---
title: "Consistency is not a localized property"
slug: consistency-is-not-a-localized-property
url: https://listedarticles.com/articles/consistency-is-not-a-localized-property
canonical_url: https://n-the-loop.com/blog/consistency-is-not-a-localized-property/
content_type: essay
language: en
published_at: 2026-10-06T00:00:00.000Z
updated_at: 2026-10-11T02:08:40.969Z
authored_by: human
publisher: "N The Loop"
publisher_url: https://n-the-loop.com/
topics: ["Distributed Systems", "Software Engineering"]
license: all-rights-reserved
word_count: 305
reading_minutes: 1
citation: "N The Loop. \"Consistency is not a localized property.\" 6 Oct 2026. https://n-the-loop.com/blog/consistency-is-not-a-localized-property/ (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# Consistency is not a localized property

> A short N The Loop essay using Kafka's years-long exactly-once effort, which still needed redesign eight years later, to argue that consistency is an end-to-end property no single component can guarantee, so someone must understand and own the whole system rather than trusting machines to hold it.

# Consistency is not a localized property

Oct 6, 2026

It is a common pattern for developers to assume that consistency is
something they can achieve inside a single component. Apache Kafka is
the cautionary tale. Making writes exactly-once took a team of
distributed systems engineers years and several new components and a
complete rewrite of older components (Gustafson et al. 2016).1

And after all of that, the people who built it are blunt about what you
get:

> Exactly-once processing is an end-to-end guarantee and the application
> has to be designed to not violate the property as
> well.(Narkhede and Wang 2017)

If the component cannot promise the property, the promise has to live
somewhere else. Two practical consequences:

* Someone has to **understand** the system end to end. Since no component
  can confirm it, something outside the components has to keep it all
  consistent.
* Someone has to **own** it. Component owners will each correctly say
  their part works. A global property needs a person who is liable for
  the whole thing, with some guarantee that it makes sense.

The lesson: do not hand global, valuable properties to machines and
assume they are held. Such guarantees are grounded in understanding, not
code.

## References

Gustafson, Jason, Flavio Junqueira, Apurva Mehta, Sriram Subramanian, and Guozhang Wang. 2016. “KIP-98: Exactly Once Delivery and Transactional Messaging.” Apache Software Foundation. 2016. <https://cwiki.apache.org/confluence/display/KAFKA/KIP-98+-+Exactly+Once+Delivery+and+Transactional+Messaging>.

Narkhede, Neha, and Guozhang Wang. 2017. “Exactly-Once Semantics Are Possible: Here’s How Kafka Does It.” Confluent. 2017. <https://www.confluent.io/blog/exactly-once-semantics-are-possible-heres-how-apache-kafka-does-it/>.

Olshan, Justine, and Calvin Liu. 2022. “KIP-890: Transactions Server-Side Defense.” Apache Software Foundation. 2022. <https://cwiki.apache.org/confluence/display/KAFKA/KIP-890:+Transactions+Server-Side+Defense>.

---

1. Eight years after it shipped, the protocol still had to be redesigned to close correctness holes that could `violate EOS` (Olshan and Liu 2022). ↩︎
