Bird's-eye Overview

PackyTrace has two browser applications, one API Gateway, and seven bounded-context services. The Gateway is the public edge and is not a bounded context. Measurement & Anonymization is a bounded context implemented by measurement-pipeline.

flowchart TB Consumer[Consumer app] --> Gateway[API Gateway] BrandUser[Brand app] --> Gateway Gateway --> Passport[Product Passport] Gateway --> Identity[Identity & Consent] Gateway --> Personalization[Personalization & Verdict] Gateway --> Fridge[Fridge] Gateway --> List[Shopping List] Gateway --> Analytics[Brand Analytics] Passport -.->|ProductScanned| Measurement[Measurement & Anonymization] Personalization -.->|VerdictComputed| Measurement Identity -.->|ConsentRevoked| Personalization Measurement -.->|minimum-size aggregate only| Analytics

Ownership

  • Product Passport owns scan records, the Open Food Facts cache, and producer-fed in-memory projections. Producer systems remain authoritative for producer data.
  • Identity & Consent owns visitors, accounts, brands, brand users, and consent records. Keycloak owns credentials and authentication.
  • Personalization & Verdict owns consent-gated health profiles and deterministic verdict policy.
  • Fridge and Shopping List own their event streams and current-state projections.
  • Measurement & Anonymization owns deduplication, aggregation windows, and the minimum-group-size privacy gate. It does not own the raw facts published by other contexts.
  • Brand Analytics owns tenant-scoped aggregate read models only.

Communication rules

Synchronous queries and commands use internal REST. Asynchronous integration facts use Kafka. Services never read another service's schema. Raw per-scan and per-visitor facts remain on the consumer side; only BrandMetricBatchPublished crosses the privacy wall.

See Microservices and Patterns and the Component & Connector views for the maintained architecture.