Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose an Elixir supervision strategy by deciding how much of a child group must be restarted to recover safely. Use :one_for_one when children recover independently, :rest_for_one when later-started children depend on earlier ones, and :one_for_all when the children must be reset together. These are design heuristics based on each strategy’s documented restart scope—not rules enforced by Elixir.

How the three strategies differ

For an unsuccessful termination that is eligible for a restart, the strategy determines which children the supervisor restarts. The Elixir v1.20.2 Supervisor documentation defines the scopes as follows:

Strategy What the supervisor restarts When it fits Trade-off
:one_for_one Only the terminated child. Children are independent or can remain valid while one child recovers. If children share state or depend on each other, restarting only one may leave the group inconsistent.
:rest_for_one The terminated child and children started after it. Later children depend on earlier children, so a failure invalidates the failed child and its downstream dependents. Child-list order affects recovery; a poor ordering can restart too much or too little.
:one_for_all All other children are terminated, then the full group, including the failed child, is restarted. The children need to initialize together to restore shared state or a coordinated session. A local failure can interrupt otherwise healthy work.

The documentation clarifies: “In the above, process termination refers to unsuccessful termination, which is determined by the :restart option.” In other words, strategy scope applies only when the child’s restart policy makes the termination eligible.

Choose the restart scope from dependencies

Map the processes supervised together and ask whether each can recover while its siblings remain untouched. The dependency-based guidance below follows from the documented restart behavior; Elixir does not infer the dependencies for you.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Use :one_for_one for independent workers when restarting one process is enough to restore service.
  2. Use :rest_for_one when later-started children rely on earlier children and a failure should reset that child and its downstream dependents.
  3. Use :one_for_all when independently restarting a failed child could leave shared state or a coordinated session invalid or mismatched.

If no strategy gives a safe recovery boundary, reconsider which children belong under the same supervisor or how they share state. A strategy controls restart scope; it does not make an unsafe dependency arrangement consistent.

Order children carefully with :rest_for_one

Supervisors start children in the order they are listed and shut them down in reverse order. Under :rest_for_one, the failed child and the children listed after it form the restart tail. Arrange the list to reflect real dependencies: children a process relies on should start before it. Review this order as part of code review because changing it changes recovery behavior.

Check restart eligibility separately

Each child specification has a :restart policy that determines whether its termination is restart-eligible:

  • :permanent restarts after any termination.
  • :temporary is never restarted.
  • :transient restarts only after abnormal termination.

These policies determine whether a child is restarted; the supervisor strategy determines the scope when a restart is called for. Setting a broad strategy does not override a child’s restart policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep restart intensity and shutdown settings in view

Restart scope is only one part of supervisor behavior. The Elixir v1.20.2 documentation lists defaults of :max_restarts equal to 3 and :max_seconds equal to 5 seconds. These are configuration defaults, not recommendations or performance measurements. Review restart intensity alongside the chosen strategy, particularly when repeated failures could exceed the permitted limit. Shutdown behavior is another separate operational setting; neither setting changes the basic scope described above.

The same documentation lists :auto_shutdown values :never, :any_significant, and :all_significant. This setting concerns shutting down a supervisor when significant children exit; it is distinct from the three restart strategies, and significant-child behavior also depends on child restart settings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use current child-specification and supervisor APIs

Child specifications describe how each child starts, stops, and restarts. For new code, use the current child specification and Supervisor APIs documented for your Elixir version. The legacy Supervisor.Spec helpers, including supervise/2, are marked deprecated in the Elixir v1.19.3 documentation.

If the application needs an evolving population of children rather than a statically listed group, consult DynamicSupervisor. Dynamic supervision is a separate design question from choosing among these three static strategy values.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.