{"article":{"slug":"consistency-is-not-a-localized-property","title":"Consistency is not a localized property","subtitle":null,"summary":"A short N The Loop essay using Kafka's years-long exactly-once effort, which still needed redesign eight years later, to argue that consistency is an end-to-end property no single component can guarantee, so someone must understand and own the whole system rather than trusting machines to hold it.","content_type":"essay","language":"en","canonical_url":"https://n-the-loop.com/blog/consistency-is-not-a-localized-property/","author":{"name":null,"url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"N The Loop","url":"https://n-the-loop.com/","listing_slug":null,"listing":null},"topics":[{"name":"Distributed Systems","slug":"distributed-systems","url":"https://listedarticles.com/topics/distributed-systems"},{"name":"Software Engineering","slug":"software-engineering","url":"https://listedarticles.com/topics/software-engineering"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":305,"reading_minutes":1,"published_at":"2026-10-06T00:00:00.000Z","added_at":"2026-10-11T02:08:40.969Z","updated_at":"2026-10-11T02:08:40.969Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/consistency-is-not-a-localized-property","markdown_url":"https://listedarticles.com/articles/consistency-is-not-a-localized-property.md","example":false,"citation":"N The Loop. \"Consistency is not a localized property.\" 6 Oct 2026. https://n-the-loop.com/blog/consistency-is-not-a-localized-property/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://n-the-loop.com/blog/consistency-is-not-a-localized-property/"},"body_markdown":"# Consistency is not a localized property\n\nOct 6, 2026\n\nIt is a common pattern for developers to assume that consistency is\nsomething they can achieve inside a single component. Apache Kafka is\nthe cautionary tale. Making writes exactly-once took a team of\ndistributed systems engineers years and several new components and a\ncomplete rewrite of older components (Gustafson et al. 2016).1\n\nAnd after all of that, the people who built it are blunt about what you\nget:\n\n> Exactly-once processing is an end-to-end guarantee and the application\n> has to be designed to not violate the property as\n> well.(Narkhede and Wang 2017)\n\nIf the component cannot promise the property, the promise has to live\nsomewhere else. Two practical consequences:\n\n* Someone has to **understand** the system end to end. Since no component\n  can confirm it, something outside the components has to keep it all\n  consistent.\n* Someone has to **own** it. Component owners will each correctly say\n  their part works. A global property needs a person who is liable for\n  the whole thing, with some guarantee that it makes sense.\n\nThe lesson: do not hand global, valuable properties to machines and\nassume they are held. Such guarantees are grounded in understanding, not\ncode.\n\n## References\n\nGustafson, Jason, Flavio Junqueira, Apurva Mehta, Sriram Subramanian, and Guozhang Wang. 2016. “KIP-98: Exactly Once Delivery and Transactional Messaging.” Apache Software Foundation. 2016. <https://cwiki.apache.org/confluence/display/KAFKA/KIP-98+-+Exactly+Once+Delivery+and+Transactional+Messaging>.\n\nNarkhede, Neha, and Guozhang Wang. 2017. “Exactly-Once Semantics Are Possible: Here’s How Kafka Does It.” Confluent. 2017. <https://www.confluent.io/blog/exactly-once-semantics-are-possible-heres-how-apache-kafka-does-it/>.\n\nOlshan, Justine, and Calvin Liu. 2022. “KIP-890: Transactions Server-Side Defense.” Apache Software Foundation. 2022. <https://cwiki.apache.org/confluence/display/KAFKA/KIP-890:+Transactions+Server-Side+Defense>.\n\n---\n\n1. Eight years after it shipped, the protocol still had to be redesigned to close correctness holes that could `violate EOS` (Olshan and Liu 2022). ↩︎\n","body_html":"<h1 id=\"consistency-is-not-a-localized-property\">Consistency is not a localized property</h1>\n<p>Oct 6, 2026</p>\n<p>It is a common pattern for developers to assume that consistency is\nsomething they can achieve inside a single component. Apache Kafka is\nthe cautionary tale. Making writes exactly-once took a team of\ndistributed systems engineers years and several new components and a\ncomplete rewrite of older components (Gustafson et al. 2016).1</p>\n<p>And after all of that, the people who built it are blunt about what you\nget:</p>\n<blockquote><p>Exactly-once processing is an end-to-end guarantee and the application\nhas to be designed to not violate the property as\nwell.(Narkhede and Wang 2017)</p></blockquote>\n<p>If the component cannot promise the property, the promise has to live\nsomewhere else. Two practical consequences:</p>\n<ul><li><p>Someone has to <strong>understand</strong> the system end to end. Since no component</p><p>can confirm it, something outside the components has to keep it all\nconsistent.</p></li><li><p>Someone has to <strong>own</strong> it. Component owners will each correctly say</p><p>their part works. A global property needs a person who is liable for\nthe whole thing, with some guarantee that it makes sense.</p></li></ul>\n<p>The lesson: do not hand global, valuable properties to machines and\nassume they are held. Such guarantees are grounded in understanding, not\ncode.</p>\n<h2 id=\"references\">References</h2>\n<p>Gustafson, Jason, Flavio Junqueira, Apurva Mehta, Sriram Subramanian, and Guozhang Wang. 2016. “KIP-98: Exactly Once Delivery and Transactional Messaging.” Apache Software Foundation. 2016. <a href=\"https://cwiki.apache.org/confluence/display/KAFKA/KIP-98+-+Exactly+Once+Delivery+and+Transactional+Messaging\" rel=\"nofollow ugc noopener\">https://cwiki.apache.org/confluence/display/KAFKA/KIP-98+-+Exactly+Once+Delivery+and+Transactional+Messaging</a>.</p>\n<p>Narkhede, Neha, and Guozhang Wang. 2017. “Exactly-Once Semantics Are Possible: Here’s How Kafka Does It.” Confluent. 2017. <a href=\"https://www.confluent.io/blog/exactly-once-semantics-are-possible-heres-how-apache-kafka-does-it/\" rel=\"nofollow ugc noopener\">https://www.confluent.io/blog/exactly-once-semantics-are-possible-heres-how-apache-kafka-does-it/</a>.</p>\n<p>Olshan, Justine, and Calvin Liu. 2022. “KIP-890: Transactions Server-Side Defense.” Apache Software Foundation. 2022. <a href=\"https://cwiki.apache.org/confluence/display/KAFKA/KIP-890:+Transactions+Server-Side+Defense\" rel=\"nofollow ugc noopener\">https://cwiki.apache.org/confluence/display/KAFKA/KIP-890:+Transactions+Server-Side+Defense</a>.</p>\n<hr />\n<ol><li>Eight years after it shipped, the protocol still had to be redesigned to close correctness holes that could <code>violate EOS</code> (Olshan and Liu 2022). ↩︎</li></ol>","headings":[{"level":1,"text":"Consistency is not a localized property","id":"consistency-is-not-a-localized-property"},{"level":2,"text":"References","id":"references"}]}}