Lease renewal extends a worker claim only when its token still owns an unexpired row and the new deadline moves forward.
Spring outbox lease renewal: extend only the current owner
The checked sequence
Worker A claims EVENT-81 from logical time 100 to 150. A renewal from worker B fails. A renewal from A to 140 also fails because it would shorten the lease. A can extend it to 200 while the claim is still live. Worker B cannot claim at 160. At 200, A can no longer renew; B reclaims to 260. A stays stale, and only B can extend the lease to 300.
The UPDATE checks the token, PENDING state, current lease greater than now and current lease shorter than the proposed deadline. The acknowledgement lesson uses the same ownership idea when a worker finishes. Renewal is useful only if the worker can report progress and stop when it loses ownership.
Do not confuse renewal with remote fencing
This token fences the H2 row, not a broker publish already started by A. A slow A may finish its remote call after B takes over. The downstream event-ID ledger still needs to reject duplicate business work. On a real service, schedule renewal before expiry with a measured safety margin, bounded clock assumptions and a maximum processing deadline.
The checked test uses caller-supplied logical time and no background renewal task. It does not cover a pause during garbage collection, network partitions, skewed worker clocks, or concurrent renewal on the deployment database. Shutdown must leave unacknowledged work recoverable if renewal stops.
Checked source
update lease_event set lease_until = ?
where event_id = 'EVENT-81' and state = 'PENDING' and claim_token = ?
and lease_until > ? and lease_until < ?;Verification boundary
ConcurrentOutboxLeaseTest.renewalRequiresCurrentUnexpiredTokenAndLongerDeadline in the downloadable Spring source kit. The excerpt is shortened; the kit contains the complete checked SQL.
Costs and limits
The test covers sequential H2 renewal with logical timestamps. It does not install a renewal timer, coordinate host clocks, or prove a remote side effect is fenced.
Common Mistakes
- Do not renew with only an event ID.
- Do not let a stale worker extend a replacement owner’s lease.
- Do not assume an extended database lease cancels a duplicate publish.
Read next
Spring outbox claim race: one conditional UPDATE wins, Spring outbox claims: lease expiry and token-fenced acknowledgement, Spring consumer idempotency: reserve an event ID with the stock mutation, Spring TaskScheduler shutdown: stop new polls and account for in-flight work.
