Home›Telecom›Non-Functional Architecture›Network & Infrastructure← NFR overview
Non-functional architecture
Reference Architecture

Network & Infrastructure

Network & Infrastructure Architecture: CDN · Load Balancers · TLS/mTLS · API Gateway · Service Mesh · Anti-Affinity.

Network & Infrastructure Architecture
CDN · Load Balancers · TLS/mTLS · API Gateway · Service Mesh · Anti-Affinity
CDN & Global Traffic Management
Edge Caching · GSLB · Anycast · Geo-routing
CDNStatic assets, API responses (GET, cacheable) and portal pages served from CDN edge. TTL configured per content type. Stale-while-revalidate for catalog API responses.
Cache TTL PolicyStatic assets: 1 year (versioned). Product catalog API: 5 min. Subscriber data: 0 (no cache). Invoice PDFs: 24 h (authenticated).
GSLBGlobal Server Load Balancing routes traffic to nearest healthy data centre. Health checks at a configurable interval. Automatic failover to secondary region on health check failure.
Anycast DNSAnycast IP routing delivers requests to the geographically nearest PoP. Low-latency DNS resolution at the edge.
Edge Cache GSLB Anycast Cache-Control
Load Balancers — L4 & L7
External · Internal · Health Checks · Algorithms
External LB (L7)HTTP/2 + gRPC aware. Path-based routing to API gateway. TLS termination. Connection draining on pod scale-down. Sticky sessions via consistent hashing where required.
Internal LB (L4)Cluster Network Proxy for east-west service-to-service traffic. Round-robin by default. Least-connections for stateful services (billing, payment).
Health ChecksLiveness: container alive? Readiness: can accept traffic? Startup: slow-starting containers. All three probes mandatory. Unhealthy pods removed from LB pool within seconds.
AlgorithmRound-robin for stateless services. Consistent hash on subscriber ID for session-sensitive flows. Least outstanding requests for high-variance latency services.
L7 Routing Health Probes Connection Draining Consistent Hash
Stateless Services & Anti-Affinity
Stateless Design · Pod Anti-Affinity · Zone Spreading
Stateless microservices have no local in-memory state between requests. All session state is externalised to In-Memory Cache or a distributed cache. Any pod replica can serve any request — enabling true horizontal scalability and zero-downtime rolling deployments.
Stateless RuleNo pod may store session state, file system state or in-memory cache that is not shared. Configuration injected via environment / ConfigMap — not baked into image.
Pod Anti-AffinityRequired anti-affinity rule: no two replicas of the same service may run on the same node. Preferred anti-affinity: spread replicas across availability zones.
Zone SpreadingTopologySpreadConstraints enforce even distribution across AZs. Minimum 2 replicas per zone for tier-1 services (billing, order management, IAM).
Node AffinityRevenue-critical services (billing, rating) scheduled on dedicated node pools — isolated from dev/test workloads and batch jobs to prevent noisy-neighbour CPU contention.
Stateless Anti-Affinity Zone Spread Node Isolation
Non-Functional Requirements — Summary Reference
NFR CategoryRequirementTarget / StandardStatus
AvailabilityPlatform availability SLO99.99% (≈ minutes per year)Mandatory
LatencyAPI P99 latency (tier-1 services)< Sub-second P99Mandatory
ThroughputCDR processing rateVery High — stream processing sustainedMandatory
RTORevenue-critical service recovery<Minutes (Tier 0 — near-zero)Mandatory
RPOMaximum data loss windowNear-zero (Tier 0 — synchronous replication)Mandatory
SecurityEncryption in transitTLS 1.3+ on external traffic, mTLS on all inter-service communicationMandatory
SecurityEncryption at restAES-256-GCM all data storesMandatory
IdentityAuthentication protocolOAuth 2.0 / OIDC + Workload Identity Standard workload identityMandatory
PII ComplianceGDPR — Right to Erasure SLAConfirmed deletion within the regulatory SLA windowMandatory
ResilienceCircuit breaker on all external callsError rate >50% in 10 s window triggers openMandatory
IdempotencyAll financial mutation endpointsIdempotency key + 24 h dedup storeMandatory
ScalabilityHPA on all stateless servicesCPU target 60%, scale within a short cool-down windowMandatory
Anti-AffinityPod distributionRequired: no two replicas on same node; Preferred: spread across AZsMandatory
Technical DebtSprint debt remediation allocationMinimum 20% per sprintRecommended
ObservabilityDistributed tracing coverage100% of requests carry traceId; 10% sampledMandatory
CI/CD SecuritySAST + SCA in every pipelineCritical/High CVEs block mergeMandatory
Non-functional architecturePrevious: Security & Identity→Non-functional architectureNext: Resilience & High Availability→