gitcaskDocsGitHub

Architecture

Each repository is a write-ahead log in the bucket; every instance is a cache or a reader of that log.

The bucket layout

Logs, packs and checkpoints are immutable. Nothing is visible before the manifest's compare-and-swap.

repos/<owner>/<repo>/
manifest.pblog/wal/checkpoints/leases/cache/lfs/
The repository prefix in the bucket holds manifest.pb, the commit point, beside log, wal, checkpoints, leases, cache and lfs.
manifest.pb

Tiny, CAS-rewritten: head_seq, the live pack set, log segments, the checkpoint pointer. The linearization point.

log/<first_seq>.pb

Immutable PUSH, REF_UPDATE and COMPACT entries. One small object per publish batch.

wal/<checksum>.pack/.idx/.rev/.bitmap/.commit-graph

Immutable packs, content-addressed by pack checksum, plus the side-files a reader needs.

checkpoints/<seq>/

Folded state at seq: live pack set and full RefSnapshot.

leases/<name>.pb

CAS lease with TTL heartbeat. The only cross-instance mutex.

cache/api/v1/, cache/archive/v1/

Shared cache of immutable API answers and archives.

lfs/objects/<aa>/<bb>/<oid>

LFS objects, sha256-addressed and immutable.

Write path

A push is acknowledged only after the bucket acknowledged it. Concurrent writers race on one CAS.

git push
index-pack
PUT pack ∥ idx ∥ log
CAS manifest.pb
ok
PUT pending/<o>/<r>
412
refetch the manifest
revalidate old values
retry with jittered backoff
A push is indexed, its pack, index and log entry are uploaded in parallel, the manifest is swapped, then ok is returned and a pending marker written. On a 412 the writer refetches, revalidates and retries.

A ref that moved meanwhile is answered ng. Concurrent pushes on one instance share one CAS within wal.batch_window (default 5ms) per repository.

Read path

Every read starts with a conditional GET of the manifest, so every instance is as fresh as a fetch.

GET manifest.pb, If-None-Match
304: serve the local copy
GET manifest.pb, If-None-Match
200: apply new entries, then serve
A conditional GET of manifest.pb answers 304 and the local copy is served, or 200 and new entries are applied first.
Sync levelBringsUsed by
RefsCheckpoint RefSnapshotand every log entry's ref transaction. No packs.info/refs, ls-refs, API refs, resolve and overview
FullRefs and every live pack, downloaded locally in parallel stripesupload-pack, receive-pack, API object endpoints, compaction

Checkpoints and compaction

A checkpoint folds the log, so a cold start reads a snapshot and the tail, never the whole log. Compaction folds fresh packs geometrically under a lease, and needs at least two of them.

KeyFires whenDefault
wal.snapshot_every_entriesThis many log entries since the last checkpoint256
wal.checkpoint_intervalThe last checkpoint is this old1h
wal.checkpoint_tail_bytesThe log tail after it exceeds this8MiB
compaction.trigger_packsThis many tier-0 packs exist16
compaction.trigger_bytesTier-0 pack bytes exceed this1GiB
compaction.retention_supersededSuperseded packs, folded logs and old checkpoints are kept this long before bucket GC7d

The maintainer

A push leaves a marker; the maintainer visits only marked repositories and does one bounded unit of the most important missing work at a time.

PUT pending/<o>/<r>
LIST pending/
run units
conditional DELETE of the marker
checkpoint
compaction
rev-index
fsck audit
bucket GC
A push writes a pending marker, the maintainer lists pending markers, runs units for each marked repository, and deletes the marker conditionally. Units run in priority order: checkpoint, compaction, rev-index, fsck audit, bucket GC.

Everything it produces is a pure function of config and WAL state, so a deleted artefact is rebuilt identically. A repository nobody pushes to is never visited; Cost model has the numbers.

Recovery

Disk and memory are caches. Wipe every instance and you lose only warmth.

every instance wiped
new instance
manifest + checkpoint + tail
refs in < 1 s
Every instance is wiped; a new instance reads the manifest, checkpoint and log tail and serves refs in under a second.

Packs download on the first object request.