ATALAIA
  1. Home
  2. Services
  3. Architecture Review
02Station 02 · Design

Architecture Review

We read the design before the first commit: where data crosses a boundary, which service trusts which, and what breaks if one of them is wrong.

Where trust changes

Four zones, the calls between them, and the four joints the review found. Each pin is a decision, not a finding.

INTERNETEDGECLUSTERDATAcredit msgtrusted by networkstaging + prod/adminUsersPartnersexternalGatewayauthAdmin panelOffersserviceQueuecreditsLedgerserviceLedger DBSigning keysecret1234
  1. 1
    The ledger trusts any caller in the cluster

    Change: service identity (mTLS) on every call to the ledger.

  2. 2
    Any pod can publish a credit

    Change: signed messages, and only the offers service may publish.

  3. 3
    One signing key for staging and prod

    Change: a key per environment, held in the key service.

  4. 4
    Admin path reachable from the internet

    Accepted for one sprint, then behind the VPN. Decision record #12.

The review, as it happens

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Read the design

Docs, diagrams and a walk-through with the people who built them.

ARCHITECTHere's rewards: a gateway, the ledger, offers, and a queue between them.

ATALAIAWho calls the ledger directly? Anything that isn't the gateway?

DEV LEADThe offers service. It's inside the cluster, so we let it through.

Leaves the roomDocs read, 1 walk-through

Step 2Mark the boundaries

Identity, network, data and tenancy boundaries on one picture.

ATALAIASo the ledger trusts anything on the network. That's a boundary nobody drew.

PLATFORMThe queue too. Any pod can publish a 'points credited' message.

Leaves the roomMap: 4 boundaries marked

Step 3Stress the joints

What an attacker, a bad deploy or a leaked key does at each boundary.

ATALAIAIf one pod is compromised, can it credit itself points?

PLATFORMToday, yes. It would look like a normal message.

ARCHITECTAnd one key signs tokens in staging and in prod.

Leaves the room6 joints stressed, 2 high risk

Step 4Agree the changes

Ranked changes, with the trade-offs written down.

ATALAIAService identity on the ledger, signed messages, one key per environment.

CTOKeys and identity this quarter. The queue rewrite waits, and we accept that on record.

ARCHITECTI'll write the decision record today.

Leaves the room3 changes, 1 risk accepted

  • ATALAIA
  • ARCHITECT
  • DEV LEAD
  • PLATFORM
  • CTO

What goes wrong

Most expensive findings are design decisions: a shared secret, a service that trusts any caller, an admin path nobody fenced. They are cheap on a whiteboard and costly in production.

SIGNS YOU'RE HERE

  • Service-to-service calls are authenticated by network location
  • One token or key unlocks several environments
  • The diagram on the wiki is two rewrites old

What you get

  • A reviewed architecture diagram with trust boundaries marked
  • Design risks ranked by impact and cost to change
  • Concrete alternatives, not just objections
  • A short decision record for each accepted risk

Typical shape: One to two weeks per system, depending on its size.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.