Skip to main content
Version: 1.3.1

Protection policy

Policy answers three independent questions:

  1. Which source volumes are in scope? Volume groups and exclusions.
  2. How should they be protected? Replication profiles.
  3. How much work may proceed? Automation profiles.

Replication profile​

ParameterMeaning
ONTAP policyExisting asynchronous mirror, mirror-vault, or vault policy
Job scheduleExisting destination cron schedule; DonkeyFleet does not create it
Throttle (Kbps)Optional relationship throttle; when empty, baseline admission uses the lower automation limit
Naming strategysuffix or same_as_source; template provisioning is currently refused
Size policyMatch source, or source size plus configured headroom
Tiering and coolingDestination storage-tier intent; select tiering explicitly

Aggregates, policies, and schedules are discovered values. DonkeyFleet refuses missing or ambiguous placement rather than guessing.

Automation modes​

ModeNew protectionDestination fillOrphan deletion
manualRecords review work onlyDetect and recommend; no autonomous growApproval always required
approveHuman approval requiredRecommended resize requires human approvalApproval always required
autoEligible work may run when effective dry-run is offOne bounded breathing-room grow may run; the target resize still requires human approvalApproval always required

Automation parameters​

The form defaults are starting points, not universal sizing recommendations.

ParameterUI defaultOperational effect
Max actions per run10Fresh-action budget applied separately to protection admission, remediation, autonomous grow, and orphan cleanup — not one shared total, so concurrent workflows can each admit up to this many in a run; persisted job recovery is not held behind it
Minimum volume age (hours)24Time since first complete observation before protection is eligible
Max orphan transitions5Absolute cap on new orphan transitions in one run
Max orphan transitions (%)10Percentage cap evaluated with the absolute orphan guardrail
Orphan grace (hours)72Minimum orphan duration before cleanup can be proposed
Fill threshold (%)90Opens a destination-fill episode and creates the human-approved resize recommendation
Autonomous grow (%)5The one auto-mode breathing-room step: a bounded 5% or 10% choice (default 5%), enforced by validation
Target utilization (%)70Calculates the separate human-approved target size; it does not size the autonomous step
Episode reset threshold (%)80An open episode closes only when usage falls below this value; falling below the fill threshold alone does not reset it
Max cumulative growth (%)25Sum-of-autonomous-growth ceiling for the relationship across episodes; it does not cap approved resize work
Max concurrent initializes1Maximum baselines admitted at once for this automation profile
Intercluster budget (Kbps)200000Total baseline bandwidth budget
Baseline throughput (Kbps)130000Estimate and default throttle input when the replication profile has no throttle
Baseline overrun factor1.5Urgent-alert multiplier over the larger of the size estimate and ten-minute floor
Initial onboarding

Set minimum volume age to 0 only when existing matching volumes should become eligible immediately. With a higher value, they remain in Backlog with min_volume_age until the age is reached and a reconcile observes them again.

Raising max_concurrent_initializes does not guarantee that many simultaneous baselines. Each candidate must also fit the intercluster budget. Estimate the impact on existing scheduled SnapMirror traffic before raising either value.

See Fill protection and growth for the two resize formulas and Orphan cleanup for the transition, grace, and approval flow.

Volume groups and exclusions​

Lower numeric group priority wins. Rules inside a group are ordered AND conditions. A matching group assigns both profiles; DonkeyFleet never infers an automation profile from a replication profile.

For Trident-backed Kubernetes storage, volume groups select the backing ONTAP volumes using ONTAP-visible attributes such as the storage prefix and provisioning metadata in the volume comment. DonkeyFleet applies policy to the ONTAP volume UUID, not to the PV or PVC object.

Some discovered volumes should never be protected — scratch and temporary volumes, or volumes owned by another tool. Exclude them on Policy → Exclusions:

  • Manual named exclusions. Search discovery for the specific volumes, stage them into a bulk list, and add them to a named exclusion — a name plus a reason, recorded once when the name is first created. Add later volumes to the same name to grow the list. An excluded volume is pinned by its volume UUID, never its name (invariant 2), and is dropped from candidacy at the query boundary — never proposed for protection. Include returns it to candidates on the next observe.
  • Clones. FlexClones are detected structurally from their clone attributes and are always excluded and read-only — there is nothing to configure.

An exclusion is retired automatically if its source volume is later deleted. Once a complete observation of the volume's pair no longer contains it, DonkeyFleet removes the exclusion entry and its stale candidate, keeps the named exclusion for reuse, and records an informational notification. A partial or aborted observation never retires anything, so a transient outage leaves exclusions untouched.

The Exclusions tab lists everything held out of candidacy grouped by exclusion name, with the structural Clones group shown alongside; each volume carries its last-observed provisioned and physical size. Always preview the resulting candidates in dry-run before enabling Apply.