
  • 前言
  • 综述
  • zookeeper保证
    • 理解zookeeper的顺序一致性
  • 之前使用zookeeper客户端踩到的坑
  • curator 连接保证
  • 连接状态监控以及重试机制
  • 实例管理
  • Recipes 场景支持
    • 基本操作
    • 监听watch
    • 实现的recipes
      • Elections 选举
      • locks 锁
    • counters 计数器
      • caches 缓存
      • Nodes/Watchers
      • Queues 队列
      • 事务
    • tech note
  • 参考链接






官方文档这样描述Curator存在的意义:ZooKeeper is a very low level system that requires users to do a lot of housekeeping. See: Zookeeper FAQ. The Curator Framework is designed to hide as much of the details/tedium of this housekeeping as is possible.




  • Sequential Consistency - Updates from a client will be applied in the order that they were sent.
  • Atomicity - Updates either succeed or fail. No partial results.
  • Single System Image - A client will see the same view of the service regardless of the server that it connects to. i.e., a client will never see an older view of the system even if the client fails over to a different server with the same session. 如果client首先看到了新数据,再尝试重连到存有旧数据的follower,该follower会拒绝该连接(client的zxid高于follower)
  • Reliability - Once an update has been applied, it will persist from that time forward until a client overwrites the update.
  • Timeliness - The clients view of the system is guaranteed to be up-to-date within a certain time bound.

根据我的实践,认为zookeeper只是一个最终一致性的分布式系统,并且历史上zookeeper还经常爆出违反分布式共识的bug,比如expired ephemeral node reappears after ZK leader change这个,session expired之后,临时节点仍然存在


ZooKeeper Programmer’s Guide提到:

Sometimes developers mistakenly assume one other guarantee that ZooKeeper does not in fact make. This is:
Simultaneously Conistent Cross-Client Views
ZooKeeper does not guarantee that at every instance in time, two different clients will have identical views of ZooKeeper data. Due to factors like network delays, one client may perform an update before another client gets notified of the change. Consider the scenario of two clients, A and B. If client A sets the value of a znode /a from 0 to 1, then tells client B to read /a, client B may read the old value of 0, depending on which server it is connected to. If it is important that Client A and Client B read the same value, Client B should should call the sync() method from the ZooKeeper API method before it performs its read.
So, ZooKeeper by itself doesn’t guarantee that changes occur synchronously across all servers, but ZooKeeper primitives can be used to construct higher level functions that provide useful client synchronization.



  1. zk session 处理

    • 忽略了connecting事件,client与server心跳超时之后没有将选主服务及时下线掉,导致双主。
    • 多个线程处理zk的连接状态,导致产生了多套zk线程连接zkserver。
    • zk超时时间不合理,导致重连频率太高,打爆zkserver。
    • 所有的zkserver全部重置(zk server全部状态被重置),这种情况下客户端不会受到expired事件,我之前实现的客户端也不会重新去建立zk session。导致之前的zkclient建立的session全部不可用,陷入无限重连而连不上的窘境。
  2. 多线程竞态
    • zk自己的线程do_completion会调用watcher的回调函数,和业务线程产生竞争,导致core dump。
  3. 同步api
    • 同步API没有超时时间,如果zkserver状态不对,会导致调用同步zk API的线程卡死。
    • 供业务使用的api设计不当,导致初始化时调用的同步版本api造成死锁。

curator 连接保证


  1. 所有的Curator operation(create、get.sync等)都会在zookeeper连接建立之后再进行
  2. 所有的Curator operation都可以通过重试机制正确的处理zookeeper session loss/expireds事件
  3. 如果当前session lost了,Curator operation可以保持一致重试直到成功
  4. 所有的curator client都会以一种合理的方式处理zookeeper连接问题。



Curator will set the LOST state when it believes that the ZooKeeper session has expired. ZooKeeper connections have a session. When the session expires, clients must take appropriate action. In Curator, this is complicated by the fact that Curator internally manages the ZooKeeper connection. Curator will set the LOST state when any of the following occurs: a) ZooKeeper returns a Watcher.Event.KeeperState.Expired or KeeperException.Code.SESSIONEXPIRED; b) Curator closes the internally managed ZooKeeper instance; c) The session timeout elapses during a network partition. It is possible to get a RECONNECTED state after this but you should still consider any locks, etc. as dirty/unstable.




    /*** @param ensembleProvider the ensemble provider  连接ipstring* @param sessionTimeoutMs session timeout  就是我们设置的sessiontimeout超时时间* @param connectionTimeoutMs connection timeout  连接超时,这么久还没有连上就不连了* @param watcher default watcher or null* @param retryPolicy the retry policy to use  retryforever*/public CuratorZookeeperClient(EnsembleProvider ensembleProvider, int sessionTimeoutMs, int connectionTimeoutMs, Watcher watcher, RetryPolicy retryPolicy){this(new DefaultZookeeperFactory(), ensembleProvider, sessionTimeoutMs, connectionTimeoutMs, watcher, retryPolicy, false);}


Recipes 场景支持


Most Curator recipes will autocreate parent nodes of paths given to the recipe as CreateMode






  • 重启zk:type=CONNECTION_RECONNECTED, data=null
  • 更新子节点:type=CHILD_UPDATED
  • 删除子节点type=CHILD_REMOVED



Elections 选举

  • LeaderSelector:只要takeLeadership不退出,当前节点就一直是leader。实际上是用InterProcessMutex做的
  • LeaderLatch:一旦选举出Leader,除非有客户端挂掉重新触发选举,否则不会交出领导权。

locks 锁


counters 计数器

由于zk的写是递交到leader去写的,而读是follower就可以读,所以不知道这个计数器会不会引起stale read

caches 缓存



这个主要指创建一些persist node,和与之对应的watcher

Queues 队列



tech note

  1. 所有的watcher事件都应该在同一个线程里执行,然后再这个线程里对访问的资源加锁(这个操作应该由zk库在zk线程里自己完成)
  2. 认真对待session生命周期,如果expired就需要重连,如果session已经expired了,所有与这个session相关的操作也应该失败。session和临时节点是绑定的,session expired了临时节点也就没了
  3. zookeeper可以把sessionid和password保存起来,下次新建连接的时候可以直接用之前的
  4. zookeeper不适合做消息队列,因为
    • zookeeper有1M的消息大小限制
    • zookeeper的children太多会极大的影响性能
    • znode太大也会影响性能
    • znode太大会导致重启zkserver耗时10-15分钟
    • zookeeper仅使用内存作为存储,所以不能存储太多东西。
  5. 最好单线程操作zk客户端,不要并发,临界、竞态问题太多
  6. Curator session 生命周期管理:
    • CONNECTED:第一次建立连接成功时收到该事件
    • READONLY:标明当前连接是read-only状态
    • SUSPENDED:连接目前断开了(收到KeeperState.Disconnected事件,也就是说curator目前没有连接到任何的zk server),leader选举、分布式锁等操作遇到SUSPENED事件应该暂停自己的操作直到重连成功。Curator官方建议把SUSPENDED事件当作完全的连接断开来处理。意思就是把收到SUSPENDED事件的时候就当作自己注册的所有临时节点已经掉了。
    • LOST:如下几种情况会进出LOST事件
      • curator收到zkserver发来的EXPIRED事件。
      • curator自己关掉当前zookeeper session
      • 当curator断定当前session被zkserver认为已经expired时设置该事件。在Curator 3.x,Curator会有自己的定时器,如果收到SUSPENDED事件一直没有没有收到重连成功的事件,超时一定时间(2/3 * session_timeout)。curator会认为当前session已经在server侧超时,并进入LOST事件。
    • RECONNECTED:重连成功


When Curator receives a KeeperState.Disconnected message it changes its state to SUSPENDED (see TN12, errors, etc.). As always, our recommendation is to treat SUSPENDED as a complete connection loss. Exit all locks, leaders, etc. That said, since 3.x, Curator tries to simulate session expiration by starting an internal timer when KeeperState.Disconnected is received. If the timer expires before the connection is repaired, Curator changes its state to LOST and injects a session end into the managed ZooKeeper client connection. The duration of the timer is set to the value of the “negotiated session timeout” by calling ZooKeeper#getSessionTimeout().
The astute reader will realize that setting the timer to the full value of the session timeout may not be the correct value. This is due to the fact that the server closes the connection when 2/3 of a session have already elapsed. Thus, the server may close a session well before Curator’s timer elapses. This is further complicated by the fact that the client has no way of knowing why the connection was closed. There are at least three possible reasons for a client connection to close:

  • The server has not received a heartbeat within 2/3 of a session
  • The server crashed
  • Some kind of general TCP error which causes a connection to fail

In situtation 1, the correct value for Curator’s timer is 1/3 of a session - i.e. Curator should switch to LOST if the connection is not repaired within 1/3 of a session as 2/3 of the session has already lapsed from the server’s point of view. In situations 2 and 3 however, Curator’s timer should be the full value of the session (possibly plus some “slop” value). In truth, there is no way to completely emulate in the client the session timing as managed by the ZooKeeper server. So, again, our recommendation is to treat SUSPENDED as complete connection loss.

curator默认使用100%的session timeout时间作为SUSPENDED到LOST的转换时间,但是用户可以根据需求配置为33%的session timeout以满足上文所说的情况的场景


  1. 基于Apache Curator框架的ZooKeeper使用详解
  2. Zookeeper客户端Curator使用详解
  3. ZooKeeper和Curator相关经验总结
  4. Welcome to Curator
  5. Curator Error Handling
  6. Recipescurator支持的业务类型,比如选举,计数,跨线程锁等
  7. 基于Zookeeper实现的分布式互斥锁 - InterProcessMutex
  8. how to properly recreate ephemeral nodes and reset watches after a session expiry


