Architecture Case Study
Resilience, Security & Operations
External-dependency resilience, secret handling, trust boundaries and operational support.
Trust boundaries
The public browser must not receive supplier credentials.
Secrets, authentication state and supplier-specific protocol behaviour remain inside the backend integration boundary.
External dependency
Live holiday search introduces a synchronous dependency on an external service.
The architecture therefore needs to distinguish:
- invalid customer input;
- integration/authentication failure;
- supplier unavailability;
- supplier timeout;
- valid search with no availability.
These are different customer and operational conditions and should not collapse into one generic error.
Timeout and failure behaviour
The integration layer should apply bounded timeouts and return a controlled website-facing response when the supplier cannot be reached.
The frontend should remain usable and communicate that live results cannot currently be retrieved rather than exposing raw integration failures.
Observability
Useful operational signals include:
- request success/failure by operation;
- upstream response time;
- timeout rate;
- authentication failures;
- result counts;
- external error categories.
Sensitive request/response content should not be logged unnecessarily.
Security
Key controls include:
- server-side secret storage;
- no supplier credentials in Webflow;
- validation of customer inputs;
- controlled outbound network path;
- sanitised logging;
- separation between public website requests and supplier authentication.
Support boundary
The integration layer provides the point at which website issues can be separated from supplier-service issues.
That boundary supports clearer ownership and incident diagnosis.