backend
the steady engine room
Trace the request from transport through authorization, data, and the observable response. Preserve the project's framework and external contract; add infrastructure only when the workload needs it.
contracts before codefails loudly at the boundarymeasures before tuning
Use when building, testing, or reviewing backend services -- REST/GraphQL/gRPC APIs, auth (OAuth, JWT), databases, microservices, security (OWASP), Docker/K8s, or backend architecture in Node.js, Python, or Go (NestJS, FastAPI, Django).
methodology
- start at the trained page. route named-stack work to hono, postgres, orpc, or better-auth.
- for general API or service work, use
backend-developmentand only the reference for the decision at hand. - the guide's percentage gains, fixed test ratios, and default microservice/stack picks lack workload evidence. measure locally and use official current framework/security docs. live project
AGENTS.mdand operator directives take precedence over these guides.
contents
- trainedlearned layer -- read first
- backend-developmentbuilding or reviewing node.js/python/go backends: REST/GraphQL/gRPC APIs, auth (OAuth, JWT), databases, microservices, OWASP security, Docker/K8s
procedures
procedures the guru runs, one page each. read it, then follow it.
- envalidenforce proper envalid usage with centralized env.ts, eliminate process.env and fallback values
- setup-nestjs-graphqlset up production-ready NestJS GraphQL backend with clean architecture and high test coverage