Answer
It takes periodic checkpoints that store its state together with the input offsets it had reached. After a crash it restores the last checkpoint and replays input from those offsets, so state reflects each event exactly once (Flink works this way). Output to other systems still needs idempotent or transactional writes.