Contract
Khai báo endpoint, method, request/response fields, pagination semantics, error classes, ownership và behavior khi dependency unavailable.
method · schema · pagination · failure contract
D2 Automation Knowledge · API Reliability
Một HTTP request thành công nói rất ít về production readiness. Integration đáng tin cậy phải có contract rõ cho authentication, completeness, validation, rate limits, retries, duplicate-sensitive side effects, schema drift, observability và recovery.
Direct answer
Production readiness là một contract — không phải một HTTP 200. Integration phải biết credentials thay đổi ra sao, lấy đủ records thế nào, payload nào hợp lệ, limits được tôn trọng ra sao, failure nào được retry, side effect nào phải idempotent và operator recover thế nào khi remote outcome không chắc chắn.
Reliability model
Khai báo endpoint, method, request/response fields, pagination semantics, error classes, ownership và behavior khi dependency unavailable.
method · schema · pagination · failure contract
Xem API keys và OAuth như lifecycle gồm scope, storage, refresh, rotation, expiration và failure handling.
scope · expiry · rotation · secret storage
Consume pagination/cursors đến termination condition đã chứng minh và checkpoint các pull dài để request xanh không che missing records.
cursor · page count · checkpoint · completeness
Tôn trọng provider limits và thiết kế backpressure thay vì chỉ xử lý throttling sau khi production đã lỗi.
429 · quota · concurrency · backoff
Validate required fields, types và supported business states ở boundary trước khi payload trở thành downstream data.
required fields · types · business rules
Classify failure trước retry và bảo vệ repeat-sensitive writes bằng stable business keys, unique constraints hoặc provider idempotency controls.
timeout · attempts · idempotency key · reconciliation
Persist correlation IDs, dependency status, error class, attempts và affected business object để operator diagnose beyond generic HTTP failure.
correlation ID · status · attempts · business ID
Định nghĩa retry, reconcile, replay và escalation mà không bypass validation/idempotency controls đã dùng trong live path.
retry · replay · reconcile · escalate
8 release gates
Document integration boundary trước khi build HTTP nodes.
Credentials thay đổi sau launch; integration phải survive lifecycle đó an toàn.
Completeness và capacity control là một phần correctness.
JSON syntactically valid vẫn có thể vi phạm business contract.
Missing response không đồng nghĩa remote business operation thất bại.
Protect business action, không chỉ workflow execution.
Operator cần trace được một integration event end-to-end.
Production readiness bao gồm path sau failure, không chỉ happy path.
Failure decisions
DO NOT RETRY UNCHANGED
Giữ rejected context, sửa data/mapping rồi reprocess có chủ đích.
RESTORE CREDENTIALS FIRST
Kiểm token expiry, scope, rotation hoặc permissions trước retry.
DEFER WITH BOUNDED BACKOFF
Respect quota/retry guidance và giảm concurrency khi phù hợp.
RETRY ONLY IF SAFE
Dùng bounded attempts; reconcile trước nếu side effect trước đó có thể đã thành công.
RECONCILE BEFORE REPEAT
Query bằng idempotency/business key; chỉ repeat khi remote state chứng minh an toàn.
QUARANTINE / INVESTIGATE
Ngăn malformed/newly interpreted fields silently corrupt downstream state.
Anti-patterns
Page-one success, partial write hoặc valid JSON vẫn có thể tạo incomplete business data.
Auth, validation và schema failures trở thành retry noise hoặc duplicate-side-effect risk.
Export/source/debugging surfaces có thể làm credentials bị lộ ngoài ý muốn.
Integration có thể chạy lâu trên incomplete dataset nhưng nhìn vẫn technically healthy.
Timeout bị coi là failure dù provider có thể đã hoàn tất write.
Operator biết HTTP node fail nhưng không biết object nào, attempt nào hoặc recovery action nào cần làm.
Claim boundaries
HTTP success chỉ nói request được xử lý theo transport/application response; nó không chứng minh pagination, business completeness hoặc downstream correctness.
Timeout chứng minh caller không nhận usable response, không chứng minh remote side effect chưa xảy ra.
Retry chỉ an toàn khi operation repeat-safe hoặc có idempotency/reconciliation control phù hợp.
Mỗi page có thể trả 200 trong khi termination logic sai và records vẫn bị bỏ sót.
Syntax đúng không chứng minh required fields, types, enum semantics hoặc business state hợp lệ.
Provider thêm/đổi fields hoặc enum có thể làm mapping silently sai nếu boundary không validate và version rõ.
Logs/metrics giúp detect và diagnose nhưng không tự bảo đảm dữ liệu đầy đủ, side effect idempotent hoặc business state đúng.
Idempotency chỉ bảo vệ đúng logical identity và scope được thiết kế; key sai hoặc quá rộng có thể gây duplicate hoặc suppress action hợp lệ.
Có retries, rate limiting và monitoring không tự chứng minh uptime, throughput, latency hay recovery time nếu chưa đo production.
Related reading
Thiết kế auth, validation, events và downstream integration boundaries như một operated system.
Read nextBảo vệ duplicate-sensitive side effects khi providers redeliver events hoặc retries đi qua uncertain boundary.
Read nextXem normalization, validation, deduplication, routing và lineage trên nhiều data sources.
Read nextQuay lại knowledge hub về source of truth, retries, observability, queue mode và production readiness.
Read nextFAQ
Integration cần explicit contract, managed authentication lifecycle, complete pagination, rate-limit handling, request/response validation, bounded timeouts/retries, idempotency cho repeat-sensitive side effects, schema-drift detection, durable error context, observability và recovery path rõ khi một bên unavailable.
Dùng platform credential storage hoặc dedicated secret manager. Không embed secrets trong workflow logic, exported JSON, source files hoặc logs. Rotation, expiry và scope changes phải được xem là một phần integration lifecycle.
Không. Chỉ retry khi failure có khả năng transient và operation an toàn để lặp. Với side-effecting write, timeout/5xx ambiguous có thể cần query remote state hoặc reconcile bằng idempotency/business key trước khi repeat.
Integration có thể nhận 200 OK nhưng chỉ lấy page đầu. Nếu cursor/page termination sai, records bị silently omit dù mọi request thực hiện đều thành công. Completeness phải là một phần contract.
Validate required fields/types ở boundary, preserve rejected context khi phù hợp, alert repeated contract violations và version mappings có chủ đích. Silent coercion dễ biến provider change thành incorrect downstream data.
Nó chỉ chứng minh caller không nhận usable response; không chứng minh remote operation chưa xảy ra. Trước khi repeat charge, order, CRM write hoặc action irreversible, query remote state hoặc dùng idempotency/stable business key.
Tôn trọng Retry-After hoặc documented quota window khi available, giảm concurrency nếu cần và dùng bounded backoff/defer policy. Không nên tạo retry storm làm rate limit nặng hơn.
Dùng cho logical business actions có duplicate risk như create order, payment, CRM write hoặc external mutation khi provider hỗ trợ. Key phải gắn với đúng business event/action scope và đi cùng reconciliation cho ambiguous outcome.
Không mặc định. Cần đủ correlation/error/business context để diagnose nhưng phải tránh credentials và unnecessary sensitive payload data. Logging nên theo least-data principle phù hợp với operating need.
Chưa đủ. Vẫn cần contract, auth lifecycle, pagination completeness, validation, idempotency, schema handling, ownership, recovery runbook và business-outcome verification.
Không nên. Replay phải đi qua cùng validation, state checks và duplicate protection như live path; nếu bypass controls trong incident recovery, duplicate hoặc corrupt state rất dễ xảy ra.
Không. Đây là reliability/control framework. Uptime, latency, throughput, failure rate và recovery time chỉ nên claim khi có measured production evidence.
Production API review
D2 có thể map contract, credentials, pagination, validation, retries, idempotency, observability và recovery trước khi integration được đưa vào production workflow.
Tác giả & trách nhiệm
Đội ngũ D2 AI & AutomationAutomation production, API, data pipeline và hệ thống có AI hỗ trợ
D2 tách claim, giả định và evidence. Citation chỉ được gắn khi có nguồn hoặc evidence asset phù hợp; nội dung chưa kiểm chứng không được tự động trình bày như fact đã xác nhận.
Xem phương pháp evidence của D2 →