IoT telemetry on React Router v8, Postgres (Neon) and Better Auth
Type-checked against the real SDKs, migration applied to a live Postgres (Neon), connection clients load-tested, then tracked for upstream drift and re-verified when it moves. How we verify
session validation runs in server components and route handlers, not at the edge
What you're getting
React Router v8 (framework mode) — SSR, config/file routes under app/, loaders/actions, and resource routes for API endpoints.
Postgres on Neon via Drizzle ORM and the postgres-js driver.
Better Auth — self-hosted auth running inside your app against your Postgres (Drizzle adapter).
IoT telemetry — user-owned devices, append-only sensor readings, threshold alert rules, and fired alert instances.
Setup
bun add react-router react react-dom drizzle-orm postgres better-authDATABASE_URLNeon pooled (-pooler) connection stringBETTER_AUTH_SECRETgenerate with `openssl rand -base64 32`BETTER_AUTH_URLyour app's base URLApply the schema with bunx drizzle-kit push
Initialization
Database client
IoT telemetry schema: devices, readings, alert rules & alerts
Devicesuser-owned device registry with a unique device_key and an online/offline status CHECK
Sensor readings (time-series)append-only rows of metric + numeric value per device, indexed for time-range rollups
Alert rules & alertsper-device threshold rules (gt/lt/gte/lte comparator CHECK) and the alert instances they fire, with firing/resolved lifecycle
Deploy targets
Decisions and compatibility
Framework mode (not data/library mode): routes live under app/, declared in app/routes.ts. API endpoints are resource routes (a route module exporting loader/action but no default component).
prepare: false is mandatory — Neon's pooled endpoint is PgBouncer in transaction mode, where server-side prepared statements break across the pool.
Drizzle is paired here (not Prisma): Prisma's prepared-statement reliance is incompatible with transaction-mode pooling.
Self-hosted: Better Auth owns the user/session/account/verification tables. This stack emits them (db/auth-schema.ts) and hands them to the Drizzle adapter, so app-type schemas can foreign-key `user` directly.
devices.device_key carries a unique constraint — it is the physical device's identity token and must be generated once at provisioning time, never regenerated.
sensor_readings is append-only (no update path, composite index on device_id + recorded_at) — roll up by device + time window for dashboards rather than mutating any running aggregate.