11 — Next Steps
Goal: Point you toward the modules and documentation topics that let you take your blog API from a development prototype to a production system.
Files touched: (no new files — curated links only)
Concepts: Authentication, persistent stores, deployment targets, observability, testing.
Congratulations — you have built a complete blog API with REST, GraphQL, and gRPC from a single TypeScript domain model. Below are the natural next topics, each with a link to the relevant module page.
Authentication
The blog currently allows anyone to create, update, and delete any resource. Real applications restrict operations to authenticated users.
- Email/password + OAuth —
@webda/corecovers the built-inAuthenticationservice which handles email-based login and provides hooks for OAuth. - Google OAuth —
@webda/google-auth— plug-and-play Google Sign-In that adds/auth/googleand/auth/google/callbackroutes automatically. - HAWK authentication —
@webda/hawk— MAC-based API authentication for server-to-server scenarios.
Once authentication is in place, tighten canAct on each model:
async canAct(context: WebContext, action: string): Promise<boolean> {
// Only allow the author to modify their own posts
if (action === "update" || action === "delete") {
return context.getCurrentUserId() === this.authorUuid;
}
return true;
}
Persistent stores
MemoryStore is reset on every server restart — swap it for a durable backend before going to production.
| Backend | Package | Link |
|---|---|---|
| MongoDB | @webda/mongodb | @webda/mongodb |
| PostgreSQL | @webda/postgres | @webda/postgres |
| AWS DynamoDB / S3 | @webda/aws | @webda/aws |
Changing the store is a config-only change — no model code is modified:
{
"postStore": {
"type": "Webda/MongoStore",
"model": "MyBlog/Post",
"mongoUrl": "mongodb://localhost:27017/myblog",
"collection": "posts"
}
}
Deployment
Webda includes first-class deployers for cloud platforms.
| Target | Package | Link |
|---|---|---|
| AWS Lambda + CloudFormation | @webda/aws | @webda/aws |
| Kubernetes | @webda/kubernetes | @webda/kubernetes |
| Google Cloud | @webda/gcp | @webda/gcp |
Deploying to AWS uses a dedicated deployment config:
{
"services": {
"postStore": {
"type": "Webda/DynamoStore",
"model": "MyBlog/Post",
"table": "myblog-posts-prod"
}
}
}
Then deploy with:
webda -d aws deploy
Observability
Logging — @webda/workout — provides structured log output, memory logging for tests, and a useLog helper used throughout this tutorial.
OpenTelemetry — @webda/otel — instruments your services with traces and metrics compatible with any OpenTelemetry backend (Jaeger, Grafana Tempo, AWS X-Ray, etc.).
Add to webda.config.json:
{
"OtelService": {
"type": "Webda/OtelService",
"serviceName": "my-blog",
"endpoint": "http://localhost:4318"
}
}
Testing
@webda/test provides:
WebdaTestbase class for Vitest/Mocha integration tests@testWrapperdecorator for automatic memory-log export on failure- Helpers to spin up an in-process application, register services, and send mock HTTP requests
import { WebdaTest } from "@webda/test";
class PostApiTest extends WebdaTest {
async testCreatePost() {
const ctx = await this.newContext({ method: "POST", url: "/posts", body: { ... } });
await this.execute(ctx);
assert.strictEqual(ctx.statusCode, 200);
}
}
Other packages you may find useful
| Package | Description | Link |
|---|---|---|
@webda/mock | Generates realistic mock data for models (Faker-backed) | @webda/mock |
@webda/elasticsearch | Full-text search integration | @webda/elasticsearch |
@webda/cache | In-process and Redis-backed caching | @webda/cache |
@webda/versioning | Immutable object patches and audit trails | @webda/versioning |
@webda/amqp | AMQP/RabbitMQ queue workers | @webda/amqp |
@webda/cloudevents | CloudEvents ingestion and emission | @webda/cloudevents |
(end of tutorial — return to QuickStart index)