Context
A cross-border payment moves value on a chain, through a bridge, at a partner and in a ledger. None of these will hold a lock or prepare a commit on Corridor’s behalf.Decision
Each plan runs as a saga: durable steps in Postgres, each leg withforward and an optional compensate, retries with backoff, one worker per saga through a lease, and compensation in reverse order on failure. Failures after money has left Corridor’s control stop at manual_review instead of compensating.
Consequences
- Every intermediate state is a real state, visible in the console with its transactions.
- Legs must be idempotent: they look for their movement by reference before sending.
- A lease that expires mid-leg can let a slow worker finish a call; fencing tokens on bookings are on the roadmap.
Alternatives rejected
- Two-phase commit: impossible with external parties that do not participate.
- Fire-and-forget with nightly repair: leaves money in unknown states for hours, which is the failure mode this product exists to remove.