Central IP Access Control
Tenant-aware APIs and an IP registry for a shared platform.
- My role
- Backend contributor · Raha ICT · September 2026
- Focus
- Tenant isolation · API contracts · IP/CIDR data modeling
Overview
CIPAC is a centralized IP/CIDR access-policy and CDN-routing platform for administrators and subscribers. It brings a Next.js portal and a NestJS backend together in an Nx modular monolith. My contribution covered backend management modules, data access, API contracts, and integration reliability within a team-built product.
Technical challenge
The same management operations needed to serve the portal and REST clients while keeping subscriber data isolated. IP records also needed consistent handling of equivalent address representations, network overlap, and unreliable external metadata lookups.
What I worked on
- Implemented tenant-scoped owner, application, and environment management, including lifecycle operations, validation, repository access, and API contracts.
- Built CDN management and assignment APIs, with REST documentation and tRPC integration for the portal.
- Implemented IP/CIDR registry normalization, persistence, containment and overlap checks; fixed duplicate handling, soft-delete reservations, and owner validation.
- Added RDAP lookup and persistence, then preserved existing metadata when a refresh returned no usable result.
- Added use-case, repository, API, and MySQL integration coverage for the areas I changed. My frontend changes were limited integration and formatting fixes; the portal was a team effort.
Technical approach & decisions
Carry tenant context into data access
Application use cases and repository methods take subscriber context explicitly. Lookups constrain both the record ID and subscriber account, while REST and tRPC adapters call the backend use cases. Authorization is enforced beyond the interface, with tests for tenant boundaries.
Store IPs for comparison as well as display
The registry keeps normalized text alongside binary network and range boundaries. Containment and overlap checks filter by tenant and IP version. Parameterized SQL handles binary range comparisons that Prisma’s byte filters do not express, keeping that database-specific work inside the repository.
Keep useful metadata through failed refreshes
The RDAP refresh use case saves a successful lookup, but reuses previously stored metadata when a new lookup has no result. Regression tests cover that fallback and tenant isolation. An external lookup failure therefore does not erase a record’s existing enrichment.
Stack
Project stack
Next.js, React, TypeScript, NestJS, Nx, tRPC, TanStack Query, Prisma, MySQL, and Redis. Verified from the workspace manifest, framework configuration, schema, and source. This is the team’s stack, not a claim that I built every layer.
Visible in my contribution
NestJS and TypeScript use cases; tRPC and REST/OpenAPI contracts; Prisma schemas, migrations, and MySQL queries; Zod validation; IP normalization; RDAP integration; Jest and MySQL integration tests.
Outcome
Merged backend work supports tenant-scoped management of owners, applications, environments, CDNs and assignments, alongside IP/CIDR normalization, containment and overlap checks, and persisted RDAP metadata. These are implemented capabilities in the reviewed repository; deployment status and business impact are not established by the code history.
Source & scope
Based on authored commits and merged history in an accessible local checkout of the raha-ict repository. The source is not publicly accessible, so no repository link is published. This study describes merged backend work and does not claim ownership of the portal or authentication system.