Change Data Capture Pipeline · View 05 of 21 · People and journeys
The finding
- The emotional low is not the migration; it is being told afterwards that something downstream paused, and not knowing whether that counts as an outage.
- That turns schema handling into two requirements: detection from the stream itself, and a blast radius of exactly one table (ADR-08).
- A compatible change must propagate with no human in the loop, or engineers will route around replication by avoiding it.
Numbers
- Compatible change propagates within 60 s; breaking change pauses that table within 10 s (assumptions).
- A replication-list check in CI is the cheapest fix for the first phase's pain and is Phase 2 scope, not MVP.
Risks
- A primary-key change looks compatible to a careless classifier and is not: it invalidates every key in the sink (view 15).
- A dropped column that the pipeline silently ignores is the worst outcome of all — correct-looking and wrong.