ContentsThe library

Moving Data Without Losing Any

Run It Twice on Purpose and See What Breaks

Last timeAt Least Once, At Most Once

If the transport can deliver twice, the destination has to not care. Three techniques do this, they cost almost nothing, and one of them is wrong for your case.

What safe to repeat means

The last lesson ended somewhere specific. The transport will deliver at least

once, which means it will sometimes deliver twice, and no amount of work on the

transport changes that. So the work moves to the destination, and the property

the destination needs is this: running the step twice leaves the system in the

same state as running it once.

Three words in that sentence are doing real work.

State, not return value. The second delivery may well return something

different, perhaps a note saying it was already applied, and that is fine. What

must not differ is what anybody looking at the data afterwards can see.

Same, not similar. A total that is right to the penny after one delivery and

wrong by one unit after two is not safe to repeat. The property is exact or it

is absent.

And twice includes every number above twice. A retry loop with a bad timeout can

deliver the same message eleven times, and a step that survives two deliveries

and not eleven has not been made safe, only made lucky.

FIG 1The error a repeated step leaves behind
the error in the stored total
how many times the message was delivered
the value the message carried
For an operation that adds, the error grows with every extra delivery and never corrects itself. For one that sets, v is effectively zero and the formula collapses, which is the whole difference between the two shapes. Note what this says about discovery: the error is proportional to the value, so the duplicates that matter most are the ones that are hardest to spot in a total.

The easy ones and the hard ones

Operations sort into three groups, and the sorting rule is whether the result

depends on what was there before.

Setting a value is already safe. Store the temperature as 21 degrees and store

it again and it is 21 degrees. Nothing needs doing, and a surprising share of a

pipeline turns out to be of this shape once the messages carry the full new

value rather than a change to the old one.

Adding is not safe. Add 40 to the balance twice and the balance is wrong by 40,

and the amount of wrongness is exactly the thing that will be noticed and

exactly the thing nobody can reconstruct six weeks later.

And then the hard group: anything whose effect leaves your system. An email to

a customer. A charge on a card. A message to a device that opens a door. These

cannot be made safe by anything you write, because the thing that would have to

remember is somebody else's.

FIG 2Operations by shape, with what each one needs
already safeneeds a remembered keyneeds a state ruledepends on someone else
store a reading1000
add to a running total0100
replace a profile1000
increment a counter0100
advance an order to ship0010
email a receipt0001
charge a card0001
The first column needs no work at all, which is why rewriting a message to carry the full value instead of a change is often the cheapest fix available. The marked rows are the ones no technique in this lesson closes, and the next section says what to do about them.

For the last group there is still something to do, and it is worth saying

before the techniques, because it changes what you build. Ask whether the far

end will accept a key of your choosing and refuse to act twice on it. Payment

providers do. Several messaging services do. Where the answer is yes, the hard

case collapses into the easy one and the far end does the remembering. Where the

answer is no, the honest design is to record locally that you sent it, before

sending, and accept that a crash between the record and the send loses the

message rather than duplicating it: at most once, chosen deliberately, for the

one step where a duplicate is worse than a loss.

The lesson stops here

2 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Nothing Crashed, Nothing Alerted, and the Total Is Short by Nine Hundred
  2. 02The Sender Cannot Tell Which Half of the Journey Failedopening only
  3. 03Run It Twice on Purpose and See What Breaksyou are here
  4. 04Two Writes, and the Order Between Them Is the Whole Designopening only
  5. 05The Row Was Saved at 10:04 and Became Visible at 10:06opening only
  6. 06Start the Stream Before You Read the Old Rowsopening only
  7. 07Tuesday's Number Arrived on Friday and Tuesday Is Already Publishedopening only
  8. 08The Check Takes Four Minutes a Day and Almost Nobody Runs Itopening only

Read alongside