# Noor Yasser > Noor Yasser is the professional name of Noor Eldin Yasser El Nahhal. He is a Product Engineer, Software Engineer, AI Engineer and Cloud Engineer building digital products, multi-tenant SaaS platforms, AI agents and scalable cloud systems. English is the default at the site root; Arabic is under /ar/. Project pages describe Noor’s engineering contributions, not ownership of the companies or products. Educational articles include illustrative designs and their references. Contact: contact@nooryasser.com · Egypt phone & WhatsApp: +201556630230 · https://wa.me/201556630230 · WhatsApp: https://wa.me/972597606412 LinkedIn: https://www.linkedin.com/in/nooryasserx · GitHub: https://github.com/nooryasserx · Medium: https://nooryasserx.medium.com/ The list below links to the canonical HTML pages, which are the primary and current content source. ## Main pages - [Noor Yasser — Product, Software & AI Engineer](https://nooryasser.com/): Noor Yasser is a Product Engineer, Software Engineer, AI Engineer and Cloud Engineer building digital products, AI agents and scalable cloud systems. - [About Noor Yasser — Engineering Work & Experience](https://nooryasser.com/about/): Meet Noor Yasser and explore his experience building software products, AI systems, SaaS platforms, integrations and reliable cloud infrastructure. - [Software, Product & AI Engineering Services — Noor Yasser](https://nooryasser.com/services/): Software development by Noor Yasser: SaaS platforms, backend APIs, Salla and Zid apps, AI integrations, cloud performance and websites. Discuss your project. - [Software, AI & Cloud Engineering Skills — Noor Yasser](https://nooryasser.com/skills/): Explore Noor Yasser’s expertise in software architecture, AI agents, RAG, API integrations and cloud infrastructure, from product design to reliable delivery. - [Software, AI & Website Projects — Noor Yasser](https://nooryasser.com/work/): Explore Noor Yasser’s work in SaaS, AI, merchant messaging, events, logistics, enterprise integrations and websites, with details of his contribution. - [Book a 30-Minute Call with Noor Yasser](https://nooryasser.com/book/): Book a 30-minute Google Meet with Noor Yasser to discuss your product, software, AI or cloud project. Choose a time and receive an email confirmation. - [Contact Noor Yasser — Software, Product & AI Engineering](https://nooryasser.com/contact/): Contact Noor Yasser about software engineering, product development, AI agents and API integrations. Discuss your project by email, WhatsApp or LinkedIn. - [Engineering Topic Hubs — Noor Yasser](https://nooryasser.com/topics/): Explore Noor Yasser’s connected engineering guides on AI and RAG, cloud and Kubernetes, e-commerce integrations, SaaS architecture and product engineering. - [Backend, SaaS & AI Engineering Articles — Noor Yasser](https://nooryasser.com/articles/): Read engineering guides by Noor Yasser on SaaS architecture, RAG, PostgreSQL, Laravel queues, Redis and APIs, with examples, diagrams and primary sources. ## Engineering topics - [AI, RAG & Vector Search](https://nooryasser.com/topics/ai-rag-vector-search/): Grounded AI systems, from ingestion and embeddings to retrieval, evaluation and safe agent execution. - [Cloud, DevOps & Kubernetes](https://nooryasser.com/topics/cloud-devops-kubernetes/): Practical reliability, delivery, observability and capacity decisions for production systems. - [E-commerce Engineering](https://nooryasser.com/topics/ecommerce-engineering/): Reliable Salla, Zid and Shopify integrations across webhooks, orders, inventory, payments and loyalty. - [APIs, SaaS & System Architecture](https://nooryasser.com/topics/api-saas-architecture/): Multi-tenant boundaries, API contracts, distributed consistency and integration architecture. - [Product Engineering](https://nooryasser.com/topics/product-engineering/): Turning product assumptions into measurable, accessible and reversible delivery decisions. ## Services - [SaaS & digital product development](https://nooryasser.com/services/saas-products/): Turn a defined business need into a working product with tenant management, permissions and dependable workflows. - [Backend engineering & API integrations](https://nooryasser.com/services/backend-apis/): Connect payment, shipping, ERP and external services through clear contracts and resilient processing. - [Salla & Zid apps and merchant tools](https://nooryasser.com/services/salla-zid/): Build merchant experiences for memberships, offers and connected operations that fit the platform’s capabilities. - [AI integrations & retrieval systems](https://nooryasser.com/services/applied-ai/): Add useful AI features grounded in your data, with access controls, evaluation and clear limits. - [Performance, cloud & delivery](https://nooryasser.com/services/performance-cloud/): Find bottlenecks, improve database and queue behavior, and make deployments and failures easier to manage. - [Professional websites & portfolios](https://nooryasser.com/services/websites-portfolios/): Present your work or business through a fast, responsive website with clear content and a direct contact journey. ## Projects - [Murshid](https://nooryasser.com/work/murshid/): A multi-tenant AI assistant for Salla merchants: product recommendations, visual search, order follow-up and complaint escalation. - [Member Plus](https://nooryasser.com/work/member-plus/): A white-label membership product for Salla and Zid, bringing tiered subscriptions, cashback, loyalty points and exclusive discounts to live stores. - [AI Action Studio](https://nooryasser.com/work/ai-action-studio/): Merchant automation that turns store context into approval-gated playbooks, with a shared layer for OpenAI, Gemini and Anthropic. - [Logistics at scale](https://nooryasser.com/work/logistics/): A high-throughput logistics platform connecting providers, large data imports, real-time updates and ERP workflows. - [Hadir](https://nooryasser.com/work/hadir/): GPS attendance and payroll for field teams, with company-level isolation, safe offline synchronization and Saudi leave-entitlement rules. - [Zeedly](https://nooryasser.com/work/zeedly/): An Arabic-first offers engine for Salla, with storefront sections, live-preview editing and a synchronized product catalogue. - [SADA](https://nooryasser.com/work/sada/): A multi-tenant employee advocacy platform connecting social publishing, insights and account synchronization in an Arabic-first experience. - [Rentoor](https://nooryasser.com/work/rentoor/): A rental platform connecting property experiences, payments, accounting and custom domains with production cloud operations. - [WhatsApp Hero](https://nooryasser.com/work/whatsapp-hero/): A Salla app connecting store notifications, abandoned-cart reminders, campaigns and customer conversations through WhatsApp. - [SOCPA Hackathon](https://nooryasser.com/work/socpa-hackathon/): A hackathon platform for participant and team registration, verification, project submissions and attachment management. - [Sirkits](https://nooryasser.com/work/circuits/): A system for monitoring networks, tracking network invoices and improving billing workflows. - [Cisco ICM Integration](https://nooryasser.com/work/cisco-icm/): Backend integration and troubleshooting work around batch processing, Oracle data and Cisco Unified ICM for ZATCA. - [Saba Brelvi](https://nooryasser.com/work/saba-brelvi/): An author website presenting Saba Brelvi, The Squatters, events and book-order links, with a clear contact experience. - [TAZ Charity](https://nooryasser.com/work/taz-charity/): Bilingual content and technical SEO improvements for TAZ Charity, covering articles, images, sharing previews and donation calls to action. ## Articles - [Salla webhook rotation: change endpoints without losing events](https://nooryasser.com/articles/salla-webhook-endpoint-rotation-cutover/): A production cutover plan for moving Salla webhooks between endpoints while preserving events, security, rollback and per-store subscription state. - [Qdrant multitenancy: isolate retrieval, scoring and storage](https://nooryasser.com/articles/qdrant-multitenancy-payload-idf-isolation/): A production design for tenant-safe Qdrant retrieval: enforce scope in trusted code, separate sparse scoring populations and promote heavy tenants deliberately. - [Anthropic CVP: reduced cyber blocks need stronger architecture](https://nooryasser.com/articles/anthropic-cyber-verification-program-security-architecture/): Anthropic expanded CVP into three tiers. The real deployment work is identity, authorization, isolation, egress control, retention and revocation. - [OpenAI Decisions API: build a decision system, not a magic threshold](https://nooryasser.com/articles/openai-decisions-api-production-architecture/): OpenAI's Decisions API turns text and images into probabilities, choices and scores. The hard part is the policy around the answer. - [Migrate embeddings in Qdrant without breaking search](https://nooryasser.com/articles/qdrant-embedding-model-migration-zero-downtime/): A production migration plan for new embedding models: named vectors or blue-green collections, dual writes, backfill, shadow evaluation, cutover and rollback. - [Anthropic Models API `line`: stop parsing model IDs](https://nooryasser.com/articles/anthropic-models-api-line-model-routing/): Anthropic added a model-family field to the Models API. Here is how to use it for discovery without confusing family, capability and release policy. - [OpenAI textGrain: what text watermarking can—and cannot—prove](https://nooryasser.com/articles/openai-textgrain-watermarking-provenance-api/): OpenAI made text watermarking opt-in for select API models. This guide explains textGrain, detection limits and a safe provenance architecture. - [Transactional Outbox: fix dual writes without pretending they are atomic](https://nooryasser.com/articles/transactional-outbox-dual-write-cdc-polling/): A production guide to committing state and events together, then publishing through polling or CDC with ordering, idempotency and observable recovery. - [Kubernetes topology spread: schedule for zone failures, not averages](https://nooryasser.com/articles/kubernetes-topology-spread-multi-zone-scheduling/): A production guide to topology spread constraints, maxSkew, minDomains, affinity, taints, autoscaling and failure-aware Kubernetes scheduling. - [Docker runtime hardening: rootless, seccomp and least privilege](https://nooryasser.com/articles/docker-runtime-hardening-rootless-seccomp-capabilities/): A production guide to rootless Docker, user namespaces, capabilities, seccomp, AppArmor, read-only filesystems and verifiable least privilege. - [RAG chunking for complex PDFs: preserve structure, tables and context](https://nooryasser.com/articles/rag-pdf-layout-aware-chunking/): A production guide to layout-aware PDF chunking, table handling, parent-child retrieval, overlap, contextual metadata and measurable RAG evaluation. - [Gemini 3.8 TTS in production: voices, streaming and consent](https://nooryasser.com/articles/gemini-3-8-tts-voice-api-production/): A production guide to Gemini 3.8 Flash TTS and Flash-Lite covering model routing, streaming audio, reusable voices, consent, caching and evaluation. - [GPT-6 agent loops: async tools, steering and safe recovery](https://nooryasser.com/articles/gpt-6-async-tools-mid-turn-steering/): A production guide to GPT-6 async tool calling and mid-turn steering with pending-work registries, WebSocket recovery, approvals, budgets and observability. - [OpenAI Ultrafast mode: engineer latency, not just token speed](https://nooryasser.com/articles/openai-ultrafast-mode-latency-architecture/): A production guide to routing GPT-6 Astra Ultrafast requests with WebSockets, latency budgets, rate limits, residency checks, fallbacks and cost controls. - [GPT-6.1 Sol in production: route by evidence, not hype](https://nooryasser.com/articles/gpt-6-1-sol-production-routing/): A practical architecture for adopting GPT-6.1 Sol with model routing, prompt caching, bounded tools, eval gates, fallbacks and cost-quality telemetry. - [Secure Docker builds: fast caches without leaked secrets](https://nooryasser.com/articles/docker-buildkit-cache-secrets-provenance/): A production guide to BuildKit layer, mount and registry caches; secret isolation; multi-stage runtime images; and verifiable SBOM and provenance. - [Shopify bundles: design the cart transform contract](https://nooryasser.com/articles/shopify-bundles-cart-transform-contract/): A production guide to fixed and customized Shopify bundles: composition, pricing, inventory, Cart Transform operations, failure policy and reconciliation. - [Claude Code Mods: event middleware for safer AI coding](https://nooryasser.com/articles/claude-code-mods-event-middleware-security/): Anthropic’s new Mods can rewrite Claude Code events and UI. Here is how to use them safely, test their order and choose between Mods, hooks, Skills and MCP. - [Production RAG: from chunks to grounded LLM answers](https://nooryasser.com/articles/production-rag-pipeline-chunking-qdrant-reranking/): A production design for chunking, embeddings, Qdrant retrieval, reranking, context assembly, citations and evaluation—with clear alternatives to RAG. - [SaaS tenant context: propagate identity without data leaks](https://nooryasser.com/articles/saas-tenant-context-propagation-security/): A production architecture for deriving trusted tenant identity once, carrying it across APIs and jobs, and enforcing isolation at every data boundary. - [Kubernetes requests and limits: capacity without throttling or OOM](https://nooryasser.com/articles/kubernetes-resource-requests-limits-rightsizing/): A production method for sizing Kubernetes CPU and memory requests, choosing limits, protecting nodes and keeping HPA signals meaningful. - [PostgreSQL connection pooling: protect capacity with PgBouncer](https://nooryasser.com/articles/postgresql-pgbouncer-admission-control/): A production guide to sizing PgBouncer as an admission-control queue instead of turning PostgreSQL max_connections into an unsafe concurrency target. - [Evaluate MCP tool-using agents: score the whole trajectory](https://nooryasser.com/articles/mcp-tool-use-agent-evaluation-traces/): A production evaluation contract for AI agents that discovers, selects, approves and calls MCP tools without hiding unsafe or duplicated effects behind a good answer. - [Reliable Shopify webhooks: durable inbox and reconciliation](https://nooryasser.com/articles/shopify-webhooks-durable-inbox-reconciliation/): A production design for authenticating, deduplicating, ordering and recovering Shopify webhook-driven order and inventory synchronization. - [Reliable Salla delivery promises: cutoffs, calendars and zones](https://nooryasser.com/articles/salla-delivery-promises-cutoff-calendar/): A production design for turning Salla delivery-promise settings into versioned, testable checkout commitments without confusing them with carrier tracking. - [Salla OAuth refresh tokens: rotate once, recover safely](https://nooryasser.com/articles/salla-oauth-refresh-token-rotation-race/): A production design for Salla OAuth token refresh that prevents concurrent reuse, stores each rotation atomically and handles uncertain network outcomes safely. - [Qdrant hybrid search: fuse meaning, terms and tenant scope](https://nooryasser.com/articles/qdrant-hybrid-search-production-fusion/): A production design for dense and sparse retrieval in Qdrant, from candidate generation and fusion to tenant filters, reranking and evaluation. - [Claude prompt caching: stable prefixes that actually hit](https://nooryasser.com/articles/claude-prompt-caching-production-prefixes/): A production guide to Claude prompt caching: prefix design, breakpoints, TTLs, invalidation, diagnostics and the metrics that prove a real cache hit. - [Safe Kubernetes rollouts: readiness, draining and PDB limits](https://nooryasser.com/articles/kubernetes-rollout-readiness-draining-contract/): A practical Kubernetes deployment guide connecting readiness, graceful shutdown and disruption budgets to customer operations that must survive a release. - [Build a cryptographic inventory for Saudi post-quantum readiness](https://nooryasser.com/articles/saudi-post-quantum-crypto-inventory/): SAMA requires Saudi financial institutions to identify and classify cryptographic assets by Q4 2026. This is an engineering plan for doing it well. - [Cloudflare K2 changes the trade-offs of event streaming](https://nooryasser.com/articles/cloudflare-k2-object-storage-event-streams/): K2 builds a durable serverless log on object storage. Here is what its batching, leases and at-least-once delivery mean in production. - [Measure reliability at the user journey, not the server](https://nooryasser.com/articles/user-journey-slo-product-engineering/): Turn a critical user journey into an SLO, an error budget and a release gate that joins frontend experience with backend correctness. - [Zid storefront analytics: build an event contract you can trust](https://nooryasser.com/articles/zid-storefront-event-contract/): Turn Zid storefront events into dependable product analytics with one versioned schema, idempotent delivery, identity stitching and order reconciliation. - [Claude Sonnet 5.5: migrate the workflow, not just the model](https://nooryasser.com/articles/claude-sonnet-5-5-production-routing/): Claude Sonnet 5.5 changes thinking, tool choice and response handling. Here is a production migration and routing plan grounded in real task economics. - [Design onboarding around the first value moment](https://nooryasser.com/articles/onboarding-first-value-path/): Replace forced product tours with a resumable path to one meaningful result, supported by contextual help, saved progress and outcome evidence. - [Salla product variants: migrate the schema, not rows](https://nooryasser.com/articles/salla-product-variant-schema-migration/): Changing a Salla option can reshape every sellable variant. Use stable identity, shadow validation and reconciliation before writing prices or stock. - [OpenAI Dots need durable agent supervision](https://nooryasser.com/articles/openai-dots-durable-agent-supervision/): OpenAI's always-on Dots move agents from request handling to durable operations. Here is the task, memory, permission and recovery architecture that implies. - [Prioritize product opportunities before solutions](https://nooryasser.com/articles/product-opportunity-prioritization-evidence/): A practical discovery workflow for moving from a measurable outcome to user opportunities, risky assumptions and the cheapest evidence that can change a decision. - [Zid AI Agent Skill and MCP: a verified integration workflow](https://nooryasser.com/articles/zid-ai-agent-skill-mcp-architecture/): Zid provides an AI Agent Skill and an MCP server for its developer documentation. Here is how to turn them into a safe, testable integration workflow. - [OpenAI Agents API computer use needs a trust architecture](https://nooryasser.com/articles/openai-agents-api-computer-use-architecture/): OpenAI added hosted browser computer use to the Agents API. The important work is designing approvals, authentication, recovery and verification around it. - [Claude Opus 5.5: the production migration is more than a model swap](https://nooryasser.com/articles/claude-opus-5-5-production-migration/): Anthropic released Claude Opus 5.5 with lower prices, a 1M context window and API changes that can break thinking, tool-use and computer-use integrations. - [Your AI evals need a portable product contract](https://nooryasser.com/articles/portable-ai-evaluation-contract/): A Product Engineering framework for turning AI evals into portable release evidence tied to user outcomes, cost, latency and reversible rollout decisions. - [Treat Salla customer groups as checkout policy](https://nooryasser.com/articles/salla-customer-groups-checkout-policy/): A practical architecture for using Salla customer groups to control payment, shipping and offer eligibility without turning segmentation into fragile manual configuration. - [Drag-and-drop needs a second path](https://nooryasser.com/articles/accessible-reordering-beyond-drag-and-drop/): A practical Product Design framework for reorder flows that work with pointer, touch, keyboard and assistive technology without turning accessibility into a hidden shortcut. - [GPT-6.1 Sol: what developers should test before migrating](https://nooryasser.com/articles/gpt-6-1-sol-developer-migration/): OpenAI released GPT-6.1 Sol with stronger coding, agent and computer-use claims at Sol pricing. Here is the practical evaluation and migration plan. - [Salla API limits: fair queues before more workers](https://nooryasser.com/articles/salla-api-budget-fair-queues/): Design per-store API budgets and fair queues for Salla integrations, with controlled retries, uncertain-write recovery and visible synchronization progress. - [Feature flags need an exit plan, not just a toggle](https://nooryasser.com/articles/feature-flag-product-contract/): A product-engineering contract for feature flags: stable cohorts, real exposure events, outcome guardrails, failure defaults, progressive rollout and safe cleanup. - [Zid reverse orders: separate return approval from refund execution](https://nooryasser.com/articles/zid-reverse-order-refund-control/): A practical architecture for Zid returns that separates approval, physical inspection, inventory decisions and refund execution while preventing duplicate financial actions. - [Checkout errors should offer a recovery path, not a dead end](https://nooryasser.com/articles/checkout-error-recovery-design/): A practical Product Design framework for classifying checkout failures, preserving user input, writing actionable errors, handling uncertain payments and measuring recovery. - [OpenTelemetry tail sampling: keep evidence without overloading Collectors](https://nooryasser.com/articles/opentelemetry-tail-sampling-capacity/): A production guide to sizing and scaling OpenTelemetry tail sampling with trace-ID routing, decision windows, policy budgets, late-span handling and measurable overload protection. - [Salla shipments: build a state machine that can recover](https://nooryasser.com/articles/salla-shipment-state-machine/): A production design for keeping Salla, a shipping carrier and an ERP consistent through duplicate webhooks, delayed events, unknown outcomes, cancellations and returns. - [Product experiments need a decision contract](https://nooryasser.com/articles/product-experiment-decision-contract/): A practical product-management framework for defining hypotheses, success metrics, guardrails, data-quality checks and ship-or-stop rules before an experiment starts. - [Kubernetes inference routing: balance tokens, not requests](https://nooryasser.com/articles/kubernetes-inference-aware-routing/): A practical architecture for routing self-hosted LLM traffic with InferencePool and an Endpoint Picker using queue, cache and model signals instead of blind round robin. - [Salla payment reconciliation: an order is not a ledger](https://nooryasser.com/articles/salla-payment-reconciliation-ledger/): A production design for reconciling Salla orders, payment transactions and refunds without treating a webhook or order status as complete accounting evidence. - [PostgreSQL logical replication: monitor drift, not just lag](https://nooryasser.com/articles/postgresql-logical-replication-drift/): A production runbook for PostgreSQL logical replication covering apply conflicts, WAL retention, schema drift, reconciliation, slot failover and safe recovery. - [Salla abandoned carts: build a recovery pipeline that knows when to stop](https://nooryasser.com/articles/salla-abandoned-cart-recovery-pipeline/): A production design for Salla abandoned-cart recovery using signed webhooks, current-state reads, durable suppression, reconciliation and external delivery providers. - [Gemini 3.8 Live agents: design the session, not just the prompt](https://nooryasser.com/articles/gemini-3-8-live-voice-agent-architecture/): A production architecture for Gemini 3.8 Live covering WebSocket sessions, barge-in, async tools, reconnection, cost controls and durable business actions. - [Zid bulk coupons: design the campaign before generating codes](https://nooryasser.com/articles/zid-bulk-coupon-campaign-safety/): A practical architecture for Zid bulk coupon campaigns covering rule snapshots, channel gates, secure distribution, cart validation and usage reconciliation. - [Zid loyalty integrations: build around the ledger, not the balance](https://nooryasser.com/articles/zid-loyalty-ledger-integration/): A practical architecture for Zid loyalty integrations using transaction history, command idempotency, read-back confirmation and scheduled reconciliation. - [Kubernetes API Priority and Fairness: isolate noisy controllers](https://nooryasser.com/articles/kubernetes-api-priority-fairness/): A practical APF design for protecting kube-apiserver from bursty controllers, operators and AI agents without starving critical traffic. - [Salla App Functions: choose the right execution boundary](https://nooryasser.com/articles/salla-app-functions-sync-async/): A practical architecture for separating blocking decisions from background commerce workflows in Salla App Functions. - [Durable AI agents: checkpoints are not enough](https://nooryasser.com/articles/durable-ai-agent-execution/): A production architecture for AI agents that survive restarts, pause for approval and execute external side effects safely under retries. - [Salla's light order contract: migrate without losing fulfillment data](https://nooryasser.com/articles/salla-light-order-contract-migration/): A practical migration architecture for Salla order integrations after expanded responses ended, using selective hydration, queues and sequential reconciliation. - [PostgreSQL 19 Beta 4: test the upgrade, not the feature list](https://nooryasser.com/articles/postgresql-19-beta-4-production-readiness/): A practical pre-production test plan for PostgreSQL 19 Beta 4, covering reverted features, REPACK concurrency, replication, query plans and rollback evidence. - [Zid multi-location inventory: choose the right batch boundary](https://nooryasser.com/articles/zid-multi-location-inventory-sync/): A practical architecture for syncing ERP or WMS stock with Zid, choosing product-centric or location-centric batches and verifying every write through reconciliation. - [Google Cloud X5 reaches 48 TB: when scale-up is worth the trade-offs](https://nooryasser.com/articles/google-cloud-x5-48tb-memory/): Google Cloud's new X5 bare-metal series raises single-node memory to 48 TB. Here is what architects must test across NUMA, Hyperdisk, recovery and SAP HANA before scaling up. - [Salla and ERP inventory sync: make every stock movement auditable](https://nooryasser.com/articles/salla-erp-inventory-sync-audit/): A practical architecture for syncing ERP stock with Salla using bulk deltas, branch mapping, change reasons, a durable outbox and scheduled reconciliation. - [GKE raises the limit to 512 Pods per node—should you use it?](https://nooryasser.com/articles/gke-512-pods-per-node/): GKE Standard now supports 512 Pods per node. Here is the IP math, density benefit, failure impact and a safe node-pool migration plan. - [Salla conditional webhooks: filter events before they reach your app](https://nooryasser.com/articles/salla-conditional-webhooks-rules/): A practical guide to Salla Rules: choosing webhook conditions, registering them safely, testing changes and preserving reliable downstream processing. - [AlloyDB for AI agents: live data without sharing production compute](https://nooryasser.com/articles/alloydb-agentic-database-architecture/): Google's new AlloyDB preview gives AI agents read-only PostgreSQL nodes on isolated compute while keeping an up-to-the-second view of production data. - [Salla and Zid webhooks: order sync that survives missed events](https://nooryasser.com/articles/salla-zid-webhook-recovery/): A practical architecture for Salla and Zid apps that combines verified webhooks, a durable inbox, idempotent processing and API reconciliation. - [Cloudflare Containers: the storage boundary behind tenant isolation](https://nooryasser.com/articles/cloudflare-containers-storage-isolation/): A fresh Cloudflare disclosure prompts a practical review of storage reuse, ephemeral disks and tenant boundaries in SaaS and AI agent infrastructure. - [GitHub Copilot’s new default feature policy: what enterprises must review](https://nooryasser.com/articles/github-copilot-default-feature-policy/): GitHub’s new Copilot policy can enable unconfigured GA features from 22 October. Learn the scope, exceptions, and a practical review plan for engineering teams. - [GitHub proof of presence: fresh identity checks for sensitive actions](https://nooryasser.com/articles/github-proof-of-presence-enterprise-security/): GitHub adds identity checks before sensitive enterprise actions. What the preview covers, how it works, and what product teams should test before rollout. - [Tenant isolation with PostgreSQL Row-Level Security](https://nooryasser.com/articles/postgresql-tenant-isolation/): A practical design for tenant context, database roles and isolation tests in a shared SaaS database. - [How to evaluate a RAG pipeline before changing the model](https://nooryasser.com/articles/rag-retrieval-quality/): Separate retrieval failures from answer failures with a small evaluation set, source checks and realistic commerce examples. - [Designing webhooks for duplicates, retries and delayed events](https://nooryasser.com/articles/reliable-webhook-processing/): A durable inbox, signature checks and idempotent processing for payment and commerce integrations. - [Laravel queues: retries, transactions and safe side effects](https://nooryasser.com/articles/laravel-queues-production/): A production-oriented approach to job boundaries, transaction timing, retries and operational visibility. - [Choose PostgreSQL indexes from real query patterns](https://nooryasser.com/articles/postgresql-indexes-from-query/): Read query plans, design a candidate composite index and measure the cost of faster reads. - [Redis caching: freshness, tenant keys and invalidation](https://nooryasser.com/articles/redis-cache-invalidation/): Design cache-aside around acceptable staleness, safe keys and an explicit invalidation strategy. - [A modular monolith before microservices: defining real boundaries](https://nooryasser.com/articles/modular-monolith-boundaries/): Design modules around business ownership and explicit contracts before adding distributed operations. - [Custom domains in SaaS: ownership, routing and TLS](https://nooryasser.com/articles/saas-custom-domains/): Model custom domain onboarding as a lifecycle, from verified ownership to secure routing and removal. - [Backend observability: follow the user’s operation across services](https://nooryasser.com/articles/backend-observability/): Connect metrics, structured logs and traces to diagnose slow requests and failed background operations. - [Designing API contracts that survive real integrations](https://nooryasser.com/articles/api-contracts-pagination-errors/): Define schemas, errors, pagination and compatibility before a client depends on your API. ## Optional - [الدليل العربي](https://nooryasser.com/ar/llms.txt) - [Sitemap](https://nooryasser.com/sitemap.xml): Canonical HTML pages and last modification dates.