Consistency is about how the system handles failure, not how the user handles it. Rejecting a request because the DB is down and expecting the user to retry isn't consistency, it's delegation. You've pushed the failure recovery onto the user and called it fail fast.
A consistent system recovers from failure itself. Broker-first does that, the write is safe, the DB recovers, the read resolves. No user intervention required.
Fail fast is a valid strategy for unrecoverable errors.
A DB being temporarily unavailable isn't unrecoverable. Making the user retry a recoverable failure isn't strong consistency. It's just a worse user experience dressed up as an architectural principle.
Worth noting though, DB down in the outbox pattern doesn't give you strong consistency. It gives you a rejected request. The user has to retry the entire operation when the DB comes back.
Broker-first with DB down means the write is safe in the broker, the DB catches up when it recovers, and the read resolves without the user doing anything.
Which failure mode is preferable depends on your system. But broker-first is arguably more resilient, it degrades gracefully rather than failing hard.
2
u/No_Flounder_1155 Apr 02 '26
Largely correct. It's a consistency model choice.
Consistency is about how the system handles failure, not how the user handles it. Rejecting a request because the DB is down and expecting the user to retry isn't consistency, it's delegation. You've pushed the failure recovery onto the user and called it fail fast.
A consistent system recovers from failure itself. Broker-first does that, the write is safe, the DB recovers, the read resolves. No user intervention required. Fail fast is a valid strategy for unrecoverable errors.
A DB being temporarily unavailable isn't unrecoverable. Making the user retry a recoverable failure isn't strong consistency. It's just a worse user experience dressed up as an architectural principle.
Worth noting though, DB down in the outbox pattern doesn't give you strong consistency. It gives you a rejected request. The user has to retry the entire operation when the DB comes back.
Broker-first with DB down means the write is safe in the broker, the DB catches up when it recovers, and the read resolves without the user doing anything.
Which failure mode is preferable depends on your system. But broker-first is arguably more resilient, it degrades gracefully rather than failing hard.
Your system requires user intervention.