Learning · Software Engineering Manifesto

Limit blast radius

Isolate failure — least privilege, quotas, and defaults that fail closed between services.

Principle

Assume components fail and credentials leak. Design so one bad deploy, dependency, or tenant cannot take everything down or read everything.

Therefore we practice

  • Authenticate and authorize service-to-service calls; least privilege for data access
  • Separate identities for apps and pipelines; no shared god credentials
  • Apply rate limits, size limits, and isolation (tenancy, queues, pools) where abuse or load can spread
  • Prefer fail-closed for security-sensitive paths
  • Scope secrets tightly; rotate; never log them

Smells

  • One API key that can do anything in every environment
  • Public endpoints without auth “temporarily”
  • A single shared DB user for all microservices
  • Unlimited upload/request sizes on external APIs

← Software Engineering Manifesto