Stand up a production web app with auth, a relational database, and CI deploys - in days, with no servers to babysit.
Recommended stack
- Next.js (App Router) - framework. Server components and route handlers cover UI + API in one deployable.
- Supabase - Postgres + auth + storage. Real Postgres with row-level security; auth that hands you a JWT your DB enforces.
- Tailwind CSS - styling. Design tokens in markup; no stylesheet drift between teammates or agents.
- Vercel - hosting & CI. Preview deploy per PR is the review workflow.
- zod - validation. Parse, don't trust: every boundary (form, API, webhook) gets a schema.
Build steps
- Model the schema first; write SQL migrations with RLS policies for every table (deny by default).
- Wire Supabase auth with the SSR helpers; gate server components on the session.
- Build one vertical slice end-to-end (page β server action β DB β render) before broadening.
- Validate all inputs with zod at the boundary; return typed errors the UI can show.
- Set up Vercel previews; treat
npm run buildpassing as the merge gate.
Watch out for
- Skipping RLS because "the API checks it" - defense in depth starts in the database.
- Client-fetching data a server component could render - it's slower and leaks API shape.
- Hand-rolled auth flows when the platform provides them.
Definition of done
- Sign up β do the core action β sign out works on a phone
- Anonymous users can't read or write protected rows (test with curl, not the UI)
- Lighthouse performance β₯ 90 on the main page