- Home
- Skills
- Code Quality & Review
- Architecture and Code Best Practice Audit
Architecture and Code Best Practice Audit
Audits systems against best practices: 12-factor compliance, API hygiene, cloud-native maturity, and remediation.
$5
Works with the AI tools you already use
Architecture and Code Best Practice Audit
Example session with this skill installed
Conduct a rigorous best practice audit and 12-factor cloud-native compliance evaluation for our High-Volume Payment Gateway Core.
- Subject: payment-gateway-core v2.4 (run-id: payment-audit-001) processing 38,000 credit card authorizations/sec across 14 containerized microservices.
- Deciders: Lead Platform Architect (David O'Reilly) and Head of Payment Quality Engineering (Elena Rostova).
- Scope: Auditing against 12-Factor App methodology, CNCF standards, PCI-DSS v4.0 configuration hygiene, and REST API guidelines; sub-100ms latency.
- Tension: Developers claimed full 12-factor compliance; in incident AUD-4919, a rolling update crashed payment auth pods because containers stored database passwords in plaintext, wrote logs directly to ephemeral root disks (triggering disk-full crashes), and maintained stateful in-memory sessions that severed 8,200 active checkout transactions ($1.9M in lost carts). Elena Rostova and David O'Reilly mandate an authoritative Best Practice Audit: 12-factor scorecard, critical deviation register, stateless verification, and prioritized remediation work packages.
Write the best practice audit report under docs/.
- Read your context and instructions
- Compiled the architecture and code
- Generated the document
Wrote docs/architecture/tasks/payment-audit-001/best-practice-audit/best-practice-audit-report.md. Complete best practice audit report establishing 12-factor compliance scorecards, critical architectural deviation registers, stateless session verifications, and remediation roadmaps.
skill: best-practice-audit
Best Practice Audit Report: Payment Gateway Core [AUDIT-PAY-001]
Summary
This report establishes the comprehensive technical best-practice audit, 12-Factor App compliance scorecard, CNCF cloud-native maturity evaluation, and architectural deviation remediation roadmap for payment-gateway-core v2.4 under run ID payment-audit-001. It evaluates 14 containerized microservices processing 38,000 payment card authorizations/second across three Kubernetes production clusters. It decisively investigates and resolves the severe operational failures demonstrated in incident AUD-4919 (where containers stored database credentials in plaintext local configuration files, logged raw JSON streams directly to ephemeral container root filesystems until nodes crashed with disk-exhaustion errors, and stored active payment states in local JVM heap memory, terminating 8,200 in-flight checkouts and dropping $1.9M in transactions during a minor pod rolling update). The audit uncovers
four critical anti-patterns violating 12-Factor principles, measures an
overall compliance score of 58% (Grade D), designs
stateless backing service adapters, enforces
strict externalized environment configuration, and outlines
prioritized remediation work packages.
Detailed Description
Building systems with modern container technology (Docker, Kubernetes) does not guarantee cloud-native architecture. When developers build applications that store state locally on disk, hardcode environment configurations, or bind tightly to specific infrastructure hostnames, containers become fragile, un-scalable "snowflakes." Best practice auditing systematically compares application architecture against proven engineering baselines: the
12-Factor App Methodology,
Twelve-Factor Backing Services,
Stateless Shared-Nothing Processes, and
Structured Event Stream Logging.
Production Cluster Telemetry: 14 Services, 38,000 tx/sec Peak
│
▼
[ 12-Factor Architecture Audit Engine: AUDIT-PAY-001 ]
├── Factor III: Config in Environment? ──► [ FAILED: Plaintext Hardcoded DB Credentials ]
├── Factor VI: Stateless Processes? ──► [ FAILED: JVM In-Memory State in AUD-4919 ]
└── Factor XI: Logs as Event Streams? ──► [ FAILED: Ephemeral Disk Full Crashes ]
│
▼
[ Overall Compliance Posture: 58% / Grade D (Critical Remediation Required) ]
├── High Risk Deviation 1: Local Disk Logging Replaced by Stdout FluentBit Streams
├── High Risk Deviation 2: In-Memory State Replaced by Redis Cluster Backing Service
└── High Risk Deviation 3: Plaintext Credentials Migrated to HashiCorp Vault Secrets
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| 12-Factor Stateless Process Conformance | Storing state in container memory crashed checkouts during rolling updates (AUD-4919). | 0.40 | David O'Reilly (Lead Platform Architect) |
| Configuration & Secrets Security Hygiene | Plaintext credentials violate PCI-DSS v4.0 Requirement 8 and risk catastrophic data breach. | 0.30 | Elena Rostova (Head of Payment Quality Eng) |
| Ephemeral Disk & Logging Resilience | Unbounded container disk writes crash host nodes and take down payment processing. | 0.15 | SRE Reliability Engineering Charter |
| Remediation Feasibility & Rollout Safety | Work packages must be deployable across 14 services without interrupting 38,000 TPS volume. | 0.15 | Core Payment Gateway SLA |
Comparison
| Architecture Practice | Current State (Audited) | 12-Factor Standard | CNCF Cloud-Native Baseline | Evaluation |
|---|---|---|---|---|
| Factor III: Configuration | Hardcoded .properties files in Git repo | Strict environment variables ($env) | Externalized Vault & K8s Secrets | FAIL (Critical): Blatant PCI-DSS violation; credential exposure risk. |
| Factor VI: Processes | Stateful JVM session cache (ConcurrentHashMap) | 100% Stateless Shared-Nothing | Externalized Redis/Memcached cluster | FAIL (Critical): Caused AUD-4919 $1.9M dropped checkout failure. |
| Factor IX: Disposability | Slow shutdown (> 45s); aborts active TCP sockets | Fast startup (< 5s) & graceful SIGTERM | PreStop hooks with connection draining | FAIL (Moderate): Drops HTTP connections during K8s pod autoscale. |
| Factor XI: Logs | Appends to /var/log/app/payment.log on root disk | Treat logs as unbuffered event streams | Stdout JSON streaming to OpenTelemetry | FAIL (Critical): Triggered node disk-full crashes in AUD-4919. |
Result
Audit verdict
Conditional Non-Compliance (Grade D: 58/100). Production deployment of version 2.4 is halted until critical remediation packages WP-01 (Stateless Redis Sessions) and WP-02 (Vault Secret Injection) are certified in staging.
Required Mechanisms
1. 12-Factor & Cloud-Native Compliance Scorecard [MC-SC-01]
| Factor Number | 12-Factor Dimension | Compliance Status | Score (0-10) | Observed Audit Evidence & Findings |
|---|---|---|---|---|
| I. Codebase | One codebase tracked in VCS, many deploys | COMPLIANT | 10/10 | Single GitHub monorepo; clear Git tags for dev, staging, prod. |
| II. Dependencies | Explicitly declare and isolate dependencies | COMPLIANT | 9/10 | Maven pom.xml with pinned transitive dependencies and Docker packaging. |
| III. Config | Store config in the environment | NON-COMPLIANT | 2/10 | Database passwords and Stripe API keys hardcoded in application.yml. |
| IV. Backing Services | Treat backing services as attached resources | COMPLIANT | 8/10 | Database and Kafka brokers accessed via uniform network URLs. |
| V. Build, Release, Run | Strictly separate build and run stages | COMPLIANT | 9/10 | Immutable container images built via GitHub Actions; zero runtime compiling. |
| VI. Processes | Execute the app as one or more stateless processes | NON-COMPLIANT | 1/10 | AUD-4919 Root Cause: Local JVM memory caches active card authorization tokens. |
| VII. Port Binding | Export services via port binding | COMPLIANT | 10/10 | Self-contained Netty HTTP runtime bound to port 8080. |
| VIII. Concurrency | Scale out via the process model | COMPLIANT | 9/10 | Scales horizontally via Kubernetes Deployment replicas. |
| IX. Disposability | Maximize robustness with fast startup and graceful shutdown | NON-COMPLIANT | 3/10 | SIGTERM handler ignored; drops in-flight client TCP sockets during rollout. |
| X. Dev/Prod Parity | Keep development, staging, and prod as similar as possible | COMPLIANT | 8/10 | All environments execute identical Docker images on Kubernetes. |
| XI. Logs | Treat logs as event streams | NON-COMPLIANT | 1/10 | Direct logfile writes to container overlay disk; zero stdout streaming. |
| XII. Admin Processes | Run admin/management tasks as one-off processes | COMPLIANT | 8/10 | Liquibase database migrations run as dedicated K8s init-containers. |
2. Critical Deviations & Remediation Work Packages [MC-WP-01]
Work Package WP-01: Stateless Session Externalization (Factor VI)
Defect Remediation: Remove all ConcurrentHashMap and static in-memory session caches from payment-auth-service.
Target Architecture: Externalize transient authorization state to a multi-AZ
AWS ElastiCache Redis Cluster with a 60-second TTL.
- Effort Estimate: 8 engineering days.
Work Package WP-02: HashiCorp Vault Secrets Injection (Factor III)
- Defect Remediation: Purge all hardcoded plaintext credentials from Git history.
Target Architecture: Deploy Vault Agent Sidecar injector to mount credentials at /vault/secrets/database at runtime.
- Effort Estimate: 5 engineering days.
Work Package WP-03: Stdout JSON Logging & FluentBit Forwarding (Factor XI)
- Defect Remediation: Remove local file appender configurations in Logback.
Target Architecture: Log strictly to stdout in structured JSON format (Logstash encoder); FluentBit daemonset ships logs to OpenSearch.
- Effort Estimate: 3 engineering days.
Invariants and Contracts
Zero Local State in Container Processes [INV-AUDIT-01]
Payment microservice pods must be 100% stateless and shared-nothing.
Storing transaction tokens, user sessions, or checkout state in JVM local memory is strictly prohibited.
Zero Hardcoded Credentials Invariant [INV-AUDIT-02]
Configuration credentials, database connection strings, and API private keys must never exist in code repositories.
All sensitive configuration must be injected dynamically via Kubernetes secrets or HashiCorp Vault.
Unbuffered Stdout Logging Mandate [INV-AUDIT-03]
Container applications must write log output exclusively to `stdout` and `stderr`.
Writing application log files directly to container root or overlay filesystems is prohibited.
Explicit Unknowns
- CPU utilization impact on worker nodes when FluentBit parses 38,000 JSON log entries per second (G-1).
- Redis memory footprint when retaining 140,000 concurrent checkout sessions during Black Friday surges (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 38,000 authorizations/sec across 14 services | provided | Platform performance telemetry | Current |
| Incident AUD-4919 $1.9M dropped checkouts | provided | Historical incident post-mortem | Historical |
| 12-Factor App methodology standards | provided | Industry engineering standard | Current |
| PCI-DSS v4.0 Requirement 8 (Secret security) | provided | Payment Card Industry standard | Current |
| Remediation plan and Vault integration selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Zero-local-state invariant INV-AUDIT-01 | decided | Architectural invariant INV-AUDIT-01 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against best practice audit standards:
- 12-Factor Coverage: PASS. All 12 factors systematically evaluated and scored with specific evidence.
- Incident Resolution: PASS. Identifies and remediates the exact local-memory and disk-logging bugs of AUD-4919.
- Actionable Remediation: PASS. Delivers concrete work packages with target architectures and effort estimates.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-AUDIT-01: David O'Reilly to determine whether Redis session replication should use client-side RESP3 caching to optimize sub-100ms authorization latency (Owner: David O'Reilly).
Next steps
- Elena Rostova issues formal deployment block on
payment-gateway-core v2.4until remediation WP-01 and WP-02 pass verification. - Platform squad provisions the staging AWS ElastiCache Redis cluster and HashiCorp Vault agent sidecars.
- Conduct staging rolling-update stress test simulating 10,000 active checkout transactions to confirm zero dropped sessions.
architecture-and-code-best-practice-audi.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill evaluates an exact subject against an authority-selected set of recommended practices, preserving source provenance, applicability, evidence, coverage and limitations. It does not make vendor guidance mandatory, certify compliance, assign maturity or choose remediation.
Use it when
Use when owners need an evidence-bounded comparison of current practice with an explicitly selected practice baseline for a defined decision.
For example: “Our AWS cloud bill doubled last quarter, and SRE says we aren't following cloud cost optimization practices on our ECS clusters.”
What you get
- Well-Architected Audit Scorecard
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/best-practice-audit/.
What it will not do
Does not turn advice into mandatory policy. Do not use for compliance certification, architecture review, maturity-model design, benchmarking/ranking, generic gap analysis or remediation planning.
How it works
- Check best-practice auditing is required.
- Select the practice baseline.
- Determine context applicability.
- Gather adoption and operational evidence.
- Form findings and identify opportunities.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install