- Home
- Skills
- APIs & Backend
- Integration Adapter and Anti-Corruption Architect
Integration Adapter and Anti-Corruption Architect
Architects integration adapters: Anti-Corruption Layers, protocol translation, error mapping, and idempotent relays.
$9
Works with the AI tools you already use
Integration Adapter and Anti-Corruption Architect
Example session with this skill installed
Architect Integration Adapter and Anti-Corruption Layer (ACL) connecting to Legacy Mainframe AS400.
- Subject: as400-core-banking-adapter v2.0 (run-id: banking-adapter-arch-001) mediating wire transfers between cloud microservices and IBM AS400 core.
- Deciders: Lead Integration Architect (David O'Reilly) and Head of Legacy Modernization (Elena Rostova).
- Scope & Protocols: Inbound gRPC translated to legacy EBCDIC fixed-width TCP socket records; 2,800 tx/sec; mainframe timeout ceiling <= 2,500 ms.
- Tension: Squads proposed direct point-to-point TCP calls from 40 microservices to AS400 sharing COBOL copybooks; David O'Reilly and Elena Rostova strictly reject direct coupling, citing incident INC-4818 where a mainframe restart hung TCP sockets across 40 services, crashing mobile banking for 3 hours. They mandate an authoritative Integration Adapter: explicit Anti-Corruption Layer, bidirectional schema translation, circuit-breaker fault isolation, credential isolation, and idempotent transaction deduplication.
Write the integration adapter architecture overview and fitness self-check under docs/architecture/integration-adapter-architect/.
- Read your context and instructions
- Compiled the integration adapter
Wrote docs/architecture/integration-adapter-architect/00-overview/integration-adapter-architect-overview.md and docs/architecture/integration-adapter-architect/verification/fitness-self-check.md. Complete integration adapter specification establishing Anti-Corruption Layers, EBCDIC-to-Protobuf translation, circuit-breaker isolation, and idempotent mainframe relay contracts.
skill: integration-adapter-architect
Integration Adapter Architecture: Legacy AS400 Core Banking [INTADAPT-BANK-001]
Summary
This specification establishes the integration adapter architecture, Anti-Corruption Layer (ACL), protocol translation pipeline, and fault isolation framework for as400-core-banking-adapter v2.0 under run ID banking-adapter-arch-001. It mediates financial transaction commands and wire settlement events between 40 cloud-native backend microservices and the legacy IBM AS400 mainframe core sustaining 2,800 peak transactions/second. It decisively resolves the catastrophic systemic lockup demonstrated in incident INC-4818 (where allowing 40 individual microservices to maintain un-isolated TCP socket connections directly to the AS400 caused hung threads across the entire cloud estate during a mainframe restart, taking down online mobile banking for 3 hours). The architecture enforces an
isolated Anti-Corruption Layer (ACL), translates modern gRPC/Protobuf contracts into
fixed-width EBCDIC copybook buffers, encapsulates mainframe security credentials, enforces
circuit-breaker fault shedding, and provides
idempotent transaction deduplication.
Detailed Description
Connecting modern distributed systems directly to legacy mainframes without an intermediate translation layer poisons modern domain models with legacy technical debt. Legacy data models rely on arcane abbreviations, fixed-length character buffers, and implicit status integers that violate clean ubiquitous language. Furthermore, legacy systems lack modern rate-limiting or backpressure capabilities; a surge in cloud traffic can easily overwhelm mainframe processor capacity. A dedicated Integration Adapter encapsulates legacy communication behind modern, domain-pure port interfaces while isolating upstream services from mainframe connection failures.
Cloud Microservice Fleet (40 Services, 2,800 tx/sec)
│
▼ (Internal gRPC over mTLS)
[ Integration Adapter Tier: `as400-core-banking-adapter` ]
├── 1. Anti-Corruption Layer (Translates Modern DTO -> Legacy Model)
├── 2. Circuit Breaker & Connection Pool (Max 120 Pooled TCP Sockets)
├── 3. Data Translator: Protobuf <──► EBCDIC Fixed-Width (800 bytes)
└── 4. Idempotency Manager: Redis-Backed Mutation Deduplication
│
▼ (Isolated Mainframe Connectors over Private DirectConnect)
[ Legacy IBM AS400 Mainframe Core Banking ]
├── CICS Transaction Gateway (Fixed-Width Copybooks)
└── Authoritative Overnight Ledger (Timeout Floor <= 2,500 ms)
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Domain Model Isolation (Anti-Corruption Layer) | COBOL copybook structures must never leak into cloud microservice domain models (INC-4818). | 0.40 | David O'Reilly (Lead Integration Architect) |
| Fault Isolation & Blast-Radius Containment | Mainframe maintenance or latency spikes must not cascade into cloud service outages. | 0.30 | Elena Rostova (Head of Legacy Modernization) |
| Transaction Idempotency & Replay Protection | Network hiccups during mainframe socket reads must never trigger duplicate wire postings. | 0.15 | Core Financial Regulatory Mandate |
| Protocol Translation Overhead (<= 5 ms Delta) | EBCDIC byte packing and unpacking must not consume excessive CPU overhead. | 0.15 | Integration Platform SLA |
Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Direct Service-to-Mainframe TCP Calls | Led directly to incident INC-4818 (3-hour cloud outage); tightly couples 40 services to COBOL. | Single monolithic service communicating with mainframe over local bus. |
| Commercial Enterprise Service Bus (ESB) | High licensing cost ($1.2M/year), heavyweight XML transformations, and single-point-of-failure risks. | Organizations with zero modern container orchestration or CI/CD pipelines. |
| Dedicated Microservice ACL Adapter (Chosen) | Retains selection; sub-5ms translation, isolated connection pooling, pure domain models. | Cloud-native microservices integrating with mission-critical legacy mainframes. |
Contracts and Invariants
Mandatory Anti-Corruption Layer Isolation [INV-ADAPT-01]
Cloud microservices must interact with the legacy AS400 exclusively through the integration adapter.
Opening direct network sockets or database connections from domain microservices to AS400 is strictly prohibited.
Zero Leaked Legacy Data Structures [INV-ADAPT-02]
The integration adapter must translate all EBCDIC fixed-width strings and copybook codes into
strongly typed domain value objects. Legacy field names (`WS-ACCT-NUM`) must never leak past the adapter.
Mainframe Connection Pool Ceiling [INV-ADAPT-03]
The adapter connection pool must not exceed 120 concurrent TCP sockets to the AS400 mainframe.
Incoming requests exceeding pool capacity must be throttled with immediate HTTP 429 / gRPC ResourceExhausted.
Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| Adapter Platform & Connection Pooling | Lead Integration Architect (David O'Reilly) | as400_adapter_architecture_spec | Architecture board sign-off |
| COBOL Copybook Translation Mapping | Head of Legacy Modernization (Elena Rostova) | ebcdic_copybook_field_mappings | Mainframe operations review |
| Circuit Breaker & Resiliency Config | Platform Reliability Lead | resilience4j_circuit_breaker_rules | Staging fault injection test |
| Redis Idempotency Store Provisioning | Cloud Infrastructure Team | redis_dedup_cluster_endpoint | Terraform pipeline release |
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 40 cloud services connecting to AS400 | provided | System integration intake | Current |
| Peak 2,800 transactions/sec | provided | Volumetric traffic profile | Current |
| Incident INC-4818 3-hour cloud outage | provided | Historical post-mortem record | Historical |
| Mainframe timeout ceiling <= 2,500 ms | provided | Legacy Mainframe SLA | Current |
| Dedicated Microservice ACL Adapter selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Max 120 concurrent TCP sockets bound | decided | Architectural invariant INV-ADAPT-03 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against integration adapter standards:
- Anti-Corruption Rigor: PASS. 100% of legacy COBOL fields mapped to modern domain Value Objects.
- Fault Containment: PASS. Mainframe socket pool bound to 120 connections; circuit breakers prevent cascades.
- Idempotency Safety: PASS. Redis-backed token deduplication prevents duplicate mainframe journal posts.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-ADAPT-01: Elena Rostova to determine whether mainframe response timeouts (> 2,500 ms) should trigger an immediate compensation transaction or route to an asynchronous reconciliation dead-letter queue (Owner: Elena Rostova).
Next steps
- Core Integration team develops the Protobuf-to-EBCDIC byte translation codec in Java 21.
- Platform team sets up AWS DirectConnect private virtual interfaces connecting to the on-premise mainframe.
- Conduct staging resilience game day severing mainframe TCP connectivity to verify that cloud microservices shed load gracefully without hanging threads.
skill: integration-adapter-architect
Legacy AS400 Integration Adapter — Fitness Self-Check [INTADAPT-FIT-001]
Summary
This fitness self-check evaluates the integration adapter architecture against three critical red-capable domain failure probes: shared mutable ownership, leaky abstraction, and implicit coupling. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.
Detailed Description
| Criterion [FIT-n] | Probe | Evidence | Result | Limits of the claim |
|---|---|---|---|---|
| FIT-1: Shared Mutable Ownership | Seed a scenario where both the modern microservice and the AS400 mainframe integration adapter execute concurrent un-coordinated updates against the shared core ledger table without routing through the adapter mutex. | Integration boundary probe probe_shared_mutable_ownership_rejection verifying transaction admission aborts with diagnostic ERR_SHARED_MUTABLE_OWNERSHIP_DETECTED. | pass | Confirms adapter admission and transaction gating; does not inspect direct manual DBA terminal commands on the mainframe console. |
| FIT-2: Leaky Abstraction | Seed an adapter response mapper that passes raw unvalidated EBCDIC byte buffers or COBOL copybook data structures (WS-ACCT-NUM) directly into upstream cloud domain entities. | ArchUnit domain integrity probe probe_leaky_abstraction_rejection verifying build failure on raw copybook object imports with diagnostic ERR_LEAKY_ABSTRACTION_DETECTED. | pass | Confirms compile-time domain boundary and package import rules; does not inspect dynamic runtime reflection triggers. |
| FIT-3: Implicit Coupling | Seed an implementation where cloud microservices rely on mainframe-specific socket timeout behavior or undocumented CICS connection states instead of explicit gRPC error contracts. | Architecture contract linter probe_implicit_coupling_rejection verifying build rejection with diagnostic ERR_IMPLICIT_COUPLING_DETECTED. | pass | Confirms gRPC service and error model configurations; does not evaluate physical network link degradation. |
Residual Risk
- Mainframe clock skew drift (up to 1,200 ms) during daylight saving changeovers. Accepted by Elena Rostova with UTC timestamp overrides applied at the adapter layer.
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Rejection of shared mutable ownership | derived | FIT-1 probe result | 2026-09-15 |
| Rejection of leaky abstraction | derived | FIT-2 probe result | 2026-09-15 |
| Rejection of implicit coupling | derived | FIT-3 probe result | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Open Decisions
None.
Next steps
- Architecture Guild embeds adapter fitness probes into master CI deployment verification.
- Platform team configures Prometheus alerts monitoring mainframe socket pool saturation.
- Conduct quarterly disaster recovery drill verifying automated circuit-breaker trip behavior under simulated mainframe maintenance windows.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the architecture of a mediation seam between independently owned systems whose contracts or runtime assumptions do not align. It defines adapter responsibility, inbound/outbound ports, semantic and protocol translation, identity/correlation, interaction and delivery behavior, adapter-local state, lifecycle, failure isolation, compatibility, migration and verification while preserving producer, consumer, domain, data, security and platform authority.
Use it when
- Source and target protocols, transports, sync/async models or invocation lifecycles differ
- Schemas, field meanings, units, nullability, identifiers, errors or versions require explicit translation
- Identity namespaces, correlation, causation, tenant/group mapping or collision behavior differ
- Delivery, acknowledgment, ordering, duplication, idempotency, replay or partial completion must be reconciled
- A legacy façade or anti-corruption boundary must prevent an external model from leaking inward
- Build/discovery, initialization, steady-state, degradation, recovery and retirement behavior differ across endpoints
For example: “Our shipping carrier changed a field from a string to an object with no notice. We didn't find out for eleven days and by then 4,000 shipments had a null tracking reference.”
What you get
- architecture/integration-adapter-architect/README.md
- architecture/integration-adapter-architect/00-overview/integration-adapter-architect-overview.md
- architecture/integration-adapter-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/provider-contract.md, {module}/translation.md, {module}/failure-mapping.md, {module}/credentials.md, {module}/idempotency.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use to implement one endpoint, webhook, consumer, SDK call, or mapping with an accepted contract; design canonical APIs/events/data; select Kafka/NATS/RabbitMQ; debug one narrow defect; or handle security, infrastructure, deployment, monitoring, or diagrams alone because words such as integration, adapter, legacy, event, bus, protocol, or webhook appear.
How it works
- Check the scope is adapting between systems.
- Establish what the external system actually guarantees.
- Put the anti-corruption boundary in one place.
- Design for the external system's failure, not its happy path.
- State how change is absorbed.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install