The summary.
EVERYTHING IN A SERVICE PROVIDER'S BOOT METHOD COSTS EVERY REQUEST
No queries, no external calls, nothing slow. When every page is slow, look at bootstrapping.
PUSH FILTERING, SORTING AND AGGREGATION TO THE DATABASE
Filtering thousands of records in a collection after loading them all is far slower than filtering in the query.
RATE LIMIT ANYTHING EXPENSIVE
Sign-in, registration, password reset, search, mail sending.
Be careful with address-based limits — offices and networks share public addresses, so many users appear as one.
SOFT-DELETED RECORDS STILL OCCUPY UNIQUE VALUES
Someone cannot reuse an address or reference until it is genuinely removed. Plan permanent deletion after a retention period.
RACE CONDITIONS DO NOT APPEAR IN DEVELOPMENT
Requests arrive one at a time there. Use locking or atomic operations for stock, balances and references.
Record an idempotency key to survive duplicate submissions.
RECORD WHAT PEOPLE SEARCH FOR AND WHAT RETURNS NOTHING
It shows what they expect to find and which vocabulary you are missing.
BEFORE ADDING RESOURCES, FIX QUERY MULTIPLICATION AND ADD INDEXES
That usually buys substantially more capacity on the same hosting.