# Executive Brief: 2026-07-15 Kafka file-download consumer-group replay and Nearmap throttling

Incident: `INC-2026-07150002`  
Severity: **SEV-2**  
Status: **Monitoring / Remediation Pending**

## What Happened

A production deployment changed the Kafka consumer-group identity used by file downloads. Because the replacement group had no committed offsets and the consumer was configured to read from the beginning, it replayed retained historical requests during rollout. The duplicate traffic exceeded Nearmap rate limits and caused customer-facing iframe design-generation failures.

## Business And Customer Impact

- Multiple iframe customers could not reliably generate designs.
- Customers saw `Aerialytic error (code undefined)` rather than a useful correlation code.
- Exactly `2222` DLQ outcomes occurred during the bad-release window, but that count must not be treated as unique impacted customers or jobs.
- Exact impact, recovery scope, and any SLA effect remain under investigation.

## Current Position

- Production is rolled back to version `2.0.0` and current runtime checks are healthy.
- The incident remains open in Monitoring / Remediation Pending.
- PR #4241 is a partial candidate mitigation, not live and not complete prevention.
- Failed-job recovery, customer/job inventory, customer follow-up, and permanent release controls are still required.

## Executive Decisions Required

- Maintain P0 ownership through exact impact inventory and failed-job recovery.
- Do not release #4241 as "complete prevention" without explicit disposition of distributed provider pacing, offset continuity, idempotency, consumer ownership, and urgent security blockers.
- Approve customer communications only after the deduplicated impact list is available.
