docs(ploeg): propose ADR-0060 durable webhook inbox and publication outbox #185

Merged
ryangr0 merged 1 commit from ryangr0/ploeg-adr-webhook-inbox-and-outbox into development 2026-10-03 12:27:06 +00:00 AGit
Owner

Forge dedup marks a delivery seen before its effects run, so a crash or
error after the insert loses the effects and the honest redelivery is
ignored. GitLab, Vikunja and ClickUp webhooks have no dedup at all, and
requested-changes rows have no unique key. Review findings, budget-stop
notices and tracker write-backs are published best-effort, after the
transition, and nothing retries them once the Shift is closed.

The record proposes a webhook_inbox table (verify, insert, 202; a
SKIP LOCKED worker with backoff and dead letter; content keys for
providers without delivery ids; conflicts surfaced as 409) with
idempotent effects per event kind, and a publication_outbox written in
the lifecycle transaction, delivered with deterministic logical ids and
a remote marker so a crash between send and ack does not duplicate.
It adds metrics and operator API fields for stuck rows, and lists six
owner questions.

Proposed; covers VIK-1727 and VIK-1728. Six owner questions at the end of the ADR. Code facts found while drafting: GitLab webhooks have no dedup at all (only X-Forgejo/X-Gitea-Delivery are read); Vikunja/ClickUp have none either; work_item_reviews, gate_transitions and status_transitions have no unique key, so a redelivered review becomes a second fix round.

Verified with mise run verify on the pinned toolchain (all gates passed).

Ticket: https://vikunja.webgrip.dev/tasks/1727

🤖 Generated with Claude Code

Forge dedup marks a delivery seen before its effects run, so a crash or error after the insert loses the effects and the honest redelivery is ignored. GitLab, Vikunja and ClickUp webhooks have no dedup at all, and requested-changes rows have no unique key. Review findings, budget-stop notices and tracker write-backs are published best-effort, after the transition, and nothing retries them once the Shift is closed. The record proposes a webhook_inbox table (verify, insert, 202; a SKIP LOCKED worker with backoff and dead letter; content keys for providers without delivery ids; conflicts surfaced as 409) with idempotent effects per event kind, and a publication_outbox written in the lifecycle transaction, delivered with deterministic logical ids and a remote marker so a crash between send and ack does not duplicate. It adds metrics and operator API fields for stuck rows, and lists six owner questions. Proposed; covers VIK-1727 and VIK-1728. Six owner questions at the end of the ADR. Code facts found while drafting: GitLab webhooks have no dedup at all (only X-Forgejo/X-Gitea-Delivery are read); Vikunja/ClickUp have none either; work_item_reviews, gate_transitions and status_transitions have no unique key, so a redelivered review becomes a second fix round. Verified with `mise run verify` on the pinned toolchain (all gates passed). Ticket: https://vikunja.webgrip.dev/tasks/1727 🤖 Generated with [Claude Code](https://claude.com/claude-code)
docs(ploeg): propose ADR-0060 durable webhook inbox and publication outbox
Some checks failed
[Workflow] On Pull Request / checks (pull_request) Successful in 11m37s
[Workflow] On Pull Request / release-policy (pull_request) Successful in 33s
[Workflow] On Pull Request / warnings (pull_request) Has been cancelled
28876b5513
Forge dedup marks a delivery seen before its effects run, so a crash or
error after the insert loses the effects and the honest redelivery is
ignored. GitLab, Vikunja and ClickUp webhooks have no dedup at all, and
requested-changes rows have no unique key. Review findings, budget-stop
notices and tracker write-backs are published best-effort, after the
transition, and nothing retries them once the Shift is closed.

The record proposes a webhook_inbox table (verify, insert, 202; a
SKIP LOCKED worker with backoff and dead letter; content keys for
providers without delivery ids; conflicts surfaced as 409) with
idempotent effects per event kind, and a publication_outbox written in
the lifecycle transaction, delivered with deterministic logical ids and
a remote marker so a crash between send and ack does not duplicate.
It adds metrics and operator API fields for stuck rows, and lists six
owner questions.

VIK-1727
VIK-1728
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ryangr0 merged commit bc4bd3ad45 into development 2026-10-03 12:27:02 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/unfold!185
No description provided.