Skip to content
bitzorcas
中EN

Concept

Transactional event delivery

Business state and CAP outbox data commit together before asynchronous delivery.

Last updated

Question and use cases

Business state and CAP outbox data commit together before asynchronous delivery.

Use this view to reason about the boundary between a committed business change and asynchronous delivery.

Use the diagram during design review, incident diagnosis, code walkthroughs, and onboarding. It intentionally omits classes and projects unrelated to the focused question, so read it together with the source entry point and related topic pages.

This page covers only the named responsibilities and relationships; consult the relevant module documentation for capabilities not shown here.

Reading path

  1. Step 1: Start with the aggregate and local transaction.
  2. Step 2: Confirm that the outbox row commits with business state before broker delivery.
  3. Step 3: Finish at the consumer’s local transaction, retry, and audit boundary.

Do not skip arrow direction, numbering, or group titles: they express dependency or time direction, execution order, and responsibility boundaries. If the diagram differs from current source or accepted architecture decisions, correct the generated catalog immediately.

Legend and notation

Visual elementMeaningWhat it does not imply
Coral focusThe decision point or primary path emphasized by this viewThat the element is always more important or privileged
Blue boundaryAn external system, protocol edge, or explicit boundaryThat it must be an independently deployed service
Muted connectorA dependency, call, transition, or data flow as named by its labelSynchronous, same-transaction, or exactly-once behavior
Group frameA responsibility, layer, or lifecycle phaseA team or physical-machine boundary

This is a ARCHITECTURE diagram. Use that form to understand the layout, then test your interpretation against the source facts below.

Key relationships and design meaning

Relationship 1

Source fact: Business state and CAP outbox data commit in the same database transaction.

Architectural meaning: Committing state and outbox together removes the window in which business data succeeds but its integration event disappears.

Review action: What stable event identity allows duplicate delivery to be absorbed?

Relationship 2

Source fact: The broker delivery happens after commit and can be retried independently.

Architectural meaning: Delivery after commit favors eventual consistency; callers must not assume a consumer has finished when the command returns.

Review action: Can a consumer evolve independently from the publisher’s aggregate?

Relationship 3

Source fact: Consumers own their local state and record asynchronous processing audit data.

Architectural meaning: Consumer-owned state keeps bounded contexts autonomous, while local audit evidence makes asynchronous failures diagnosable.

Review action: Where is failed delivery observed and replayed?

Design review questions

Answer each question when reviewing or implementing a related change. If code, tests, or an ADR cannot support the answer, do not decide from the diagram alone.

  • What stable event identity allows duplicate delivery to be absorbed?
  • Can a consumer evolve independently from the publisher’s aggregate?
  • Where is failed delivery observed and replayed?

How to use the answers

  1. Identify the single owner of the capability or rule.
  2. Confirm that dependency, call, or event direction does not reverse ownership.
  3. Capture the conclusion with an automated test or repeatable command.

Boundaries and common mistakes

Boundary 1

The outbox prevents state/message divergence; it does not make consumers exactly-once.

  • Do not infer: A connector in the diagram does not mean every implementation uses synchronous calls, a shared transaction, or shared data ownership.
  • Review requirement: Can a consumer evolve independently from the publisher’s aggregate?

Boundary 2

Consumers still need idempotent handling and stable event contracts.

  • Do not infer: A connector in the diagram does not mean every implementation uses synchronous calls, a shared transaction, or shared data ownership.
  • Review requirement: Where is failed delivery observed and replayed?

Source verification and regeneration

The primary verification entry point is BitzOrcas.Infrastructure.SqlSugar.Outbox.Cap/CapSqlSugarUnitOfWork.cs + BitzOrcas.Infrastructure.EfCore.Outbox.Cap/CapEfCoreUnitOfWork.cs. Inspect it and its direct references before regenerating diagram assets and pages.

Terminal window
# Regenerate bilingual SVG, standalone HTML, and documentation pages
npm run diagrams
# Check locale pairs, references, safety attributes, accessibility, and canvas bounds
npm run verify:diagrams
Terminal window
# Confirm that generation changed only the intended diagrams and pages
git diff -- scripts/diagrams diagram-sources public/diagrams src/content/docs
# Verify internal links, MDX structure, and professional depth gates
npm run verify:docs
npm run audit:docs-depth

Change-completion checklist

  • Responsibilities, order, states, and relationships match current source.
  • Every new element helps answer this page’s question instead of turning the diagram into an inventory.
  • Arrows have explicit direction and semantics without implying nonexistent synchronous or transactional guarantees.
  • Chinese and English titles, labels, facts, and boundaries remain semantically equivalent.
  • The diagram remains readable on narrow screens, in fullscreen, and while zoomed, with no overlap or overflow.
  • Relevant architecture tests, integration tests, or verification commands have run.
  • If a long-lived constraint changed, its ADR or architecture documentation is updated.

Continue reading

100%

Scroll or use controls to zoom · drag when enlarged · double-click for 100% / 200%