Reliable ingestion & retries
Accept once, process safely and make failure visible.
The inbox pattern
Proposed receivers validate and persist before acknowledging acceptance. A unique index on the integration-scoped event key prevents repeat provider delivery from generating duplicate business work. In one transaction, insert the inbox record and schedule its processing.
BEGIN INSERT inbox(event_key, body) ON CONFLICT DO NOTHING INSERT pending_work(inbox_id) IF inbox_was_inserted COMMIT
Retry policy
Define a maximum attempt count, exponential delay with jitter and a dead-letter state. Distinguish temporary network failures from invalid data. A poison message should not block every later event from the same integration.
Ordering and stale events
Do not assume arrival order is measurement order. Keep provider receive time and your own ingest time. Define a lateness window for charts and rules. A delayed packet should not overwrite a newer device state without a deliberate policy.
Operations
Monitor inbox age, processing latency, rejection counts and dead-letter volume. Redact credentials and customer measurements from routine logs. Provide controlled replay with the same idempotency protections as normal processing.