Communitygithub.com

YepAPI/skills

Tenant isolation (row-level vs schema), subdomain routing, per-tenant config, and data partitioning.

skills とは?

skills is a Claude Code agent skill that tenant isolation (row-level vs schema), subdomain routing, per-tenant config, and data partitioning.

対応~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/YepAPI/skills/tree/HEAD/skills/multi-tenancy

お気に入りのAIに質問する

このエージェントスキルを事前に読み込んだ状態で新しいチャットを開きます。

ドキュメント

Multi-Tenancy

Rules

  • Row-level isolation (default): add tenantId column to every tenant-scoped table — enforce via middleware or RLS (Row-Level Security)
  • Schema-per-tenant: use when tenants need custom schemas or strict data isolation — more complex ops, better isolation
  • Subdomain routing: parse tenant from {tenant}.app.com — resolve in middleware, set tenantId on request context
  • Custom domains: CNAME to your app, lookup tenant by Host header — use a domains table mapping custom domains to tenant IDs
  • Per-tenant config: store theme (logo, colors), feature flags, and limits in a tenant_settings table — cache in memory with TTL
  • RLS pattern (Postgres): ALTER TABLE posts ENABLE ROW LEVEL SECURITY; CREATE POLICY tenant_isolation ON posts USING (tenant_id = current_setting('app.tenant_id'))
  • Middleware: extract tenant from subdomain/header, set on context, apply to all database queries — never let a query run without tenant scope
  • Data partitioning: for large tables, partition by tenantId — improves query performance and enables per-tenant backup/restore

Row-Level Isolation Pattern

// Middleware - extract tenant from subdomain
function getTenantFromHost(host: string): string {
  const subdomain = host.split(".")[0];
  return subdomain; // or lookup in tenants table
}

// Prisma middleware - auto-filter by tenantId
prisma.$use(async (params, next) => {
  if (TENANT_MODELS.includes(params.model)) {
    params.args.where = { ...params.args.where, tenantId: context.tenantId };
  }
  return next(params);
});

Subdomain Routing (Next.js Middleware)

export function middleware(request: NextRequest) {
  const host = request.headers.get("host") ?? "";
  const tenant = host.split(".")[0];
  const response = NextResponse.next();
  response.headers.set("x-tenant-id", tenant);
  return response;
}

Avoid

  • Queries without tenant scope — one missing WHERE tenantId = ? leaks data across tenants
  • Hardcoding tenant in client — resolve from subdomain/domain server-side
  • No index on tenantId — every tenant-scoped table needs a composite index starting with tenantId
  • Mixing tenant data in shared caches — namespace cache keys with {tenantId}:{key}

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

YepAPI/skills

WCAG 2.1 AA — semantic HTML, keyboard navigation, screen readers.

YepAPI/skills

CRUD generators, data tables, user management, role-based access, and bulk operations.

YepAPI/skills

Tool-use patterns, multi-step reasoning, agent orchestration, and structured outputs.

YepAPI/skills

Chat UI components, streaming responses with AI SDK, context window management, and RAG patterns.

YepAPI/skills

Monitor what ChatGPT and Gemini say about your brand using YepAPI.

YepAPI/skills

Web analytics integration — event tracking, custom dashboards, privacy-first.

YepAPI/skills

Framer Motion — transitions, scroll animations, layout animations.

YepAPI/skills

OpenAPI 3.1 from Zod schemas, interactive docs with Swagger/Scalar, versioning, and example requests for every endpoint.

YepAPI/skills

Authentication security — bcrypt/argon2 hashing, brute force protection, secure password resets.

YepAPI/skills

Session auth, social providers, CSRF protection, and secure cookie patterns.

YepAPI/skills

Queue workers with BullMQ/Inngest/Trigger.dev, job retries, dead letter queues, concurrency.

YepAPI/skills

Link building research and backlink audit using YepAPI.

YepAPI/skills

MDX blog setup, RSS feed generation, sitemap.xml, structured data/JSON-LD, and related posts.

YepAPI/skills

Redis caching, CDN cache headers, stale-while-revalidate, cache invalidation, React Query.

YepAPI/skills

Recharts/Chart.js data visualization — bar, line, area, pie charts.

YepAPI/skills

Commander.js, interactive prompts with Clack, spinners, colors, config files, exit codes, and npm publishing.

YepAPI/skills

cmdk integration, Cmd+K trigger, fuzzy search, grouped actions, keyboard navigation, and dynamic action registration.

YepAPI/skills

Threaded comments, @mentions, reactions, moderation queue, optimistic UI, and cursor pagination.

YepAPI/skills

Competitive analysis between domains using YepAPI.

YepAPI/skills

Experiment setup, variant splitting, statistical significance, and feature flag integration.

関連スキル