Splitting a payments monolith without a rewrite

Took a six-year-old payments monolith from weekly release trains to daily deploys by moving ownership before moving code.

  • Release cadence moved from weekly trains to 14 deploys a day
  • Median change-failure rate fell from 11% to 2.8%
  • Settlement reconciliation moved off the shared schema with no migration weekend

Northwind had forty engineers and one deployable unit. Every attempt to split it had started with a service boundary and stalled in the database.

Ownership before code

We started with ownership instead: a written list of which service was allowed to write each of the ninety-one tables. Producing that list took nine days and settled four arguments that had been open for a year.

The mechanical split

From there the split was mechanical. Write permissions were revoked one table at a time, read views were issued to the previous writers, and only then did code move. The first service left the monolith in week seven. Nothing was rewritten.

  • TypeScript
  • Postgres
  • Kafka
  • AWS