NASEBANAL Stack

The technologies NASEBANAL currently adopts, and how the set has changed. NASEBANAL provides consulting to its clients with these technologies as its core. The NASEBANAL Stack is reviewed as the business environment and technology landscape shift, and every change is recorded on this page.

Current Constituents

Listed by implementation layer: programming, middleware, managed services and development tooling. Just as the constituent stocks of the Dow Jones Industrial Average are periodically reviewed and replaced, the NASEBANAL Stack swaps its constituent technologies to match the business environment and technology landscape. Each technology name links to its official site.

Programming13 technologies

Languages, frameworks and libraries used to implement

Programming
CategoryTechnologyWhat we use it for
LanguagesTypeScriptThe common language across frontends, APIs, the CLI and the SDK
PythonAI, machine learning, image recognition and FastAPI backends
Web & BackendNext.jsWeb frontend framework, deployed to Cloudflare Workers via OpenNext
ReactUI library, shared by web and mobile
Tailwind CSSStyling for web frontends
FastAPIPython API framework (REST, GraphQL and MCP)
MobileExpo (React Native)Foundation for the iOS and Android mobile app
AI, ML & VisionPyTorchDeep-learning framework (underlies YOLO)
YOLO (Ultralytics)Object detection and pose estimation on images
OpenCVImage pre-processing
TensorFlow / KerasDeep-learning model development
scikit-learnMachine learning and evaluation metrics
pandasData aggregation and preparation

Middleware13 technologies

Infrastructure software that runs beneath the applications: gateways, messaging, identity, data and monitoring

Middleware
CategoryTechnologyWhat we use it for
AI / API GatewayKong GatewayAPI gateway (routing, authentication, switching the backend to a mock)
agentgatewayMCP gateway for AI agents (builds MCP tools from an OpenAPI contract)
MessagingApache KafkaEvent streaming that buffers writes asynchronously
Identity & AccessKeycloakOpen-source identity provider (issues JWTs)
Secrets ManagementHashiCorp VaultSecrets management and dynamic database credentials
DatabasePostgreSQLOpen-source relational database
MySQLOpen-source relational database
ObservabilityOpenTelemetryCollection of traces, metrics and logs (OTLP)
PrometheusMetrics collection and alerting
LokiLog aggregation
TempoDistributed trace storage
GrafanaDashboards for metrics, logs and traces
MLOpsMLflowMachine-learning experiment and model tracking

Managed Services27 technologies

Cloud, SaaS and AI services we use with the operations left to the provider (listed by kind of service, not by vendor)

Managed Services
CategoryTechnologyWhat we use it for
ComputeCloudflare WorkersRuntime for the APIs and the Next.js frontends
Google Cloud RunRuntime for containerized APIs
Google Kubernetes EngineManaged Kubernetes
Data & StorageCloudflare D1Serverless SQLite-based database
Cloudflare R2Object storage for attachments and other files
Google Cloud StorageStorage for files and models
Google Cloud SQLFully managed relational databases (MySQL, PostgreSQL and others)
Google BigQueryData warehouse for large-scale analytics
Network & SecurityCloudflare RulesEdge rules such as redirects
Cloudflare WAFWeb application firewall
Cloudflare API ShieldAPI protection
Cloudflare DDoS ProtectionDDoS mitigation
Cloudflare TurnstileBot protection for forms
Cloudflare AccessZero Trust access control
Cloudflare GatewayZero Trust secure web gateway
Cloudflare WARPZero Trust device client
Cloudflare App LauncherZero Trust application launcher
LLMs & AI AgentsCloudflare Agents (Remote MCP)Foundation for AI agents and remote MCP servers
Claude (Anthropic)The LLM at the core of the AI agents and of AI coding (Claude Code)
Google ADKAI agent development framework (Agent Development Kit)
Google AntigravityAgent-first development environment (agentic IDE)
AuthenticationAuth0Authentication shared by every app
Payments & EmailStripePayments
ResendEmail delivery
MonitoringNew RelicUptime monitoring and log retention
Source HostingGitHubSource hosting, issues and package distribution
GitLabSource hosting and issue tracking

Development, Quality & Ops Tooling13 technologies

Tools for infrastructure as code, CI/CD, testing and security checks

Development, Quality & Ops Tooling
CategoryTechnologyWhat we use it for
IaC & ContainersTerraformInfrastructure as code for GitHub settings, DNS and R2
Docker (Compose)Containerization and bringing up whole setups locally
CI/CD & Dependency ManagementGitHub ActionsCI/CD and operational-metric posting
GitLab CI/CDCI/CD on GitLab
RenovateAutomated dependency updates
DependabotDependency vulnerability alerts
TestingVitestTypeScript unit tests
pytestPython unit tests
PlaywrightEnd-to-end tests
LocustLoad tests
Contract Tests & MocksSpecmaticContract tests and stubs from the OpenAPI contract (contract-driven development)
MicrocksAPI mocks built from the specification
Security TestingOWASP ZAPVulnerability scanning of web apps and APIs

Try the NASEBANAL Stack hands-on

Some of the middleware and test tooling in the NASEBANAL Stack can be run and tried for real with NASEBANAL Quickstarts, our open-source toolkit.

NASEBANAL Quickstarts

Kong, Kafka, Keycloak, Vault, the observability stack, Specmatic and more all start with the same Docker Compose command, make <module>:up.

Update History

Adoptions and retirements from the NASEBANAL Stack, newest first. Last updated:

  1. First published

    66 technologies — Technologies already in use when this page was first published. The date each was individually adopted was not recorded.

Talk to us about putting the NASEBANAL Stack to work

From selecting and introducing these technologies to applying them in your environment, we can help.

Contact us