Smart Contract Interaction Service

  • Backend
  • DevOps
  • Blockchain

Production · NestJS, Node.js, AWS (KMS/Secrets Manager), Terraform …

Executive Overview

A high-integrity NestJS microservice dedicated exclusively to executing and monitoring blockchain write transactions, isolating cryptographic signing keys, managing transaction nonces, and ensuring auditability.
The Challenge & Bottleneck

Core Problem

Direct smart contract write interactions are fraught with operational risk: concurrent service requests attempting to send transactions using the same Ethereum wallet produce nonce collisions, causing transactions to stall or fail. Furthermore, baking private keys into application environments creates catastrophic security exposure, and volatile network gas fees can freeze transactions indefinitely in the mempool.

Engineering Approach

Architectural Solution

Developed an isolated transaction gateway service featuring an in-memory sequential nonce manager backed by Redis, automated dynamic gas fee calculation with speed-up transaction replacement policies, and zero-plaintext key storage using AWS KMS / Secrets Manager.

Quantified Outcomes

Measurable Impact

Achieved zero nonce collisions across tens of thousands of automated transactions, eliminated stalled transactions via automated gas-bump replacements, and provided full cryptographic auditability across all platform contract calls.

System Architecture

Component topology, protocol boundaries, and data flow.

Smart Contract Interaction Service System Topology
Architecture Flow
CLIENT CONSUMERWeb & API CallsHTTPS / REST PayloadsJSON Schema InputBOUNDARY GATEWAYNginx / Reverse ProxyTLS TerminationRate Limiting & AuthNSERVICE CORE LOGIC• Domain Services & Controllers• DTO Runtime Validation• AWS Secrets Manager Config• Health Readiness ProbesPERSISTENCEPostgreSQL / RedisACID TransactionsDocker / EKS Hosted

Reliability & Production Security

Signing keys are stored in AWS KMS and injected only at runtime within secure memory segments. The service features automatic mempool transaction monitoring: if a transaction remains unmined after N blocks, the service automatically signs and broadcasts a replacement transaction with 15% higher gas (EIP-1559 priority fee boost).

Deployment & Infrastructure

Packaged in multi-stage Docker images and deployed in private Kubernetes subnets with no public ingress. Monitored with Prometheus metrics tracking gas expenditures, pending mempool transactions, and transaction confirmation latencies.
Engineering Post-Mortem & Insights

What I Learned

Technical trade-offs, battle-tested discoveries, and operational takeaways from this project.

1

Nonce Management Must Be Centralized and Serialized

In EVM networks, transactions from an address must execute sequentially by nonce. Allowing multiple microservices to sign independently causes immediate nonce clashes; a centralized signing service with a distributed mutex is critical.

2

Automated Gas Speed-Ups Are Essential During Congestion

When gas prices spike, transactions broadcast with low base fees become stuck in the mempool for hours. Implementing automated replacement transactions with matching nonces and higher priority fees keeps workflows moving.

3

Never Store Private Keys in Environment Variables or Source Files

Credential isolation through HSMs, AWS KMS, or hardware vaults drastically reduces key compromise risk and provides an unalterable audit log of every signature.

4

Wait for Multiple Confirmations Before Declaring Success

Emitting an internal success event after 1 block confirmation can result in corrupted state if that block is subsequently reorganized. Requiring a 3-6 block confirmation window ensures finalized transactions.

Future Roadmap & Architectural Evolution

  • →Integrate multi-signature vault workflows (Safe / Fireblocks) for high-value contract calls.
  • →Implement automated ledger reconciliation against block receipts.
Smart Contract Interaction Service | Siddhant Ghosh