Change Data Capture Pipeline · View 08 of 21 · Structure
Decisions
- Control state lives in Spanner, apart from every projection: a few million exact rows and billions of rebuildable ones have different recovery stories (ADR-14).
- One Dataflow job per sink, each with its own offset, so a sink's failure is a sink's failure.
- The rebuild runner is a first-class component, not a script: rebuild is the primary recovery path for every sink (ADR-11).
Stack
- Datastream for log-based capture; Pub/Sub for the change log; Dataflow for transform and apply; Cloud Run for the operator API; Spanner for control state.
- The requirement stays vendor-neutral: every one of these has an equivalent on two other clouds and in open source (see the stack table).
Omitted
- Search and fan-out sink edges, Secret Manager and IAM into capture, and all metrics edges.