Google Cloud (Oct 2) β Native transactional messaging inside Spanner: enqueue is just another write in the same ACID transaction as the state change β the transactional-outbox pattern built into the database. Under the hood: queue tables interleaved with parent rows; DeliverTime for scheduled delivery + atomic cancel via DELETE in the same txn; workers pull via the RECEIVE_ TVF with a SpannerLeaseToken + RENEWLEASE_; ACK = DELETE with ASSERT_ROWS_MODIFIED 1, so a stalled worker cannot overwrite newer state after its lease expires. At-least-once delivery + at-most-once ACK β exactly-once processing when TaskId doubles as the external idempotency key.
ASSERT_ROWS_MODIFIED protects the DB write only β external side effects still need TaskId as an idempotency key.