Protection policy
Policy answers three independent questions:
- Which source volumes are in scope? Volume groups and exclusions.
- How should they be protected? Replication profiles.
- How much work may proceed? Automation profiles.
Replication profile
| Parameter | Meaning |
|---|---|
| ONTAP policy | Existing asynchronous mirror, mirror-vault, or vault policy |
| Job schedule | Existing destination cron schedule; DonkeyFleet does not create it |
| Throttle (Kbps) | Optional relationship throttle; when empty, baseline admission uses the lower automation limit |
| Naming strategy | suffix or same_as_source; template provisioning is currently refused |
| Size policy | Match source, or source size plus configured headroom |
| Tiering and cooling | Destination storage-tier intent; select tiering explicitly |
Aggregates, policies, and schedules are discovered values. DonkeyFleet refuses missing or ambiguous placement rather than guessing.
Automation modes
| Mode | New protection | Destination fill | Orphan deletion |
|---|---|---|---|
manual | Records review work only | Detect and recommend; no autonomous grow | Approval always required |
approve | Human approval required | Recommended resize requires human approval | Approval always required |
auto | Eligible work may run when effective dry-run is off | One bounded breathing-room grow may run; the target resize still requires human approval | Approval always required |
Automation parameters
The form defaults are starting points, not universal sizing recommendations.
| Parameter | UI default | Operational effect |
|---|---|---|
| Max actions per run | 10 | Fresh-action budget applied separately to protection admission, remediation, autonomous grow, and orphan cleanup — not one shared total, so concurrent workflows can each admit up to this many in a run; persisted job recovery is not held behind it |
| Minimum volume age (hours) | 24 | Time since first complete observation before protection is eligible |
| Max orphan transitions | 5 | Absolute cap on new orphan transitions in one run |
| Max orphan transitions (%) | 10 | Percentage cap evaluated with the absolute orphan guardrail |
| Orphan grace (hours) | 72 | Minimum orphan duration before cleanup can be proposed |
| Fill threshold (%) | 90 | Opens a destination-fill episode and creates the human-approved resize recommendation |
| Autonomous grow (%) | 5 | The one auto-mode breathing-room step: a bounded 5% or 10% choice (default 5%), enforced by validation |
| Target utilization (%) | 70 | Calculates the separate human-approved target size; it does not size the autonomous step |
| Episode reset threshold (%) | 80 | An open episode closes only when usage falls below this value; falling below the fill threshold alone does not reset it |
| Max cumulative growth (%) | 25 | Sum-of-autonomous-growth ceiling for the relationship across episodes; it does not cap approved resize work |
| Max concurrent initializes | 1 | Maximum baselines admitted at once for this automation profile |
| Intercluster budget (Kbps) | 200000 | Total baseline bandwidth budget |
| Baseline throughput (Kbps) | 130000 | Estimate and default throttle input when the replication profile has no throttle |
| Baseline overrun factor | 1.5 | Urgent-alert multiplier over the larger of the size estimate and ten-minute floor |
Set minimum volume age to 0 only when existing matching volumes should become eligible
immediately. With a higher value, they remain in Backlog with min_volume_age until the age is
reached and a reconcile observes them again.
Raising max_concurrent_initializes does not guarantee that many simultaneous baselines. Each
candidate must also fit the intercluster budget. Estimate the impact on existing scheduled
SnapMirror traffic before raising either value.
See Fill protection and growth for the two resize formulas and Orphan cleanup for the transition, grace, and approval flow.
Volume groups and exclusions
Lower numeric group priority wins. Rules inside a group are ordered AND conditions. A matching group assigns both profiles; DonkeyFleet never infers an automation profile from a replication profile.
For Trident-backed Kubernetes storage, volume groups select the backing ONTAP volumes using ONTAP-visible attributes such as the storage prefix and provisioning metadata in the volume comment. DonkeyFleet applies policy to the ONTAP volume UUID, not to the PV or PVC object.
Some discovered volumes should never be protected — scratch and temporary volumes, or volumes owned by another tool. Exclude them on Policy → Exclusions:
- Manual named exclusions. Search discovery for the specific volumes, stage them into a bulk list, and add them to a named exclusion — a name plus a reason, recorded once when the name is first created. Add later volumes to the same name to grow the list. An excluded volume is pinned by its volume UUID, never its name (invariant 2), and is dropped from candidacy at the query boundary — never proposed for protection. Include returns it to candidates on the next observe.
- Clones. FlexClones are detected structurally from their clone attributes and are always excluded and read-only — there is nothing to configure.
An exclusion is retired automatically if its source volume is later deleted. Once a complete observation of the volume's pair no longer contains it, DonkeyFleet removes the exclusion entry and its stale candidate, keeps the named exclusion for reuse, and records an informational notification. A partial or aborted observation never retires anything, so a transient outage leaves exclusions untouched.
The Exclusions tab lists everything held out of candidacy grouped by exclusion name, with the structural Clones group shown alongside; each volume carries its last-observed provisioned and physical size. Always preview the resulting candidates in dry-run before enabling Apply.