Skip to content

feat(multi-tenant-crm): add Multi-Tenant CRM sample for Aurora DSQL - #2016

Open
charycha wants to merge 2 commits into
aws-samples:mainfrom
charycha:feat/multi-tenant-crm
Open

charycha wants to merge 2 commits into
aws-samples:mainfrom
charycha:feat/multi-tenant-crm

Conversation

@charycha

@charycha charycha commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

A Node.js + Express (TypeScript) multi-tenant CRM proof of concept designed for the pooled SaaS tenancy model on Amazon Aurora DSQL, running on Amazon ECS Express Mode.

Key patterns demonstrated:

  • Pooled tenancy with tenant_id discriminator on every table
  • Tenant isolation enforced through a centralized data-access layer
  • IAM-authenticated connections via @aws/aurora-dsql-node-postgres-connector (no database passwords, no credential rotation)
  • OCC retry via AuroraDSQLPool.transaction() (built-in retry on 40001)
  • CREATE INDEX ASYNC with sys.wait_for_job for deterministic migrations
  • UUID primary keys to distribute writes across DSQL storage
  • Signed HS256 JWTs for tenant identity (vs trusting X-Tenant-Id header)
  • Application-level referential integrity (DSQL supports FKs, blog discusses the trade-off)

Schema: six CRM tables (tenants, users, accounts, contacts, opportunities, activities) with per-table secondary indexes on tenant_id.

Companion blog: 'Build a multi-tenant CRM on Amazon Aurora DSQL' (in AWS Database Blog editorial pipeline, DBBLOG-6005).

By submitting this pull request, I confirm that my contribution is made under
the terms of the MIT-0 license.

Thank you for your contribution!

A Node.js + Express (TypeScript) multi-tenant CRM proof of concept
designed for the pooled SaaS tenancy model on Amazon Aurora DSQL,
running on Amazon ECS Express Mode.

Key patterns demonstrated:
- Pooled tenancy with tenant_id discriminator on every table
- Tenant isolation enforced through a centralized data-access layer
- IAM-authenticated connections via @aws/aurora-dsql-node-postgres-connector
  (no database passwords, no credential rotation)
- OCC retry via AuroraDSQLPool.transaction() (built-in retry on 40001)
- CREATE INDEX ASYNC with sys.wait_for_job for deterministic migrations
- UUID primary keys to distribute writes across DSQL storage
- Signed HS256 JWTs for tenant identity (vs trusting X-Tenant-Id header)
- Application-level referential integrity (DSQL supports FKs, blog
  discusses the trade-off)

Schema: six CRM tables (tenants, users, accounts, contacts,
opportunities, activities) with per-table secondary indexes on tenant_id.

Companion blog: 'Build a multi-tenant CRM on Amazon Aurora DSQL' (in
AWS Database Blog editorial pipeline, DBBLOG-6005).
@praba2210
praba2210 self-requested a review October 9, 2026 21:27
The committed lockfile pinned transitive dependencies with known
advisories, which failed the dependency-review gate:

  proxy-addr 2.0.7  critical  GHSA-jqcg-44mw-7w3h
                              IP spoofing via IPv4-mapped IPv6 trust subnet
  qs 6.15.3          moderate  GHSA-x5fp-wj9c-mxmx
                              array-limit bypass via bracket-key comma parsing
  qs 6.15.3          moderate  GHSA-4mjr-xmp4-gh2g
                              denial of service via attacker controlled isBuffer

Regenerated the lockfile with npm audit fix. The patched versions were
already permitted by the existing express ^4.21.0 range, so package.json
is unchanged and no source changes were required.

  body-parser  1.20.6 -> 1.20.8
  express      4.22.2 -> 4.22.3
  proxy-addr   2.0.7  -> 2.0.8
  qs           6.15.3 -> 6.16.0

npm audit --audit-level=moderate now reports 0 vulnerabilities.
Verified with npm run typecheck and npm run build.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant