Job contract
Delivery, retries and recovery
The queue provides durable at-least-once execution, not magical exactly-once side effects.
A worker can complete an external action and fail before recording success. Executors and destinations must therefore use the job or event identifier as an idempotency key. Lease expiry permits another worker to recover abandoned work.
Dead letters
After the configured maximum attempts, a job becomes dead. Inspect and repair the cause before retrying; retry resets the attempt counter and preserves the original identity and payload.
Shutdown
Shutdown stops new claims through context cancellation. Any unfinished lease later returns to pending. The Trestle process never executes arbitrary user code.