Is there a more specific 'rule of thumb' for scrub frequency? What variables should one consider?
Is there a more specific 'rule of thumb' for scrub frequency? What variables should one consider?
In the past, I've gone for a few years between scrubs. One system had a marginal I/O setup and was unreliable for high streaming load. When copying the pool off of it, I had to throttle the I/O to keep it reliable. No data loss though.
Scrubs are intensive. They will IMO provoke failure in drives sooner than not doing them. But they're the kind of failures you want to bring forward if you can afford the replacements (and often the drives are under warranty anyway).
If you don't scrub, eventually you generally start seeing one of two things: delays in reads and writes because drive error recovery is reading and rereading to recover data; or, if you have that disk behaviour disabled via firmware flags (and you should, unless you're reslivering and on your last disk of redundancy), you see zfs kicking a drive out of the pool during normal operations.
If I start seeing unrecoverable errors, or a drive dropping out of the pool, I'll disable scrubs if I don't have a spare drive on hand to start mirroring straight away. But it's better to have the spares. At least two, because often a second drive shows weakness during resilver.
There is a specific failure mode that scrubs defend against: silent disk corruption that only shows up when you read a file, but for files you almost never read. This is a pretty rare occurrence - it's never happened to me in about 50 drives worth of pools over 15 years or so. The way I think about this is, how is it actionable? If it's not a failing disk, you need to check your backups. And thus your scrub interval should be tied to your backup retention.
But you're balancing the cost of the scrub vs the benefit of learning about a problem as soon as possible.
A scrub does a lot of I/O and a fair amount of computing. The scrub load competes with your application load and depending on the size of your disk(s) and their read bandwidth, it may take quite some time to do the scrub. There's even maybe some potential that the read load could push a weak drive over the edge to failure.
On my personal servers, application load is nearly meaningless, so I do an about monthly scrub from cron which I think will only scrub one zpool at a time per machine, which seems reasonable enough to me. I run relatively large spinning disks, so if I scrubbed on a daily basis, the drives would spend most of the day scrubbing and that doesn't seem reasonable. I haven't run ZFS in a work environment... I'd have to really consider how the read load impacted the production load and if scrubbing with limits to reduce production impact would complete in a reasonable amount of time... I've run some systems that are essentially alwayd busy and if a scrub would take several months, I'd probably only scrub when other systems indicate a problem and I can take the machine out of rotation to examine it.
If I had very high reliability needs or a long time to get replacement drives, I might scrub more often?
If I was worried about power consumption, I might scrub less often (and also let my servers and drives go into standby). The article's recommendation to scan at least once every 4 months seems pretty reasonable, although if you have seriously offline disks, maybe once a year is more approachable. I don't think I'd push beyond that, lots of things don't like to sit for a year and then turn on correctly.
Scrubbing every quarter is usually sufficient without putting high wear on the HDD.
As I understand it, the primary reason for the 80% was that you're getting close to another limit, which IIRC was around 90%, where the space allocator would switch from finding a nearby large-enough space to finding the best-fitting space. This second mode tanks performance and could lead to much more fragmentation. And since there's no defrag tool, you're stuck with that fragmentation.
It has also changed, now[1] the switch happens at 96% rather than 90%. Also the code has been improved[2] to better keep track of free space.
However, performance can start to degrade before you reach this algorithm switch[3], as you're more likely to generate fragmentation the less free space you have.
However, it was also a generic advice, which was ignorant to your specific workload. If you have a lot of cold data, low churn but it's fairly equal in size, then you're probably less affected than if you have high churn with lots of files of varied sizes.
[1]: https://openzfs.github.io/openzfs-docs/Performance%20and%20T...
[2]: https://utcc.utoronto.ca/~cks/space/blog/solaris/ZFSZpoolFra...
[3]: https://www.bsdcan.org/2016/schedule/attachments/366_ZFS%20A...
You don't lose tracks in 3 months. If you don't read the tracks for a year and if the HDD is operated in high temperatures, then the controller might struggle to read them.
The very act of scrubbing generates heat, so we should use it sparingly.
#!/bin/bash
#
# ZFS scrub script for monthly maintenance
# Place in /etc/cron.monthly/zfs-scrub
POOL="storage"
TAG="zfs-scrub"
# Log start
logger -t "$TAG" -p user.notice "Starting ZFS scrub on pool: $POOL"
# Run the scrub
if /sbin/zpool scrub "$POOL"; then
logger -t "$TAG" -p user.notice "ZFS scrub initiated successfully on pool: $POOL"
else
logger -t "$TAG" -p user.err "Failed to start ZFS scrub on pool: $POOL"
exit 1
fi
exit 0update: figured how you can improve that call to add logs to logger
If this cost is affordable on a daily basis, then do a scrub daily. If it's only affordable less often, then do it less often.
(Whatever the case: It's not like a scrub causes any harm to the hardware or the data. It can run as frequently as you elect to tolerate.)
(https://www.toshiba-storage.com/trends-technology/mttf-what-...)
For SSDs, writes matter a lot more. Reads may increase the temperature of the drive, so they'll have some effect, but I don't think I've seen a read endurance rating for an SSD.
For what its worth, I scrub daily mostly because I can. It's completely overkill, but if it only takes half an hour, then it can run in the middle of the night while I'm sleeping.