Change Data Capture Pipeline · View 16 of 21 · Operations
Decisions
- Single capture region. Active-active capture would mean two readers of one replication slot, which is a correctness problem rather than a capacity one (ADR-15).
- The standby holds no state: it resumes from the last committed log position in Spanner, which is why control state is regional-durable and separate.
- BigQuery in EU multi-region and the archive dual-region, because the derived data is where residency obligations are actually read.
Numbers
- RTO 5 minutes in-region, 30 minutes cross-region; RPO 0 relative to the source log position (assumptions).
- Capture availability ≥ 99.9% monthly per source stream; control plane ≥ 99.5%.
Risks
- A source failover changes the log-position timeline; comparing positions across it is the subtlest correctness trap in the design (ADR-15, view 21).
- The standby is exercised only if it is exercised: an untested failover is an assumption, not an RTO.