Skip to content

Toolset · TypeScript, Prisma, BullMQ

Node / Express

  • Node.js
  • TypeScript
  • Express

A TypeScript Node backend. Express for the minimal, unopinionated core (or Nest when a team wants structure and DI), with typed data access, schema validation, and a real queue.

Where two tools compete, the one marked our default is what we reach for.

01

Package manager

1 tool
pnpmour default

Fast, strict, disk-efficient. Our default.

02

Framework & DI

3 tools
Expressour default

Minimal, ubiquitous HTTP framework. Our default for small-to-mid services. Decision rule: start with Express for its simplicity and flexibility; consider Nest.js for large teams, or Fastify for performance-critical services.

Structured, opinionated framework with first-class DI and modules. Choose it for larger teams and complex applications that benefit from enforced architecture.

@Injectable()
export class UserService {
  constructor(private readonly repo: UserRepository) {}   // constructor DI
}

@Module({ providers: [UserService, UserRepository] })
export class UserModule {}

High-performance alternative to Express with schema-based validation. Choose it when performance is critical.

03

Environment variables

1 tool
@t3-oss/env-coreour default

Validate env vars at startup with a Zod schema per variable. Define the schema, validate it in the app bootstrap, and fail fast on anything missing or invalid rather than discovering it at runtime. Never hardcode values. Our default.

04

ORM & validation

3 tools
Prismaour default

Type-safe ORM with migrations. Our default.

SQL-first, lightweight typed query builder. Decision rule: start with Prisma for its productivity and safety; consider Drizzle only when you need complex raw SQL or when Prisma's abstraction becomes a limitation.

Zodour default

Validate request bodies, env, and boundaries. Our default.

05

Authentication & authorization

2 tools

JWT for API authentication — verify the token's signature on every request in middleware; never trust decoded claims without verification. Store tokens in HTTP-only cookies or the Authorization header, never in localStorage. Our default.

Enforce authorization with roles resolved server-side and checked per request — never from a client-supplied role. See the RBAC spec for the data model and enforcement points.

06

Security

2 tools
Helmetour default

Set secure HTTP headers (CSP, HSTS, X-Content-Type-Options, and more) with one middleware. Minimal security hygiene for any production API. Our default.

Basic rate limiting to blunt brute-force and abuse. Back it with a shared store (Redis) once you run more than one instance, so limits are enforced across the fleet.

07

Queues & async

1 tool
BullMQour default

Redis-backed job queue with retries and rate limiting; carry IDs, make jobs idempotent (see the job contract). Our default.

08

HTTP & logging

2 tools

The fast HTTP client under Node's fetch. Our default.

Pinoour default

Low-overhead structured JSON logging.

09

Testing

1 tool

Unit tests and HTTP-level integration tests. Our default.

10

Monitoring & observability

3 tools
Sentryour default

Error and performance monitoring with Express middleware. Our default for errors.

OpenTelemetryour default

Vendor-neutral traces, metrics, and logs; auto-instrument HTTP and DB, export anywhere. Our default for tracing.

Prometheus metrics (histograms, counters) exposed at /metrics for scraping.

11

CI/CD

5 tools
GitHub Actionsour default

Test, lint, and build the image on every push. Our default CI.

Dockerour default

Containerise the service for a reproducible deploy. Our default.

Push-to-deploy container hosting close to your users.

Process manager for VM deploys with clustering and zero-downtime reload.

Handle SIGTERM to stop accepting new requests, let in-flight requests finish, and close database and queue connections before exiting. This prevents dropped requests during restarts and is what makes zero-downtime deploys actually zero-downtime.

12

Linting & formatting

4 tools
ESLintour default

Linting with typescript-eslint for a TS backend. Our default.

Prettierour default

Consistent formatting. Our default.

Fast single-binary lint + format alternative.

tsc --noEmit as a type gate in CI.

Building on Node / Express?

We ship production Node / Expresswith exactly this stack. Tell us what you're building.

Start a conversation