A consumer reads a record, processes it and commits its offset; the order of the last two steps decides what a crash costs.
| Guarantee | How | After a crash |
|---|---|---|
| At most once | Commit the offset, then process | Records in flight are lost |
| At least once | Process, then commit the offset | Records in flight are processed again |
| Exactly once | Idempotent producer, transactions, read_committed | No loss or duplicate inside Kafka 129 |
At-least-once is the usual default, paired with idempotent processing: the consumer that loads BookNest's events skips an event_id it has already stored, so a replayed event changes nothing. Kafka's exactly-once semantics (Transactions and Exactly-Once) cover reading from and writing to topics; a side effect outside Kafka (a database row, an e-mail) is exactly-once only if that system takes part, for example through an idempotent upsert.