Message Passing - Senior¶
Production correctness includes duplicates, loss, reordering, poison messages, backpressure, and partial failure.
flowchart LR
Receive --> Validate
Validate -->|valid| Effect[Idempotent effect]
Validate -->|bad| DLQ[Quarantine]
Effect --> Ack
Effect -->|transient failure| Retry[Bounded retry with jitter]
| Decision | Safe default |
|---|---|
| Retry | bounded exponential backoff with jitter |
| Poison event | quarantine with reason and replay tool |
| Schema change | backward-compatible reader-first rollout |
| Overload | bounded queues and upstream flow control |
| Cross-service workflow | saga with explicit compensation |
For CDC, preserve source position and transaction identity. Do not let a DLQ silently break entity ordering. Test broker restart, consumer crash after effect but before acknowledgement, and schema rollback.
Continue to professional.md.
Test yourself¶
- How do you recover from a crash between effect and acknowledgement?
- When can a DLQ violate ordering?
- What limits a retry storm?