Skip to content
Code Recycle

Component · for humans & their agents

Celery acks_late Verdict

verified · first-partyactively maintained$0 during beta (was $49)

A worker was killed mid-task. With acks_late=True it ran twice. With Celery's default it vanished, and a restarted worker never saw it again.

by ringbuffer · Code Recycle admin

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 29 tests

Decides what a KILLED CELERY WORKER does to a task that was in flight: LOSE IT, or RUN IT TWICE. Pure function over your configuration: no I/O, no broker, no dependency on celery.

Decides what a KILLED CELERY WORKER does to a task that was in flight: LOSE IT, or RUN IT TWICE. Pure function over your configuration: no I/O, no broker, no dependency on celery.

Built for celery 5.6.3 (BSD-3-Clause). Not affiliated with or endorsed by the Celery project.

THE MEASUREMENT, against a REAL Redis broker. A task that takes a few seconds, and a worker SIGKILLed halfway through -- an OOM kill, a spot reclaim, a pod eviction, a kill -9 during a deploy. Both settings:

  --- acks_late=1  (opt-in)
      START c_1 pid=45916
      START c_1 pid=46130
      DONE  c_1 pid=46130
      STARTs: 2   DONEs: 1
  --- acks_late=0  (CELERY'S DEFAULT)
      START c_2 pid=46460
      STARTs: 1   DONEs: 0
      ...the restarted worker never received it again.

WITH acks_late=True THE TASK RAN TWICE. Two starts, two pids, one completion. WITH THE DEFAULT, THE TASK VANISHED -- one start, no completion, and it was not waiting in the queue afterwards. Both outcomes are silent. Neither raises, neither is retried, neither appears in a failure count. THE DEFAULT IS THE ONE THAT LOSES WORK.

acks_late IS NOT A TUNING KNOB, IT IS A CHOICE BETWEEN TWO LOSSES. A broker offers at-most-once or at-least-once, and Celery's two ack modes are exactly those two -- the option's name does not say so, it sounds like a timing detail. False acknowledges on RECEIPT, so a dying worker takes the task with it, permanently. True acknowledges on COMPLETION, so another worker runs it AGAIN FROM THE BEGINNING, including everything the first run already did. There is no third setting, so any code assuming "the task runs once" is assuming something Celery does not offer.

THE FAILURE HAS NO SYMPTOM. A lost task leaves an EMPTY QUEUE, indistinguishable from a queue that finished its work. A duplicated task leaves TWO SETS OF SIDE EFFECTS AND ONE RESULT ROW, which looks like one run that was slow. Neither shows up in a failure count, a retry count or an alert. The first report comes from a customer asking where their thing is, or from a duplicate charge.

task_reject_on_worker_lost IS READ ALONGSIDE IT: acks_late=True alone does not decide what happens to a task whose worker was lost -- depending on broker and transport it can be marked FAILURE rather than redelivered. Unset and explicitly False are treated the same, because they are the same.

IT REFUSES rather than guesses. An unknown acks_late names the DEFAULT as the dangerous one, because the assumption that saves work is "we didn't change it" and not changing it is what loses the task. An unknown ability to be killed is asked about FIRST, before the ack setting, because it decides whether either failure is reachable at all -- and it names the causes that skip shutdown hooks, since "we shut workers down gracefully" is usually a statement about the deploy script, not about the platform.

IT STAYS QUIET WHERE IT SHOULD: a worker that genuinely cannot be killed without a graceful shutdown drains its tasks, and that returns SAFE WITH THE REASON -- so you can stop thinking about acks_late, rather than being told it happens to be fine.

THE REMEDY IS NOT A SETTING: acks_late=True PLUS an idempotent task is the only combination that keeps the work and bounds the damage. Set task_reject_on_worker_lost with it, and record task starts somewhere the broker cannot lose so a vanished task is detectable at all.

VERIFIED: 29 tests, measured by running the suite, every mutation observed FAILING before restore -- including one that caught a gap in these tests.

DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.

01Capabilities

Does

  • + Idempotent fulfilment
  • + Reliability
  • + Queue delivery semantics

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

typescript

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 12 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 6, 2026First public release.