If the indexer reads Postgres changes through a logical replication slot, the slot tells Postgres which write-ahead log records the consumer might still need. Pausing the consumer does not pause the source application's writes. The current WAL position advances while the slot's required position stays behind, and retained WAL can grow until the source disk is in trouble. PostgreSQL's replication-slot view exposes restart_lsn and retention state. Its replication configuration explains that an unlimited slot retention setting can retain unbounded WAL.

I would check every slot, not just whether the indexing worker process is alive. Compare current WAL LSN with each slot's restart_lsn, inspect confirmed_flush_lsn for the logical consumer, slot activity, retained bytes, disk free space and WAL generation rate. restart_lsn can trail the confirmed position for reasons such as transactions still relevant to decoding, so the metric needs interpretation. A slot can remain active while downstream publishing is stuck. One abandoned slot from an old connector may be the actual cause even if the current connector is healthy.

The immediate response protects the source database first. Restore consumption if feasible, reduce incoming pressure if the business can tolerate it, and plan disk headroom from generation rate times worst-case outage duration. max_slot_wal_keep_size can bound retention, but once required WAL is removed the slot may be unusable and the consumer may need a fresh snapshot and a carefully joined change stream. Dropping a slot frees retention but gives up its continuity position. Do not do that merely to clear an alert without a recovery plan for the index.

After recovery, reconcile source document revisions against indexed revisions and prove the gap was closed. Alert on retained WAL bytes and time to disk exhaustion, not just connector lag. The CDC consumer is healthy again. Did it miss three days of changes? asks whether a healthy-again CDC consumer missed changes. This page is the reverse pressure: a stalled consumer can endanger the authoritative database before the search team notices stale answers.