The crash that charges you twice — durable execution and at-least-once delivery
A plain function keeps its progress only in RAM, so a crash after step one erases the fact that it ran — and a naive retry re-runs from the top and charges the card a second time.
Scene 01
The crash that charges you twice
- Watch
- Try it
- Predict
- Capture
Start with something that looks completely ordinary. ORDER #1001 is one plain function with four steps in order: ChargeCard($42), ReserveInventory, ShipPackage, SendConfirmationEmail. Run it once and it finishes clean — the statement reads $42, and the RAM panel ticks its progress as it goes: charged=true, then step=2, 3, 4. Now watch the same function the way real systems actually behave: the process can die at any moment. We'll drop a crash right after ChargeCard succeeds. The instant the skull hits, look at the RAM panel — it wipes blank. The only record that step 1 ever ran lived in that memory, and the crash erased it. The property this function is MISSING — progress that survives a crash, a reboot, a redeploy — is called durable execution. A plain in-memory call does not have it. Watch the clean run first, then the crash that wipes the proof.
Highlighted lines are the ones running in the diagram right now.
def fulfillOrder(order):charged = False # in RAM, dies with the processchargeCard(order, $42) # moves real money at the card networkcharged = TruereserveInventory(order)shipPackage(order)sendConfirmationEmail(order)
# every minute: find orders that never finishedfor order in db.ordersNotMarkedDone():# no memory of which steps already ran —# the only such record lived in RAM, now gonefulfillOrder(order) # starts again at chargeCard
Where this sits in Build a workflow engine (Temporal / Airflow / Cadence style)
Scene 01 of 13, in the Durability act — Why RAM double-charges; the event history.. A plain function keeps its progress in RAM, so a crash after step one erases it — and a naive cron retry re-runs from the top and charges the card a second time.
Up next. The double-charge happened because the only record that step 1 ran lived in RAM, and the crash erased it. So the first fix is obvious: stop trusting memory — write down what happened, step by step, into a place a crash can't wipe.
All 13 scenes in Build a workflow engine (Temporal / Airflow / Cadence style) · Every curriculum