Part III - Composable Web Architecture
1. Introduction

In the second part of our series, we explored how Composable Architecture empowers developers to construct robust, adaptable software systems by breaking down applications into independently deployable components in front-end and back-end development. Building on this foundation, we now turn our focus to Composable Data Architecture, a critical element for ensuring the scalability, security, and efficiency of modern applications. 

Composable Data Architecture integrates seamlessly with composable systems to effectively manage data across distributed environments. This approach enables the handling of complex, dynamic data workflows while adapting to the ever-evolving technological landscape. In this section, we'll delve into specific techniques and technologies that underpin this architectural style. 

2. Composable Data Architecture

A Composable Data Architecture is pivotal in supporting the overall flexibility and scalability of applications. It focuses on ensuring data accessibility and integrity while maintaining the independence of different services. This chapter delves into effective strategies for building a decoupled and scalable data layer. 

Part III - Composable Web Architecture
2.1 Database per Service

In a composable architecture, each microservice manages its own database or a suitably isolated subset of a larger database. This approach prevents database-level coupling between services, thereby supporting each microservice's encapsulation and independence.

Implementation Strategies:

  • Database Technology Choice: Services may choose different types of databases—SQL for relational data requirements or NoSQL for schema-less data storage—based on their specific functionality. For example, a microservice handling user profiles might use an SQL database for structured query capabilities. In contrast, another person handling real-time user activity logs might opt for a NoSQL database because of its flexibility and scalability.
     
  • Schema Management: Manage database schemas by establishing a version control system for database changes. Use migration scripts that align with each service release to modify the database schema without impacting running services. This approach ensures that any changes in the database schema are backward compatible and do not interfere with the operations of other microservices relying on the same database infrastructure.
Part III - Composable Web Architecture
2.2 Data Aggregation Techniques

Handling Data Across Services: 

  • API Composition: Use an API Gateway to orchestrate data from multiple services, ensuring a unified API response to clients. Implement this by configuring the API Gateway to route requests to the appropriate microservices and then aggregate the responses into a cohesive format before sending them back to the client. This not only simplifies client interactions but also abstracts the complexity of the underlying microservice architecture. 
     
  • Command Query Responsibility Segregation (CQRS): Implement CQRS to separate the read and write operations, enhancing system performance and scalability. This can be done by developing two distinct models: a command model that handles data updates and a query model that handles data retrieval. Use separate databases for each model if necessary to optimize performance—writes can go to a transactional database and reads can be optimized on a database built for speed and efficiency. 
     
  • Event Sourcing: 
    - Event Storage: Store state changes as a sequence of events in an event store, which acts as the authoritative source of truth for an entity's state. Each event represents a change in data, and by replaying these events, you can reconstruct the entity's state at any time. Implement this using a specialized event store database or frameworks supporting event sourcing. 
    - Integration: Combine event sourcing with CQRS to manage complex data workflows efficiently in a distributed environment. Implement this integration by using events to trigger updates in the query model, ensuring that the read data is up-to-date and consistent with the write operations. This approach decouples the data models for reading and writing, allowing each to be scaled and evolved independently. 
Part III - Composable Web Architecture
2.3 Handling Data Consistency

Ensuring data consistency across various services and databases is a significant challenge in microservices architectures due to each service's autonomous nature and the scattered distribution of data. As each microservice operates independently, coordinating its operations to maintain data integrity and consistency requires strategic planning and robust architectural designs. 

Strategies for Consistency: 

  • Distributed Transactions with the Saga Pattern offer a method to manage complex transactions across multiple services without requiring immediate consistency. In this approach, each business transaction is broken down into numerous smaller, local transactions handled by individual services. As each service completes its transaction, it publishes an event to trigger the next transaction in the sequence. If any transaction fails, subsequent compensating transactions are executed to revert previous changes, ensuring data integrity without locking resources. This pattern allows for robust, complex workflows and graceful handling of failures, maintaining high performance and scalability. 
     
  • Two-Phase Commit (2PC) is a protocol designed to ensure complete consistency across distributed systems by coordinating all transaction parts to commit or roll back together. This coordination is managed by a central transaction manager, who first checks with all services to prepare for the transaction (locking the necessary resources) and then commits if all are ready. Although 2PC provides strong consistency guarantees, it can introduce higher latency and is vulnerable to failures if the coordinator fails, making it less ideal for environments where scalability and resilience are priorities. 
     
  • Eventual Consistency is a strategy where the system accepts temporary inconsistencies, expecting all changes to eventually propagate through the system to bring all data into agreement. This is implemented by having each service publish changes as events, which other services consume asynchronously to update their state. The key benefit here is enhanced system availability and responsiveness—services can operate independently without waiting for immediate updates from others, thus reducing downtime and bottlenecks. 
Part III - Composable Web
2.4 Data Security and Compliance

Ensuring the protection of sensitive data and adhering to various regulatory standards is fundamental for maintaining the integrity and trustworthiness of any system.

Data Protection Measures: 

  • Encryption: Implementing encryption is critical for protecting sensitive data both when it is stored ("at rest") and while it is being transmitted ("in transit") between services. In composable architectures, where data often moves across different services and networks, use industry-standard encryption protocols such as AES (Advanced Encryption Standard) for data at rest and TLS (Transport Layer Security) for data in transit. This ensures that intercepted data cannot be read without the encryption keys. Managing and rotating these keys securely while ensuring they are accessible only to authorized services is crucial. 
     
  • Access Controls: Define and enforce comprehensive access control policies at the service level. This involves implementing authentication and authorization mechanisms to ensure that only legitimate users and services can access or manipulate data. Utilize role-based access control (RBAC) or attribute-based access control (ABAC) systems to grant permissions based on user roles or attributes. Each microservice should enforce these policies independently to minimize the risk of unauthorized access from compromised services. 

Compliance:

Regulatory Adherence: Composable architectures must adhere to all relevant legal and regulatory standards, which can vary significantly by industry and region. For GDPR compliance, ensure that data handling practices provide transparency, access control, and the ability to erase personal data easily. In the context of HIPAA (Health Insurance Portability and Accountability Act), protect patient information not only through encryption and access controls but also by implementing audit trails and ensuring data integrity during processing and storage. For PCI DSS (Payment Card Industry Data Security Standard) compliance, secure payment data through encryption, use secure coding practices and regularly audit data access logs. 

Regulatory adherence is not specific to composable architectures; however, implementing these compliance measures within a composable architecture does have unique implications and benefits: 

  1. Decentralized Control: In composable architectures, where services are designed to operate independently, managing compliance can be both a challenge and an advantage. Each service can independently implement and manage compliance with relevant regulations, simplifying updates and changes to compliance processes without affecting the entire system. However, this decentralized approach requires robust coordination and consistent policy enforcement across services to prevent gaps in compliance. 
     
  2. Scalability and Flexibility: Composable architectures are highly scalable and adaptable. This trait is beneficial for compliance as it allows organizations to rapidly adjust and scale specific parts of their system to address evolving regulatory requirements without overhauling the entire system. For example, adding new services to handle GDPR requests for data erasure or adapting existing services to new regulatory requirements can be achieved more fluidly. 
     
  3. Data Governance Across Services: The modular nature of composable architectures complicates data governance because data is often dispersed across many services. For instance, ensuring transparency, access control, and the ability to erase personal data under GDPR requires a coordinated and consistent approach across all services. This often necessitates sophisticated data management and governance tools that can operate across distributed environments. 
     
  4. Security and Compliance by Design: Since each component in a composable architecture can be developed and deployed independently, security and compliance measures can be integrated right from the design phase for each element. This "security and compliance by design" approach helps embed necessary controls and checks directly into the architecture and operational practices of each microservice. 

Implementation Strategies and Impact: 

  • Data Masking and Tokenization: In addition to encryption, data masking and tokenization protect sensitive information. Data masking involves altering the original data to remain usable for testing or analytical purposes but does not expose personal information. Tokenization replaces sensitive data elements with non-sensitive equivalents, known as tokens, which can only be mapped back to the original data through a secure tokenization system. These techniques are particularly effective in development and testing environments within composable architectures, where real data should not be used. 
     
  • Data Residency Solutions: Implement data residency controls to comply with regulations that require data to be stored within certain geographic boundaries. This can involve setting up data storage and processing within specific regions or countries. For modern cloud-native applications, this might mean configuring services to dynamically adapt data storage locations based on the user's location. 
     
  • Regular Compliance Audits: Conduct regular audits and security assessments to ensure ongoing compliance with all regulations. This includes automated compliance checks integrated into the CI/CD pipeline for real-time compliance verification as services are deployed. 

Implementing these data security and compliance measures in a composable architecture helps protect sensitive information from breaches and unauthorized access and builds trust with customers and users by demonstrating commitment to data security and regulatory adherence. Moreover, robust security practices can prevent potential legal and financial penalties associated with non-compliance, supporting sustainable business operations. 
By adopting these principles, organizations can create a data architecture that not only supports the scalability and independence of microservices but also ensures that data remains consistent, secure, and compliant. This foundation is critical for successfully implementing a composable architecture that can adapt to evolving business needs and technological advancements. 

3. Conclusion

In this part of our series, we've discussed how Composable Data Architecture helps modern software systems become more flexible, scalable, and secure. We've covered the importance of each microservice managing its data, using different database technologies suited to their needs, and techniques like API Composition, CQRS, and Event Sourcing. We also emphasized the need for solid data consistency and robust security measures to protect data and comply with various regulations. 
These practices ensure that composable architectures can efficiently handle complex data workflows, making it easier for organizations to adapt to new technologies and regulations without disrupting existing operations. 

composable_III_img_5

Looking Ahead
In the next part of our series, we will focus on Composable Infrastructure and Cloud Strategies. We'll explore how technologies like containerization, orchestration, and cloud-native services can enhance the performance and scalability of composable architectures. We'll also discuss how Infrastructure as Code (IaC) helps manage and automate infrastructure more effectively.

Share on:

I have read and understood the ASSIST Software website's Terms of Use and Privacy Policy.

Want to stay on top of everything?

Get updates on industry developments and the software solutions we can now create for a smooth digital transformation.

Frequently Asked Questions

1. Can you integrate AI into an existing software product?

Absolutely. Our team can assess your current system and recommend how artificial intelligence features, such as automation, recommendation engines, or predictive analytics, can be integrated effectively. Whether it's enhancing user experience or streamlining operations, we ensure AI is added where it delivers real value without disrupting your core functionality.

2. What types of AI projects has ASSIST Software delivered?

We’ve developed AI solutions across industries, from natural language processing in customer support platforms to computer vision in manufacturing and agriculture. Our expertise spans recommendation systems, intelligent automation, predictive analytics, and custom machine learning models tailored to specific business needs.

3. What is ASSIST Software's development process?  

The Software Development Life Cycle (SDLC) we employ defines the stages for a software project. Our SDLC phases include planning, requirement gathering, product design, development, testing, deployment, and maintenance.

4. What software development methodology does ASSIST Software use?  

ASSIST Software primarily leverages Agile principles for flexibility and adaptability. This means we break down projects into smaller, manageable sprints, allowing continuous feedback and iteration throughout the development cycle. We also incorporate elements from other methodologies to increase efficiency as needed. For example, we use Scrum for project roles and collaboration, and Kanban boards to see workflow and manage tasks. As per the Waterfall approach, we emphasize precise planning and documentation during the initial stages.

5. I'm considering a custom application. Should I focus on a desktop, mobile or web app?  

We can offer software consultancy services to determine the type of software you need based on your specific requirements. Please explore what type of app development would suit your custom build product.   

  • A web application runs on a web browser and is accessible from any device with an internet connection. (e.g., online store, social media platform)   
  • Mobile app developers design applications mainly for smartphones and tablets, such as games and productivity tools. However, they can be extended to other devices, such as smartwatches.    
  • Desktop applications are installed directly on a computer (e.g., photo editing software, word processors).   
  • Enterprise software manages complex business functions within an organization (e.g., Customer Relationship Management (CRM), Enterprise Resource Planning (ERP)).

6. My software product is complex. Are you familiar with the Scaled Agile methodology?

We have been in the software engineering industry for 30 years. During this time, we have worked on bespoke software that needed creative thinking, innovation, and customized solutions. 

Scaled Agile refers to frameworks and practices that help large organizations adopt Agile methodologies. Traditional Agile is designed for small, self-organizing teams. Scaled Agile addresses the challenges of implementing Agile across multiple teams working on complex projects.  

SAFe provides a structured approach for aligning teams, coordinating work, and delivering value at scale. It focuses on collaboration, communication, and continuous delivery for optimal custom software development services. 

7. How do I choose the best collaboration model with ASSIST Software?  

We offer flexible models. Think about your project and see which model would be right for you.   

  • Dedicated Team: Ideal for complex, long-term projects requiring high continuity and collaboration.   
  • Team Augmentation: Perfect for short-term projects or existing teams needing additional expertise.   
  • Project-Based Model: Best for well-defined projects with clear deliverables and a fixed budget.   

Contact us to discuss the advantages and disadvantages of each model. 

1. Is ASSIST Software a reliable company for custom engineering?

Absolutely. Our partners have given us great recommendations and reviews, leading us to win The Manifest Award for Most Reviewed Software Developers. Further proof comes from our 97% employee retention rate and ongoing client partnerships for over 8 years.  

2. Are the ASSIST Software Romanian software engineers certified?

Yes. 85% of our software programmers are certified.  

At a company level, ASSIST Software is certified and recognized by industry players such as Microsoft, AWS, Google Cloud, Adobe, Drupal, Fujitsu, ISTQB, and others.  

Our employee certifications are tremendously important as they reflect the shared commitment to long-term growth.

3. Why should I choose Romania for custom software development? 

Romania has become a significant player in custom software development, attracting businesses worldwide. Romania boasts the highest number of certified IT specialists in Europe and ranks sixth globally, surpassing even the US in tech specialists per capita.  

At ASSIST Software, what sets us apart is our team and our location: our engineers are certified, experienced, and flexible, while being in the +2 GMT time zone allows us to easily facilitate meetings with clients all over the world.

4. What team will work on my project, and where will it be located?

ASSIST Software's headquarters is in Romania, a prime country for software development outsourcing. Our 350+ software engineers speak English and have a deep passion for innovation.  

We provide regular project updates through reports, meetings, and online dashboards. Generally, you'll have access to a dedicated project manager who will be your point of contact for any questions or concerns.  

5. How much will my project cost me?

Our prices are competitive, and as per our working model, we guarantee you will be satisfied with the result. Frequent meetings, check-ins, and a great communication structure will ensure this outcome.   

Project costs depend on various factors, including complexity, scope, required technologies, and team size. We'll gather detailed information about your project during the initial consultation to provide a customized quote and we guarantee that you will be able to see the benefits of bespoke software.  

1. What technologies do you work with?

ASSIST Software tackles your projects with a robust tech stack. We build native and cross-platform mobile apps, craft user-friendly web experiences, and create stunning visuals. 

Our wide-ranging expertise starts from Java, Python, and JavaScript frameworks to cutting-edge solutions like AR/VR, blockchain, and AI/ML. We also manage databases, leverage cloud platforms, and ensure flawless project execution. We're your one-stop shop for exceptional software development from concept to deployment. You can view our expertise for more details.   

2. Are you experienced in AI/ML development?

Yes. We have extensive experience in data engineering and machine learning operations (MLOps). We can employ neural networks, computer vision, and AI models to benefit your ideas.   

You can trust our long-term experience with big data, NLP, and sentiment analysis, as over the past three years, we led a European security project with 15 partners focused on detecting radicalization on social media and the dark web.

3. Do you have a research and development department and work on European Projects?

We know R&D is crucial for businesses to stay competitive and thrive in dynamic markets. Successful R&D efforts lead to developing exceptional products or services, improved efficiency and effectiveness in operations, and enhanced market positioning.   

We have established solid partnerships with 160+ European research companies, universities, and research centers (e.g., Fraunhofer, TWI, University of Heidelberg, REWE Group, SINTEF, etc.) and have participated as technical partners in over 25 EU-funded projects.  

4. Besides custom software solutions, what other services do you offer?

  • Design Thinking for Breakthrough Products:  

    We craft user experiences that resonate. Our design process is an immersive collaboration, starting with workshops to uncover your vision and user needs. We conduct market research, analyze the competition, and guide you toward cutting-edge solutions in accordance with your business requirements.  

  • Digital Transformation to Reimagine Your Business:

    Digital transformation is nothing less than a strategic shift. We empower you to become more agile and data-driven, optimizing core processes for the digital age.  

  • Scale with Confidence as We Build for Growth:  

    We understand that business success and development mean new challenges. Our solutions are built to scale seamlessly, accommodating increasing user bases and data volumes without sacrificing performance or security.  

5. As a company, does ASSIST have its own software products?

Yes, ASSIST Software teams have been involved in designing and developing innovative products that address community needs. One such example is the web and mobile platform Autisma. This therapy assistant enables continued learning for children diagnosed with autism spectrum disorder.   

Our extensive knowledge of the Unity and Unreal engines has allowed us to develop two mobile games, Elly and the Ruby Atlas and Hooman Invaders, as well as various Unity Assets, such as the Real-Time Weather PRO and Easy Sky. These two Unity assets allow Unity developers to control the weather and sky in their projects.   

1. Is ASSIST Software hiring right now?

We are always looking for great people to join our team, whether you're a senior software engineer or a new talent seeking an IT career. Please check our careers page and contact us. Our HR department will contact you as soon as possible.   

2. Is ASSIST Software organizing internships?

Yes. Each year, we organize individual and group internships for students. Our long-term partnership with the Stefan cel Mare University of Suceava allows us to put together great events for students and help them get started in the industry. 

3. What type of learning culture does ASSIST Software encourage?

Our focus on innovation comes from a 'can do' attitude and the continuous learning we encourage our colleagues to pursue. We frequently organize workshops, learning sessions, presentations, and masterclasses. All these events are free and open to our colleagues and aim to support their professional and personal development. 

4. How does ASSIST Software focus on teamwork?

The key to stellar teamwork is the quality time we spend together. ASSIST employees and their families are frequently invited to participate in all activities. We encourage a healthy lifestyle by promoting and organizing hikes, bike riding sessions, marathons, volleyball, football and tennis matches, ping-pong championships, and many more.   

We show our care for the environment through reforestation campaigns and forest cleaning activities.   

We also have an English-speaking club, e-sports gaming nights, tech discussions, networking parties, and board game sessions.   

5. How does ASSIST Software give back to the community?

Volunteering and charity are essential to us, which is why we founded the ASSIST Humanitarian Foundation. We genuinely care about our community and want to improve the future. We invest in IT equipment for schools and award excellent teachers. We also help hospitals and fire departments enter the 21st century.   

We sponsor cultural events and deliver humanitarian aid to those in need. If you agree with our views, you can also donate.   

ASSIST Software Team Members