docs(ploeg): propose ADR-0060 durable webhook inbox and publication outbox #185
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/ploeg-adr-webhook-inbox-and-outbox"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Forge dedup marks a delivery seen before its effects run, so a crash or
error after the insert loses the effects and the honest redelivery is
ignored. GitLab, Vikunja and ClickUp webhooks have no dedup at all, and
requested-changes rows have no unique key. Review findings, budget-stop
notices and tracker write-backs are published best-effort, after the
transition, and nothing retries them once the Shift is closed.
The record proposes a webhook_inbox table (verify, insert, 202; a
SKIP LOCKED worker with backoff and dead letter; content keys for
providers without delivery ids; conflicts surfaced as 409) with
idempotent effects per event kind, and a publication_outbox written in
the lifecycle transaction, delivered with deterministic logical ids and
a remote marker so a crash between send and ack does not duplicate.
It adds metrics and operator API fields for stuck rows, and lists six
owner questions.
Proposed; covers VIK-1727 and VIK-1728. Six owner questions at the end of the ADR. Code facts found while drafting: GitLab webhooks have no dedup at all (only X-Forgejo/X-Gitea-Delivery are read); Vikunja/ClickUp have none either; work_item_reviews, gate_transitions and status_transitions have no unique key, so a redelivered review becomes a second fix round.
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1727
🤖 Generated with Claude Code