Microservice safety improved by tracking data flow between APIs

SafeNom: Data-Aware Microservice Policies

Programming LanguagesNetworking and Internet Architecture

Summary

Modern cloud applications often rely on many small services working together, sending data back and forth. Sometimes, it’s hard to check if these services behave correctly, especially when it comes to how data flows through them. The authors created SafeNom, a tool that watches service communications without changing them, making sure calls happen in the right order and data moves properly. Their method causes only small delays and works without needing to see inside the services themselves.

What this means in practice

Authors

Karuna Grewal, P. Brighten Godfrey, Justin Hsu

Abstract

Many cloud-based applications are organized as loosely coupled microservices, where invoking a service's API triggers a cascade of APIs across many services and leads to inter-service exchange of API parameters and output responses. Current tools for monitoring microservice safety properties have limited expressiveness for properties that describe the flow of data through API calls. To this end, we present SafeNom, a specification and monitoring framework for microservices based on nominal languages. SafeNom policies can express both the desired order of API calls and how the data carried in requests and responses should or should not flow between the APIs. Policies are enforced using a nominal automaton-based distributed runtime monitor which can be applied in a blackbox and non-invasive manner, without access to the service implementation and without making changes to the service implementation. Our experiments show that our monitor can efficiently enforce rich data-aware properties while incurring minimal latency overhead, on the order of a few milliseconds.