Seeking Advice: Streamlining Our Company's Web Service Infrastructure
I'm currently grappling with several challenges in our company's web service infrastructure and am seeking insights or advice on how to address them in a sustainable and scalable manner. Here's a breakdown of the issues we're facing:
Redundant Business Logic Across Backend Applications: Our codebase is cluttered with duplicate business logic across various applications. For instance, user creation involves certain checks that are replicated in both the API and a CSV Bulk onboarding application, among other examples. This redundancy extends to a lack of unified test cases, making consistency testing difficult.
Insufficient Documentation and High-Level Design Overview: Our codebase and infrastructure lack comprehensive documentation and high-level design descriptions. This absence complicates the process for developers who need to modify components but cannot easily determine the dependencies or related components that also require adjustments.
Inadequate Access Control with Hasura: We use Hasura as a strict intermediary between our database and other applications, including the frontend. However, we lack proper access control checks. Furthermore, our frontend applications perform actions that should ideally be atomic through multiple separate GraphQL mutations, complicating the implementation of effective access control in Hasura for these actions.
Complex Permission Dynamics: Our system needs to enable users to dynamically define permissions across a broad spectrum of resources, aiming for a level of sophistication comparable to AWS IAM.
Customizable Deployments for Clients: To cater to specific client needs, we create customized instances of our entire infrastructure within their clusters and data centers. This process currently involves forking our codebase and making independent developments for each deployment. As we anticipate an increase in such deployments, we're looking to manage this process more efficiently, ideally maintaining a single codebase.
Given these challenges, particularly the need for minimal rewrites, I'm eager to hear from the community about potential strategies, tools, or practices that could help us streamline our infrastructure, enhance scalability, and improve overall efficiency. Any suggestions on tackling the redundancy, improving documentation, refining access control with Hasura, managing dynamic permissions, and efficiently handling client-specific deployments would be greatly appreciated.
Thank you for your time and insights!