Reliability and recovery

Failure is an operating state. Silent loss is not.

Omni Loader gives every captured batch a durable address and every destination an independent cursor, with explicit recovery behavior.

Fsync
Durable frontier

Acknowledgement never outruns persisted changes.

N cursors
Independent recovery

Each sink restarts from its own progress.

Explicit
Failure policy

Retry, dead-letter, backpressure, or reseed.

Durable spool

The backlog has structure and a recovery path.

Segmented storage uses versioned frames, compression, grouped fsync, sparse indexes, and torn-tail recovery. Retention and encryption are explicit.

Atomic append groups and source positions
Checksummed segment recovery
Retention, backpressure, and eviction policy
Optional at-rest encryption

Apply resilience

Advance only after the sink contract succeeds.

Retry isolates transient failures. Binary splitting narrows a bad batch, dead letters preserve evidence, and idempotent paths absorb replay.

Destination-specific retry policy
Poison-record isolation
Checkpointed pause and resume
Explicit delivery semantics per path

Keep exploring

See the connected parts of the platform.

Choose recovery behavior before you need it.

Bring outage windows, retention, target idempotency, and failure policy. We will map recovery.