A comprehensive non-functional requirements reference — covering security zones, identity, encryption, resilience patterns, high availability, disaster recovery, observability, compliance, performance and cloud-native design principles for enterprise microservices platforms.
| Service Tier | Examples | RTO | RPO | DR Strategy | Backup Freq |
|---|---|---|---|---|---|
| Tier 0 — Critical Revenue | Billing, Rating, Payment | 15 min | 0 min (sync) | Active-Active multi-region; real-time sync replication | Continuous (WAL shipping) |
| Tier 1 — Customer-Facing | Party Mgmt, CRM, Orders | 1 hr | 5 min | Active-Passive warm standby; async replication <5 min lag | Every 5 min (incremental) |
| Tier 2 — Important | Catalog, Notification, IAM | 4 hr | 15 min | Active-Passive cold standby; restore from snapshot | Hourly snapshots |
| Tier 3 — Non-Critical | Reporting, DMS, Monitoring | 24 hr | 1 hr | Backup and restore; rebuild from event replay if needed | Daily backup |
| API / Operation | P50 SLO | P95 SLO | P99 SLO | Throughput Scale | Design Notes |
|---|---|---|---|---|---|
| Product Catalog Query | Very Low | Low | Sub-100ms | High — scale horizontally | In-Memory Cache-cached; cache TTL (configurable) |
| Subscriber Profile API | Very Low | Low | Sub-200ms | High — scale horizontally | DB read replica + In-Memory Cache L1 cache |
| Order Placement | Sub-500ms | Sub-second | <1 sec | Moderate — async capable | Async provisioning; sync validation only |
| Real-time Rating (CDR) | Very Low | Very Low | Low | Very High — stream processing | In-memory rate table; no DB on critical path |
| Invoice Generation | <2 sec | <5 sec | <10 secec | Batch — parallel per bill run | Async PDF generation; batch processing |
| Authentication (Token) | Very Low | Very Low | Low | High — scale horizontally | JWT validation cached; no DB lookup |
| Notification Dispatch | Sub-second | <2 sec | <5 sec | High — scale horizontally | Async event-driven; SLA is delivery time not dispatch |
| Data Type | Hot Retention | Archive | Purge |
|---|---|---|---|
| Subscriber PII | Active + 6 months post-churn | 6–13 months cold | 13 months (unless legal hold) |
| Call Records (CDR) | 6 months | 6–24 months | 24 months (regulatory minimum) |
| Invoice & Billing | 2 years | 2–7 years cold | 7 years (financial regulation) |
| Order History | 2 years | 2–5 years | 5 years |
| Audit Logs | 90 days | 90 days – 7 years | 7 years (never auto-purge) |
| Application Logs | 30 days | 30–90 days | 90 days |
| NFR Category | Requirement | Target / Standard | Status |
|---|---|---|---|
| Availability | Platform availability SLO | 99.99% (≈ minutes per year) | Mandatory |
| Latency | API P99 latency (tier-1 services) | < Sub-second P99 | Mandatory |
| Throughput | CDR processing rate | Very High — stream processing sustained | Mandatory |
| RTO | Revenue-critical service recovery | <Minutes (Tier 0 — near-zero) | Mandatory |
| RPO | Maximum data loss window | Near-zero (Tier 0 — synchronous replication) | Mandatory |
| Security | Encryption in transit | TLS 1.3+ on external traffic, mTLS on all inter-service communication | Mandatory |
| Security | Encryption at rest | AES-256-GCM all data stores | Mandatory |
| Identity | Authentication protocol | OAuth 2.0 / OIDC + Workload Identity Standard workload identity | Mandatory |
| PII Compliance | GDPR — Right to Erasure SLA | Confirmed deletion within the regulatory SLA window | Mandatory |
| Resilience | Circuit breaker on all external calls | Error rate >50% in 10 s window triggers open | Mandatory |
| Idempotency | All financial mutation endpoints | Idempotency key + 24 h dedup store | Mandatory |
| Scalability | HPA on all stateless services | CPU target 60%, scale within a short cool-down window | Mandatory |
| Anti-Affinity | Pod distribution | Required: no two replicas on same node; Preferred: spread across AZs | Mandatory |
| Technical Debt | Sprint debt remediation allocation | Minimum 20% per sprint | Recommended |
| Observability | Distributed tracing coverage | 100% of requests carry traceId; 10% sampled | Mandatory |
| CI/CD Security | SAST + SCA in every pipeline | Critical/High CVEs block merge | Mandatory |