| Configuration |
[configuration.md](rules/configuration.md) |
HIGH |
Environment config, logger setup, security options, and graceful shutdown |
| Create Server |
[create-server.md](rules/create-server.md) |
LOW-MEDIUM |
Use a buildServer() factory function for reusable, testable server setup |
| Create Plugin |
[create-plugin.md](rules/create-plugin.md) |
LOW-MEDIUM |
Encapsulate reusable functionality in plugins with fastify-plugin |
| Autoload |
[autoload.md](rules/autoload.md) |
HIGH |
Automatically load plugins and routes from the filesystem with @fastify/autoload |
| Route Best Practices |
[route-best-practices.md](rules/route-best-practices.md) |
MEDIUM |
Organize routes with plugins/prefixes, use async handlers, full route options |
| Schema Validation (Zod) |
[schema-validation-zod.md](rules/schema-validation-zod.md) |
HIGH |
Type-safe validation with Zod + fastify-type-provider-zod |
| Serialization (Zod) |
[serialization-zod.md](rules/serialization-zod.md) |
HIGH |
Type-safe response serialization with Zod schemas, output validation, and compatibility notes |
| Encapsulation |
[encapsulation.md](rules/encapsulation.md) |
HIGH |
Proper scope isolation and when to use fastify-plugin |
| Error Handling |
[error-handling.md](rules/error-handling.md) |
HIGH |
Custom error handlers, @fastify/error, 404 handling, structured responses |
| Hooks & Lifecycle |
[hooks-lifecycle.md](rules/hooks-lifecycle.md) |
MEDIUM |
All request/reply and application hooks: onRequest, preParsing, preValidation, preHandler, preSerialization, onError, onSend, onResponse, onReady, onClose |
| Logging |
[logging.md](rules/logging.md) |
HIGH |
Built-in Pino logger, request correlation, redaction, child loggers |
| Authentication |
[authentication.md](rules/authentication.md) |
HIGH |
JWT auth with @fastify/jwt, multi-strategy with @fastify/auth |
| Testing |
[testing.md](rules/testing.md) |
HIGH |
Test with inject(), buildServer pattern, vitest/node:test |
| TypeScript |
[typescript-integration.md](rules/typescript-integration.md) |
MEDIUM |
Type providers, module augmentation, typed decorators |
| Decorators |
[decorators.md](rules/decorators.md) |
MEDIUM |
Extend the Fastify instance, request, and reply with decorate / decorateRequest / decorateReply |
| Content Type Parser |
[content-type-parser.md](rules/content-type-parser.md) |
HIGH |
Custom content type parsers, body limits, multipart uploads, catch-all and regex matching |
| Multipart & File Uploads |
[multipart.md](rules/multipart.md) |
HIGH |
File uploads with @fastify/multipart, streaming, size limits, MIME validation |
| WebSockets |
[websockets.md](rules/websockets.md) |
HIGH |
Real-time bidirectional connections with @fastify/websocket, lifecycle handling, broadcasting, and authentication |
| HTTP Proxy |
[http-proxy.md](rules/http-proxy.md) |
HIGH |
API gateway / BFF patterns with @fastify/http-proxy and @fastify/reply-from, auth hooks, error handling, multi-upstream routing |
| Type Providers |
[type-providers.md](rules/type-providers.md) |
HIGH |
Compare TypeBox, json-schema-to-ts, and Zod providers; .withTypeProvider<T>(); scoped providers in plugins; provider-specific plugin types |
| Deployment |
[deployment.md](rules/deployment.md) |
HIGH |
Graceful shutdown with close-with-grace, liveness/readiness probes, listen on 0.0.0.0, trustProxy, multi-stage Dockerfile, AWS Lambda adapter |
| HTTP/2 |
[http2.md](rules/http2.md) |
MEDIUM |
Enable HTTP/2 over TLS (h2) with HTTP/1.1 fallback, or plain-text h2c for internal services; typed buildServer factory |
| CORS & Security Headers |
[cors-security.md](rules/cors-security.md) |
HIGH |
@fastify/cors allow-list (static and dynamic), @fastify/helmet CSP/HSTS, registration order, combined security plugin |
| Delay Accepting Requests |
[delay-accepting-requests.md](rules/delay-accepting-requests.md) |
HIGH |
Reject requests with 503 until dependencies are ready; liveness vs. readiness probes for Kubernetes |
| Database Integration |
[database-integration.md](rules/database-integration.md) |
HIGH |
Register a pg pool as a Fastify plugin; use @nearform/sql for safe queries |
| Database Migrations |
[database-migrations.md](rules/database-migrations.md) |
HIGH |
Run Postgrator SQL migrations at startup; never modify applied files |
| Test Containers |
[test-containers.md](rules/test-containers.md) |
HIGH |
Spin up real Postgres containers with Testcontainers for integration tests |
| Clean Architecture |
[clean-architecture.md](rules/clean-architecture.md) |
HIGH |
Pure service-layer functions + thin route handlers; explicit dependency injection |
| Unit Testing |
[unit-testing.md](rules/unit-testing.md) |
HIGH |
Unit-test service functions in isolation with mock database stubs |
| Performance |
[performance.md](rules/performance.md) |
HIGH |
Schema pre-compilation, serialization, load shedding, streaming, benchmarking |
| Rate Limiting |
[rate-limiting.md](rules/rate-limiting.md) |
HIGH |
Protect APIs with @fastify/rate-limit, per-route overrides, Redis store, custom keys |
| Serialization |
[serialization.md](rules/serialization.md) |
HIGH |
Response serialization with JSON Schema and fast-json-stringify |