Learn Labs
13. A Philosophy of Streaming Systems

13.7 Production failure catalog for this chapter

Production failure catalog
0 rows
SymptomUnderlying mechanism
Database and search index permanently disagreeApp writes to both — neither is "in charge" of ordering
Ex-partner receives the message they shouldn'tCausal dependency lost across two services with no shared order
Ordering ambiguous between two regionsTotal order broadcast doesn't scale past one leader
One failing component takes down the whole systemSynchronous distributed transactions amplify local faults
Schema migration is a terrifying all-or-nothing cutoverNo side-by-side derived views; irreversibility
Reprocessing produces different numbers than the original runNondeterministic derivation (time-dependent join, external call)
Ten pieces of infrastructure, one small team, constant incidentsPremature unbundling — "a form of premature optimization"
$22 transferred instead of $11Non-idempotent transaction + user retry past every dedup layer
Two accounts created with the same usernameUniqueness enforced without consensus, or async multi-leader
Multishard transfer half-appliedNo request-ID dedup, or a nondeterministic processor
Money stuck permanently "reserved"Lost/undelivered downstream event with no sweeper
Credits and debits don't sum to zeroIntegrity violation — permanent, needs explicit repair
Derived store silently drifted from the sourceNo reconciliation / end-to-end integrity check
Backup found to be broken during a real incidentNever restore-tested
Corruption present in every retained backupSilent corruption undetected for longer than the retention window
Uniqueness constraint violated by the database itselfA database bug — MySQL has done this
"Serializable" isolation exhibited write skewA database bug — PostgreSQL has done this
App uses weak isolation unsafely; DB "consistency" meaninglessACID consistency assumes bug-free transactions
Cannot explain why a set of rows changedMutation log without the intent; application logic was transient
UI shows stale data until reloadRead path only; write path never extended to the client