Error handlingmedium3-5 years

A consumer that deserialises a corrupted record enters a crash loop and never reaches its own error-handling code. Why, and how does a dead-letter setup actually fix it?

Deserialisation happens inside poll(), before the consumer's handler code ever runs — so a corrupted record doesn't reach the try/catch around handle() at all; it throws out of poll() itself, the consumer loop catches it, logs, and calls poll() again at the exact same offset, and fails identically. That's the poison-pill crash loop, and it's not rare — one bad producer deploy away. ErrorHandlingDeserializer wraps the real deserialiser, catches the failure inside it, and delivers a record with a null value and the exception stashed in a header instead of throwing — which turns the failure into an ordinary record the error handler can route to a dead-letter topic, after which the consumer commits past it and moves on.

The lesson behind it →