N The Loop

Consistency is not a localized property

Oct 6, 2026

It is a common pattern for developers to assume that consistency is something they can achieve inside a single component. Apache Kafka is the cautionary tale. Making writes exactly-once took a team of distributed systems engineers years and several new components and a complete rewrite of older components (Gustafson et al. 2016).1

And after all of that, the people who built it are blunt about what you get:

Exactly-once processing is an end-to-end guarantee and the application has to be designed to not violate the property as well.(Narkhede and Wang 2017)

If the component cannot promise the property, the promise has to live somewhere else. Two practical consequences:

The lesson: do not hand global, valuable properties to machines and assume they are held. Such guarantees are grounded in understanding, not code.

References

Gustafson, Jason, Flavio Junqueira, Apurva Mehta, Sriram Subramanian, and Guozhang Wang. 2016. “KIP-98: Exactly Once Delivery and Transactional Messaging.” Apache Software Foundation. 2016. https://cwiki.apache.org/confluence/display/KAFKA/KIP-98+-+Exactly+Once+Delivery+and+Transactional+Messaging.
Narkhede, Neha, and Guozhang Wang. 2017. “Exactly-Once Semantics Are Possible: Here’s How Kafka Does It.” Confluent. 2017. https://www.confluent.io/blog/exactly-once-semantics-are-possible-heres-how-apache-kafka-does-it/.
Olshan, Justine, and Calvin Liu. 2022. “KIP-890: Transactions Server-Side Defense.” Apache Software Foundation. 2022. https://cwiki.apache.org/confluence/display/KAFKA/KIP-890:+Transactions+Server-Side+Defense.

  1. Eight years after it shipped, the protocol still had to be redesigned to close correctness holes that could violate EOS (Olshan and Liu 2022). ↩︎

← All posts