Change Data Capture Pipeline · View 21 of 21 · Assurance
The pattern
- Eight of nine classes are contained to one event, one table or one sink. Only a regional outage has a whole-pipeline radius (ADR-15).
- Every recovery is resume, replay, rebuild or re-snapshot. A class whose recovery is a human writing an UPDATE is a design defect, not an incident.
- Two classes carry a correctness risk that detection alone does not remove: a truncated log and a source failover timeline.
Assumptions
- Zero acknowledged-change loss; duplicate rate ≤ 0.1% of delivered events.
- Per-row commit ordering preserved 100%; no ordering guarantee is offered across rows or tables.
The honest gap
- A bad transform is detected by reconciliation, which means it is detected in hours rather than seconds — the cheapest improvement available to this design is reconciliation coverage, not faster capture.