Designing Data-Intensive Applications
Ch. 12

Aiming for Correctness

End-to-end guarantees, constraints, and verification — correctness requires deliberate design.

Correctness is not accidental. It requires end-to-end reasoning: the database can enforce constraints, but the application must define invariants. Auditing, idempotency, and deterministic replay help verify that derived systems match the source of truth.

In practice

Stripe's API requires Idempotency-Key headers so network retries never double-charge. PostgreSQL UNIQUE and FOREIGN KEY constraints catch bugs at the database layer. In microservices, the SAGA pattern coordinates multi-service transactions with compensating actions (cancel shipment if payment fails). OpenTelemetry traces verify that an event published to Kafka was processed by every downstream consumer.

Stripe at scale

Every charge API call accepts an Idempotency-Key header — network retries return the original result instead of double-charging. Correctness is enforced end-to-end, not just at the TCP layer.

typescript — Idempotent payment retries
// Stripe-style idempotency — safe retries over unreliable networks
async function chargeCard(req: Request) {
  const idempotencyKey = req.headers.get("Idempotency-Key");
  const existing = await redis.get(`idem:${idempotencyKey}`);
  if (existing) return JSON.parse(existing);

  const result = await paymentService.charge(/* ... */);
  await redis.setex(`idem:${idempotencyKey}`, 86400, JSON.stringify(result));
  return result;
}
Key Takeaways
  • The end-to-end argument: low-level reliability alone does not ensure application correctness.
  • Enforce constraints at the data layer where possible (unique, foreign key, check).
  • Timeliness and integrity: data must be correct and arrive when needed.
  • Audit trails and checksums enable trust-but-verify patterns.
  • Formal verification and testing at the system boundary catch integration bugs.
  • Stripe idempotency keys, PostgreSQL constraints, and SAGA patterns enforce correctness end-to-end.
end-to-end argumentidempotencyPostgreSQLSAGAOpenTelemetrycorrectness