max_standby_archive_delay
Fact — official short description: “Sets the maximum delay before canceling queries when a hot standby server is processing archived WAL data.”
Identity
Lifecycle
| Fact | Value |
|---|---|
| First observed | PG9.0 (research boundary) |
| Present in | PG9.0–19 Beta 3 |
| Removed in | No |
| Introduction commit | Not asserted: predates the PG9.0 research boundary |
| Commit date | — |
| Discussion | — |
Default history
| Versions | Raw boot_val |
Unit | Human value |
|---|---|---|---|
| PG9.0–19 Beta 3 | 30000 |
ms |
30 s |
How it works
Sets the maximum delay before canceling queries when a hot standby server is processing archived WAL data. A configuration reload applies a new value; existing work already in flight is not retroactively changed.
While replaying WAL fetched from an archive, recovery may wait up to this accumulated delay for conflicting hot-standby queries before canceling them. It is measured against replay progress, not granted afresh to every query; -1 can let replay lag without bound.
Monitor and change max_standby_archive_delay together with max_standby_streaming_delay, hot_standby, hot_standby_feedback. Validate on the relevant server role and real workload, then use its sighup context to choose session change, reload, or restart; a historical boot default is not the current effective value.
Tuning advice
Advice. These are workload-specific starting points and must be validated with measurements.
| Workload | Guidance |
|---|---|
| OLTP | Size max_standby_archive_delay from topology, failover roles, slot/subscription count, and reconnect headroom. Test worst-case primary latency, standby replay, and disk retention before production. |
| OLAP | Read standbys and logical subscribers often see long queries or large transactions. Put explicit bounds on replay/apply and monitor lag, worker saturation, slot restart_lsn, and conflict cancellations. |
| Small nodes | Configure only replication capacity that is actually used. Even a small topology needs bounded timeouts and slot lifecycle; unlimited retention is not reliability. |
Pigsty
Values use the fixed 8-vCPU, 32-GiB, 100-GiB SSD fixture and render the current Pigsty templates for PG19 Beta 3; this does not assert current Pigsty support for that historical or beta release.
| Template | Effective value | Versus upstream boot | Source expression |
|---|---|---|---|
| OLTP | 10min |
different | 10min |
| OLAP | 10min |
different | 10min |
| CRIT | 10min |
different | 10min |
| TINY | 10min |
different | 10min |
Advice — pending human review. Fact from the current Pigsty template projection: OLTP: PG9.0–19 Beta 3 = 10min (dcs); OLAP: PG9.0–19 Beta 3 = 10min (dcs); CRIT: PG9.0–19 Beta 3 = 10min (dcs); TINY: PG9.0–19 Beta 3 = 10min (dcs). Advice, pending human review — Editorial interpretation, pending human maintainer review: the override appears intended to favor bounded read continuity while a standby catches up from archived WAL; confirm it against the current Pigsty templates, hardware fixture, and operational guarantees before publication.
Common pitfalls
- Changing it on the wrong primary, standby, sender, or subscriber role.
- Watching only configured bytes/time instead of actual lag, slot position, and worker state.
- Failing over to a node that lacks the old primary’s capacity or prerequisites.
- Using infinite waits or WAL retention to hide a failed consumer.
Related parameters
max_standby_streaming_delay · hot_standby · hot_standby_feedback · recovery_min_apply_delay · primary_conninfo · primary_slot_name
References
- PostgreSQL 19 Beta 3 — max_standby_archive_delay
- PostgreSQL 19 release notes
- Machine-readable GUC export