47장. 데이터 정정을 원장으로 남긴다
잘못 계산된 order를 조용히 update하지 않는다. 영향 범위를 read-only query와 checksum으로 고정하고 업무 owner가 correction rule을 승인한다. adjustment row 또는 versioned event로 before/after와 actor, reason, change id를 남긴다. batch는 idempotency key와 checkpoint를 가진다.
source와 replica, binary log, downstream warehouse·검색·알림을 count·amount로 대사한다. query 성공이 아니라 모든 소비자의 업무 invariant 일치가 종료 조건이다. 정정 export의 개인정보는 최소화하고 만료·접근을 기록한다.