Bird's-eye Overview¶
PackyTrace has two browser applications, one API Gateway, and seven bounded-context services. The Gateway is the public edge and is not a bounded context. Measurement & Anonymization is a bounded context implemented by measurement-pipeline.
flowchart TB
Consumer[Consumer app] --> Gateway[API Gateway]
BrandUser[Brand app] --> Gateway
Gateway --> Passport[Product Passport]
Gateway --> Identity[Identity & Consent]
Gateway --> Personalization[Personalization & Verdict]
Gateway --> Fridge[Fridge]
Gateway --> List[Shopping List]
Gateway --> Analytics[Brand Analytics]
Passport -.->|ProductScanned| Measurement[Measurement & Anonymization]
Personalization -.->|VerdictComputed| Measurement
Identity -.->|ConsentRevoked| Personalization
Measurement -.->|minimum-size aggregate only| Analytics
Ownership¶
- Product Passport owns scan records, the Open Food Facts cache, and producer-fed in-memory projections. Producer systems remain authoritative for producer data.
- Identity & Consent owns visitors, accounts, brands, brand users, and consent records. Keycloak owns credentials and authentication.
- Personalization & Verdict owns consent-gated health profiles and deterministic verdict policy.
- Fridge and Shopping List own their event streams and current-state projections.
- Measurement & Anonymization owns deduplication, aggregation windows, and the minimum-group-size privacy gate. It does not own the raw facts published by other contexts.
- Brand Analytics owns tenant-scoped aggregate read models only.
Communication rules¶
Synchronous queries and commands use internal REST. Asynchronous integration facts use Kafka. Services never read another service's schema. Raw per-scan and per-visitor facts remain on the consumer side; only BrandMetricBatchPublished crosses the privacy wall.
See Microservices and Patterns and the Component & Connector views for the maintained architecture.