The incident
Ledgerloop is a fictional subscription platform. Its POST /v1/charges endpoint sits on the last step of checkout, which handles about 18% of the company's monthly revenue.
On Friday, a mobile carrier dropped responses for eleven seconds. Clients retried 240 charge requests, and 17 customers were charged twice. Support refunded $1,860 that afternoon, while the finance team paused the settlement export for two hours. The API had accepted both attempts because it had no way to tell a retry from a new payment.
Your job is to make the endpoint safe to retry. Keep the existing charge path and response contract. Do not redesign the payment provider or build a durable multi-region ledger in this lab.
Lab boundary
The API and its in-memory charge store are implemented. The retry storm is simulated by concurrent local clients. A production storage choice, replication story, and provider reconciliation job belong in the write-up; the lab measures the request boundary and its local idempotency behavior.