What you’ll be able to do
- Define a small inventory record and its validation rules.
- Explain why durable data belongs behind an authorized backend.
- Test create, read, update, and reload behavior.
Get the idea
Model the task, not the universe
An inventory item might need an ID, name, location, and status. Avoid adding fields merely because an assistant suggests them. Decide which fields are required and how duplicates should behave.
Durability is a service responsibility
A browser’s in-memory list disappears. A managed database can retain records across sessions, but the application still needs validation, error handling, and access rules. A database connection is not automatically a secure API.
Keep privileged access server-side
Use the official SDK in the backend. Prefer appropriate identity-based access where supported. Do not deliver database account keys to the frontend. Partition-key choices affect how Cosmos DB distributes and queries data.
Try it yourself
- Define the inventory record and four acceptance criteria: valid creation, rejected invalid input, update, and persistence after reload.
- Follow the linked Node.js Cosmos DB quickstart in a dedicated lab scope. Review its resource settings and price before deployment.
- Ask an AI assistant to explain the sample’s database, container, and partition key. Check its explanation against the sample.
- Build a small server-side inventory API using the sample’s supported SDK pattern. Add validation and return safe errors; do not expose it publicly until authorization is implemented.
- Create a fictional item, restart the client, read it back, update its status, and delete it. Record which component makes the data durable.
Example · commands or prompt
Using this reviewed Cosmos DB Node.js sample, design an inventory
record and server-side CRUD handlers.
Validate name and status; define a partition key deliberately.
Never put database credentials in frontend code.
Explain how callers will be authorized before public deployment.
Include tests for invalid input, missing records, and persistence.Finish the lab
Remove the fictional records and dedicated database resources when finished. Check all resources created by the quickstart. Do not claim this is a free or production-ready deployment.
Quick knowledge check
If a database key is hidden in minified frontend code, is it protected?
Reveal the explanation
No. Browser-delivered code and requests can be inspected. Privileged database operations need a protected server boundary.
Take this with you
Let the platform handle storage infrastructure while you define data, access, and correctness.
Go deeper
AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.