Message Delivery Guarantees Lab (Interactive)
Push events through a flaky broker under three ack contracts and tally loss versus duplicates. Choose at-most-once, at-least-once, or exactly-once semantics, then inject broker loss and consumer crashes to count lost messages, duplicate processing, and added latency.
Delivery Semantics Pipeline
Send 24 payment events through a flaky broker. Pick the acknowledgment contract and watch loss, duplicates, and latency move together — exactly-once delivery is a myth; exactly-once processing is engineering.
Producer
24
sent
Broker
0
no silent drops
Consumer
31
clean
- Messages lost
- 0
- Duplicates
- 0
- Ledger balance errors
- 0
- Added latency
- 2–5 ms per broker ack
At-most-once skips broker acks, so a crashed producer loses buffered messages. At-least-once re-delivers after failures, so a consumer that crashed mid-processing sees the message twice — a naive consumer double-charges, an idempotent one dedupes. Exactly-once (Kafka transactions) only guarantees one effect inside the broker log; once you leave the log for a payment gateway, you are back to idempotency keys.
How It Works Under the Hood
Delivery guarantees are promises about acknowledgments, and each costs something: at-most-once never re-sends so a crash before processing silently deletes the message; at-least-once re-sends until acknowledged, so a consumer that dies after side effects but before ack replays them — duplicates are the price of never losing anything. Kafka-style exactly-once extends the transaction to offset commits inside the log, guaranteeing one effect for stream processing but not for anything downstream of the broker. This lab runs a batch of payments through each contract and reports loss, duplicates, and ledger balance errors side by side.
Core Architectural Principles
- Ack model per semantics: fire-and-forget loss versus redelivery-until-commit duplication.
- Consumer crash before offset commit produces redelivery — idempotent consumers absorb it.
- Exactly-once transactions remove in-log duplicates but not the need for downstream idempotency.
Say “exactly-once delivery is a lie; we engineer exactly-once processing with at-least-once delivery plus idempotent consumers” and give the mechanism: dedupe by message or business key, transactional outbox, or Kafka EOS for log-internal jobs. Tie the latency cost of waiting for acks to your SLO.
Stronger delivery contracts cut silent loss but add acknowledgment latency and force deduplication work.