Change Data Capture Pipeline  ·  View 15 of 21  ·  Runtime

Schema Drift — Four Paths

Five change classes, two of which stop exactly one table and nothing else.

Editable source SVG draw.io All views
Detect Classify Pipeline action Sink action Outcome Added nullable column Relation metadata from the stream Compatible Register new version effective LSN Additive DDL before first event No pause ≤ 60 s New table in allow-list Registry change Compatible Chunked snapshot view 14 Create sink table Live after backfill Dropped or renamed column DDL event Breaking Pause this table only ≤ 10 s Sink untouched no destructive DDL Operator decision resume from position Primary-key change DDL event Breaking Re-snapshot required keys no longer match Shadow then swap Rebuild, not migrate Unregistered column seen Decode mismatch Not a third option Propagate or exclude never silently drop Evolve or ignore Explicit either way Schema Drift — Four Changes, Four Paths Only the breaking rows stop anything, and they stop exactly one table. v 1.0 · owner Data Platform Architecture · date 2026-10

Decisions

  • Compatible changes propagate without a human; breaking ones pause one table and raise a decision (ADR-08).
  • A primary-key change is a re-snapshot, not a migration: the sink's keys no longer mean what they meant.
  • There is no third outcome for an unregistered column — propagate it or exclude it by allow-list. Silently dropping it is the failure this row exists to forbid.

Numbers

  • Compatible change propagates within 60 s; breaking change pauses within 10 s (assumptions).
  • A pause holds the table's position; the platform refuses a pause that would outlive source log retention.

Risks

  • Classification is the single point of judgement in the pipeline: a widened type misread as narrowed pauses needlessly, and the reverse corrupts a sink.
  • Detection depends on the source emitting decodable relation metadata; a source that does not is a polling fallback and loses this whole view.