Logging
Every request and every database write, tied to the user who made it, rotated daily and archived to S3.
The problem
When something goes wrong, the first question is "who did this?" Fastify's built-in logs record requests but not users, and Drizzle doesn't log changes at all.
What Bones does
The backend writes two log files, both newline-delimited JSON:
requests.log— every HTTP request, plus one richer line per tRPC call with its path, duration, and result.db-changes.log— everyINSERT,UPDATE, andDELETEsent to Postgres, from any code path, with no per-query setup.
Both carry the same requestId and, once a session exists, the user's id and email. You can follow one request from the HTTP layer down to the rows it changed.
Secrets never reach the logs. Inputs named like password, token, or secret are redacted, and writes to the auth tables are redacted whole.
Files rotate daily or at 20 MB. A nightly job uploads closed files to S3 and deletes them locally. Leave S3_LOG_BUCKET unset and rotation still works, without the upload.
How it compares
A hosted log platform (Datadog, Logtail) gives you search and dashboards, but you still have to attach user identity yourself. Bones does that part and writes plain files, so you can ship them anywhere later.
What it doesn't do: record outcomes. The database log shows a statement was sent, not how many rows it changed. A customer-facing audit trail ("Sam added Alex to Acme") would be built on top of this.