Delivery Semantics

A consumer reads a record, processes it and commits its offset; the order of the last two steps decides what a crash costs.

The three delivery guarantees and what a crash costs under each
Guarantee How After a crash
At most once Commit the offset, then process Records in flight are lost
At least once Process, then commit the offset Records in flight are processed again
Exactly once Idempotent producer, transactions, read_committed No loss or duplicate inside Kafka 129

At-least-once is the usual default, paired with idempotent processing: the consumer that loads BookNest's events skips an event_id it has already stored, so a replayed event changes nothing. Kafka's exactly-once semantics (Transactions and Exactly-Once) cover reading from and writing to topics; a side effect outside Kafka (a database row, an e-mail) is exactly-once only if that system takes part, for example through an idempotent upsert.