David, Yakov, I understand your fears. But liveness checks deal with _critical_ conditions, i.e. when such a condition is met we conclude the node as totally broken, and there is no sense to keep it alive regardless the data it contains. If we want to give it a chance, then the condition (long fsync etc.) should not considered as critical at all.
сб, 8 сент. 2018 г. в 15:18, Yakov Zhdanov <yzhda...@apache.org>: > Agree with David. We need to have an opporunity set backups count threshold > (at runtime also!) that will not allow any automatic stop if there will be > a data loss. Andrey, what do you think? > > --Yakov > -- Best regards, Andrey Kuznetsov.