Area: ingest / dedupe — availability
When the dedupe backend is unavailable, ingest for tables with dedupe enabled returns 503 with Retry-After (tables without dedupe are unaffected). The events are not accepted, so a client that cannot retry loses them.
Idea: accept events durably during a dedupe outage instead of refusing them — for example, park them on a side queue (or publish them marked "unchecked") and run them through dedupe once the backend is back, before they reach ClickHouse. Design questions: ordering against later events with the same id, how long parked events may wait, what a client's 200 promises in that mode, and whether it is per-tenant opt-in.
Part of #613.
Area: ingest / dedupe — availability
When the dedupe backend is unavailable, ingest for tables with dedupe enabled returns
503withRetry-After(tables without dedupe are unaffected). The events are not accepted, so a client that cannot retry loses them.Idea: accept events durably during a dedupe outage instead of refusing them — for example, park them on a side queue (or publish them marked "unchecked") and run them through dedupe once the backend is back, before they reach ClickHouse. Design questions: ordering against later events with the same id, how long parked events may wait, what a client's
200promises in that mode, and whether it is per-tenant opt-in.Part of #613.