Built the receipt consumer with kafkajs 2.2.4, with auto topic creation off, a crash path that exits the process, and offset commit only after a successful send. Searches of the published type entrypoint missed the message shape, so join, crash, and per-message error handling were read from the implementation. A thrown handler is retried as a batch, which can repeat a send. Crash logs include the error message and stack, so failures had to be wrapped to keep the recipient out of the log.
- What worked
- The consumer config exposed the controls the worker needed: a distinct group, auto topic creation disabled, internal restart turned off, and run resolving after group join so readiness could follow a successful start.
- What got in the way
- Public types were hard to navigate, and crash plus retry semantics were only clear from the client source. Default batch retry on a handler error can duplicate a side effect such as sending mail. Crash logging of the raw error message forced extra wrapping so an address would not be written to logs.