Flagship Quest
Mahak API Platform
As CTO of Dabestaniha, I refactored and scaled a shared multi-tenant platform powering 24 active applications and more than 4 million verified accounts. Aggregate traffic is typically around 10K RPS, with recurring production peaks reaching 100K completed requests per second.
- 24Active appsOne shared platform serves independently branded Android, web, and iOS products.
- 4M+Verified accountsVerified accounts across the ecosystem; the same person may be counted separately in more than one app.
- ~10KTypical RPSNormal aggregate completed-request rate measured across the active applications.
- 100KPeak RPSRecurring aggregate production peaks observed in Grafana, Prometheus, and Metabase.
- 12Tech teamCTO leadership within a 12-person technology team and a 50+ person organization.
Mission Brief
Dabestaniha needed one platform flexible enough to power a portfolio of education, content, commerce, campaign, and game experiences without operating a separate backend for every brand.
Each application connects with its own app identity and key. The shared system resolves tenant context, applies app-specific behavior and permissions, and scales horizontally according to each owner's demand.
System Map
Architecture
Product Clients
Kotlin and Compose Android apps, web clients, and iOS apps connect through stable tenant-aware APIs.
Edge & Runtime
Nginx distributes traffic across containerized PHP-FPM services that can scale horizontally by workload.
Shared Application Layer
Fat-Free and Laravel APIs coexist behind one entry point, with Laravel Nova providing tenant-aware administration.
Data & Async Work
MySQL, PostgreSQL, Redis, JWT, and Laravel queues support shared data, caching, sessions, and background jobs.
Delivery & Visibility
MinIO, Gitea Actions, Grafana, Prometheus, and Metabase cover media, deployment, health, and product insight.
Strategy Route
Battle Plan
The implementation path, checkpoint by checkpoint.
- Checkpoint 01
Refactored the shared backend while keeping existing app contracts stable, improving tenancy, database access, caching, authentication, and queue behavior.
- Checkpoint 02
Evolved legacy Fat-Free routes alongside Laravel APIs through a shared entry point, allowing incremental migration instead of a disruptive rewrite.
- Checkpoint 03
Redesigned the runtime around Nginx, PHP-FPM, Docker, Redis, queues, and horizontal scaling for predictable behavior during heavy demand.
- Checkpoint 04
Built test-gated delivery with staged deployments, runtime preservation, cache rebuilding, queue restarts, and OPcache resets through self-hosted Gitea Actions.
- Checkpoint 05
Expanded operational visibility across infrastructure and product data with health checks, Grafana, Prometheus, and Metabase.
Critical Encounter
Boss Fight
The hardest constraint was evolving a live shared platform while dozens of branded clients depended on the same contracts. Changes had to improve throughput and operability without forcing a coordinated rewrite of every app.
My work built on existing core systems: I improved tenancy, queries, Redis, JWT, and workers, then introduced or redesigned containerized horizontal scaling, object storage, observability, analytics, and CI/CD.
Achievements Unlocked
Quest Rewards
What the quest delivered.
- Reward 01 unlocked
A single maintainable platform now powers 24 active applications across multiple product categories.
- Reward 02 unlocked
The platform sustains typical aggregate traffic around 10K RPS and repeatedly handles production peaks of 100K completed RPS.
- Reward 03 unlocked
More than 4 million verified accounts are served across the app ecosystem.
- Reward 04 unlocked
The delivery and monitoring systems give the team safer releases, clearer health signals, and faster operational feedback.
Special Items
Technical Loadout
- Fat-Free
- Laravel
- Laravel Nova
- Nginx
- PHP-FPM
- Docker
- MySQL
- PostgreSQL
- Redis
- Laravel Queues
- MinIO
- Grafana
- Prometheus
- Metabase
- Gitea Actions
- Kotlin
- Jetpack Compose
Proof of Work
Explore the Quest
Scale figures are internal production measurements across the platform. Verified-account totals may overlap when the same person uses multiple apps. Private source repositories and operational dashboards are intentionally not linked.