Technology Stack
Complete Technology Inventory
This document provides a comprehensive listing of all technologies, frameworks, libraries, and services used in the PeopleHub platform.
Backend Stack
Runtime & Core Framework
| Technology | Version | Purpose |
|---|---|---|
| Node.js | 22.x LTS | JavaScript runtime (latest LTS in 2025) |
| TypeScript | 5.9.2 | Type-safe JavaScript |
| Fastify | 5.5.0 | High-performance web framework |
| ES Modules | Native | Modern JavaScript module system |
Why Fastify over Express?
- 2-3x faster request handling
- Built-in schema validation with Ajv
- Native TypeScript support
- Plugin architecture for extensibility
- Better error handling out-of-the-box
Database & ORM
| Technology | Version | Purpose |
|---|---|---|
| PostgreSQL | 17.5 | Primary relational database |
| Drizzle ORM | 0.44.4 | Type-safe SQL query builder |
| pg | 8.16.3 | PostgreSQL client for Node.js |
| Drizzle Kit | 0.31.4 | Database migrations and introspection |
Drizzle ORM Benefits:
typescript
// Type-safe queries with autocomplete
const employees = await db
.select()
.from(employeeTable)
.where(eq(employeeTable.status, 'active'))
.orderBy(employeeTable.joiningDate);
// TypeScript knows exact return type!- SQL-like syntax (not ORM magic)
- Zero runtime overhead
- Perfect TypeScript inference
- Lightweight (<10KB)
- Generate types from database schema
Authentication & Security
| Technology | Version | Purpose |
|---|---|---|
| @fastify/jwt | 10.0.0 | JWT token generation and validation |
| @fastify/cookie | 11.0.2 | Cookie parsing and serialization |
| bcryptjs | 3.0.2 | Password hashing |
| Zod | 4.1.3 | Runtime schema validation |
| Ajv | 8.17.1 | JSON schema validation |
JWT Authentication Flow:
- Access token: 4 hours (short-lived)
- Refresh token: 7 days (HTTP-only cookie)
- Bcrypt rounds: 10 (secure password hashing)
AWS SDK & Services
| Technology | Version | Purpose |
|---|---|---|
| @aws-sdk/client-s3 | 3.894.0 | S3 file storage operations |
| @aws-sdk/s3-request-presigner | 3.891.0 | Generate presigned S3 URLs |
| @aws-sdk/client-ses | 3.901.0 | Email sending (notifications service) |
| @fastify/aws-lambda | 6.1.1 | Fastify Lambda adapter |
Build & Deployment (Backend)
| Technology | Version | Purpose |
|---|---|---|
| Serverless Framework | 4.21.0 | Infrastructure as code, deployment |
| serverless-offline | 14.4.0 | Local Lambda development |
| esbuild | 0.25.11 | Fast JavaScript bundler |
| tsx | 4.20.4 | TypeScript execution and watch mode |
Deployment Configuration:
yaml
provider:
runtime: nodejs22.x
region: ap-south-1
memorySize: 1024
timeout: 10
build:
esbuild:
bundle: true
minify: true
sourcemap: true
target: node22Development Tools (Backend)
| Technology | Version | Purpose |
|---|---|---|
| ESLint | 9.33.0 | Code linting |
| Prettier | 3.6.2 | Code formatting |
| TypeScript ESLint | 8.40.0 | TypeScript-specific linting |
| simple-git-hooks | 2.13.1 | Git pre-commit hooks |
| Jest | 29.7.0 | Testing framework |
Frontend Stack
Core Framework & Build Tools
| Technology | Version | Purpose |
|---|---|---|
| React | 19.1.0 | UI framework (latest) |
| TypeScript | 5.8.3 | Type-safe JavaScript |
| Vite | 7.0.4 | Build tool and dev server |
| @vitejs/plugin-react-swc | Latest | Fast refresh with SWC |
Why Vite over Create React App?
- 10-100x faster hot module replacement (HMR)
- Native ES modules (no bundling in dev)
- Optimized production builds with Rollup
- < 1 second cold start
- Built-in TypeScript support
Routing & Navigation
| Technology | Version | Purpose |
|---|---|---|
| @tanstack/react-router | 1.130.12 | Type-safe, file-based routing |
TanStack Router Benefits:
typescript
// Type-safe route navigation
navigate({
to: '/employees/$employeeId',
params: { employeeId: '123' }, // TypeScript validates this!
search: { tab: 'documents' }
});- File-based routing (Next.js-like)
- Full TypeScript support
- Built-in route guards and loaders
- Search params validation with Zod
- 100+ routes in PeopleHub
State Management
| Technology | Version | Purpose |
|---|---|---|
| Zustand | 5.0.8 | Client-side state management |
| @tanstack/react-query | 5.85.5 | Server state management |
Why This Combination?
Zustand (Local State):
- Auth state (user, tokens, permissions)
- UI state (sidebar open/closed, modals)
- Lightweight (<1KB)
- No boilerplate (unlike Redux)
TanStack Query (Server State):
- API data fetching and caching
- Automatic background refetching
- Optimistic updates
- Request deduplication
- 5-minute stale time
Forms & Validation
| Technology | Version | Purpose |
|---|---|---|
| react-hook-form | 7.62.0 | Form state management |
| @hookform/resolvers | 5.2.1 | Form validation resolvers |
| Zod | 4.0.14 | Schema validation |
Form Handling Pattern:
typescript
const schema = z.object({
email: z.string().email(),
password: z.string().min(8)
});
const { register, handleSubmit } = useForm({
resolver: zodResolver(schema)
});Benefits:
- Type-safe form values
- Runtime validation
- Client-side + server-side validation reuse
- Excellent performance (fewer re-renders)
UI Components & Styling
| Technology | Version | Purpose |
|---|---|---|
| Radix UI | Various | Headless accessible components (40+) |
| Tailwind CSS | 4.1.11 | Utility-first CSS framework |
| @tailwindcss/vite | Latest | Vite integration for Tailwind |
| Lucide React | 0.536.0 | Icon library (2000+ icons) |
| Framer Motion | 12.23.12 | Animation library |
Radix UI Components Used:
- Dialog, Popover, Dropdown Menu, Tooltip
- Checkbox, Radio Group, Switch, Select
- Tabs, Accordion, Collapsible
- Alert Dialog, Context Menu, Hover Card
- Form primitives, Label, Separator
- Scroll Area, Slider, Toggle
Why Radix UI?
- Unstyled (full design control with Tailwind)
- Accessibility built-in (ARIA attributes, keyboard navigation)
- No CSS conflicts
- Tree-shakeable (only import what you use)
Data Visualization & UI Enhancements
| Technology | Version | Purpose |
|---|---|---|
| Recharts | 2.15.4 | Charts and graphs |
| date-fns | 4.1.0 | Date manipulation |
| react-day-picker | 9.8.1 | Date picker component |
| Sonner | 2.0.7 | Toast notifications |
HTTP Client
| Technology | Version | Purpose |
|---|---|---|
| Axios | 1.12.2 | HTTP client with interceptors |
API Client Features:
- Automatic JWT token attachment
- 401 handling with token refresh
- Request/response interceptors
- Error normalization
- Base URL configuration per environment
AWS Integration (Frontend)
| Technology | Version | Purpose |
|---|---|---|
| @aws-sdk/client-s3 | 3.894.0 | S3 file uploads |
| @aws-sdk/s3-request-presigner | Latest | Generate presigned upload URLs |
File Upload Pattern:
- Request presigned URL from backend
- Upload directly to S3 from browser
- No file data through Lambda (cost efficient)
Development Tools (Frontend)
| Technology | Version | Purpose |
|---|---|---|
| ESLint | 9.33.0 | Code linting |
| Prettier | 3.6.2 | Code formatting |
| TypeScript ESLint | 8.40.0 | TypeScript linting |
Infrastructure & DevOps
AWS Services
| Service | Purpose | Configuration |
|---|---|---|
| AWS Lambda | Serverless compute | Node.js 22.x, 1024MB RAM, 10s timeout |
| API Gateway | HTTP API routing | HTTP API (not REST API) |
| RDS PostgreSQL | Database | Multi-AZ, PostgreSQL 17.5 |
| S3 | Object storage | Documents, images, frontend hosting |
| CloudFront | CDN | Global edge locations, HTTPS only |
| AWS Secrets Manager | Secrets storage | Auto-rotation enabled (30 days) |
| AWS SES | Email sending | Transactional emails |
| CloudWatch | Logging & monitoring | Lambda logs, RDS metrics |
| IAM | Access control | Least-privilege policies |
CI/CD
| Technology | Purpose |
|---|---|
| GitHub Actions | CI/CD pipelines |
| Node.js 18 | CI runner environment |
| npm | Package management |
| Serverless CLI | Backend deployment |
| AWS CLI | S3 sync, CloudFront invalidation |
Deployment Workflows:
Frontend (deploy-dev.yml):
- Checkout code
- Install dependencies (npm ci)
- Build with Vite (
vite build --mode production) - Sync to S3 bucket
- Invalidate CloudFront cache
Backend (deploy-backend.yml):
- Checkout code
- Install dependencies
- Run TypeScript compilation
- Deploy with Serverless Framework
- Test health endpoint
Deployment Times:
- Frontend: <2 minutes
- Backend: ❤️ minutes
Python Service (PDF Generation)
Runtime & Framework
| Technology | Version | Purpose |
|---|---|---|
| Python | 3.11+ | Runtime for PDF generation |
| Weazy Print | Latest | HTML to PDF conversion |
| Fastify | (Via Lambda) | HTTP endpoint wrapper |
Why Python for PDF?
- Weazy Print: Best HTML-to-PDF library
- Complex CSS support
- Mature ecosystem for document generation
Database Schema
PostgreSQL Features Used
| Feature | Use Case |
|---|---|
| JSONB | Flexible metadata storage |
| Foreign Keys | Data integrity enforcement |
| Indexes | Query performance optimization |
| Triggers | Audit trail automation |
| Views | Complex query simplification |
| CTEs | Recursive org chart queries |
Schema Statistics:
- Tables: 140+ tables
- Relationships: Complex foreign key relationships
- Indexes: Optimized for common query patterns
- Data Volume: Designed for millions of records
Development Environment
Required Tools
| Tool | Version | Purpose |
|---|---|---|
| Node.js | 22.x+ | Backend runtime |
| npm | 10.x+ | Package manager |
| Python | 3.11+ | PDF service |
| PostgreSQL | 17.x | Local database (optional) |
| Git | 2.x+ | Version control |
| AWS CLI | 2.x+ | AWS deployments |
| Serverless CLI | 4.x+ | Lambda deployments |
IDE Recommendations
VS Code Extensions:
- ESLint
- Prettier
- TypeScript and JavaScript Language Features
- Tailwind CSS IntelliSense
- PostgreSQL (for database queries)
- Thunder Client (API testing)
Version Management Strategy
Semantic Versioning
All packages use semantic versioning (semver):
- Major: Breaking changes
- Minor: New features (backward compatible)
- Patch: Bug fixes
Update Strategy
Dependencies:
- Monthly security updates
- Quarterly feature updates
- Annual major version upgrades (with testing)
Lock Files:
package-lock.jsoncommitted to git- Ensures reproducible builds across environments
Performance Optimization
Bundle Size Optimization
Frontend:
- Code splitting: Separate chunks per route
- Tree shaking: Remove unused code
- Dynamic imports: Load components on demand
- Total bundle: ~3.1MB (optimized)
Backend:
- esbuild minification
- Lambda package: ~1.5MB per service
- Excludes dev dependencies
- Cold start: <500ms
Runtime Optimization
Database:
- Connection pooling (10 connections per Lambda)
- Query optimization with indexes
- Pagination for large result sets
API:
- Response caching (where applicable)
- Compression (gzip/brotli)
- Efficient JSON serialization
Security Tools & Practices
Code Security
| Tool | Purpose |
|---|---|
| ESLint security rules | Detect security issues in code |
| Zod validation | Runtime input validation |
| Pre-commit hooks | Prevent bad commits |
| Secrets scanning | Detect committed secrets |
Infrastructure Security
| Service | Purpose |
|---|---|
| AWS Secrets Manager | Store credentials securely |
| IAM roles | Least-privilege access |
| VPC | Network isolation (production plan) |
| WAF | Web application firewall (planned) |
| GuardDuty | Threat detection (planned) |
Monitoring & Observability
Current Tools
| Tool | Purpose |
|---|---|
| CloudWatch Logs | Lambda and application logs |
| CloudWatch Metrics | Lambda performance metrics |
| RDS Performance Insights | Database query analysis |
Planned Tools
| Tool | Purpose |
|---|---|
| X-Ray | Distributed tracing |
| CloudWatch Alarms | Proactive alerting |
| Custom Dashboards | Real-time monitoring |
Technology Selection Criteria
Every technology in PeopleHub was chosen based on:
- Performance: Must deliver sub-second response times
- Type Safety: TypeScript support required
- Maturity: Production-ready, stable releases
- Community: Active maintenance and ecosystem
- Cost: Open-source preferred, no vendor lock-in
- Learning Curve: Team familiarity or easy to learn
- Future-Proof: Modern, growing adoption
Technology Upgrade Path
Short-Term (Next 6 Months)
- All technologies up-to-date as of November 2025
- Quarterly dependency updates
- Security patches as released
Medium-Term (6-12 Months)
- Add X-Ray tracing for observability
- Implement WAF rules for API protection
- Setup GuardDuty for threat detection
- Add CloudWatch custom dashboards
Long-Term (12+ Months)
- Evaluate React 20+ features when released
- Consider Aurora Serverless v3 (if better than RDS)
- Multi-region deployment for global offices
- Advanced caching strategies (Redis/ElastiCache)
Related Documentation
- Architecture Philosophy - Why we chose these technologies
- System Overview - How technologies fit together
- AWS Architecture - AWS services in detail
- CI/CD Pipeline - Deployment process
Technology Stack Last Reviewed: January 2025