True realtime search — a document is searchable the moment its
write is acknowledged; there is no refresh and no near-real-time
window. See
How realtime works.
Write-ahead logging — local file WAL by default (Kafka-backed
optional), with configurable durability (strict / batched /
async) and crash-safe restart replay.
Partial update — deep-merge doc bodies plus an ordered ops
operator list (incr, append, rename, current_date, …), applied
atomically under optimistic concurrency control.
In-place columns — "inplace": true numeric/boolean fields get
O(1) column writes on a fast lane, independent checkpoints, and
block-summary query pruning. See
In-place columns.
Rolling-based sharding — collections partition into fixed-capacity
rollings (4.2B docs each) that roll over automatically; infinite
growth without reindexing. See
Why named Pizza.
Online resharding — change a rolling’s shard count while every
read and write keeps being served; documents keep their _id
throughout, with a progress/status/events API.
Replication — Raft-replicated metadata, per-rolling replica
counts, shard failover and re-allocation, and value-level replication
of fast-lane inplace updates.
Full-text and term queries — match, match_phrase,
query_string, bool, terms, exists, ranges, regexps, fuzzy,
wildcard, spans, and more (see the
search reference).
Geo, vector and relational queries — geo_bounding_box,
geo_distance, vector (kNN) similarity, nested documents, join and
graph traversal.
Semantic search — server-side text→vector inference through
external OpenAI-compatible embedding services: vector fields mapped
with source + model derive vectors at write time, queries accept
plain text, and the semantic query needs no field knowledge at all.
Hybrid search (BM25 + vector, RRF or linear fusion) ships natively
and through the ES retriever/knn syntaxes; point-in-time reads
pin consistent views for deep pagination.
Aggregations — metric, bucket and pipeline aggregations
(see the
aggregation reference).
Analysis — pluggable analyzers, per-collection custom analyzer
definitions, and an
analysis workbench API.
Elasticsearch syntax tolerance — common ES request bodies are
accepted as-is, easing migration.
API-key authentication with RBAC roles (platform_admin,
operator, monitor, namespace_admin, read_write, read_only),
Raft-replicated key minting/revocation, and a bootstrap-key flow. See
Security.
Runtime settings — region (cluster-wide, Raft-replicated) and
node-level settings tunable without restart, including a dynamic log
level; layered scope precedence with collection and rolling settings.
Manual maintenance — collection-wide and per-shard compaction,
epoch roll/flush, batch flush tasks, all observable via node APIs.
Observability — cluster health/state, node recovery and build
backlog, per-shard storage inspection, search slowlog and audit, and
a built-in web console with a FIRE storage explorer. See
Node observability.
CDC change feed — poll /_changes to replicate data to external
systems. See
Change feed (CDC).
Trash (recycle bin) — deleted data survives a retention window
and can be restored.
Cluster admission — join tokens for controlled node admission,
manual node removal, allocation dashboards. See
Cluster management.