课时

高级监督策略

探索 `:one_for_one` 之外的不同监督策略,并设计健壮且具备容错能力的系统。

高级监督策略 是 CoddyKit 上的免费 Elixir & Phoenix: Scalable Backend Development 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Elixir & Phoenix: Scalable Backend Development 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Elixir & Phoenix: Scalable Backend Development 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Beyond Basic Supervision

In Elixir, supervisors are key to building fault-tolerant applications. You've likely encountered the default :one_for_one strategy.

This strategy restarts only the crashing child process. But what if processes are tightly coupled or have dependencies?

Elixir offers more advanced supervision strategies to handle complex failure scenarios, ensuring your application remains robust.

Strategy: One For All

The :one_for_all strategy is powerful for tightly coupled processes.

  • What it does: If any child process dies, all other child processes are terminated and then all children are restarted.
  • When to use it: Ideal when child processes are interdependent and cannot function correctly if one of them fails. Think of a group of processes that must always be in a consistent state together.

It ensures the entire group is always fresh and consistent after a failure.

One For All in Action

Let's see :one_for_all with two workers. If Worker 1 crashes, both Worker 1 and Worker 2 will restart.

Notice the output showing both workers terminating and then starting again.

defmodule Main do
  defmodule MyWorker do
    use GenServer

    def start_link(name) do
      GenServer.start_link(__MODULE__, nil, name: name)
    end

    def init(_) do
      IO.puts("Worker #{inspect(self())} started!")
      {:ok, %{}}
    end

    def handle_call(:crash, _from, state) do
      IO.puts("Worker #{inspect(self())} crashing!")
      exit(:boom)
      {:reply, :crashed, state}
    end

    def handle_call(:status, _from, state) do
      {:reply, :ok, state}
    end

    def terminate(reason, _state) do
      IO.puts("Worker #{inspect(self())} terminating due to #{inspect(reason)}!")
    end
  end

  def main() do
    children = [
      {MyWorker, :worker1},
      {MyWorker, :worker2}
    ]

    opts = [strategy: :one_for_all, name: MyOFA_Supervisor]
    {:ok, _pid} = Supervisor.start_link(children, opts)

    Process.sleep(100)

    IO.puts("\n--- Initial state ---")
    GenServer.call(:worker1, :status, 100)
    GenServer.call(:worker2, :status, 100)

    IO.puts("\n--- Crashing Worker 1 ---")
    try do
      GenServer.call(:worker1, :crash, 100)
    rescue
      _ -> IO.puts("Worker 1 process exited.")
    end

    Process.sleep(500)

    IO.puts("\n--- After crash and restart ---")
    GenServer.call(:worker1, :status, 100)
    GenServer.call(:worker2, :status, 100)

    :ok
  end
end

Main.main()

Strategy: Rest For One

The :rest_for_one strategy is useful for processes with a linear dependency chain.

  • What it does: If a child process dies, it and all subsequent (later started) child processes are terminated and then restarted. Processes started before the crashing child are left untouched.
  • When to use it: Use this when processes have a cascading dependency. For example, if Process C depends on Process B, and Process B depends on Process A. If B crashes, C must also restart, but A is fine.

It's a more surgical restart than :one_for_all.

Rest For One in Action

Here, we have three workers. If Worker 2 crashes, Worker 2 and Worker 3 will restart, but Worker 1 will remain unaffected.

Observe how only the affected and dependent processes are restarted.

defmodule Main do
  defmodule MyWorker do
    use GenServer

    def start_link(name) do
      GenServer.start_link(__MODULE__, nil, name: name)
    end

    def init(_) do
      IO.puts("Worker #{inspect(self())} started!")
      {:ok, %{}}
    end

    def handle_call(:crash, _from, state) do
      IO.puts("Worker #{inspect(self())} crashing!")
      exit(:boom)
      {:reply, :crashed, state}
    end

    def handle_call(:status, _from, state) do
      {:reply, :ok, state}
    end

    def terminate(reason, _state) do
      IO.puts("Worker #{inspect(self())} terminating due to #{inspect(reason)}!")
    end
  end

  def main() do
    children = [
      {MyWorker, :worker1},
      {MyWorker, :worker2},
      {MyWorker, :worker3}
    ]

    opts = [strategy: :rest_for_one, name: MyRFO_Supervisor]
    {:ok, _pid} = Supervisor.start_link(children, opts)

    Process.sleep(100)

    IO.puts("\n--- Initial state ---")
    GenServer.call(:worker1, :status, 100)
    GenServer.call(:worker2, :status, 100)
    GenServer.call(:worker3, :status, 100)

    IO.puts("\n--- Crashing Worker 2 ---")
    try do
      GenServer.call(:worker2, :crash, 100)
    rescue
      _ -> IO.puts("Worker 2 process exited.")
    end

    Process.sleep(500)

    IO.puts("\n--- After crash and restart ---")
    GenServer.call(:worker1, :status, 100)
    GenServer.call(:worker2, :status, 100)
    GenServer.call(:worker3, :status, 100)

    :ok
  end
end

Main.main()

Supervisor Restart Intensity

Supervisors also come with options to prevent endless restart loops, which can consume system resources.

  • :max_restarts: The maximum number of times a child process (or group of processes, depending on strategy) can be restarted within a given time frame.
  • :max_seconds: The time frame (in seconds) during which :max_restarts is counted.

If the restart count exceeds :max_restarts within :max_seconds, the supervisor itself will terminate, potentially crashing its own supervisor.

Restart Intensity Example

Here, we set max_restarts: 2 and max_seconds: 5. If Worker 1 crashes more than twice within 5 seconds, the supervisor will give up and crash itself.

Run this code multiple times and observe the supervisor terminating.

defmodule Main do
  defmodule MyWorker do
    use GenServer

    def start_link(name) do
      GenServer.start_link(__MODULE__, nil, name: name)
    end

    def init(_) do
      IO.puts("Worker #{inspect(self())} started!")
      {:ok, %{}}
    end

    def handle_call(:crash, _from, state) do
      IO.puts("Worker #{inspect(self())} crashing!")
      exit(:boom)
      {:reply, :crashed, state}
    end

    def handle_call(:status, _from, state) do
      {:reply, :ok, state}
    end

    def terminate(reason, _state) do
      IO.puts("Worker #{inspect(self())} terminating due to #{inspect(reason)}!")
    end
  end

  def main() do
    children = [
      {MyWorker, :worker1}
    ]

    opts = [strategy: :one_for_one, name: MyIntensitySupervisor,
            max_restarts: 2, max_seconds: 5]
    {:ok, sup_pid} = Supervisor.start_link(children, opts)

    Process.sleep(100)

    IO.puts("\n--- Crashing Worker 1 repeatedly ---")
    Enum.each(1..3, fn i ->
      IO.puts("Attempt #{i}:")
      try do
        GenServer.call(:worker1, :crash, 100)
      rescue
        _ -> IO.puts("Worker 1 process exited.")
      end
      Process.sleep(100) # Short delay between crashes
    end)

    Process.sleep(1000) # Give supervisor time to react

    IO.puts("\n--- Supervisor status ---")
    if Process.is_alive(sup_pid) do
      IO.puts("Supervisor is still alive.")
    else
      IO.puts("Supervisor has terminated due to excessive restarts.")
    end

    :ok
  end
end

Main.main()

Custom Supervision Strategies

While :one_for_one, :one_for_all, and :rest_for_one cover most cases, Elixir allows for custom supervision strategies.

  • You can implement the Supervisor behaviour yourself.
  • This involves defining init/1 and handling restart logic based on the :which_child argument in handle_call/3.

This is an advanced topic, typically needed for highly specific and complex restart policies not covered by the built-in strategies.

When to Use Which Strategy?

Choosing the right strategy is crucial for your application's resilience.

  • :one_for_one: Default, independent processes. Most common.
  • :one_for_all: Tightly coupled processes where consistency is paramount.
  • :rest_for_one: Processes with linear, cascading dependencies.
  • Custom: Rare, for unique restart requirements.

Always consider the relationships and dependencies between your processes when designing your supervision tree.

Advanced Supervisor Quiz

A critical process P1 provides a service that P2 and P3 absolutely rely on. If P1 crashes, P2 and P3 cannot function correctly and also need to be restarted to ensure data consistency.

Which supervision strategy is best suited for a supervisor overseeing P1, P2, and P3 in this scenario?

Recap: Robust Supervision

You've now explored advanced Elixir supervision strategies that go beyond the default :one_for_one.

  • :one_for_all restarts all children if any child fails.
  • :rest_for_one restarts the failing child and all subsequent children.
  • You also learned about max_restarts and max_seconds to control restart intensity.

These tools allow you to design highly resilient, fault-tolerant applications by precisely controlling how your system reacts to process failures.

常见问题解答

「高级监督策略」课时是免费的吗?

是的 — 「高级监督策略」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Elixir & Phoenix: Scalable Backend Development 课程的其余内容,请升级到 CoddyKit PRO。 Elixir & Phoenix: Scalable Backend Development 课程共包含 4 节课。

「高级监督策略」这节课中我会学到什么?

探索 `:one_for_one` 之外的不同监督策略,并设计健壮且具备容错能力的系统。 你通过在浏览器中直接运行的动手代码来练习 Elixir & Phoenix: Scalable Backend Development,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Elixir & Phoenix: Scalable Backend Development 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Elixir & Phoenix: Scalable Backend Development 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。

「高级监督策略」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Elixir & Phoenix: Scalable Backend Development 课中编写并运行代码吗?

能。每节 Elixir & Phoenix: Scalable Backend Development 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 分布式 Elixir 与集群
  2. 高级监督策略
  3. 动态监督者与注册表
  4. GenStage 与背压流水线
← 返回 Elixir & Phoenix: Scalable Backend Development