Interfaces inside one organisation.
WHAT DIFFERS FROM PUBLIC INTERFACES
You know every caller Changes can be coordinated The network is usually trusted
WHAT DOES NOT DIFFER
The need for versioning, documentation and error handling.
WHY THAT NEEDS SAYING
Internal interfaces are frequently undocumented and change carelessly.
WHAT THAT CAUSES
Outages during deployment, from mismatched versions.
WHAT TO ENFORCE
Backward compatibility across a deployment.
WHY
Services deploy at different moments, and both versions run simultaneously.
WHAT THAT MEANS PRACTICALLY
Add before removing, always.
WHAT TO NEVER ASSUME ABOUT THE INTERNAL NETWORK
That it is safe.
WHY
One compromised service otherwise reaches everything.
WHAT TO IMPLEMENT
Authentication between services Authorisation for what each may do Encryption in transit
WHAT TO PROPAGATE
A correlation identifier, through every call.
WHY
It is the only way to trace a request across services.
WHAT TO BE CAREFUL WITH
Chains of synchronous calls.
WHY
Each adds latency and a failure point, and the total is worse than any single one.
WHAT TO PREFER FOR ANYTHING NOT NEEDED IMMEDIATELY
Asynchronous messaging.