A multi-tenant platform for a supply chain
A logistics company needed to replace an ageing monolith with a platform for orders, warehouses, suppliers and invoicing. The suppliers themselves were to log in, so each of them may see only their own data. That single requirement shaped the whole design.
What we delivered
- A Go backend over PostgreSQL, data separated by Row Level Security and one consistent tenant model
- A Next.js front end with React Query
- Sign-in through Keycloak (OIDC), short-lived access tokens and rotating refresh tokens
- AWS infrastructure (EKS, RDS, ElastiCache) entirely in Terraform
- Deployment through GitHub Actions, operational visibility through OpenTelemetry and Grafana
- Cloudflare in front of the application: WAF, rate limiting, DNS
Approach
Security was part of the design from the start: threat modelling, least privilege, secrets exclusively through AWS Secrets Manager, and automated scanning of dependencies and containers on every change. Before going live the whole thing went through an internal security review and a penetration test.
ResultThe platform runs in production. The separation between suppliers held up under later testing. The engagement continues as a long-term engineering retainer.