What you'll learn
Design and deliver a multi-tenant SaaS backend that demonstrates domain modeling, PostgreSQL, Redis, identity, authorization, background jobs, payments-ready boundaries, telemetry, delivery automation, and operational judgment.
By the end of this lesson, you'll be able to:
- Turn product requirements into bounded architecture
- Enforce tenant and billing invariants
- Deliver secure observable workflows
- Present production evidence and tradeoffs
Core mental model
Node.js becomes easier when you separate the JavaScript language from the runtime and the operating-system capabilities it exposes. Use this table as a decision guide.
| Concept | What it means | Decision rule |
|---|---|---|
| Tenant invariant | A rule preventing cross-customer state mixing | Carry tenant scope through identity, policies, queries, cache, jobs, and logs |
| Entitlement | Server-owned permission derived from plan and state | Check it in use cases; never trust client plan claims |
| Outbox | Committed records of events to publish | Use when database state and asynchronous delivery must not diverge |
Professional workflow
Build and verify Node.js programs from the terminal in small, observable steps.
- Define the production SaaS API boundary: inputs, outputs, invariants, ownership, and expected failures.
- Design the data or message contract before choosing implementation details.
- Implement the smallest correct path with dependencies passed explicitly.
- Add validation, failure translation, cleanup, and concurrency behavior.
- Verify the boundary with realistic data and at least one adversarial case.
- Measure or observe the behavior before optimizing or extracting abstractions.
Keep the feedback loop short
Guided code lab
Persist state and its event atomically
The outbox row commits with the domain change; a relay publishes it idempotently after commit.
return inTransaction(async (client) => {
const project = await projects.insert(client, { tenantId, id: ids.next(), name: input.name });
await outbox.append(client, {
id: ids.next(),
topic: 'project.created',
aggregateId: project.id,
payload: { tenantId, projectId: project.id },
});
return project;
});Production practice
Contract
The capstone defines users, tenants, roles, entitlements, resources, workflows, failure semantics, audit evidence, SLOs, and recovery objectives.
Verification
Prove cross-tenant isolation, concurrent quotas, idempotent commands, outbox recovery, cache failure, dependency timeouts, migration compatibility, and restore.
Operations
Provide architecture decisions, threat model, dashboards, alerts, runbooks, capacity assumptions, cost notes, and a staged release plan.
Common failure mode
Independent workshop
Build one production-quality SaaS API in a domain you can explain deeply.
Your finished workshop must include:
- Requirements and ADRs
- Multi-tenant schema
- Secure identity/policies
- Transactional async workflow
- Full test portfolio
- Deployment and operations pack
Definition of done
Recap & quick check
Key takeaways
- Requirements drive architecture
- Tenant scope is end to end
- Entitlements are server-owned
- Outboxes bridge commits and events
- Evidence tells the portfolio story
Quick check
1. Where must tenant scope appear?
2. What problem does an outbox solve?
3. What makes a capstone credible?
Next: Capstone: Real-Time Collaboration Service