Change Data Capture Pipeline · View 01 of 21 · Context and scope
Decisions
- The source databases are out of scope and read-only to this platform: capture holds a replication identity with no write privilege.
- Sinks are inside the boundary as projections, but their consumers are not: the pipeline owes them freshness, not query semantics.
- The heartbeat row written into every source database is part of the pipeline, not of the application — it is how lag is measured on an idle table.
Assumptions
- 4,000 tenants across 12 operational PostgreSQL databases and 180 replicated tables.
- 9,000 row changes a second at steady state, 36,000 for 30 minutes during a bulk tenant import.
- Three sink families today — warehouse, search, cache and webhook fan-out; a fourth is expected within a year.
Risks
- The replication slot is a shared fate with the source: an abandoned slot fills the source's disk, which is an application outage caused by this platform.
- Consumers reading the mirror without the as-of field will report staleness as wrongness.