What rate limiting is, with a bucket analogy anyone can follow — then how I built a distributed token-bucket limiter in NestJS + Redis with a live dashboard that shows requests getting throttled in real time.
Verifying Supabase access tokens locally with JWKS inside NestJS guards — no per-request calls to Supabase, with JIT user mirroring and admin promotion.
The bug that wastes the most time is the silent one where the API returns a slightly different shape than the frontend expects. Here is how a single Zod contracts package in a Turborepo kills that class of bug entirely.
What I learned decomposing a field-service product into 14 NestJS services — service boundaries, a shared Zod contract layer, an auth gateway, and async messaging — without drowning in distributed-systems complexity.
Why an interconnected SaaS suite needed its own event backbone, and how I ran a self-hosted Kafka pipeline — topic design, consumer groups, idempotency, and the failure modes you only learn in production.
Role flags do not survive contact with a real enterprise app. Here is the three-tier access model — module, feature, resource — I built for a large manufacturing dashboard, and why each tier earns its place.
Rolling your own auth is usually a mistake — but when you must, the details decide whether it is secure. Here is the access/refresh token + MFA design I built in NestJS, with the pitfalls that bite.
Real-time chat and a live calendar planner are easy on one server and surprising on three. Here is how I designed Socket.IO features in a NestJS ecosystem — rooms, presence, and scaling across instances.
A healthcare platform leans on a lot of AWS. Here is how S3, SES, SQS, Rekognition and EventBridge Scheduler fit into a NestJS API — what each one is actually for, and how to keep them testable.
Most “background job” problems are really two problems — work that should happen now-but-not-inline, and work that should happen later. Here is how I solve both on AWS without running a single always-on worker.