Field note · June 20, 2024
Contract check at the boundary, in short
Validate the shape of incoming data where it enters your system — fail loudly on structure, warn on distribution.
Someone asked why Contract check at the boundary is written the way it is. Fair question.
Validate the shape of incoming data where it enters your system — fail loudly on structure, warn on distribution.
What makes it a pattern rather than a tip is that the wrong version is the one you write naturally. It reads correctly, it runs, and it returns something. The failure is in the result, not in the execution — which means the only defence is recognising the shape before you are in it.
Two datasets on this site have the shape built in: dirty-customers and data-job-postings. Both are small enough to run the broken version, see the number, then run the corrected one and see it change.
It lives under moving because it is about data in transit: reruns, backfills, and the assumption that yesterday only ever arrives once.
The long-form treatment is in the course (schema-drift-and-contracts, testing-data-like-code); the pattern page is the version to read at 4pm with a query open.
Whether you use our version matters much less than having a version you did not re-derive under time pressure. That is what a pattern library is for.