Toolset · TypeScript, Prisma, BullMQ
Node / Express
- Node.js
- TypeScript
- Express
A TypeScript Node backend. Express for the minimal, unopinionated core (or Nest when a team wants structure and DI), with typed data access, schema validation, and a real queue.
Where two tools compete, the one marked our default is what we reach for.
Package manager
1 toolFast, strict, disk-efficient. Our default.
Framework & DI
3 toolsMinimal, ubiquitous HTTP framework. Our default for small-to-mid services. Decision rule: start with Express for its simplicity and flexibility; consider Nest.js for large teams, or Fastify for performance-critical services.
Structured, opinionated framework with first-class DI and modules. Choose it for larger teams and complex applications that benefit from enforced architecture.
@Injectable()
export class UserService {
constructor(private readonly repo: UserRepository) {} // constructor DI
}
@Module({ providers: [UserService, UserRepository] })
export class UserModule {}High-performance alternative to Express with schema-based validation. Choose it when performance is critical.
Environment variables
1 toolValidate env vars at startup with a Zod schema per variable. Define the schema, validate it in the app bootstrap, and fail fast on anything missing or invalid rather than discovering it at runtime. Never hardcode values. Our default.
ORM & validation
3 toolsType-safe ORM with migrations. Our default.
SQL-first, lightweight typed query builder. Decision rule: start with Prisma for its productivity and safety; consider Drizzle only when you need complex raw SQL or when Prisma's abstraction becomes a limitation.
Validate request bodies, env, and boundaries. Our default.
Authentication & authorization
2 toolsJWT for API authentication — verify the token's signature on every request in middleware; never trust decoded claims without verification. Store tokens in HTTP-only cookies or the Authorization header, never in localStorage. Our default.
Enforce authorization with roles resolved server-side and checked per request — never from a client-supplied role. See the RBAC spec for the data model and enforcement points.
Security
2 toolsSet secure HTTP headers (CSP, HSTS, X-Content-Type-Options, and more) with one middleware. Minimal security hygiene for any production API. Our default.
Basic rate limiting to blunt brute-force and abuse. Back it with a shared store (Redis) once you run more than one instance, so limits are enforced across the fleet.
Queues & async
1 toolRedis-backed job queue with retries and rate limiting; carry IDs, make jobs idempotent (see the job contract). Our default.
HTTP & logging
2 toolsThe fast HTTP client under Node's fetch. Our default.
Low-overhead structured JSON logging.
Testing
1 toolUnit tests and HTTP-level integration tests. Our default.
Monitoring & observability
3 toolsError and performance monitoring with Express middleware. Our default for errors.
Vendor-neutral traces, metrics, and logs; auto-instrument HTTP and DB, export anywhere. Our default for tracing.
Prometheus metrics (histograms, counters) exposed at /metrics for scraping.
CI/CD
5 toolsTest, lint, and build the image on every push. Our default CI.
Containerise the service for a reproducible deploy. Our default.
Push-to-deploy container hosting close to your users.
Process manager for VM deploys with clustering and zero-downtime reload.
Handle SIGTERM to stop accepting new requests, let in-flight requests finish, and close database and queue connections before exiting. This prevents dropped requests during restarts and is what makes zero-downtime deploys actually zero-downtime.
Linting & formatting
4 toolsBuilding on Node / Express?
We ship production Node / Expresswith exactly this stack. Tell us what you're building.
Start a conversation