Change Data Capture Pipeline · View 18 of 21 · Operations
Why a loop
- A sink is never repaired in place. Divergence or a bad transform sends it back to rebuild, and rebuild is the same code path as the original backfill (ADR-11).
- The swap is atomic into a shadow table, so a rebuild never serves partial state.
- Retirement is on the loop deliberately: a sink nobody reads is a cost with a tenant-data footprint.
Assumptions
- Every tier-1 table's largest sink is rebuilt from the archive quarterly and diffed against live, so the 8-hour rebuild figure is measured rather than hoped.
- Verification is daily for tier-1, weekly for tier-2.
Risks
- A rebuild competes with live apply for sink write capacity; the MVP throttles it rather than scheduling it, which is the cruder of the two options.