Back
Secure Task API — Reference Architecture
Production-style API with auth, validation, rate limiting, and containerized deploy.
[User] → [Next.js] → [API + Validation] → [Auth/RBAC] → [Service] → [PostgreSQL]
↘ [Redis Rate Limit]
[Caddy TLS] ← [Docker] ← [GitHub Actions CI]Problem
Needed a realistic API to practice secure design end-to-end.
Requirements
- •JWT auth + RBAC
- •Input validation
- •Rate limiting
- •CI/CD + Docker
Components
Next.js ClientExpress APIAuth MiddlewareService LayerPostgreSQLRedis
Data Flow
Client → API (validation) → Auth (JWT/RBAC) → Service → DB; Redis for rate limit; Caddy for TLS.
Security Boundaries
- •TLS at edge
- •Validation at entry
- •AuthZ per resource
- •Secrets via env
Deployment
Docker multi-stage, GitHub Actions CI, VPS with Caddy + healthcheck.
Trade-offs
JWT stateless vs revocation — short TTL + refresh rotation balances UX and security.