Aias00 opened a new issue, #6584:
URL: https://github.com/apache/shenyu/issues/6584

   ## Description
   The retry logic operates below the plugin chain with no awareness of 
circuit-breaker state. The Resilience4J circuit breaker is not enabled by 
default. The failover retry checks `UpstreamCacheManager` for healthy 
upstreams, but that lags real-time failures. When all upstreams in a selector 
go down, every incoming request fires `retryTimes` retries (each timing out) 
before failing — no fast-fail path.
   
   ## Location
   ```
   shenyu-plugin-divide/.../DividePlugin.java:94-141 (no CB wrapping)
   shenyu-plugin-resilience4j/.../Resilience4JPlugin.java:80-90 (optional, must 
be explicitly configured per-route)
   ```
   
   ## Impact
   With `retryTimes=3` and 1000 RPS, that's 4000 outbound requests/s to dead 
upstreams for the outage duration plus 3000 held connections.
   
   ## Suggested fix
   Make a lightweight circuit breaker (open-on-N-consecutive-failures, 
half-open-probe) the default in the Divide/HTTP retry path, not an opt-in 
plugin.
   
   ## Related existing issue(s)
   None
   
   _Identified during the 2026-08-02 audit; full list in 
[`docs/issue-candidates-2026-08-02.md`](docs/issue-candidates-2026-08-02.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to