Delivery guaranteessenior8+ years

A team advertises their Kafka pipeline as 'exactly-once end to end.' What does Kafka's exactly-once actually cover, and where does that claim break down?

Kafka's own exactly-once is narrower than the phrase suggests: it covers a consumer reading from Kafka and a producer writing back to Kafka in the same application, using a transactional producer so the output records and the consumed input's offset commit become visible atomically — a crash never produces duplicate output or silently skips input, for that one Kafka-to-Kafka hop. What it does not cover is anything outside Kafka: a database write, an HTTP call, an email send. Those still need an idempotent consumer — a dedupe key stored in the same transaction as the side effect — because "exactly-once" in Kafka means exactly-once between topics, and end to end it's honestly at-least-once delivery with idempotent effects, not a stronger guarantee than that.

The lesson behind it →