Home›Telecom›Non-Functional Architecture›Observability & CI/CD← NFR overview
Non-functional architecture
Reference Architecture

Observability & CI/CD

Observability & CI/CD: Metrics · Logs · Traces · Alerting · SLOs · Pipelines · SAST/DAST · GitOps.

Observability & CI/CD
Metrics · Logs · Traces · Alerting · SLOs · Pipelines · SAST/DAST · GitOps
Three Pillars of Observability
Metrics · Structured Logs · Distributed Traces
MetricsRED method per service: Rate (req/s), Errors (error %), Duration (latency histogram). USE method per node: Utilisation, Saturation, Errors. Metrics Collection Platform scrape interval: configurable. Retention: configurable hot/cold retention tiers.
Structured LogsJSON-structured logs only — no free-text log lines. Mandatory fields: timestamp, traceId, spanId, serviceId, level, message. PII must never appear in logs — masked at emission point.
Distributed TracingW3C TraceContext propagation across all services. Every request carries a traceId. configurable sampling rate in production; 100% for errors and slow requests and slow requests (>P99). Span retention: configurable.
SLOsEach tier-1 service defines: Availability SLO (99.9%), Latency SLO (P99 < 500ms), Error Rate SLO (<0.1%). Error budget burn rate alerts at 2× and 5× burn rate. SLO dashboards public to engineering.
AlertingAlert on symptoms (SLO breach, error budget burn), not causes (CPU%). Multi-window multi-burn-rate alerting (1h/6h windows). Runbook URL mandatory in every alert. On-call rotation with defined escalation path.
RED Method SLO/SLA W3C TraceContext Error Budget No PII in Logs
CI/CD Pipeline — Security & Quality Gates
SAST · DAST · SCA · Container Scan · GitOps
Pipeline Stages — Every Service
Build → Unit Tests → SAST Scan → SCA → Image Scan
Contract Tests → Integration Tests → DAST Scan → Deploy (Canary)
SASTStatic analysis on every commit. Blocks merge on critical/high severity findings. OWASP Top 10, injection flaws, insecure deserialization, hardcoded secrets.
SCASoftware Composition Analysis: all third-party dependencies scanned for CVEs. CVSS ≥7.0 blocks pipeline. Licence compliance checked — GPL dependencies flagged.
Container ScanningBase image and application layer scanned for CVEs before push to registry. Only images from approved base registries accepted. Distroless images preferred.
DASTDynamic Application Security Testing runs against deployed service in integration environment. DAST Scanner / DAST Scanner. Automated attack scenarios including SQLi, XSS, IDOR.
GitOpsKubernetes manifests in Git are the single source of truth for cluster state. GitOps Controller/GitOps Controller continuously reconciles. No manual kubectl apply in production. All changes via PR with review.
SAST DAST SCA GitOps Distroless Canary Deploy
Non-Functional Requirements — Summary Reference
NFR CategoryRequirementTarget / StandardStatus
AvailabilityPlatform availability SLO99.99% (≈ minutes per year)Mandatory
LatencyAPI P99 latency (tier-1 services)< Sub-second P99Mandatory
ThroughputCDR processing rateVery High — stream processing sustainedMandatory
RTORevenue-critical service recovery<Minutes (Tier 0 — near-zero)Mandatory
RPOMaximum data loss windowNear-zero (Tier 0 — synchronous replication)Mandatory
SecurityEncryption in transitTLS 1.3+ on external traffic, mTLS on all inter-service communicationMandatory
SecurityEncryption at restAES-256-GCM all data storesMandatory
IdentityAuthentication protocolOAuth 2.0 / OIDC + Workload Identity Standard workload identityMandatory
PII ComplianceGDPR — Right to Erasure SLAConfirmed deletion within the regulatory SLA windowMandatory
ResilienceCircuit breaker on all external callsError rate >50% in 10 s window triggers openMandatory
IdempotencyAll financial mutation endpointsIdempotency key + 24 h dedup storeMandatory
ScalabilityHPA on all stateless servicesCPU target 60%, scale within a short cool-down windowMandatory
Anti-AffinityPod distributionRequired: no two replicas on same node; Preferred: spread across AZsMandatory
Technical DebtSprint debt remediation allocationMinimum 20% per sprintRecommended
ObservabilityDistributed tracing coverage100% of requests carry traceId; 10% sampledMandatory
CI/CD SecuritySAST + SCA in every pipelineCritical/High CVEs block mergeMandatory
Non-functional architecturePrevious: Performance & Scalability→Non-functional architectureNext: Compliance & Data Governance→