Option
HeimHeim Skill Entwicklertools senior-backend

Entwickelt und implementiert Backend-Systeme, darunter REST-APIs, Microservices, Datenbankarchitekturen, Authentifizierungsabläufe und Sicherheitsmaßnahmen. Behandelt Themen wie die Entwicklung von „Node.js/Express/Fastify“, die Optimierung von PostgreSQL, API-Sicherheit und Backend-Architekturmuster.

...Alle erweitern
22
Zeit aktualisiert 30. August 2026

Senior-Backend-Entwickler

Backend-Entwicklungsmuster, API-Design, Datenbankoptimierung und Sicherheitspraktiken.

Schnellstart

# Generate API routes from OpenAPI spec
python scripts/api_scaffolder.py openapi.yaml --framework express --output src/routes/

# Analyze database schema and generate migrations
python scripts/database_migration_tool.py --connection postgres://localhost/mydb --analyze

# Load test an API endpoint
python scripts/api_load_tester.py https://api.example.com/users --concurrency 50 --duration 30

Übersicht über die Tools

1. API-Scaffolder

Generiert API-Route-Handler, Middleware und OpenAPI-Spezifikationen aus Schema-Definitionen.

Eingabe: OpenAPI-Spezifikation (YAML/JSON) oder Datenbankschema Ausgabe: Routen-Handler, Validierungs-Middleware, TypeScript-Typen

Verwendung:

# Generate Express routes from OpenAPI spec
python scripts/api_scaffolder.py openapi.yaml --framework express --output src/routes/
# Output: Generated 12 route handlers, validation middleware, and TypeScript types

# Generate from database schema
python scripts/api_scaffolder.py --from-db postgres://localhost/mydb --output src/routes/

# Generate OpenAPI spec from existing routes
python scripts/api_scaffolder.py src/routes/ --generate-spec --output openapi.yaml

Unterstützte Frameworks:

  • Express.js (--framework express)
  • Fastify (--framework fastify)
  • Koa (--framework koa)

2. Tool zur Datenbankmigration

Analysiert Datenbankschemata, erkennt Änderungen und generiert Migrationsdateien mit Rollback-Unterstützung.

Eingabe: Datenbank-Verbindungszeichenfolge oder Schemadateien Ausgabe: Migrationsdateien, Schema-Differenzbericht, Optimierungsvorschläge

Verwendung:

# Analyze current schema and suggest optimizations
python scripts/database_migration_tool.py --connection postgres://localhost/mydb --analyze
# Output: Missing indexes, N+1 query risks, and suggested migration files

# Generate migration from schema diff
python scripts/database_migration_tool.py --connection postgres://localhost/mydb \
  --compare schema/v2.sql --output migrations/

# Dry-run a migration
python scripts/database_migration_tool.py --connection postgres://localhost/mydb \
  --migrate migrations/20240115_add_user_indexes.sql --dry-run

3. API-Lasttest-Tool

Führt HTTP-Lasttests mit konfigurierbarer Parallelität durch und misst Latenz-Perzentile sowie den Durchsatz.

Eingabe: URL des API-Endpunkts und Testkonfiguration Ausgabe: Leistungsbericht mit Latenzverteilung, Fehlerraten und Durchsatzkennzahlen

Verwendung:

# Basic load test
python scripts/api_load_tester.py https://api.example.com/users --concurrency 50 --duration 30
# Output: Throughput (req/sec), latency percentiles (P50/P95/P99), error counts, and scaling recommendations

# Test with custom headers and body
python scripts/api_load_tester.py https://api.example.com/orders \
  --method POST \
  --header "Authorization: Bearer token123" \
  --body '{"product_id": 1, "quantity": 2}' \
  --concurrency 100 \
  --duration 60

# Compare two endpoints
python scripts/api_load_tester.py https://api.example.com/v1/users https://api.example.com/v2/users \
  --compare --concurrency 50 --duration 30

Workflows für die Backend-Entwicklung

API-Design-Workflow

Verwenden Sie diese Funktion beim Entwurf einer neuen API oder bei der Überarbeitung bestehender Endpunkte.

Schritt 1: Ressourcen und Operationen definieren

# openapi.yaml
openapi: 3.0.3
info:
  title: User Service API
  version: 1.0.0
paths:
  /users:
    get:
      summary: List users
      parameters:
        - name: "limit"
          in: query
          schema:
            type: integer
            default: 20
    post:
      summary: Create user
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateUser'

Schritt 2: Routen-Scaffolding generieren

python scripts/api_scaffolder.py openapi.yaml --framework express --output src/routes/

Schritt 3: Geschäftslogik implementieren

// src/routes/users.ts (generated, then customized)
export const createUser = async (req: Request, res: Response) => {
  const { email, name } = req.body;

  // Add business logic
  const user = await userService.create({ email, name });

  res.status(201).json(user);
};

Schritt 4: Validierungs-Middleware hinzufügen

# Validation is auto-generated from OpenAPI schema
# src/middleware/validators.ts includes:
# - Request body validation
# - Query parameter validation
# - Path parameter validation

Schritt 5: Aktualisierte OpenAPI-Spezifikation generieren

python scripts/api_scaffolder.py src/routes/ --generate-spec --output openapi.yaml

Workflow zur Datenbankoptimierung

Verwenden Sie diesen Workflow, wenn Abfragen langsam sind oder die Datenbankleistung verbessert werden muss.

Schritt 1: Aktuelle Leistung analysieren

python scripts/database_migration_tool.py --connection $DATABASE_URL --analyze

Schritt 2: Langsame Abfragen identifizieren

-- Check query execution plans
EXPLAIN ANALYZE SELECT * FROM orders
WHERE user_id = 123
ORDER BY created_at DESC
LIMIT 10;

-- Look for: Seq Scan (bad), Index Scan (good)

Schritt 3: Indexmigrationen generieren

python scripts/database_migration_tool.py --connection $DATABASE_URL \
  --suggest-indexes --output migrations/

Schritt 4: Migration testen (Trockenlauf)

python scripts/database_migration_tool.py --connection $DATABASE_URL \
  --migrate migrations/add_indexes.sql --dry-run

Schritt 5: Anwenden und überprüfen

# Apply migration
python scripts/database_migration_tool.py --connection $DATABASE_URL \
  --migrate migrations/add_indexes.sql

# Verify improvement
python scripts/database_migration_tool.py --connection $DATABASE_URL --analyze

Workflow zur Sicherheitshärtung

Verwenden Sie diesen Workflow bei der Vorbereitung einer API für den Produktivbetrieb oder nach einer Sicherheitsüberprüfung.

Schritt 1: Authentifizierungskonfiguration überprüfen

// Verify JWT configuration
const jwtConfig = {
  secret: process.env.JWT_SECRET,  // Must be from env, never hardcoded
  expiresIn: '1h',                 // Short-lived tokens
  algorithm: 'RS256'               // Prefer asymmetric
};

Schritt 2: Ratenbegrenzung hinzufügen

import rateLimit from 'express-rate-limit';

const apiLimiter = rateLimit({
  windowMs: 15 * 60 * 1000,  // 15 minutes
  max: 100,                   // 100 requests per window
  standardHeaders: true,
  legacyHeaders: false,
});

app.use('/api/', apiLimiter);

Schritt 3: Alle Eingaben validieren

import { z } from 'zod';

const CreateUserSchema = z.object({
  email: z.string().email().max(255),
  name: z.string().min(1).max(100),
  age: z.number().int().positive().optional()
});

// Use in route handler
const data = CreateUserSchema.parse(req.body);

Schritt 4: Lasttest mit Angriffsmustern

# Test rate limiting
python scripts/api_load_tester.py https://api.example.com/login \
  --concurrency 200 --duration 10 --expect-rate-limit

# Test input validation
python scripts/api_load_tester.py https://api.example.com/users \
  --method POST \
  --body '{"email": "not-an-email"}' \
  --expect-status 400

Schritt 5: Überprüfen Sie die Sicherheits-Header

import helmet from 'helmet';

app.use(helmet({
  contentSecurityPolicy: true,
  crossOriginEmbedderPolicy: true,
  crossOriginOpenerPolicy: true,
  crossOriginResourcePolicy: true,
  hsts: { maxAge: 31536000, includeSubDomains: true },
}));

Referenzdokumentation

Datei Enthält Verwendung bei
references/api_design_patterns.md REST vs. GraphQL, Versionierung, Fehlerbehandlung, Paginierung Entwurf neuer APIs
references/database_optimization_guide.md Indizierungsstrategien, Abfrageoptimierung, N+1-Lösungen Behebung langsamer Abfragen
references/backend_security_practices.md OWASP Top 10, Authentifizierungsmuster, Eingabevalidierung Sicherheitshärtung

Schnellübersicht über gängige Muster

REST-API-Antwortformat

{
  "data": { "id": 1, "name": "John" },
  "meta": { "requestId": "abc-123" }
}

Format von Fehlerantworten

{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Invalid email format",
    "details": [{ "field": "email", "message": "must be valid email" }]
  },
  "meta": { "requestId": "abc-123" }
}

HTTP-Statuscodes

Code Anwendungsfall
200 Erfolg (GET, PUT, PATCH)
201 Erstellt (POST)
204 Kein Inhalt (DELETE)
400 Validierungsfehler
401 Authentifizierung erforderlich
403 Zugriff verweigert
404 Ressource nicht gefunden
429 Ratenlimit überschritten
500 Interner Serverfehler

Strategie für Datenbankindizes

-- Single column (equality lookups)
CREATE INDEX idx_users_email ON users(email);

-- Composite (multi-column queries)
CREATE INDEX idx_orders_user_status ON orders(user_id, status);

-- Partial (filtered queries)
CREATE INDEX idx_orders_active ON orders(created_at) WHERE status = 'active';

-- Covering (avoid table lookup)
CREATE INDEX idx_users_email_name ON users(email) INCLUDE (name);

Häufige Befehle

# API Development
python scripts/api_scaffolder.py openapi.yaml --framework express
python scripts/api_scaffolder.py src/routes/ --generate-spec

# Database Operations
python scripts/database_migration_tool.py --connection $DATABASE_URL --analyze
python scripts/database_migration_tool.py --connection $DATABASE_URL --migrate file.sql

# Performance Testing
python scripts/api_load_tester.py https://api.example.com/endpoint --concurrency 50
python scripts/api_load_tester.py https://api.example.com/endpoint --compare baseline.json

Annahmen und überprüfbare Erfolgskriterien (Karpathy-Disziplin)

Bevor diese Funktion eine Unterstützung bereitstellt, ein Muster empfiehlt oder ein Schema ändert, MÜSSEN die folgenden vier Annahmen ermittelt werden. Ist eine davon unbekannt, bricht die Funktion ab und greift stattdessen auf die Bibliothek der „Forcing-Fragen“ zurück.

  1. Lese-/Schreib-Verhältnis + p99-QPS für ein Jahr – bestimmt die Auswahl von Datenbank, Cache, Warteschlange und Partitionierung. Kleppmann, DDIA (2017).
  2. Tenancy-Modell – Single-Tenant, Shared Multi-Tenant, Isolated Multi-Tenant. Bestimmt das Datenzugriffsmuster.
  3. Datensensitivitätsstufe – öffentlich / intern / PII / PHI / PCI. Bestimmt die Mindestanforderungen an die Compliance.
  4. SLO + benannter Fehlerbudget-Verbraucher – Standard aus dem Google SRE-Workbook. Kein SLO = keine Priorisierung von Zuverlässigkeitsmaßnahmen.

Überprüfbare Erfolgskriterien (Karpathy Nr. 4) – jede Empfehlung, die diese Funktion ausgibt, muss Folgendes enthalten:

  • Latenzziele (p50, p95, p99 in ms)
  • Verfügbarkeits- / SLO-Ziel
  • RPO + RTO

Wenn einer dieser drei Punkte nicht angegeben ist, ist die Empfehlung unvollständig – kehre zu Frage 7 der Bibliothek mit den Leitfragen zurück.

Das scripts/backend_decision_engine.py Tool berücksichtigt diese Prüfungen: Es lehnt es ab, ein Profil zu empfehlen, bei dem das Lese-/Schreib-Verhältnis, die QPS, die Mandantenanzahl, die Datensensitivität sowie die Musterpräferenz fehlen.

Anpassungsprofile

Vier integrierte Profile in profiles/ kalibrieren jede Empfehlung:

Profil Wann zu wählen Muster Mindestlatenz (p99)
node-express TS-Team, < 15 Entwickler, kundenorientiertes SaaS Modularer Monolith auf Postgres 600 ms
fastapi-python Python-Team, < 20 Entwickler, ML-nah Modularer Monolith auf Postgres (asynchron) 500 ms
django-monolith Inhaltsintensives CRUD + Admin, < 25 Entwickler Modularer Monolith auf Postgres 800 ms
go-or-rust-microservice Ausgelagerter Service, ≥ 30 Entwickler, Plattformteam, QPS ≥ 1000 Ausgelagerter Dienst 200 ms

Wählen Sie ein Profil aus über:

python scripts/backend_decision_engine.py \
  --team-size 8 --qps-p99 50 --read-write-ratio 20 \
  --tenancy shared-multi-tenant --data-sensitivity pii \
  --pattern modular-monolith --language-preference typescript

Das Tool gibt das am besten passende Profil, den zweitbesten Kompromiss (sofern der Unterschied weniger als 15 % beträgt), Stack-Empfehlungen, Anti-Patterns, benannte Genehmiger und den SLO-Mindestwert zurück. Dieses Tool führt niemals eine automatische Genehmigung durch.

So fügen Sie ein benutzerdefiniertes Profil hinzu: Kopieren Sie profiles/node-express.json in profiles/.json und passen Sie constraints + success_thresholds + named_approver_chain.

Zusammensetzungsübersicht

Diese Funktion implementiert den Zuständigkeitsbereich der Spezialisten der Stufe „POWERFUL“ NICHT neu. Sie verzweigt sich in diese. Siehe references/composition_map.md für die vollständige Routing-Tabelle. Wichtige Verzweigungen:

Betroffenheit Verzweigung in
API-Vertrag / Risiko einer Kompatibilitätsänderung engineering/skills/api-design-reviewer/
Schema-Design + ERD + Indizierung engineering/skills/database-designer/
Schema-Migration ohne Ausfallzeiten engineering/skills/migration-architect/
SLO + SLI + Fehlerbudget engineering/slo-architect/
Observability / Golden Signals engineering/skills/observability-designer/
CI/CD-Pipeline engineering/skills/ci-cd-pipeline-builder/
Sicherheit / Bedrohungsmodell engineering-team/skills/senior-security/, adversarial-reviewer
Nachweis der Compliance (HIPAA / ISO 27001) ra-qm-team/
Karpathy-Prüfung vor dem Commit engineering/karpathy-coder/
Architektur-Checkliste vor dem Start engineering/grill-me/

Der cs-backend-engineer Agent koordiniert diese Forks über context: fork. Rufen Sie ihn von einem anderen Agenten aus auf, entweder Agent({subagent_type: "cs-backend-engineer", prompt: "..."}) oder über die /cs:backend-review .

Bibliothek für Forcing-Fragen (Matt Pocock grill)

Bevor eine Backend-Entscheidung endgültig festgelegt wird, sollten die sieben Forcing-Fragen in references/forcing_questions.md. Regel:

  1. Eine Frage pro Runde. Keine Bündelung.
  2. Empfehle die Antwort stets unter Angabe der Quelle.
  3. Erfassen Sie die Antworten in /tmp/backend-grill-.md.
  4. Wenn ein Ausschlusskriterium zutrifft, höre auf. Umgehe eine ungelöste Lücke nicht.
  5. Nach Frage 7 die backend_decision_engine.py mit den sieben Antworten fort.

Zusammenfassung:

  1. Lese-/Schreibverhältnis + p99-QPS-Prognose?
  2. Tenancy-Modell – einzeln / gemeinsam genutzt / isoliert?
  3. Synchron / asynchron / ereignisgesteuert — Standard + Ausnahmen?
  4. Datensicherheitsstufe – PII / PHI / PCI?
  5. Monolith / modularer Monolith / Microservices – Begründung anhand der Teamgröße?
  6. RPO + RTO?
  7. SLO + benannter Fehlerbudget-Verbraucher?

Aufruf durch andere Agenten und Skills

Drei Schnittstellen:

  1. Slash-Befehl: /cs:backend-review — Vollzugriff + Entscheidungsengine + Kompositions-Routing.
  2. Agent-Subagent: Agent({subagent_type: "cs-backend-engineer", prompt: "..."}) — verzweigt den Kontext, gibt eine Zusammenfassung von ≤ 200 Wörtern zurück.
  3. Direkter Tool-Aufruf: python scripts/backend_decision_engine.py ... — deterministischer Profilabgleich, wenn die Eingaben bekannt sind.

Siehe agents/engineering/cs-backend-engineer.md den vollständigen Aufrufvertrag.

Auf GitHub ansehen
---
name: senior-backend
description: Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. Covers Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns.
---

# Senior Backend Engineer

Backend development patterns, API design, database optimization, and security practices.

---

## Quick Start

```bash
# Generate API routes from OpenAPI spec
python scripts/api_scaffolder.py openapi.yaml --framework express --output src/routes/

# Analyze database schema and generate migrations
python scripts/database_migration_tool.py --connection postgres://localhost/mydb --analyze

# Load test an API endpoint
python scripts/api_load_tester.py https://api.example.com/users --concurrency 50 --duration 30
```

---

## Tools Overview

### 1. API Scaffolder

Generates API route handlers, middleware, and OpenAPI specifications from schema definitions.

**Input:** OpenAPI spec (YAML/JSON) or database schema
**Output:** Route handlers, validation middleware, TypeScript types

**Usage:**
```bash
# Generate Express routes from OpenAPI spec
python scripts/api_scaffolder.py openapi.yaml --framework express --output src/routes/
# Output: Generated 12 route handlers, validation middleware, and TypeScript types

# Generate from database schema
python scripts/api_scaffolder.py --from-db postgres://localhost/mydb --output src/routes/

# Generate OpenAPI spec from existing routes
python scripts/api_scaffolder.py src/routes/ --generate-spec --output openapi.yaml
```

**Supported Frameworks:**
- Express.js (`--framework express`)
- Fastify (`--framework fastify`)
- Koa (`--framework koa`)

---

### 2. Database Migration Tool

Analyzes database schemas, detects changes, and generates migration files with rollback support.

**Input:** Database connection string or schema files
**Output:** Migration files, schema diff report, optimization suggestions

**Usage:**
```bash
# Analyze current schema and suggest optimizations
python scripts/database_migration_tool.py --connection postgres://localhost/mydb --analyze
# Output: Missing indexes, N+1 query risks, and suggested migration files

# Generate migration from schema diff
python scripts/database_migration_tool.py --connection postgres://localhost/mydb \
  --compare schema/v2.sql --output migrations/

# Dry-run a migration
python scripts/database_migration_tool.py --connection postgres://localhost/mydb \
  --migrate migrations/20240115_add_user_indexes.sql --dry-run
```

---

### 3. API Load Tester

Performs HTTP load testing with configurable concurrency, measuring latency percentiles and throughput.

**Input:** API endpoint URL and test configuration
**Output:** Performance report with latency distribution, error rates, throughput metrics

**Usage:**
```bash
# Basic load test
python scripts/api_load_tester.py https://api.example.com/users --concurrency 50 --duration 30
# Output: Throughput (req/sec), latency percentiles (P50/P95/P99), error counts, and scaling recommendations

# Test with custom headers and body
python scripts/api_load_tester.py https://api.example.com/orders \
  --method POST \
  --header "Authorization: Bearer token123" \
  --body '{"product_id": 1, "quantity": 2}' \
  --concurrency 100 \
  --duration 60

# Compare two endpoints
python scripts/api_load_tester.py https://api.example.com/v1/users https://api.example.com/v2/users \
  --compare --concurrency 50 --duration 30
```

---

## Backend Development Workflows

### API Design Workflow

Use when designing a new API or refactoring existing endpoints.

**Step 1: Define resources and operations**
```yaml
# openapi.yaml
openapi: 3.0.3
info:
  title: User Service API
  version: 1.0.0
paths:
  /users:
    get:
      summary: List users
      parameters:
        - name: "limit"
          in: query
          schema:
            type: integer
            default: 20
    post:
      summary: Create user
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateUser'
```

**Step 2: Generate route scaffolding**
```bash
python scripts/api_scaffolder.py openapi.yaml --framework express --output src/routes/
```

**Step 3: Implement business logic**
```typescript
// src/routes/users.ts (generated, then customized)
export const createUser = async (req: Request, res: Response) => {
  const { email, name } = req.body;

  // Add business logic
  const user = await userService.create({ email, name });

  res.status(201).json(user);
};
```

**Step 4: Add validation middleware**
```bash
# Validation is auto-generated from OpenAPI schema
# src/middleware/validators.ts includes:
# - Request body validation
# - Query parameter validation
# - Path parameter validation
```

**Step 5: Generate updated OpenAPI spec**
```bash
python scripts/api_scaffolder.py src/routes/ --generate-spec --output openapi.yaml
```

---

### Database Optimization Workflow

Use when queries are slow or database performance needs improvement.

**Step 1: Analyze current performance**
```bash
python scripts/database_migration_tool.py --connection $DATABASE_URL --analyze
```

**Step 2: Identify slow queries**
```sql
-- Check query execution plans
EXPLAIN ANALYZE SELECT * FROM orders
WHERE user_id = 123
ORDER BY created_at DESC
LIMIT 10;

-- Look for: Seq Scan (bad), Index Scan (good)
```

**Step 3: Generate index migrations**
```bash
python scripts/database_migration_tool.py --connection $DATABASE_URL \
  --suggest-indexes --output migrations/
```

**Step 4: Test migration (dry-run)**
```bash
python scripts/database_migration_tool.py --connection $DATABASE_URL \
  --migrate migrations/add_indexes.sql --dry-run
```

**Step 5: Apply and verify**
```bash
# Apply migration
python scripts/database_migration_tool.py --connection $DATABASE_URL \
  --migrate migrations/add_indexes.sql

# Verify improvement
python scripts/database_migration_tool.py --connection $DATABASE_URL --analyze
```

---

### Security Hardening Workflow

Use when preparing an API for production or after a security review.

**Step 1: Review authentication setup**
```typescript
// Verify JWT configuration
const jwtConfig = {
  secret: process.env.JWT_SECRET,  // Must be from env, never hardcoded
  expiresIn: '1h',                 // Short-lived tokens
  algorithm: 'RS256'               // Prefer asymmetric
};
```

**Step 2: Add rate limiting**
```typescript
import rateLimit from 'express-rate-limit';

const apiLimiter = rateLimit({
  windowMs: 15 * 60 * 1000,  // 15 minutes
  max: 100,                   // 100 requests per window
  standardHeaders: true,
  legacyHeaders: false,
});

app.use('/api/', apiLimiter);
```

**Step 3: Validate all inputs**
```typescript
import { z } from 'zod';

const CreateUserSchema = z.object({
  email: z.string().email().max(255),
  name: z.string().min(1).max(100),
  age: z.number().int().positive().optional()
});

// Use in route handler
const data = CreateUserSchema.parse(req.body);
```

**Step 4: Load test with attack patterns**
```bash
# Test rate limiting
python scripts/api_load_tester.py https://api.example.com/login \
  --concurrency 200 --duration 10 --expect-rate-limit

# Test input validation
python scripts/api_load_tester.py https://api.example.com/users \
  --method POST \
  --body '{"email": "not-an-email"}' \
  --expect-status 400
```

**Step 5: Review security headers**
```typescript
import helmet from 'helmet';

app.use(helmet({
  contentSecurityPolicy: true,
  crossOriginEmbedderPolicy: true,
  crossOriginOpenerPolicy: true,
  crossOriginResourcePolicy: true,
  hsts: { maxAge: 31536000, includeSubDomains: true },
}));
```

---

## Reference Documentation

| File | Contains | Use When |
|------|----------|----------|
| `references/api_design_patterns.md` | REST vs GraphQL, versioning, error handling, pagination | Designing new APIs |
| `references/database_optimization_guide.md` | Indexing strategies, query optimization, N+1 solutions | Fixing slow queries |
| `references/backend_security_practices.md` | OWASP Top 10, auth patterns, input validation | Security hardening |

---

## Common Patterns Quick Reference

### REST API Response Format
```json
{
  "data": { "id": 1, "name": "John" },
  "meta": { "requestId": "abc-123" }
}
```

### Error Response Format
```json
{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Invalid email format",
    "details": [{ "field": "email", "message": "must be valid email" }]
  },
  "meta": { "requestId": "abc-123" }
}
```

### HTTP Status Codes
| Code | Use Case |
|------|----------|
| 200 | Success (GET, PUT, PATCH) |
| 201 | Created (POST) |
| 204 | No Content (DELETE) |
| 400 | Validation error |
| 401 | Authentication required |
| 403 | Permission denied |
| 404 | Resource not found |
| 429 | Rate limit exceeded |
| 500 | Internal server error |

### Database Index Strategy
```sql
-- Single column (equality lookups)
CREATE INDEX idx_users_email ON users(email);

-- Composite (multi-column queries)
CREATE INDEX idx_orders_user_status ON orders(user_id, status);

-- Partial (filtered queries)
CREATE INDEX idx_orders_active ON orders(created_at) WHERE status = 'active';

-- Covering (avoid table lookup)
CREATE INDEX idx_users_email_name ON users(email) INCLUDE (name);
```

---

## Common Commands

```bash
# API Development
python scripts/api_scaffolder.py openapi.yaml --framework express
python scripts/api_scaffolder.py src/routes/ --generate-spec

# Database Operations
python scripts/database_migration_tool.py --connection $DATABASE_URL --analyze
python scripts/database_migration_tool.py --connection $DATABASE_URL --migrate file.sql

# Performance Testing
python scripts/api_load_tester.py https://api.example.com/endpoint --concurrency 50
python scripts/api_load_tester.py https://api.example.com/endpoint --compare baseline.json
```

---

## Assumptions and Verifiable Success Criteria (Karpathy discipline)

Before this skill scaffolds, recommends a pattern, or modifies a schema, the following four assumptions MUST be surfaced. If any are unknown, the skill stops and walks the [Forcing-question library](#forcing-question-library-matt-pocock-grill) instead.

1. **Read/write ratio + one-year p99 QPS** — drives DB, cache, queue, and partitioning choices. Kleppmann, *DDIA* (2017).
2. **Tenancy model** — single-tenant, shared multi-tenant, isolated multi-tenant. Drives data-access pattern.
3. **Data sensitivity tier** — public / internal / PII / PHI / PCI. Drives compliance floor.
4. **SLO + named error-budget consumer** — Google SRE Workbook canon. No SLO = no reliability work prioritization.

**Verifiable success criteria** (Karpathy #4) — every recommendation this skill emits must include:

- Latency targets (p50, p95, p99 in ms)
- Uptime / SLO target
- RPO + RTO

If any of those three is not stated, the recommendation is incomplete — return to Q7 of the forcing-question library.

The `scripts/backend_decision_engine.py` tool encodes these checks: it refuses to recommend a profile without read/write ratio + QPS + tenancy + data sensitivity + pattern preference.

---

## Customization profiles

Four built-in profiles in `profiles/` calibrate every recommendation:

| Profile | When to pick | Pattern | Latency floor (p99) |
|---|---|---|---|
| `node-express` | TS team, < 15 eng, customer-facing SaaS | Modular monolith on Postgres | 600ms |
| `fastapi-python` | Python team, < 20 eng, ML-adjacent | Modular monolith on Postgres (async) | 500ms |
| `django-monolith` | Content-heavy CRUD + admin, < 25 eng | Modular monolith on Postgres | 800ms |
| `go-or-rust-microservice` | Extracted service, ≥ 30 eng, platform team, QPS ≥ 1000 | Extracted service | 200ms |

Pick a profile via:

```bash
python scripts/backend_decision_engine.py \
  --team-size 8 --qps-p99 50 --read-write-ratio 20 \
  --tenancy shared-multi-tenant --data-sensitivity pii \
  --pattern modular-monolith --language-preference typescript
```

The tool returns the best-fit profile, runner-up tradeoff (if within 15%), stack picks, anti-patterns, named approvers, and SLO floor. **This tool never auto-approves.**

To add a custom profile: copy `profiles/node-express.json` to `profiles/<your-org>.json` and adjust `constraints` + `success_thresholds` + `named_approver_chain`.

---

## Composition map

This skill does NOT reimplement scope owned by the POWERFUL-tier specialists. It forks into them. See `references/composition_map.md` for the full routing table. Key forks:

| Concern | Fork into |
|---|---|
| API contract / breaking-change risk | `engineering/skills/api-design-reviewer/` |
| Schema design + ERD + indexing | `engineering/skills/database-designer/` |
| Zero-downtime schema migration | `engineering/skills/migration-architect/` |
| SLO + SLI + error-budget | `engineering/slo-architect/` |
| Observability / golden signals | `engineering/skills/observability-designer/` |
| CI/CD pipeline | `engineering/skills/ci-cd-pipeline-builder/` |
| Security / threat model | `engineering-team/skills/senior-security/`, `adversarial-reviewer` |
| Compliance evidence (HIPAA / ISO 27001) | `ra-qm-team/` |
| Pre-commit Karpathy review | `engineering/karpathy-coder/` |
| Pre-flight architecture grill | `engineering/grill-me/` |

The `cs-backend-engineer` agent orchestrates these forks via `context: fork`. Invoke it from another agent with `Agent({subagent_type: "cs-backend-engineer", prompt: "..."})` or via `/cs:backend-review <your problem>`.

---

## Forcing-question library (Matt Pocock grill)

Before locking any backend decision, walk the seven forcing questions in `references/forcing_questions.md`. Discipline:

1. One question per turn. No bundling.
2. Always recommend the answer with cited canon.
3. Track answers in `/tmp/backend-grill-<date>.md`.
4. If a kill criterion trips, stop. Don't scaffold around an unresolved gap.
5. After Q7, run `backend_decision_engine.py` with the seven answers.

Summary:

1. Read/write ratio + p99 QPS forecast?
2. Tenancy model — single / shared / isolated?
3. Sync / async / event-driven — default + exceptions?
4. Data sensitivity tier — PII / PHI / PCI?
5. Monolith / modular monolith / microservices — team-size justification?
6. RPO + RTO?
7. SLO + named error-budget consumer?

---

## Invocation from other agents and skills

Three surfaces:

1. **Slash command:** `/cs:backend-review <prompt>` — full grill + decision engine + composition routing.
2. **Agent subagent:** `Agent({subagent_type: "cs-backend-engineer", prompt: "..."})` — forks context, returns ≤ 200-word digest.
3. **Direct tool call:** `python scripts/backend_decision_engine.py ...` — deterministic profile match when inputs are known.

See `agents/engineering/cs-backend-engineer.md` for the full invocation contract.

Alle Dateien

0 Dateien

senior-backend installieren

Laden Sie die Skill-Dateien herunter und entpacken Sie sie in Ihr Verzeichnis „.claude/skills/“.

ZIP herunterladen

Klonen Sie das Repository und kopieren Sie die Skill-Dateien in Ihr Projekt.

git clone https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/senior-backend # Copy SKILL.md to your .claude/skills/ directory

Kopieren Kopieren
Schnelle Einrichtung: Kopiere den Skill-Ordner nach .claude/skills/ Claude erkennt den Skill automatisch und nutzt ihn.

Ähnliche Skills

algorithmic-art
Zeit aktualisiert 27. August 2026
tech-debt-tracker
Zeit aktualisiert 29. August 2026
receiving-code-review
Zeit aktualisiert 3. September 2026
deprecation-and-migration
Zeit aktualisiert 3. September 2026
OR