Examples
Nineteen complete projects, written the way you would actually write them — including the parts that are usually left out.
The reference tells you what exists. These show how it fits together. Each one is a working file layout you can copy into yatta/backend/ and run.
Todo API
Auth, CRUD, cachingSession middleware, per-user data isolation, validated bodies, cursor pagination, a cache in front of a hot read, and a job that sends the daily digest.
- Session middleware and ownership checks
- Validating a JSON body
- Cache-aside with tags
- Fan-out work onto a queue
Image pipeline
Uploads, storage, workersAn upload that returns immediately. The request validates and stores the original, then a worker resizes it, emits an event, and pushes progress to the browser over SSE.
- Streaming an upload to a disk
- Reporting progress from inside a job
- Emitting an event the UI is listening for
- Streaming progress to the client
Realtime chat
WebSockets, rooms, presenceA chat server where joining a room is permission-checked, presence is tracked per room, and messages fan out through rooms rather than a global broadcast.
- Authorising a socket join
- Scoping broadcasts to a room
- Tracking presence without a database write
- Reconnecting clients cleanly
Multi-tenant SaaS
Tenant isolation, scopesRow-level isolation with a per-request tenant scope, a scoped table wrapper that removes the chance of forgetting the filter, and tenant id attached to every span.
- Resolving tenant from the host
- A scoped query helper
- Roles per workspace
- Tenant as a span attribute
Webhook relay
Signing, retries, dead lettersOutbound webhooks that survive a flaky consumer: HMAC over the raw bytes, exponential backoff, and a dead-letter state for endpoints that will never recover.
- Signing and verifying with HMAC
- Constant-time signature comparison
- Distinguishing 4xx from 5xx on retry
- Replaying a dead-letter queue
Audit log
Hash chaining, verificationAn append-only trail where each row commits to the previous one, so deleting or editing a record breaks every link after it and a verifier proves it.
- Stable canonical JSON serialisation
- Chained hashes
- Detecting a tampered or deleted row
- Storing diffs instead of whole rows
Full-text search
Full-text searchFTS5 with a synchronised index, ranked results, and a cache that does not go stale. The index is maintained by triggers, so nothing can write without it.
- FTS5 with triggers
- Ranking and snippets
- Cached queries
- Rebuildable index
Feature flags
Typed flags, live updatesFlags declared once so a rename is a type error, read through a singleflight cache, overridable per user, and pushed to open browsers over a socket.
- A typed flag set
- Singleflight flag reads
- Tag-based invalidation
- Server hydration to avoid a flash
Rate-limited API
Sliding window, tiersA limiter that counts inside a single statement so concurrent requests cannot both slip past the limit, with honest Retry-After values and per-key tiers.
- Atomic increments
- Retry-After and RateLimit headers
- Per-key instead of per-IP limits
- Expiring the counter table
Notification hub
One intent, many channelsCall sites declare an intent; the hub routes it to email, in-app and realtime according to per-user preferences, and batches digests overnight.
- One intent, many channels
- Per-user preferences
- Digest batching
- Live unread badge
Cron scheduler
Overlap locking, jitterScheduled jobs that do not double-run, do not stampede, and survive a restart. Leases are taken in the same statement that reads them.
- Overlap locking
- Jitter
- Misfire handling
- Timezone buckets
CSV import
Streaming, batching, progressA 400MB file that never enters memory, never blocks a request, and reports progress while it runs. Includes a dry run so you see the problems before committing.
- Streaming parser
- Batched writes
- Progress reporting
- Dry run first
Product analytics
Events, rollups, funnelsEvent recording on a queue so it never sits on the request path, with daily rollups that keep queries fast as the raw table grows.
- Non-blocking capture
- Daily rollups
- Idempotent aggregation
- Funnels
Billing & subscriptions
Billing & subscriptionsPlans, proration, idempotent webhooks, dunning, and usage metering that survives a retry.
- Money in minor units
- Proration maths
- Idempotent charges
- Dunning sequence
Admin console
Admin consoleUser management, session revocation, and audited impersonation behind a permission guard.
- Permission-guarded routes
- Audited impersonation
- Session revocation
- Read-only mode
AI support agent
AI support agentA tool-calling agent with full tracing, token and cost accounting, and a hard budget cap.
- Tools as child spans
- Argument validation
- Cost caps
- Human handoff
Quota enforcement
Quota enforcementPer-plan quotas with soft and hard limits, predictive warnings, and usage headers.
- Atomic counting
- Soft vs hard limits
- Predictive exhaustion
- Quota headers
Incident console
Incident consoleThe on-call console you would otherwise write by hand, assembled from the framework's own tracing.
- Issue queue and triage
- Trace waterfall
- Deploy correlation
- Alerting on edges
Full-stack Next.js app
Every subsystem, one projectAll of Yatta behind a Next.js frontend: auth, database, jobs, events, storage, mail, cache, realtime and observability, with one trace spanning both.
- CORS with credentials
- Session auth from React
- SSE progress into state
- Feedback tied to a trace