Distributed Locks with Redis

  使用 Redis 的分布式锁

A distributed lock pattern with Redis
使用 Redis 的分布式锁模式

Distributed locks are a very useful primitive in many environments where different processes must operate with shared resources in a mutually exclusive way.

There are a number of libraries and blog posts describing how to implement a DLM (Distributed Lock Manager) with Redis, but every library uses a different approach, and many use a simple approach with lower guarantees compared to what can be achieved with slightly more complex designs.
许多的库和博客描述如何使用 Redis 来实现一个 DLM(分布式锁管理),但每个库都采用不同的方法,并且有很多都是用了一个简单的方法,而这种方法相较于稍加复杂的设计来说,不太敢担保能实现(DLM)。

This page describes a more canonical algorithm to implement distributed locks with Redis.
本页描述了使用 Redis 实现分布式锁的一个更权威的算法。

We propose an algorithm, called Redlock, which implements a DLM which we believe to be safer than the vanilla single instance approach.

We hope that the community will analyze it, provide feedback, and use it as a starting point for the implementations or more complex or alternative designs.


Before describing the algorithm, here are a few links to implementations already available that can be used for reference.

Safety and Liveness Guarantees


We are going to model our design with just three properties that, from our point of view, are the minimum guarantees needed to use distributed locks in an effective way.

  1. Safety property: Mutual exclusion. At any given moment, only one client can hold a lock.

  2. Liveness property A: Deadlock free. Eventually it is always possible to acquire a lock, even if the client that locked a resource crashes or gets partitioned.

  3. Liveness property B: Fault tolerance. As long as the majority[^majority] of Redis nodes are up, clients are able to acquire and release locks.
    活跃属性B:容错。只要大多数 Redis 节点正常运行,客户端就可以获取和释放锁。

Why Failover-based Implementations Are Not Enough


To understand what we want to improve, let’s analyze the current state of affairs with most Redis-based distributed lock libraries.
了解我们想要改进的地方,让我们一起来分析一下大部分基于 Redis 的分布式锁库的当前状态。

The simplest way to use Redis to lock a resource is to create a key in an instance.
使用 Redis 锁定资源的最简单方法是在一个实例中创建 Key 。

The key is usually created with a limited time to live, using the Redis expires feature, so that eventually it will get released (property 2 in our list).
通常使用 Redis 过期功能(类似于 TTL)创建的 Key 具有有限的生存时间,因此最终它会被释放(我们列表中的属性 2)。

When the client needs to release the resource, it deletes the key.
当客户端需要释放资源时,它会删除该 Key 。

Superficially this works well, but there is a problem: this is a single point of failure in our architecture.

What happens if the Redis master goes down? Well, let’s add a replica!
如果 Redis 主节点挂掉了会发生什么?好吧,让我们加上一个副本。

And use it if the master is unavailable. This is unfortunately not viable.

By doing so we can’t implement our safety property of mutual exclusion, because Redis replication is asynchronous.
通过这样做,我们无法实现我们互斥的安全属性,因为 Redis 复制是异步的。

There is a race condition with this model:

  1. Client A acquires the lock in the master.
    客户端 A 在主节点中获得锁

  2. The master crashes before the write to the key is transmitted to the replica.
    在对 Key 的写入传到副本之前,主节点崩溃了。

  3. The replica gets promoted to master.

  4. Client B acquires the lock to the same resource A already holds a lock for. SAFETY VIOLATION!
    客户端 B 获取了 A 已经持有的同一资源的锁。安全违规!

Sometimes it is perfectly fine that, under special circumstances, for example during a failure, multiple clients can hold the lock at the same time.

If this is the case, you can use your replication based solution. Otherwise we suggest to implement the solution described in this document.

Correct Implementation with a Single Instance


Before trying to overcome the limitation of the single instance setup described above, let’s check how to do it correctly in this simple case,

since this is actually a viable solution in applications where a race condition from time to time is acceptable,

and because locking into a single instance is the foundation we’ll use for the distributed algorithm described here.

To acquire the lock, the way to go is the following:

SET resource_name my_random_value NX PX 30000

The command will set the key only if it does not already exist (NX option), with an expire of 30000 milliseconds (PX option).
该命令只有在 Key 不存在时(NX选项)才会设置 Key ,并设置过期时间为30000毫秒(PX选项)。

The key is set to a value “my_random_value”. This value must be unique across all clients and all lock requests.
这个 Key 设置的值为“my_random_value”。这个值在所有客户端和所有锁定请求中必须是唯一的。

Basically the random value is used in order to release the lock in a safe way, with a script that tells Redis: remove the key only if it exists and the value stored at the key is exactly the one I expect to be.
基本上,这个随机值被用来以安全的方式释放锁,并通过一个脚本告诉 Redis: 仅当 Key 存在并且存储在 Key 中的值正是我期望的值时才删除该 Key 。

This is accomplished by the following Lua script:
通过以下 Lua 脚本来实现:

if redis.call("get",KEYS[1]) == ARGV[1] then
    return redis.call("del",KEYS[1])
    return 0

This is important in order to avoid removing a lock that was created by another client.
For example a client may acquire the lock, get blocked performing some operation for longer than the lock validity time (the time at which the key will expire), and later remove the lock, that was already acquired by some other client.
例如一个客户端可能会获取锁,在执行某些操作时被阻止,时间长于锁有效期( Key 过期时间),然后删除已被其他客户端获取的锁。
Using just DEL is not safe as a client may remove another client's lock. With the above script instead every lock is “signed” with a random string, so the lock will be removed only if it is still the one that was set by the client trying to remove it.
仅使用 DEL 并不安全,因为客户端可能会删除另一个客户端的锁。使用上面的脚本,每个锁都用随机字符串“签名”,因此,除非它仍然是由试图删除它的客户端所设置的锁时,该锁才会被删除。

What should this random string be? We assume it’s 20 bytes from /dev/urandom, but you can find cheaper ways to make it unique enough for your tasks.
For example a safe pick is to seed RC4 with /dev/urandom, and generate a pseudo random stream from that.
例如,一个安全的选择是使用 /dev/urandom 为 RC4 播种,并从中生成伪随机流。
A simpler solution is to use a UNIX timestamp with microsecond precision, concatenating the timestamp with a client ID. It is not as safe, but probably sufficient for most environments.
一个更简单的解决方案是使用微秒精度的 UNIX 时间辍,将时间戳与客户端 ID 连接起来。它不太安全,但对于大多数环境来说可能足够了。

The "lock validity time" is the time we use as the key's time to live.
“锁有效期”是我们用作 Key 生存时间的时间。
It is both the auto release time, and the time the client has in order to perform the operation required before another client may be able to acquire the lock again, without technically violating the mutual exclusion guarantee, which is only limited to a given window of time from the moment the lock is acquired.

So now we have a good way to acquire and release the lock. With this system, reasoning about a non-distributed system composed of a single, always available, instance, is safe. Let’s extend the concept to a distributed system where we don’t have such guarantees.

The Redlock Algorithm


In the distributed version of the algorithm we assume we have N Redis masters.
在算法的分布式版本中,我们假设我们有N个 Redis 主节点

Those nodes are totally independent, so we don’t use replication or any other implicit coordination system.
We already described how to acquire and release the lock safely in a single instance.
We take for granted that the algorithm will use this method to acquire and release the lock in a single instance.
In our examples we set N=5, which is a reasonable value, so we need to run 5 Redis masters on different computers or virtual machines in order to ensure that they’ll fail in a mostly independent way.
在我们的示例中,我们设置 N=5,这是一个合理的值,所以我们需要在不同的计算机或虚拟机中运行5个 Redis 主节点,以确保他们将以一种基本独立的方式失败。

In order to acquire the lock, the client performs the following operations:

  1. It gets the current time in milliseconds.

  2. It tries to acquire the lock in all the N instances sequentially, using the same key name and random value in all the instances.
    尝试依次获取N个实例中所有的锁,在所有实例中使用相同的 Key 名称和随机值。
    During step 2, when setting the lock in each instance, the client uses a timeout which is small compared to the total lock auto-release time in order to acquire it.
    For example if the auto-release time is 10 seconds, the timeout could be in the ~ 5-50 milliseconds range.
    This prevents the client from remaining blocked for a long time trying to talk with a Redis node which is down: if an instance is not available, we should try to talk with the next instance ASAP.
    这可以防止客户端在尝试与已关闭的 Redis 节点通信时 长时间处于阻塞状态:如果某个实例不可用,我们应该尽快尝试与下一个实例对话。

  1. The client computes how much time elapsed in order to acquire the lock, by subtracting from the current time the timestamp obtained in step 1.
    客户端通过从当前时间减去步骤 1 中获得的时间戳来计算获取锁所花费的时间。
    If and only if the client was able to acquire the lock in the majority of the instances (at least 3), and the total time elapsed to acquire the lock is less than lock validity time, the lock is considered to be acquired.

  2. If the lock was acquired, its validity time is considered to be the initial validity time minus the time elapsed, as computed in step 3.
    如果获取了锁,则其有效时间被视为初始有效时间减去经过的时间(如步骤 3 中计算的那样)。

  3. If the client failed to acquire the lock for some reason (either it was not able to lock N/2+1 instances or the validity time is negative), it will try to unlock all the instances (even the instances it believed it was not able to lock).
    如果客户端由于一些原因(要么无法锁定 N/2+1 个实例,要么有效时间为负)获取锁失败,它将尝试解锁所有实例(甚至它认为无法锁定的实例能够锁定)。

Is the Algorithm Asynchronous?


The algorithm relies on the assumption that while there is no synchronized clock across the processes, the local time in every process updates at approximately at the same rate, with a small margin of error compared to the auto-release time of the lock.
This assumption closely resembles a real-world computer: every computer has a local clock and we can usually rely on different computers to have a clock drift which is small.
At this point we need to better specify our mutual exclusion rule: it is guaranteed only as long as the client holding the lock terminates its work within the lock validity time (as obtained in step 3), minus some time (just a few milliseconds in order to compensate for clock drift between processes).
此刻,我们需要更好地指定我们的互斥规则:只有持有锁的客户端在锁有效时间内(如步骤 3 中获得的)终止其工作,减去一些时间(仅几毫秒,以补偿进程之间的时钟漂移),才能保证它。

This paper contains more information about similar systems requiring a bound clock drift: Leases: an efficient fault-tolerant mechanism for distributed file cache consistency.

Retry on Failure


When a client is unable to acquire the lock, it should try again after a random delay in order to try to desynchronize multiple clients trying to acquire the lock for the same resource at the same time (this may result in a split brain condition where nobody wins).
Also the faster a client tries to acquire the lock in the majority of Redis instances, the smaller the window for a split brain condition (and the need for a retry), so ideally the client should try to send the SET commands to the N instances at the same time using multiplexing.
另外,客户端在大多数 Redis 实例中尝试获取锁的速度越快,则脑裂情况的窗口就越小(并且需要重试),因此理想情况下,客户端应尝试使用多路复用同时将 SET 命令发送到 N 个实例。

It is worth stressing how important it is for clients that fail to acquire the majority of locks, to release the (partially) acquired locks ASAP,
so that there is no need to wait for key expiry in order for the lock to be acquired again (however if a network partition happens and the client is no longer able to communicate with the Redis instances, there is an availability penalty to pay as it waits for key expiration).
这样就不需要等待 Key 过期了再次获取锁(然而,如果发生网络分区并且客户端不再能够与 Redis 实例通信,则在等待 Key 过期时会产生可用性损失)。

Releasing the Lock


Releasing the lock is simple, and can be performed whether or not the client believes it was able to successfully lock a given instance.

Safety Arguments


Is the algorithm safe? Let's examine what happens in different scenarios.

To start let’s assume that a client is able to acquire the lock in the majority of instances.
All the instances will contain a key with the same time to live. However, the key was set at different times, so the keys will also expire at different times.
所有实例将包含一个有着相同存活时间的 Key 。但是, Key 是在不同时间设置的,因此 Key 也会在不同时间过期。
But if the first key was set at worst at time T1 (the time we sample before contacting the first server) and the last key was set at worst at time T2 (the time we obtained the reply from the last server), we are sure that the first key to expire in the set will exist for at least MIN_VALIDITY=TTL-(T2-T1)-CLOCK_DRIFT.
但如果第一个 Key 在 T1(我们在联系第一台服务器之前采样的时间) 时刻被设置为最差,最后一个 Key 在 T2(我们从最后一个服务器获得回复的时间)时刻被设置为最差,那么我们确信集合中第一个过期的 Key 将至少存在 MIN_VALIDITY=TTL-(T2-T1)-CLOCK_DRIFT
All the other keys will expire later, so we are sure that the keys will be simultaneously set for at least this time.
所有其他 Key 稍后都会过期,因此我们确信至少这一次将同时设置这些 Key 。
During the time that the majority of keys are set, another client will not be able to acquire the lock, since N/2+1 SET NX operations can’t succeed if N/2+1 keys already exist. So if a lock was acquired, it is not possible to re-acquire it at the same time (violating the mutual exclusion property).
在设置大多数 Key 期间,另一个客户端将无法获取锁,因为如果 N/2+1 个 Key 已经存在,则 N/2+1 SET NX 操作无法成功。因此,如果获取了锁,则不可能在同一时间重新获取它(违反了互斥属性)。

However we want to also make sure that multiple clients trying to acquire the lock at the same time can’t simultaneously succeed.

If a client locked the majority of instances using a time near, or greater, than the lock maximum validity time (the TTL we use for SET basically), it will consider the lock invalid and will unlock the instances,
如果客户端使用接近或大于锁最大有效时间(我们基本上用于 SET 的 TTL)的时间锁定了大多数实例,那么它将认为锁无效并解锁实例,
so we only need to consider the case where a client was able to lock the majority of instances in a time which is less than the validity time.
In this case for the argument already expressed above, for MIN_VALIDITY no client should be able to re-acquire the lock.
在这种情况下,对于上面已经表达的论点,对于 MIN_VALIDITY,没有客户端应该能够重新获取锁。
So multiple clients will be able to lock N/2+1 instances at the same time (with "time" being the end of Step 2) only when the time to lock the majority was greater than the TTL time, making the lock invalid.
因此,只有当锁定多数实例的时间大于 TTL 时间时,多个客户端才能够在同一时间(“时间”是第 2 步的结束时间)锁定 N/2+1个实例,从而使锁定无效。

Liveness Arguments


The system liveness is based on three main features:

  1. The auto release of the lock (since keys expire): eventually keys are available again to be locked.
    锁(由于 Key 过期)自动释放:最终 Key 可以再次被锁定。

  2. The fact that clients, usually, will cooperate removing the locks when the lock was not acquired, or when the lock was acquired and the work terminated, making it likely that we don’t have to wait for keys to expire to re-acquire the lock.
    实际上,当没有获取锁时,或者当获取锁并且工作终止时,客户端通常会配合删除锁,这使得我们不必等待 Key 过期来重新获取锁。

  3. The fact that when a client needs to retry a lock, it waits a time which is comparably greater than the time needed to acquire the majority of locks, in order to probabilistically make split brain conditions during resource contention unlikely.

However, we pay an availability penalty equal to TTL time on network partitions, so if there are continuous partitions, we can pay this penalty indefinitely.
然而,我们在网络分区上支付相当于 TTL 时间的可用性惩罚,因此若有连续分区,我们可以无限期地支付这笔罚款。
This happens every time a client acquires a lock and gets partitioned away before being able to remove the lock.

Basically if there are infinite continuous network partitions, the system may become not available for an infinite amount of time.

Performance, Crash Recovery and fsync

性能,崩溃恢复及 fsync

Many users using Redis as a lock server need high performance in terms of both latency to acquire and release a lock, and number of acquire / release operations that it is possible to perform per second.
许多使用 Redis 作为锁服务的用户在获取和释放锁的延迟以及每秒可以执行的获取/释放操作的数量方面都需要高性能。
In order to meet this requirement, the strategy to talk with the N Redis servers to reduce latency is definitely multiplexing (putting the socket in non-blocking mode, send all the commands, and read all the commands later, assuming that the RTT between the client and each instance is similar).
为了满足需求,与N个 Redis 服务器通信以减少延迟的策略一定是多路复用(将套接字置于非阻塞模式,发送所有命令,然后读取所有命令,假设 Redis 服务器之间的 RTT 客户端和每个实例都是相似的)。
However there is another consideration around persistence if we want to target a crash-recovery system model.

Basically to see the problem here, let’s assume we configure Redis without persistence at all. A client acquires the lock in 3 of 5 instances.
基本上为了看到这儿的问题,我们假设我们根本没有配置 Redis 持久性。客户端在 5 个实例中的 3 个实例中获取了锁。
One of the instances where the client was able to acquire the lock is restarted, at this point there are again 3 instances that we can lock for the same resource, and another client can lock it again, violating the safety property of exclusivity of lock.

If we enable AOF persistence, things will improve quite a bit. For example we can upgrade a server by sending it a SHUTDOWN command and restarting it.
如果我们启用 AOF 持久化,事情将会改善很多。例如,我们可以通过向服务器发送 SHUTDOWN 命令并重新启动来升级服务器。
Because Redis expires are semantically implemented so that time still elapses when the server is off, all our requirements are fine.
因为 Redis 过期是语义实现的,所以当服务器关闭时,时间仍会流逝,所以我们的所有要求都很好。
However everything is fine as long as it is a clean shutdown. What about a power outage? If Redis is configured, as by default, to fsync on disk every second, it is possible that after a restart our key is missing.
但是,只要干净关闭,一切都很好。停电了怎么办(指非正常关机)?如果 Redis 默认情况下配置为每秒在磁盘上 fsync 一次,则重新启动后我们的 Key 可能会丢失。
In theory, if we want to guarantee the lock safety in the face of any kind of instance restart, we need to enable fsync=always in the persistence settings. This will affect performance due to the additional sync overhead.
理论上讲,如果我们想在任何类型的实例重启时保证锁的安全,我们需要在持久化设置中启用 fsync=always。由于额外的同步开销,这将影响性能。
However things are better than they look like at a first glance. Basically, the algorithm safety is retained as long as when an instance restarts after a crash, it no longer participates to any currently active lock.
This means that the set of currently active locks when the instance restarts were all obtained by locking instances other than the one which is rejoining the system.

To guarantee this we just need to make an instance, after a crash, unavailable for at least a bit more than the max TTL we use.
为了保证这一点,我们只需要让一个实例在崩溃后不可用的时间至少比我们使用的最大 TTL 长一点。
This is the time needed for all the keys about the locks that existed when the instance crashed to become invalid and be automatically released.
这是当实例崩溃时存在的锁的所有 Key 失效并自动释放所需的时间。
Using delayed restarts it is basically possible to achieve safety even without any kind of Redis persistence available, however note that this may translate into an availability penalty.
使用延迟重启,即使没有任何可用的 Redis 持久性,基本上也可以实现安全性,但请注意,这可能会转化为可用性损失。
For example if a majority of instances crash, the system will become globally unavailable for TTL (here globally means that no resource at all will be lockable during this time).
例如如果大多数实例崩溃了,系统将变得全局不可用于 TTL(这里的全局指的是在这段时间内没有任何资源是可锁定的)。

Making the algorithm more reliable: Extending the lock


If the work performed by clients consists of small steps, it is possible to use smaller lock validity times by default, and extend the algorithm implementing a lock extension mechanism.
Basically the client, if in the middle of the computation while the lock validity is approaching a low value, may extend the lock by sending a Lua script to all the instances that extends the TTL of the key if the key exists and its value is still the random value the client assigned when the lock was acquired.
基本上,如果在计算过程中,当锁有效性接近较低值时,客户端可以通过向所有扩展该 Key 的 TTL 的实例发送 Lua 脚本(如果该 Key 存在并且其值仍然是)来扩展锁。获取锁时客户端分配的随机值。

The client should only consider the lock re-acquired if it was able to extend the lock into the majority of instances, and within the validity time (basically the algorithm to use is very similar to the one used when acquiring the lock).

However this does not technically change the algorithm, so the maximum number of lock reacquisition attempts should be limited, otherwise one of the liveness properties is violated.



