5 ms·
There's a benefit of microservices that I don't hear talked about. At my workplace, there's absolutely no respect for api boundaries. Devs will monkey patch and
by icholy 2y ago
There's a benefit of microservices that I don't hear talked about. At my workplace, there's absolutely no respect for api boundaries. Devs will monkey patch and reach into other module's internals without a second thought. I can't imagine the monstrosity that would exist if the network boundary wasn't there to stop them ...
- duxup 2y agoMicroservices (like a lot of things) might just be there to solve human developer problems as much as anything else. There are times where I'm all "No the authentication service is doing great, leave it alone!!!".
- aitchnyu 2y agoWe can enforce module boundaries in code with tooling. An example for Python: https://github.com/gauge-sh/tach https://github.com/gauge-sh/tach
- NoGravitas 2y agoThat's just another way of saying that microservices don't solve a technical problem, they solve an organizational problem.
- BillyTheKing 2y agoyes - and writing code also doesn't solve a technical problem, a computer runs fine with 0s and 1s, no need for code, in fact code produces a performance overhead - but it solves a human abilities problem, namely that 0s and 1s aren't particularly expressive for us. Almost everything we do solves for communication, some things on an individual scale, like programming languages, and other things on an organisational scale like micro-services (I'm also not blindly advocating for micro-services, but I do get why if done somewhat competently it's easier to organise a team of 1000 developers into 50 teams of 20 each responsible for one service rather than 1000 developers responsible for everything)
- kgeist 2y ago>Devs will monkey patch and reach into other module's internals without a second thought. I can't imagine the monstrosity that would exist if the network boundary wasn't there to stop them ... We have a tool in our modular monolith, which is like a linter which checks architectural violations like that. If someone tries to bypass the API layer of a module and peek directly into the internals, it refuses to build (and CI/CD refuses to deploy/release). No need to replace a basic linter with a network boundary...
- the1024 2y agoWe've encountered the exact same problem in the past, and open sourced our solution to enforce those boundaries! https://github.com/gauge-sh/tach https://github.com/gauge-sh/tach Alongside CODEOWNERs, you can effectively constrain teams to focus on where they need to be.
- 10000truths 2y agoYou don't need network level separation for that, UNIX sockets and pipes are just as effective at enforcing those boundaries.
- vilunov 2y agoWhat's stopping them from violating network boundaries?
- immibis 2y agothe network
- the1024 2y agoTypically teams won't have access to the code that's being deployed on the other side of the network boundary. This physical separation is overkill though; something like CODEOWNERs and https://github.com/gauge-sh/tach https://github.com/gauge-sh/tach can do this without incurring remotely the same overhead.