High availability and disaster recovery

Lose a process, host, or database node. Keep one safe owner of the stream.

SQL Flow coordinates leased ownership, fences stale writers, and resumes replacement agents from durable state without turning a transient failure into a blind reseed.

The job to be done

Move committed data with a path your team can explain.

A capability matters when it removes an operational decision, not when it adds another checkbox. SQL Flow connects source-aware capture, durable progress, target apply, and validation so the page you are reading leads to a usable operating path.

The control plane schedules an eligible agent and advances an ownership epoch during takeover. Source readers and destinations validate that ownership. SQL Flow handles durable lease and epoch state; automatic capability-aware reassignment; sink fencing before target mutation; visible owner and recovery progress.

Why this path matters

Leases decide ownership; epochs fence the sink.

The control plane schedules an eligible agent and advances an ownership epoch during takeover. Source readers and destinations validate that ownership. SQL Flow handles durable lease and epoch state; automatic capability-aware reassignment; sink fencing before target mutation; visible owner and recovery progress.

What changes for you

Failover validates database identity and the promoted source timeline before capture resumes. Ambiguous state stops loudly with a recovery action. SQL Flow handles source-family-specific promotion validation; checkpoint transfer between eligible agents; backlog drain after recovery; planned switchover and unplanned failover.

The outcome

Bring the database topology, agent locations, and recovery objectives. We will map ownership, fencing, failover, and validation.

The payoff

See what the capability changes.

1 owner

Fenced execution

A stale agent cannot apply after ownership moves.

Auto

Agent failover

Healthy capacity takes over a failed pipeline.

Durable

Resume state

Capture and apply restart from persisted positions.

Where the work happens

The details that make the result usable.

Read each capability as part of the operating path. The important question is not whether a feature exists, but what work it removes and what evidence it leaves behind.

No double writer

Leases decide ownership; epochs fence the sink.

The control plane schedules an eligible agent and advances an ownership epoch during takeover. Source readers and destinations validate that ownership.

SQL Flow handles durable lease and epoch state; automatic capability-aware reassignment; sink fencing before target mutation; visible owner and recovery progress.

  • Durable lease and epoch state
  • Automatic capability-aware reassignment
  • Sink fencing before target mutation
  • Visible owner and recovery progress

Database-aware continuity

Follow promotion without guessing at the log timeline.

Failover validates database identity and the promoted source timeline before capture resumes. Ambiguous state stops loudly with a recovery action.

SQL Flow handles source-family-specific promotion validation; checkpoint transfer between eligible agents; backlog drain after recovery; planned switchover and unplanned failover.

  • Source-family-specific promotion validation
  • Checkpoint transfer between eligible agents
  • Backlog drain after recovery
  • Planned switchover and unplanned failover

Before you choose

Check the path against your environment.

Use the page-specific details below as a short discovery checklist. They are the conditions and work areas that shape the capability, not generic product promises.

  • Durable lease and epoch state
  • Automatic capability-aware reassignment
  • Sink fencing before target mutation
  • Visible owner and recovery progress
  • Source-family-specific promotion validation
  • Checkpoint transfer between eligible agents

The path to confidence

See the work. Make the call. Prove the result.

The page keeps the product detail close to the decision it supports. Your team can see what the software handles automatically, what it changes for the target, and what the result leaves ready to operate.

  1. Leases decide ownership; epochs fence the sink.

    The control plane schedules an eligible agent and advances an ownership epoch during takeover. Source readers and destinations validate that ownership. SQL Flow handles durable lease and epoch state; automatic capability-aware reassignment; sink fencing before target mutation; visible owner and recovery progress.

  2. Follow promotion without guessing at the log timeline.

    Failover validates database identity and the promoted source timeline before capture resumes. Ambiguous state stops loudly with a recovery action. SQL Flow handles source-family-specific promotion validation; checkpoint transfer between eligible agents; backlog drain after recovery; planned switchover and unplanned failover.

Keep the plan connected

Take the next useful step.

A capability becomes easier to operate when the next decision follows from the constraint you just uncovered. Explore the related work that completes this part of the path.

Your working set

What this page leaves you with

  • Fenced execution
  • Agent failover
  • Leases decide ownership; epochs fence the sink.
  • Follow promotion without guessing at the log timeline.
  • Plan for the failure you cannot schedule.

Take the next step

Plan for the failure you cannot schedule.

Bring the database topology, agent locations, and recovery objectives. We will map ownership, fencing, failover, and validation.

Talk through my use case