Series · 26 phần
Node.js Production Engineering — Từ Runtime đến Hệ thống phân tán
Lộ trình tiếng Việt gồm 26 phần dành cho kỹ sư muốn hiểu Node.js như một nền tảng production, không chỉ như công cụ dựng API. Series đi từ V8, libuv, event loop, HTTP và Express 5 đến data layer, security, testing, performance, delivery và modular monolith; đào sâu PostgreSQL, Prisma, Redis, NestJS, queue, GraphQL, gRPC, realtime và OpenTelemetry; rồi chuyển sang volume thực chiến về overload control, stream dữ liệu lớn, production diagnostics, multi-tenant SaaS, webhook/payment và một capstone game day. Mỗi phần dùng TypeScript, giải thích mental model trước API, phân tích trade-off và failure mode, kèm tiêu chí vận hành, bài tập cùng tài liệu chính thức để biến kiến thức thành quyết định kỹ thuật.
01 Runtime, API và trust boundary
Hiểu Node.js từ event loop và HTTP tới Express, data layer, authentication và API security.
-
Hiểu đường đi của một tác vụ qua V8, libuv và event loop; từ đó kiểm soát concurrency, stream, worker thread, bộ nhớ và độ trễ production.
-
Theo một HTTP request từ wire tới Node.js handler, rồi thiết kế API contract có giới hạn, timeout, cache, streaming, CORS và graceful shutdown rõ ràng.
-
Thiết kế Express 5 như một request pipeline có thứ tự, validation boundary, error contract, proxy trust và graceful shutdown kiểm chứng được.
-
Thiết kế data layer đúng khi có concurrency: query shape, index, pool, transaction, pagination, repository, MongoDB và cache contract cho API.
-
Thiết kế authentication và API security theo threat model: password hashing, session/JWT, cookie, OAuth/OIDC, authorization và defense-in-depth.
02 Nền tảng production engineering
Thiết kế codebase lớn, delivery, performance, test portfolio và kiến trúc có khả năng tiến hóa.
-
Thiết kế ranh giới module, dependency injection, transaction, cache, queue và resilience để codebase Node.js tiếp tục thay đổi an toàn khi sản phẩm và đội ngũ cùng lớn lên.
-
Biến source code thành một service vận hành được: image bất biến, config và secret, probe, graceful shutdown, migration, rollout, rollback, CI/CD và quan sát deployment.
-
Xây quy trình tối ưu Node.js dựa trên SLO, workload, percentile, profiling, event-loop health, query plan, worker pool, cache, memory và capacity thay vì phỏng đoán.
-
Thiết kế test portfolio theo rủi ro cho domain, HTTP, database, contract, dependency failure, concurrency và migration; đồng thời kiểm soát coverage, flakiness và thời gian phản hồi CI.
-
Thiết kế modular monolith theo bounded context, giữ dependency rule bằng fitness function, ghi ADR và chỉ dùng outbox, saga, CQRS hay microservice khi constraint đòi hỏi.
03 Data, framework và identity chuyên sâu
Đào sâu PostgreSQL, Prisma, Redis, NestJS và identity architecture bằng các invariant production.
-
Thiết kế PostgreSQL 18 cho production: invariant trong schema, index theo workload, đọc EXPLAIN, transaction đúng khi đồng thời, keyset pagination, pooling, MVCC và vận hành từ Node.js.
-
Prisma ORM 7 từ cấu hình ESM, generated client và driver adapter tới migration an toàn, query có kiểm soát, transaction giữ invariant, pooling, observability và test production.
-
Dùng Redis 8 có chủ đích: cache consistency, stampede control, Pub/Sub và Streams, rate limit atomic, distributed lock với fencing, session, BullMQ và vận hành production.
-
Thiết kế NestJS 11 như một runtime kiến trúc: module boundary, DI scope, request lifecycle, validation, policy guard, interceptor, error contract, Prisma 7, testing và graceful shutdown.
-
Thiết kế identity cho Node.js production: threat model, JWT validation, access/refresh token, atomic token-family rotation đa thiết bị, cookie/BFF, OIDC Authorization Code với state, nonce, PKCE và authorization theo resource.
04 Async và distributed systems
Xây queue, GraphQL, microservices/gRPC, realtime và observability theo user journey.
-
Thiết kế background jobs có thể vận hành: BullMQ, delivery semantics, idempotency, transactional outbox, retry có jitter, dead-letter workflow, backpressure và graceful shutdown.
-
Thiết kế GraphQL như một API contract: schema, resolver lifecycle, nullability, DataLoader, cursor pagination, authorization, query-cost control, schema evolution và observability.
-
Tách service có kiểm soát: bounded context, data ownership, gRPC/Protobuf, deadline propagation, retry budget, outbox, saga, mTLS, observability và chiến lược migration.
-
Chọn polling, SSE hay WebSocket từ product contract; triển khai delivery, reconnect, authentication, presence, backpressure, scale-out và graceful draining với Node.js.
-
Xây observability từ user journey: SLI/SLO, error budget, structured logs, metrics cardinality, distributed traces, sampling, Collector topology và incident workflow.
05 Reliability và diagnostics
Kiểm soát overload, stream dữ liệu lớn và điều tra CPU, event loop, heap cùng native memory.
-
Giữ service ổn định khi dependency chậm hoặc traffic tăng: deadline, cancellation, concurrency budget, load shedding, retry, circuit breaker và graceful shutdown.
-
Xử lý upload, export và transform dữ liệu lớn với memory hữu hạn: stream.pipeline, highWaterMark, abort, size limit, integrity, cleanup và observability.
-
Điều tra Node.js bằng evidence: event-loop delay, CPU profile, heap snapshot, RSS/native memory, diagnostic report, trace correlation và controlled experiment.
06 Case study production
Giải bài toán multi-tenant SaaS, webhook/payment và hoàn thiện capstone bằng một production game day.
-
Cô lập tenant xuyên HTTP, PostgreSQL RLS, cache, queue và object storage; kiểm soát authorization, noisy neighbor, migration, audit và incident response.
-
Xử lý webhook đáng tin cậy: raw-body signature, replay defense, inbox, duplicate/out-of-order event, payment state machine, reconciliation và audit.
-
Ghép toàn series thành Order Platform thực tế: invariant, API, PostgreSQL, payment webhook, outbox, stream export, overload, observability, rollout và incident drills.