Architecture Case Study

Resilience, Security & Operations

External-dependency resilience, secret handling, trust boundaries and operational support.

9 architecture viewsSectionArchitecture dossier
architecture: API Architecturearchitecture: Integration Architectureconcern: Live Search

Trust boundaries

The public browser must not receive supplier credentials.

Secrets, authentication state and supplier-specific protocol behaviour remain inside the backend integration boundary.

External dependency

Live holiday search introduces a synchronous dependency on an external service.

The architecture therefore needs to distinguish:

  • invalid customer input;
  • integration/authentication failure;
  • supplier unavailability;
  • supplier timeout;
  • valid search with no availability.

These are different customer and operational conditions and should not collapse into one generic error.

Timeout and failure behaviour

The integration layer should apply bounded timeouts and return a controlled website-facing response when the supplier cannot be reached.

The frontend should remain usable and communicate that live results cannot currently be retrieved rather than exposing raw integration failures.

Observability

Useful operational signals include:

  • request success/failure by operation;
  • upstream response time;
  • timeout rate;
  • authentication failures;
  • result counts;
  • external error categories.

Sensitive request/response content should not be logged unnecessarily.

Security

Key controls include:

  • server-side secret storage;
  • no supplier credentials in Webflow;
  • validation of customer inputs;
  • controlled outbound network path;
  • sanitised logging;
  • separation between public website requests and supplier authentication.

Support boundary

The integration layer provides the point at which website issues can be separated from supplier-service issues.

That boundary supports clearer ownership and incident diagnosis.

Scroll to zoom, drag to move
Expanded diagram