Jamal Aldeen

Cairo local time

Colour theme

Selected workCircuit 1 · Traffic

Edge router

Moving customers to a new system with no downtime

My role
Designed and built
When
ABM Egypt · Nov 2025 – present
Where it stands
In production
routersha256(key)currentnewrequests
one key at a time · one switch back

What I built

A router that sits in front of the company’s whole API and decides, request by request, which platform should answer.

Why it mattered

We are replacing the platform our customers depend on. Moving everyone at once would put every integration at risk in the same minute. The router lets us move one customer at a time, and move them back at once.

Try itType any API key. The router hashes it, looks the hash up in its route map and picks a platform. Then move the key, cut the route source, or send everyone back.

sha256…

routed toCurrent platform

The route map is empty, so every key goes to the current platform.

Illustration running in your browser. It follows the real system’s rules in simplified form; names and numbers are invented, and nothing here touches the real system.

What made it difficult

  • It can’t be the outage

    Every request goes through it, so a bug in the router is downtime for every customer.

  • Its source of truth is young

    The route map comes from the new platform, which is new itself. The router has to keep working when that source goes quiet.

  • Keys are secrets

    It routes by API key without storing or logging a single one.

How I solved it

  1. Keep the last good answer

    The route map is polled. If polling fails, the router keeps the last map it trusted, and anything unknown goes to the current platform. It never guesses.

  2. Hash, never store

    Routes are looked up by the SHA-256 of the key, so a raw key never sits in the router’s memory or logs.

  3. Never replay an uncertain create

    A request that may already have created a task is never retried on the other platform, so a task can’t run twice.

  4. One switch back

    A break-glass switch sends all traffic to the current platform. Status and metrics endpoints show the on-call engineer exactly what it is doing.

What I delivered

In production since September 2026: every live request to the company’s API passes through it.

Today that traffic goes to the current platform. Moving a customer to the new one is a change to the route map, not a deploy.

I also built the tools to trust it: a load generator, a queue-polling simulator and a callback receiver that injects failures.

Built with

  • Go (standard library)
  • SHA-256
  • Prometheus metrics