2.Microservices & Platform
Software Architecture & Engineering · 13 notes
- OpenID Connecthistorical
Identity layer on OAuth with ID tokens, UserInfo, issuer/audience/nonce validation, and authentication sessions.
- JSON Web Token (JWT)historical
Signed token format, claims, validation, expiration, key management, and common security misconceptions.
- OAuth 2.xhistorical
Delegated authorization with resource owner, client, authorization server, resource server, scopes, access tokens, and secure redirect flows.
- Designing a Configuration Centerhistorical
Versioned configuration distribution with environments, validation, watches, rollout, caching, security, and rollback.
- Designing Load Balancinghistorical
Endpoint discovery, selection algorithms, health/outlier detection, connection reuse, locality, weighting, and overload-aware routing.
- Designing a Service Registryhistorical
Service membership registration, discovery, leases/health, staleness, replication, client caches, and failure handling.
- Designing an API Gatewayhistorical
Gateway routing and cross-cutting policy with authentication, limits, deadlines, observability, resilience, and safe ownership boundaries.
- Designing an Observability Systemhistorical
Metrics, logs, traces, events, SLOs, correlation, storage, alerting, dashboards, and cost/cardinality control.
- Designing Distributed Tracinghistorical
Trace/span context propagation, sampling, storage, causality, asynchronous work, and correlation with metrics/logs.
- Designing Resilience Componentshistorical
Timeouts, deadlines, retries, circuit breakers, bulkheads, rate limits, load shedding, fallbacks, and idempotency.
- Designing Logginghistorical
Structured logs, severity, correlation, context, sampling, retention, privacy, and operational querying.
- Designing Metrics Monitoringhistorical
Metric naming/types, labels, cardinality control, RED/USE signals, SLOs, aggregation, and alerting.
- Designing Authentication and Authorizationhistorical
Identity proof, sessions/tokens, authorization policy, least privilege, service identity, revocation, and audit.