Observability Standards
Priority: P1 (OPERATIONAL)
Logging, monitoring, and observability patterns for production applications.
- Standard: Use
nestjs-pinofor high-performance JSON logging.- Why: Node's built-in
console.logis blocking and unstructured.
- Why: Node's built-in
- Configuration:
- Redaction: Mandatory masking of sensitive fields (
password,token,email). - Context: Always inject
Loggerand set the context (LoginService).
- Redaction: Mandatory masking of sensitive fields (
Tracing (Correlation)
- Request ID: Every log line must include a
reqId(Request ID).nestjs-pinohandles this automatically usingAsyncLocalStorage.- Propagation: Pass
x-request-idto downstream microservices/database queries key to trace flows.
API Overhead & Database Benchmarking
- Execution Bucket Strategy: When performance profiling is enabled, utilize global interceptors combined with
AsyncLocalStorageto split and expose latency into logical buckets. - Headers: Expose the metrics via HTTP Headers on the response for immediate feedback during development or testing:
X-Response-Duration-Ms(Total execution time)X-DB-Execution-Ms(Time spent exclusively in database queries, tracked via TypeORM loggers)X-API-Overhead-Ms(Time spent in NestJS interceptors, guards, and serialization)
- Security: Only enable performance headers and detailed SQL benchmarking in development or when a specific feature flag (
ENABLE_PERFORMANCE_BENCHMARK) is explicitly active.
Metrics
- Exposure: Use
@willsoto/nestjs-prometheusto expose/metricsfor Prometheus scraping. - Key Metrics:
http_request_duration_seconds(Histogram)db_query_duration_seconds(Histogram)memory_usage_bytes(Gauge)
Health Checks
- Terminus: Implement explicit logic for "Liveness" (I'm alive) vs "Readiness" (I can take traffic).
- DB Check:
TypeOrmHealthIndicator/PrismaHealthIndicator. - Memory Check: Fail if Heap > 300MB (prevent crash loops).
- DB Check:
Anti-Patterns
- No console.log: Use nestjs-pino for async, structured, JSON-formatted logging.
- No missing reqId: Propagate
x-request-idheader to all downstream services and queries. - No perf data in production by default: Gate benchmarking behind
ENABLE_PERFORMANCE_BENCHMARKflag.