Web Backends Best Practices
Advocacy rules for maintainable, secure, and fast Rust HTTP services.
Busca en todas las páginas de la documentación
Advocacy rules for maintainable, secure, and fast Rust HTTP services.
users.rs, billing.rs, not one giant file.schemas module. Separate input and output types.core crate in workspaces. Avoid copying structs across binaries.AppError enum implementing IntoResponse. Stable JSON error shape everywhere.validator before database calls.unwrap in handlers. Use ? and typed errors.sqlx::PgPool in AppState behind Clone. Pool is internally Arc-like.permissive() in production without review.axum::serve. Drain in-flight requests on SIGTERM./health and /ready separately. Ready checks DB connectivity.tracing + JSON subscriber in prod. Correlate with request IDs.Default new services to Axum; keep Actix when migration cost exceeds benefit.
Skipping validation, timeouts, and explicit error contracts at the HTTP edge.
tower::ServiceExt::oneshot for handlers; testcontainers for DB integration.
Avoid blocking I/O; use spawn_blocking for rare CPU-heavy sections.
Recommended for public APIs; optional for internal services with strong types.
Start with trace + timeout + body limit; add auth and rate limit per route group.
api binary + domain + db crates keeps compile times manageable.
Env vars for secrets; config or figment crate for typed settings.
cargo audit in CI; pin major versions in Cargo.toml.
Request logs, error rate, latency histograms, and DB pool metrics.
Stack versions: This page was written for Rust 1.97.0 (edition 2024), Tokio 1.x, Axum 0.8, serde 1.0, sqlx 0.8, clap 4, and Polars 0.46+.
Revisado por Chris St. John·Última actualización: 16 jul 2026