← Engineering notes

Why an Outbox Is Still At-Least-Once

A transactional outbox closes one dangerous gap: business state cannot commit locally while the intent to publish its event disappears. It does not make delivery exactly once.

The remaining instruction window

CommerceCore commits the business fact and an outbox row in the same PostgreSQL transaction. A publisher later sends that fact to Kafka. If Kafka accepts the event and the publisher crashes before recording completion, the row will be retried.

Kafka accepted event
publisher did not record completion
publisher restarts
event is sent again

There is no missing event, but there may be a duplicate.

Contain the duplicate

CommerceCore gives events durable identity and makes downstream business transitions idempotent. Webhook receipts use the same approach. The transport is allowed to redeliver; the state transition is not allowed to happen twice.

The outbox changed what I ask of messaging guarantees. The useful claim is not that every event appears once. It is that a committed fact remains publishable, and repeated delivery does not repeat the business effect.


Related project: CommerceCore →