Part 16 · Capstone & Mock Interview
30 câu hỏi bảo vệ capstone end-to-end
Không trả lời bằng “best practice”; nối requirement → decision → alternative → failure → evidence và giới hạn hiện tại.
Architecture và domain
1. Vì sao tách Order và Payment?
Data/ownership/change/failure và security boundary khác; thừa nhận operational cost. Với scope nhỏ modular monolith cũng là alternative hợp lệ.
2. Invariants quan trọng nhất?
Một command identity không tạo hai payment effects; legal order transitions; amount/currency ổn định; terminal decisions audit được.
3. POST /orders trả 201 hay 202?
201 nếu resource đã tạo và Location rõ; 202 nếu processing async chưa terminal, kèm status resource/polling semantics.
4. Bảo vệ concurrent order updates?
State transition guard + optimistic version/conditional update và unique constraints; test stale/cancel-confirm race.
5. Vì sao không gọi Payment trong DB transaction?
External latency/failure giữ connection/locks, tăng contention và không tạo distributed atomicity; persist intent/outbox rồi coordinate.
6. Money representation?
Decimal/minor integer với currency/scale/rounding explicit; không binary float. Snapshot amount để product price đổi không sửa lịch sử.
7. API error contract?
Problem Details, stable type/code, validation fields, correlation; không leak stack/secrets và phân biệt retryable/permanent semantics.
8. Frontend chưa làm thì demo sao?
CLI/API collection hoặc minimal static client; backend evidence không phụ thuộc UI. React adapter được thêm sau Part 06–07.
9. SLO chọn thế nào?
Từ user journey/workload/business tolerance; valid-event SLI cho create/terminal payment, target/error budget và measurement source rõ.
10. Scale limit hiện tại?
Nêu evidence load test và first bottleneck: DB pool/index, connector, broker partitions/provider quota; capacity model và next experiment.
Distributed failure và data
11. Timeout payment có nghĩa failed?
Không; outcome unknown. Giữ pending/unknown, query/reconcile bằng provider reference và idempotency key, không charge lại mù.
12. Idempotency implementation?
Scoped key + request fingerprint, unique persisted record, atomic owner/effect, replay same response, conflict mismatched payload và expiry/recovery policy.
13. Retry ở layer nào?
Một owner gần caller, chỉ transient/idempotent, deadline/attempt budget, exponential backoff+jitter và telemetry; tránh nested amplification.
14. Circuit breaker fallback?
Không trả success giả. Reject/degrade thành pending với truthful semantics; observe circuit và protect capacity bằng bulkhead/load shedding.
15. Sync vs async?
Sync đơn giản/low latency nhưng temporal coupling; async buffer/decouple nhưng lag, duplicates, ordering, schema và operations. Chọn theo requirement.
16. Outbox giải quyết gì?
Atomic business state + publish intent trong local transaction; relay vẫn at-least-once nên consumer idempotency và lag monitoring cần.
17. Exactly-once?
Broker transaction có scope giới hạn; DB/provider effects vẫn cần idempotency/reconciliation. Nêu boundary thay vì claim toàn hệ thống exactly-once.
18. Saga compensation?
Business action như cancel/refund/reserve release, có thể fail và cần retry/manual repair; không phải database rollback.
19. Event schema thay đổi?
Version/compatibility policy, additive-first, consumer contract tests, mixed-version rollout và replay old event verification.
20. Restore DB rồi làm gì?
Xác định point/RPO, pause/sequence writers, reconcile outbox/broker/provider và detect duplicates/missing effects trước mở traffic.
Platform, production và interview
21. Readiness vs liveness?
Readiness quyết định nhận traffic; liveness chỉ restart deadlocked/unrecoverable process; startup bảo vệ slow initialization. Sai probe gây cascade.
22. Graceful shutdown?
Mark unready, stop intake, drain in-flight/consumers trong grace period, checkpoint/commit đúng, close pools; test SIGTERM giữa payment/event.
23. Build once/promote?
Cùng image digest đã test được promote; environment config/secret ngoài artifact. Rebuild per env phá identity/provenance.
24. Secret và workload identity?
Không commit/bake; short-lived federation/service account, least privilege, rotation/audit và restricted mount/env exposure.
25. Telemetry tối thiểu?
User SLI, RED/USE, structured/audit logs, HTTP/DB/message traces; outbox age, queue lag, pool wait và reconciliation backlog.
26. P99 cao CPU thấp?
Map queues/waits: connector, executor, DB/HTTP pool, locks, DNS/TLS, downstream, broker lag; correlate trace phases và saturation.
27. Demo failure nào thuyết phục?
Payment timeout after effect hoặc duplicate event: show alert/trace/state, safe mitigation, reconciliation và proof no double charge.
28. Security scope?
Trust boundaries, authn/authz, resource ownership, validation, TLS/secrets/audit, dependency/image supply chain; không lưu real card data.
29. Trade-off lớn nhất?
Chọn decision thật, nêu rejected options, consequence đã xảy ra, evidence và trigger đổi—not tuyên bố technology hoàn hảo.
30. Nếu có thêm hai tuần?
Prioritize bằng risk/evidence gap: reconciliation, restore/game day, authz, load/cost hoặc frontend adapter; nêu measurable acceptance.
Cross-part follow-up prompts (không tăng count 30 câu canonical)
Các prompt từ Markdown closeout dùng để đào sâu sau một câu canonical, không được tính thành question entry mới:
- React tránh stale status overwrite newer result như thế nào?
- CI ngăn untrusted code truy cập deploy credentials ra sao?
- Retry amplification có thể xuất hiện ở những layer nào?
- RPO/RTO và backup restore evidence được chứng minh bằng artifact nào?
- Migrate sync → async không downtime và vẫn giữ idempotency/auditability như thế nào?