# AI-Fullstack-SaaS-Boilerplate: the workspace layout, and the gaps in its own text

> A pnpm workspace that puts Drizzle, Fastify, tRPC and React 19 behind a dozen root scripts, whose badges point at a differently named repository, whose setup runs push instead of a migration, and whose newest tag is about seventeen months older than the last push.

**alan345/AI-Fullstack-SaaS-Boilerplate** — Fullstack SaaS Boilerplate built with tRPC, Fastify and React

- Repository: https://github.com/alan345/AI-Fullstack-SaaS-Boilerplate
- Website: https://alan345.github.io/AI-Fullstack-SaaS-Boilerplate/
- Stars: 1,429 · Forks: 222
- Language: TypeScript
- License: MIT
- Published: 2026-09-14 · Updated: 2026-09-14 · Language: en
- Canonical page: https://hysenlabs.com/projects/alan345-ai-fullstack-saas-boilerplate

## Every badge resolves a repository name without the AI prefix

The four badges under the project heading point at alan345/Fullstack-SaaS-Boilerplate, and so do the star history chart and both environment file links. The repository they live in is alan345/AI-Fullstack-SaaS-Boilerplate, and the homepage configured for it, alan345.github.io/AI-Fullstack-SaaS-Boilerplate, keeps the AI prefix. The two names differ in exactly the row of links a newcomer clicks first. The LICENSE badge adds a second mismatch: it reaches into blob/master/LICENSE, while the default branch is main and the two environment file links use blob/main. Nothing else in the file mentions a master branch. Follow the star badge and you may land on a rename, a fork, or nothing at all. Follow the LICENSE badge and you are asking a host for a branch that may not exist on the repository you cloned. Read the license from the LICENSE file on main instead, and treat the badge row as decoration until you have checked where each of the four URLs actually resolves.

## The root manifest holds a task runner and two dependencies

The root package.json is marked private and declares two runtime dependencies: npm-run-all at ^4.1.5 and drizzle-orm at ^0.45.2. It carries no React, no Fastify, and nothing else that the two stack tables list. The application itself is split across five workspace packages that every script addresses by scope name: @fsb/drizzle, @fsb/shared, @fsb/server, @fsb/client and @fsb/tests-e2e. The workspace layout lives in pnpm-workspace.yaml and packages/, next to client/, server/ and tests-e2e/ at the top level. Each root script is either a pnpm --filter call into one of those packages or an npm-run-all composition of them. Two of them use globs rather than fixed lists: dev is run-p dev:* and start is run-p start:*, each of which starts every script with that prefix in parallel, so a sixth dev: script would join the run without any edit to the orchestrator.

## The clean script deletes pnpm-lock.yaml with node_modules

clean is the one script in the root manifest that does not delegate to a workspace package, and it runs find twice. The first pass prunes every node_modules directory and deletes package-lock.json, yarn.lock and pnpm-lock.yaml. The second pass removes every dist directory. pnpm-lock.yaml is the lockfile of the package manager the installation section tells you to install first with npm install -g pnpm, so the command that wipes your dependencies also discards the record of which versions were installed. The manifest also asks for ranges rather than exact pins, drizzle-orm at ^0.45.2 and npm-run-all at ^4.1.5, which means a clean followed by pnpm install resolves to whatever those ranges point at on the day you run it, not to the graph you had before. pnpm-workspace.yaml survives the command and every package still lines up, so what you lose is only the version record.

## Setup is push then seed, and no migrate script exists

The documented setup order is four commands from the root directory: pnpm install, pnpm run push, pnpm run seed, and pnpm run dev, and the comment on the last line notes that it runs the client and the server automatically. push maps to pnpm --filter @fsb/drizzle run push, and seed maps to the same package, so both database commands live in the Drizzle workspace. No script in the root manifest is named migrate or generate, and no migrations directory appears among the top level entries. The database is therefore brought up by a push command rather than a chain of numbered steps, so the state of the fsb database follows the schema files as they stand when you run it. The name fsb is fixed everywhere it appears: the database to create, the workspace scope prefix, and the demo host fsb-client.onrender.com.

```bash
# Install the dependencies
pnpm install

# Setup the database
pnpm run push

# Seed the database
pnpm run seed

# Run the app (it will run the client and the server automatically)
pnpm run dev
```

## The README's own psql line carries a JavaScript comment

Before any of those commands you need Postgres running and a new database called fsb. Two printed lines cover that step:

```bash
psql -U user // replace user by your postgres user
CREATE DATABASE fsb;
```

The first line does not work in a shell. A double slash is JavaScript comment syntax, and bash has no such comment, so psql is handed every word after the flag as an argument, starting with a program named //. Copy the line as printed and the command fails before it connects. Drop the trailing note or move it above the command as a real hash comment and the line works, since user is the placeholder you replace with your own Postgres role. The second line carries no owner, no encoding, and no privilege flags, so the new database inherits whatever your role's defaults give it. Elsewhere in the file the shell comment habit is right: the install block marks each step with a hash, which makes this single line the exception rather than the pattern.

## The production build runs four workspace packages in a fixed order

The build is a chain of serial runs rather than a loop over packages. build:frontend runs build:backend and then build:client. build:backend runs build:drizzle, build:zod and build:server in that order, and build:zod is the script name the shared package is built under, the package that the dependency table ties to Zod, the TypeScript-first schema validation library. Because npm-run-all's run-s waits for each step, the Drizzle package is compiled before the shared package, the shared package before the server, and the client goes last. Two commands make up the production path:

```bash
pnpm run build
pnpm run start
```

start then runs start:server and start:client in parallel, the same shape as dev. The single root devDependency, wait-port, is a helper that blocks until a port answers, yet none of these scripts hands it one, so whatever waits on a port lives inside a workspace package rather than in the orchestrator. The tests follow the same pattern: pnpm run test filters @fsb/tests-e2e, matching the tests-e2e directory at the top level and the Playwright entry in the dependency table.

## The demo sleeps on a free tier, and the newest release is the chat

The demo link points at fsb-client.onrender.com, and the note under it says the demo is hosted by render.com for free, that the free tier spins down with inactivity, and that this can delay requests by 50 seconds or more. That warning sits directly above a feature list whose most distinctive entry is chat over Server-Sent Events, chosen there because SSE is easier to set up and needs no WebSocket server. A streaming response is the request most exposed to a cold start, and the file says nothing about what the chat stream does while the instance is asleep or waking, so treat the demo as a place to look at the UI rather than as a latency reference. The release history lines up with the feature list. v2.0.5 is titled with manual auth and dates from 2025-03-30. v2.0.6, titled Simple stable without chat, follows a day later on 2025-04-10. v2.0.7, titled Chat feature, lands on 2025-04-11 and is the newest tag. The authentication library in the dependency table is Better Auth, so the manual auth in that older tag name is not what the current tree is built on. The last push on record is 2026-09-02, about seventeen months after that tag.

## The last README section stops inside a video link

The file ends with a heading reading End-to-end typesafe with tRPC and one line that reads Video fro. There is no text under it, no code block, and no explanation of how shared types travel between the Fastify server and the React client. Everything above that heading is complete: the two stack tables, the star history, four feature lines, installation, the production build, two screenshots, and the motivation paragraph. What is missing is exactly the part a reader evaluating a typesafe API would want, which leaves the tRPC claim in the project title without written support in the file itself. Two other loose ends sit nearby. The motivation paragraph explains the decision not to use Next.js, so the frontend stays static files that can be stored in cloud object storage such as AWS S3, and it calls the result suited to building web apps rather than traditional websites, because it is not SEO-friendly. That sentence is the clearest statement in the repository of what this stack will not do for you. And _layouts/ sits at the top level next to client/, server/ and packages/, named in a way that no script or file in the repository refers to.

## Conclusion

Treat this repository as a readable example of one specific pnpm workspace shape rather than as a product to ship unchanged. Before building on it, confirm where the badge links resolve and read the LICENSE file on main, because the badge row names another repository and reaches for a branch that is not the default. Decide early whether a static client with no server rendering closes off your traffic plan, and plan your own database history, because push is the only schema command in the manifest and no migrations directory exists.

## FAQ

### Does AI-Fullstack-SaaS-Boilerplate use Next.js?

No. The motivation section says the author opted not to use Next.js so the frontend can stay static files that are easy to store in cloud object storage such as AWS S3, and it says the stack suits web apps rather than traditional websites because it is not SEO-friendly. The comparison it draws is with the T3 app at create.t3.gg.

### What do I need before running AI-Fullstack-SaaS-Boilerplate locally?

Rename the example.env files to .env with your own credentials, both the one at the repository root and the one in client/. Have Postgres running and create a new database called fsb. Then run pnpm install, pnpm run push, pnpm run seed and pnpm run dev from the root directory, where dev starts the client and the server together.

### What does pnpm run push do in AI-Fullstack-SaaS-Boilerplate?

The root manifest maps push to pnpm --filter @fsb/drizzle run push, so the command runs in the Drizzle workspace package. The same package handles seed. No script in the root manifest is named migrate or generate, and the repository has no migrations directory at its top level.

### Is AI-Fullstack-SaaS-Boilerplate archived and which release should I read?

The repository is not archived, and the last push on record is 2026-09-02. The newest tagged release is v2.0.7, titled Chat feature, from 2025-04-11, so the tag history is much older than the branch. v2.0.6 from the day before is titled Simple stable without chat.

### Which database, server framework and auth library does AI-Fullstack-SaaS-Boilerplate use?

The stack tables name Drizzle as the TypeScript-first ORM, Fastify as the server framework, Postgres as the database, React 19 and Tailwind v4 on the client, tRPC for the API, and Better Auth as the authentication library for Node.js. OpenAI is listed as a dependency for GPT models and embeddings.

## Sources

- [alan345/AI-Fullstack-SaaS-Boilerplate on GitHub](https://github.com/alan345/AI-Fullstack-SaaS-Boilerplate)
- [License: MIT](https://github.com/alan345/AI-Fullstack-SaaS-Boilerplate/blob/main/LICENSE)
- [Project website](https://alan345.github.io/AI-Fullstack-SaaS-Boilerplate/)
- [README](https://github.com/alan345/AI-Fullstack-SaaS-Boilerplate/blob/main/README.md)
- [Releases](https://github.com/alan345/AI-Fullstack-SaaS-Boilerplate/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/alan345-ai-fullstack-saas-boilerplate
