1---2name: software-architect3description: Design scalable systems with sound trade-offs, clear boundaries, and maintainable patterns.4---56# Software Architecture Rules78## Design Principles9- Simple until proven insufficient — complexity is a cost, not a feature10- Separate what changes from what stays stable — boundaries at change boundaries11- Design for the next 10x, not 100x — over-engineering wastes resources12- Make decisions reversible when possible — defer irreversible ones until necessary13- Constraints clarify design — embrace limitations, don't fight them early1415## System Boundaries16- Define clear interfaces between components — contracts enable independent evolution17- Boundaries where teams split — Conway's Law is real, design with it18- Data ownership at boundaries — one source of truth per entity19- Async communication for loose coupling — sync calls create distributed monoliths20- Fail independently — one component's failure shouldn't cascade2122## Trade-off Analysis23- Every decision has costs — articulate what you're giving up24- Consistency vs availability vs partition tolerance — pick two (CAP theorem)25- Performance vs maintainability — optimize hot paths, keep the rest readable26- Build vs buy — build differentiators, buy commodities27- Document the "why not" for rejected alternatives — future you needs context2829## Scalability30- Stateless services scale horizontally — state makes scaling hard31- Cache aggressively, invalidate carefully — caching solves and creates problems32- Database is usually the bottleneck — read replicas, sharding, or denormalization33- Queue work that can be async — users don't need to wait for everything34- Scale for expected load, prepare for 3x spikes — headroom prevents outages3536## Data Architecture37- Schema design constrains everything — get it right early, migrations are expensive38- Normalize for writes, denormalize for reads — optimize for access patterns39- Event sourcing when audit trail matters — reconstruct state from events40- CQRS when read/write patterns differ significantly — separate models for each41- Data gravity is real — processing moves to data, not vice versa4243## Reliability44- Design for failure — everything fails eventually, handle it gracefully45- Timeouts on all external calls — hung connections cascade into outages46- Circuit breakers prevent cascade failures — fail fast, recover gradually47- Idempotency for retries — duplicate messages shouldn't corrupt state48- Graceful degradation over total failure — partial functionality beats error pages4950## Security51- Defense in depth — multiple layers, no single point of failure52- Least privilege — minimal permissions for each component53- Encrypt in transit and at rest — assume networks and disks are hostile54- Validate at boundaries — don't trust input from outside your system55- Secrets management from day one — retrofitting is painful5657## Evolution58- Design for replacement, not immortality — components will be rewritten59- Incremental migration over big bang — strangler fig pattern works60- Backwards compatibility for APIs — breaking changes break trust61- Feature flags decouple deploy from release — ship dark, enable gradually62- Monitor before, during, and after changes — data beats intuition6364## Documentation65- Document decisions, not just structures — ADRs capture reasoning66- Diagrams at multiple zoom levels — C4 model: context, containers, components67- Keep docs near code — separate wikis go stale68- Update docs when architecture changes — wrong docs are worse than none69- Document operational aspects — runbooks, SLOs, failure modes7071## Communication72- Translate technical decisions to business impact — stakeholders need context73- Present options with trade-offs — don't just recommend, explain74- Listen to operators — they know what breaks75- Involve security early — bolt-on security is weak security76- Decisions need buy-in — imposed architecture breeds resentment