Limits
This page lists the limits and defaults Astraeus enforces, with their values,
grouped by area. When a request goes over a limit, the error names it; see
Errors for the codes.
Names
| Item |
Limit |
| Organisation, workspace and cluster slugs |
2 to 40 characters: lower-case letters, digits and -, not starting or ending with - |
| Workspace namespace on a cluster |
ws- and 12 hexadecimal digits (assigned; at most 40 characters for any namespace) |
| Names inside a workspace |
No . (the namespace separator) |
| Run name |
Letters, digits, - and _; at most 57 characters, so that <run>-<rank> fits a 63-character DNS label with room for a five-digit rank |
| Run name with worker groups |
At most 63 − 1 − (group name length) − 6 for each group other than default; the tightest applies |
| Replica group name |
As a run name, less the length of -<max replicas − 1> |
Any DNS name, with .astraeus.local. |
At most 254 characters |
| Machine placement labels set from the console (pool, site, rack, fabric) |
At most 63 characters: letters, digits and -._:/ |
Labels under astraeus.io/ |
Reserved for the system |
| API token name |
1 to 100 characters |
| Alert channel and event stream name |
At most 100 characters |
| Run template |
Name at most 100 characters; spec at most 256 KiB |
Accounts and sign-in
| Item |
Value |
| Password |
12 characters minimum, 1024 bytes maximum |
| E-mail address |
At most 254 characters |
| E-mail verification link |
24 hours, single use |
| Password reset link |
1 hour, single use |
| Organisation invitation |
7 days, single use |
| Browser session |
12 hours |
CLI session (astra login) |
30 days |
| CLI sign-in code |
10 minutes; the CLI polls every 5 s |
| SSO, Google or GitHub sign-in |
Must complete within 10 minutes; 60 s clock skew allowed on ID tokens |
| API token expiry |
1 to 3650 days, or none |
Rate limits (fixed windows; over them, 429 TOO_MANY_ATTEMPTS):
| Action |
Limit |
| Sign-in |
10 per 15 minutes per address and e-mail; 100 per 15 minutes per address; 50 per 15 minutes per e-mail |
| Sign-up |
20 per hour per address |
| Password reset request |
10 per hour per address |
| CLI sign-in start |
30 per hour per address |
Organisations and workspaces
| Item |
Default |
Set by |
| Workspaces per organisation |
No limit |
Astralyx |
| Machines per organisation on Astraeus Cloud, including those enrolled but not yet connected |
10 |
Astralyx, on request |
| Workspace quota on a cluster |
Unlimited |
Organisation admins; see quotas |
| Fair-share weight |
1 (minimum 1) |
Organisation admins |
| Maximum run priority of a workspace |
0 |
Organisation admins |
| Enrollment token validity (unused) |
3600 s; 60 to 604800 s |
Whoever creates it |
Requests
| Item |
Limit |
| JSON request body, most endpoints |
2 MiB (413 from the HTTP layer) |
| Request body under a workspace's cluster path |
16 MiB (400 BODY_TOO_LARGE) |
| JSON response under a workspace's cluster path |
256 MiB (503 RESPONSE_TOO_LARGE) |
| Answer a machine returns for a request (a log, a catalog page) |
1 MiB (400 RESPONSE_TOO_LARGE) |
| Waiting for a machine's answer (logs, trace, activity) |
30 s (504 TIMEOUT) |
| A cluster at capacity |
503 OVERLOADED, Retry-After: 1 |
| Requests per machine credential |
burst 60, then 5 per second (429 RATE_LIMITED, Retry-After: 5) |
| Listing |
Default |
Maximum |
Worker log (tail) |
1000 lines |
10000 lines |
Worker activity (limit) |
500 entries |
2000 entries |
Workspace or cluster events (limit) |
100 |
500 |
Audit log (limit) |
100 |
1000 |
| Workspace run list across clusters |
the 1000 most recently changed |
— |
| Usage period |
the current month |
400 days |
Runs and workers
| Item |
Limit |
| Priority |
−1000 to 1000; at most the workspace's maximum |
| Array size |
1 to 10000 |
Worker time limit (time_limit_seconds) |
60 s to 366 days |
Worker heartbeat TTL (heartbeat_ttl_seconds) |
10 to 86400 s; default 60 s |
Restarts after an expired heartbeat (max_heartbeat_retries) |
0 to 1000 |
| Outbound rules per worker |
64 rules, 32 ports per rule |
| Outputs a worker writes |
64 pairs; keys at most 64 characters (a-z, 0-9, _); 4096 bytes in all |
| Metrics scrape interval |
at least 5 s; default 15 s |
| Interactive run idle timeout |
60 s to 7 days; default 1800 s |
Code packed by astra astraeus run --code |
900 KiB after compression and base64 |
Services
| Item |
Limit |
| Replica group size |
1 to 1000 replicas |
| External access listen ports |
30000 to 32767 |
| External access proxy body |
default 1,000,000 bytes; at most 1,400,000 bytes |
| External access proxy timeout |
default 10 s; at most 60 s |
| Health check defaults |
every 10 s, 5 s timeout, 3 failures |
Machines
| Item |
Value |
| Machine heartbeat |
60 s: a machine that has not reported for that long is marked Down |
| Memory pressure |
from 95 % used; relieved below 90 % |
| Disk pressure |
below 10 % free; relieved above 15 % free |
| CPU pressure |
five-minute load from 1.5 per core; relieved below 1.2 |
Usage, events and audit
| Item |
Value |
| Usage sampling |
every 60 s; gaps over 10 minutes are not charged |
| Hourly usage kept |
400 days |
| Workspace events |
kept, unless the workspace sets 1 to 3660 days |
| Machine events |
kept |
| Audit log |
kept |
| Alert delivery |
15 s per attempt; 8 attempts, the last about 2 hours after the first |
| Alert deliveries shown in the console |
the last 50 |
| E-mail alert channel |
1 to 20 addresses |
| A deployment counts as down after |
5 minutes without a serving replica |
| Event stream batch |
up to 200 events |
| Event stream retries |
from 1 minute, doubling, at most 1 hour apart; never skipped |
| Event stream timeouts |
30 s per HTTP request; syslog 10 s to connect, 10 s for TLS, 30 s to write |