Establish safe boundaries
Enforce tenant isolation, predictable API contracts, authorization, and auditability inside your application.
Start with tenancy
Open-source modules protect data and delivery. Nestarc Reliability follows evidence across requests, databases, queues, workers, and webhooks — without collecting payloads.
Open-source packages keep execution in your environment. Nestarc Reliability correlates the bounded operational evidence those systems explicitly report; it does not execute customer work or collect request bodies, webhook payloads, raw logs, or SQL.
Use tenancy, idempotency, outbox, jobs, and webhook independently or together inside your NestJS application.
Follow one operation from request to external effect. The current pilot is read-only, and recovery controls are not enabled.
Supported packages have active compatibility coverage and maintained documentation. Preview packages are usable, but their APIs and operating contracts are still evolving. Status does not replace the version number or changelog when assessing upgrade risk.
PostgreSQL TEXT/UUID RLS, Prisma tenancy, live audits, and validated RPC tenant context.
Supported · v0.15.0safe-responseAPI response wrapper with Swagger integration, field selection, error catalogs, and i18n support.
Supported · v0.3.0paginationPrisma 7 cursor, keyset, and offset pagination with filters, sorting, and Swagger helpers.
Supported · v0.7.2soft-deletePrisma soft-delete with relation filters, cascade, bulk restore, purge, events, and optional atomic audit lifecycles.
Preview · v0.4.0idempotencyIETF draft-07 Idempotency-Key handling with stable fingerprints, Redis/Postgres storage, and response/header replay.
Supported · v0.7.0audit-logRecord who changed what. Start with one business event or atomic-required Prisma tracking, then query and export the evidence.
Preview · v0.4.0api-keysTenant-scoped API keys with Prisma 5/6/7 storage, request authorization, atomic rotation, and safe management summaries.
Supported · v0.5.0feature-flagDB-backed feature flags with cache adapters, Admin API, rollouts, and tenant overrides.
Supported · v0.2.2rbacTyped tenant-aware permissions, identity-source reconciliation, HTTP guards, Prisma 5/6/7 storage, and final decision audits.
Preview · v0.3.0outboxPrisma transactional outbox with renewable leases, persisted retries, tenant admin scopes, and broker publishing.
Preview · v0.4.0jobsTyped jobs with bounded tenant-fair local workers, BullMQ producer/worker roles, Redis dedupe, retention, and outbox publishing.
Supported · v0.13.1webhookIdempotent HMAC-signed delivery with Prisma 5/6/7 repositories, retry/replay controls, worker metrics, and retention.
Preview · v0.2.0data-subjectGDPR/CCPA export and erase workflows with entity policies, retention, and outbox fan-out.
Multi-tenant SaaS teams repeatedly implement the same high-risk infrastructure. nestarc provides tested building blocks with explicit compatibility ranges, operational contracts, and documented limitations.
// Scattered across 50+ services, easy to forget, hard to audit
async updateUser(id: string, dto: UpdateUserDto) {
const before = await this.prisma.user.findUnique({ where: { id } });
await this.prisma.$executeRaw`SELECT set_config('app.current_tenant', ${tenantId}, true)`;
const after = await this.prisma.user.update({ where: { id, deletedAt: null }, data: dto });
await this.auditService.log({
action: 'user.update',
targetType: 'User',
targetId: id,
metadata: { before, after },
});
return { success: true, data: after, timestamp: new Date() };
}// Tenant isolation, audit logging, soft-delete filtering, and response wrapping
// are all handled automatically by Prisma extensions and NestJS interceptors.
// PrismaService exposes a client created with:
// createAuditedClient(base, { consistency: 'atomic-required', trackedModels: ['User'] });
async updateUser(id: string, dto: UpdateUserDto) {
return this.prisma.client.withAuditTransaction((tx) =>
tx.user.update({ where: { id }, data: dto }),
);
}Package documentation publishes benchmark setup, compatibility ranges, and known limitations alongside the feature guide. Benchmark results describe specific code paths under documented conditions; they are not universal latency promises or cross-package comparisons.
Static security scanning for MCP server implementations and MCP client configuration files. It is published under the @nestarc scope, but lives separately from the NestJS SaaS module lineup.
Explore mcp-guard →