Healthie.NET.LeaderElection
4.1.2
Prefix Reserved
See the version list below for details.
dotnet add package Healthie.NET.LeaderElection --version 4.1.2
NuGet\Install-Package Healthie.NET.LeaderElection -Version 4.1.2
<PackageReference Include="Healthie.NET.LeaderElection" Version="4.1.2" />
<PackageVersion Include="Healthie.NET.LeaderElection" Version="4.1.2" />
<PackageReference Include="Healthie.NET.LeaderElection" />
paket add Healthie.NET.LeaderElection --version 4.1.2
#r "nuget: Healthie.NET.LeaderElection, 4.1.2"
#:package Healthie.NET.LeaderElection@4.1.2
#addin nuget:?package=Healthie.NET.LeaderElection&version=4.1.2
#tool nuget:?package=Healthie.NET.LeaderElection&version=4.1.2

Healthie.NET.LeaderElection
Deprecated as of 4.1.0
Leader election now ships in Healthie.NET, the core package. Call
AddHealthieLeaderElection()there and drop this reference — running the checks on one replica at a time works exactly as it does here.Nothing breaks if you keep it. This package is still published, as an assembly of type forwards, so an application referencing it keeps compiling and running untouched. It carried no third-party dependency, so keeping it separate cost you an install and saved you nothing. It will not gain features.
▶ Live demo — board.healthie-dotnet.dev — a read-only Healthie.NET dashboard watching real status pages (Anthropic, OpenAI, GitHub, Cloudflare, and more), built from these packages. Full documentation at healthie-dotnet.dev.
Runs pulse checks on one replica at a time.
The problem it solves
Without it, every replica runs every check. Three replicas mean:
- a database asked three times whether it is healthy, on every interval
- three sets of results racing to write the same state document, two of them wasted
- one outage paging somebody three times
None of that is visible from a dashboard, which is what makes it worth fixing before it matters.
Installation
dotnet add package Healthie.NET.LeaderElection
Usage
using Healthie.LeaderElection;
builder.Services
.AddHealthie(typeof(Program).Assembly)
.AddHealthieLeaderElection(); // after the scheduler it should wrap
builder.Services.AddSingleton<ILeaseProvider, YourSharedLeaseProvider>();
Call it after the scheduler. It decorates whatever IPulseScheduler is registered at that point, so unlike every other AddHealthie* in this library it is not order-independent. Calling it first throws with an explanation rather than silently wrapping the built-in timer when you meant Quartz.
It works with every scheduler — the built-in timer, Quartz, Hangfire, Coravel, Temporal — because it wraps rather than replaces.
You need a shared lease provider
The default keeps leases in memory, which makes every replica the leader of itself and leaves the problem exactly where it was. It exists so the feature can be switched on and tested without standing anything up.
Implement ILeaseProvider against something your replicas share — a table with a conditional update, a Redis SET NX, a blob lease. It is two methods:
Task<bool> TryAcquireAsync(string leaseName, string holderId, TimeSpan duration, CancellationToken ct);
Task ReleaseAsync(string leaseName, string holderId, CancellationToken ct);
Acquire and renew are one operation on purpose — take it if nobody holds it, if it has expired, or if it is already mine. Separating them invites a renew that succeeds against a lease somebody else now holds.
Failover
A lease expires rather than being handed over, because the failure worth designing for is the replica that stops without saying anything — killed, redeployed, partitioned away. Another replica takes over once the lease lapses, without needing its cooperation.
LeaseDuration (30s default) is therefore how long checks pause when a leader dies abruptly. RenewInterval (10s) is comfortably shorter, so a single slow round trip does not move leadership for no reason.
If the lease store becomes unreachable, the replica stands down. It can no longer prove it leads, and two leaders is the state this exists to prevent.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Healthie.NET.DependencyInjection (>= 4.1.2)
-
net8.0
- Healthie.NET.DependencyInjection (>= 4.1.2)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
### Fixed
- The dashboard event-log and about dialogs now move focus inside, keep keyboard focus contained,
close with Escape, and restore focus to the control that opened them.
- Dashboard checker rows now expose selection as a real button alongside their action buttons,
removing nested interactive controls while preserving whole-row pointer selection.
- A dashboard state-provider failure now shows a recoverable unavailable state with a retry action
instead of looking like an empty installation with no registered checkers.
- The Blazor sample now keeps the dashboard stylesheet in its static host head, preventing an
unstyled flash while the interactive head reconnects on a slow network.
- HTTP checker display names and result messages now omit URI user information, query strings, and
fragments, server-controlled reason phrases, and transport exception details, preventing embedded
credentials and tokens from reaching stored history, alerts, logs, or the dashboard while requests
still use the complete configured URI.
- Alert-history persistence now loads durable history before its first post-restart write and
coalesces changes raised during a slow state-provider write into one latest-state follow-up. This
preserves earlier alerts without duplicating the new one and avoids an unbounded queue of tasks
and redundant full-history writes during alert bursts.
- The Web API sample maps its unauthenticated management API and mutation-enabled MCP endpoint only
in Development, so deploying the sample with a production environment no longer exposes those
local demonstration surfaces. Liveness and readiness probes remain available.
- History clearing and startup trimming now use optimistic concurrency, so they no longer overwrite
a check result or setting changed by another replica between the read and write.
- Leader election now serializes schedule changes with leadership transitions and reconciles every
registered checker's persisted active state and schedule through a bulk read on lease renewal. A
pause or cadence change made through another replica now reaches the leader, a fresh leader
removes inactive durable jobs left by the previous process, and reconciliation runs with bounded
concurrency while an independent lease heartbeat prevents slow scheduler calls from expiring an
otherwise healthy leader. Partial and cancelled transitions remain tracked until cleanup succeeds,
and shutdown does not release the lease over work it could not stop.
- CosmosDB multi-state reads now use `ReadManyItemsAsync`, avoiding one sequential network round
trip per checker during dashboard loads and leader renewal.
- The in-memory lease provider now returns exactly one winner when replicas contend concurrently.
- Coravel, Hangfire, Temporal, and the leader-election decorator now validate schedules before they
are persisted. Cronos expressions requiring an absent jitter seed are reported as validation
failures instead of escaping as server errors. The built-in timer also rejects periods outside
`PeriodicTimer`'s supported range before replacing a working schedule.
- Temporal now preserves Healthie.NET's six-field, leading-seconds cron meaning by translating it
to Temporal's seven-field seconds form. It rejects Cronos-only relative-day and descending-range
expressions whose Temporal meaning differs, and fixed periods outside Temporal's supported range,
before an existing schedule is removed.
- Uptime recording now starts a new observation segment on the first fresh result after a process
restart, even when its health matches persisted state. Time while no process was observing the
checker remains unknown, and a transition that finds the bounded queue full is retried by the next
fresh result.
Full changelog: https://github.com/ivanvyd/Healthie.NET/blob/v4.1.2/CHANGELOG.md