CSCD01 Engineering Large Software Systems
Non-functional requirements Pt 3
Cho Yin Yong / Aleksander Bodurri

Architecture Arena starts this week

Attend your tutorial.

Your peer reviews of other teams' arenas are part of your assessment.

What do Snapchat, Fortnite, and Duolingo have in common?

October 20, 2025

Just before midnight Pacific, a race condition in AWS's own DNS automation left the address of its database service, DynamoDB, empty in the Northern Virginia region (us-east-1).

The automation could not repair the problem, so AWS operators had to fix it by hand.

Anything that needed DynamoDB could no longer find it, including other AWS services. Snapchat, Fortnite, and Duolingo went down.

The address was back by 2:25 AM Pacific, but the incident lasted 14.5 hours.

Source: AWS post-event summary, aws.amazon.com/message/101925
CrowdStrike, 2024 AWS, 2025
A bad update reached every customer Nothing was pushed. Everyone was already sharing
Deployability, Upgradability ?

Why does your Duolingo lesson depend on a DNS record in Virginia?

They rent.

Each one is a tenant in a “building” shared by thousands of companies.

AWS us-east-1
Snapchat
Fortnite
Duolingo
AWS services
DynamoDB
(empty DNS record)
depend on

Multi-tenancy

What is a tenant?

A group of users who share access to a software product.

Usually one customer organization.

Single-tenant
Tenant A
Tenant B
Tenant C
Multi-tenant
Shared
App
Database
App
Database
App
Database
Tenant A
Tenant B
Tenant C
App
Database

Single-tenant or multi-tenant?

Pros Cons
Single Security, customization, independent updates Higher cost, resource-intensive, hard to scale
Multi Cost-effective, scalable, efficient Security risks, performance issues, less customization

The noisy neighbour

One tenant over-consumes shared CPU, memory, bandwidth, or disk I/O.

We can't stop it. We can limit the damage.

  • Horizontal scaling and elasticity (expensive)
  • Application performance monitoring
  • Per-tenant rate limiting
  • A dedicated single-tenant instance
Shared
Tenant A
Tenant B
Tenant C
App
Database

Where would you put the per-tenant rate limiter?

Multi-tenant system
[Software System]
Tenant users [Person]

Staff at many customer organizations

Web application [Container: Ruby on Rails]

Serves requests from every tenant

Database [Container: PostgreSQL]

Stores every tenant's data

Uses
[HTTPS]
Reads and writes
[SQL]
Web application
[Container: Ruby on Rails]
Tenant users [Person]

Staff at many customer organizations

Rate limiter [Component: Rack middleware]

Limits each tenant's requests

Request handlers [Component: Rails controllers]

Implement the product's features

Data access [Component: Active Record]

Reads and writes tenant data

Database [Container: PostgreSQL]

Stores every tenant's data

Uses
[HTTPS]
Allowed requests
Calls
Reads and writes
[SQL]

Container diagram

Component diagram, zoomed into the web application

System context diagramContainer diagramComponent diagram, inside the web application

August 9, 2021

Researchers found that a feature of Azure's managed database, Cosmos DB, could be used to get the keys to other customers' databases.

With a key, an attacker could view, modify, and delete the data in that account.

Microsoft disabled the feature within 48 hours and told customers to regenerate their keys.

Sources: Wiz Research (chaosdb.wiz.io); Microsoft Security Response Center

What keeps one tenant out of another's data?

Multi-tenant system
[Software System]
Tenant users [Person]

Staff at many customer organizations

Web application [Container: Ruby on Rails]

Serves requests from every tenant

Database [Container: PostgreSQL]

Stores every tenant's data

Uses
[HTTPS]
Reads and writes
[SQL]

Security

Every system should follow security best practices in its code.

Some systems also have security as a requirement, because another NFR drives it.

Multi-tenancy is one driver. No tenant can read or change another's data.

White labeling

Canvas is made by a company called Instructure. U of T calls its copy Quercus.

Instructure gives each school a theme editor, so its admins choose their own colours and images.

A school can also upload its own CSS and JavaScript. Then the school is responsible for maintaining any code that conflicts with what Canvas supports.

Configurability

How easily a non-developer can change what the system does.

Ex. Each customer sets its own logo, known as white labelling.

Often at odds with maintainability.

Support staff change behaviour, components read it

Web application
[Container: Ruby on Rails]
Tenant users [Person]

Staff at many customer organizations

Rate limiter [Component: Rack middleware]

Limits each tenant's requests

Request handlers [Component: Rails controllers]

Implement the product's features

Tenant settings [Component: Active Record model]

Per-tenant options, such as limits and branding

Support staff [Person]

Non-developers who change settings

Uses
[HTTPS]
Allowed requests
Reads limits
Reads branding
Edits
[HTTPS]

Maintainability

How easily a developer can change the system.

Maintainability Lines of code Inversely proportional Spaghetti code

Change one component. What else can break?

Web application
[Container: Ruby on Rails]
Request handlers [Component: Rails controllers]

Handle web requests

Business logic [Component: Service objects]

Applies business rules

Data access [Component: Active Record]

Reads and writes data

Email sender [Component: Action Mailer]

Emails customers

Calls
Loads and saves
Queries directly
Emails directly
Emails on save
Looks up customer

Tangled, with 6 dependencies

Web application
[Container: Ruby on Rails]
Request handlers [Component: Rails controllers]

Handle web requests

Business logic [Component: Service objects]

Applies business rules

Data access [Component: Active Record]

Reads and writes data

Email sender [Component: Action Mailer]

Emails customers

Calls
Loads and saves
Sends emails with

Layered, with 3 dependencies

Localization

The extent to which software allows for its user facing interfaces to be presented in various languages (English, French, etc.)

A system with this property must evaluate the impacts on performance, cost and maintainability.

The rise of AI tooling has changed these impacts on cost and maintainability a lot.

Time to market

"This needs to be done by November 16th for UAT."

  • Agility is how fast this can be done
  • Deployability
  • Testability

Legality

Regulations govern what you can and cannot do.

  • PHIPA (Ontario health data) covers auditable record access, data residency, patient authorization to share
  • GDPR and other privacy law

Where does each customer's data live?

Amazon Web Services
[Deployment node: cloud provider]
ca-central-1 (Canada)
[Deployment node: AWS region]
us-east-1 (Northern Virginia)
[Deployment node: AWS region]
Users in Canada [Person]

Customers in Canada

Users elsewhere [Person]

All other customers

Web application [Container: Ruby on Rails]

Serves Canadian customers

Database [Container: PostgreSQL]

Stores Canadian customers' data

Web application [Container: Ruby on Rails]

Serves all other customers

Database [Container: PostgreSQL]

Stores all other customers' data

Uses
[HTTPS]
Reads and writes
[SQL]
Uses
[HTTPS]
Reads and writes
[SQL]

Two ways to draw a system

Whiteboarding

  • Ad hoc, early in a project
  • Made for brainstorming and talking
  • Easy to change

Technical diagrams

  • Follows a standard like UML or C4
  • Documents the system for years
  • Hard to change
SpeedPrecision

Software architecture diagramming maturity model

Level 1
InitialNo software architecture diagrams.
Level 2
Ad hocSoftware architecture diagrams with ad hoc abstractions and notation, in a general purpose diagramming tool.
Level 3
DefinedSoftware architecture diagrams with defined abstractions and notation, in a general purpose diagramming tool.
Level 4
ModelledSoftware architecture diagrams with defined abstractions and notation, in a modelling tool, authored manually.
Level 5
Optimising- Model elements are shared between teams across the organisation.
- Models are used as queryable datasets.
- Automatic generation of model elements from source code, deployment environment, logs, etc.
- etc
C4 model

How to write technical diagrams: C4

Terminology: High Level vs Low Level

High and low define a range, so maybe the question we should ask is: “What do we mean by level?”

Level here refers to level of abstraction.

Terminology: Abstraction

Everyone should know this one. The concept of abstraction is very important when creating software diagrams and whiteboarding.

Abstraction refers to the generalization of complexity.

Something is complex and too difficult to reason about? Let’s make a bunch of assumptions about it until we reach a level of abstraction that we are comfortable reasoning about.

What can we learn from C4?

The C4 model is about layers of Abstraction, with each C being one such layer

  • Context (System)
  • Container
  • Component
  • Class/Code ←Same as UML Class Diagram

Elements in C4 Diagrams

C4 is notation independent, it does not prescribe strict definitions for what can and cannot be elements in its diagrams.

Instead it describes some rules for elements, each element should have:

Web application [Container: Ruby on Rails] Serves requests from every tenant A label A sub-label describing its “type” A short description

Elements in C4 Diagrams

A System is comprised of containers, which are comprised of components (which are comprised of code)

Relationships in C4 Diagrams

Arrow between elements = elements are related

Just like in other diagramming specs, relationships are represented with arrows. Once again, there is no strict prescription here, but there is a permissive set of rules.

All arrows are unidirectional. Whatever the relationship they are describing, each arrow should only describe one side of it.

Every arrow should be labeled.

If the arrow is defining a communication relationship between two elements, the label should specify which communication protocol is being used (for example HTTPS).

Ownership in C4 Diagrams

Often we use third party services in our architectures. In C4 diagrams we use colour to differentiate between elements that we “own” and elements that are brought in from third parties.

Tenant users [Person]

Staff at many customer organizations

Multi-tenant system [Software System]

Serves many customer organizations

Amazon Web Services [Software System]

Cloud provider that hosts the system

Uses
Runs on

Context/System

The top level of the C4 model is the “Context’ diagram. “Context” and “System” are used interchangeably here.

Tenant users [Person]

Staff at many customer organizations

Multi-tenant system [Software System]

Serves many customer organizations

Uses

Container

A container in C4 is either an application or a data store. Think Ruby on Rails app or a PostgreSQL instance.

A container is a deployable unit of code.

Some web applications have both an API layer and serve some frontend code, so should we have 1 container for the entire application? Or should we have two containers, one for the API layer and one for the frontend code?

Multi-tenant system
[Software System]
Tenant users [Person]

Staff at many customer organizations

Web application [Container: Ruby on Rails]

Serves requests from every tenant

Database [Container: PostgreSQL]

Stores every tenant's data

Uses
[HTTPS]
Reads and writes
[SQL]

Component

A component is not a deployable unit, but rather the building block that composes a deployable unit.

Components are inside containers. All components in the same container execute in the same process.

Web application
[Container: Ruby on Rails]
Tenant users [Person]

Staff at many customer organizations

Rate limiter [Component: Rack middleware]

Limits each tenant's requests

Request handlers [Component: Rails controllers]

Implement the product's features

Data access [Component: Active Record]

Reads and writes tenant data

Database [Container: PostgreSQL]

Stores every tenant's data

Uses
[HTTPS]
Allowed requests
Calls
Reads and writes
[SQL]

Class/Code (we are not doing this one)

Who can tell me why?

Deployment

Big Bank Wide Area Network
[Deployment Node]
Developer Laptop
[Deployment Node: Microsoft Windows 11 or Apple macOS]
Web Server Container
[Deployment Node: Docker Container]
Web Server
[Deployment Node: nginx]
Web Browser
[Deployment Node:
Chrome, Firefox,
Safari, or Edge]
Mock Simple Email Service
[Deployment Node: Docker Container]
Java Virtual Machine
[Deployment Node:
Eclipse Temurin - JDK 21 - LTS]
Statement Store Server Container
[Deployment Node: Docker Container]
Statement Store Server
[Deployment Node: MinIO]
Database Server Container
[Deployment Node: Docker Container]
Database Server
[Deployment Node: MySQL 8.4 LTS]
Big Bank Data Center
[Deployment Node]
corebanking-dev
[Deployment Node: Ubuntu 24.04 LTS]
Static Content [Container: Directory]

HTML, CSS, JavaScript, etc.

UI [Container: JavaScript and Angular]

Single-page app that provides Internet banking functionality to customers via their web browser.

Amazon Web Services Simple Email Service [Software System]

Cloud-based email service provider.

Backend [Container: Java and Spring Boot]

Provides Internet banking functionality via a JSON/HTTP API.

Statement Store [Container: Amazon Web Services S3 Bucket]

Bank account statements rendered as PDF files.

Database [Container: MySQL Database Schema]

User account information, access logs, etc.

Core Banking System [Software System]

Handles core banking functions including customer information, bank account management, transactions, etc.

Delivers
Makes API requests to
[JSON/HTTP]
Sends e-mails to customers
using
[AWS SES API/HTTP]
Makes API requests to
[XML/HTTPS]
Reads from and writes to
[AWS S3 API/HTTP]
Reads from and writes to
[MySQL protocol]
Redrawn from the example at c4model.com/diagrams/deployment (Simon Brown, CC BY 4.0)

Read more about C4

The official site explains every diagram type, with examples.

c4model.com

Creating diagrams with AI

Diagram as text

Mermaid.js and C4-PlantUML turn a text DSL into a diagram. The AI writes the text, the tool draws it.

C4Context
  Person(users, "Tenant users", "Staff at many customer orgs")
  System(sys, "Multi-tenant system", "Serves many orgs")
  Rel(users, sys, "Uses")

Diagram as HTML/SVG

An agent draws the diagram directly as HTML or SVG, then exports it.

Recall from lecture 1 that you may use AI to generate the diagrams in your group architecture document.
Please access AI models through ai.xyspace.dev.