Building a Config CDN for White-Label SaaS — Cached CSS/JS Injection Architecture
The delivery backbone: one pasted script tag discovers its sub-account, fetches the whole config in 5 parallel queries, applies ten features, survives SPA navigation, and can never break a client's CRM.
<50ms
Median cached config
99.9%+
Delivery uptime
1 tag
Ten features
The challenge
What made this hard
Every feature in the suite ships through one constraint: agencies can paste one script tag into GHL's custom code box — at agency level only. That single tag must discover which sub-account it's running in, fetch the right config, apply ten independent features, survive GHL's SPA navigation, and never, ever break a client's CRM.
The solution
How I built it
One loader, one request, aggressive caching, and fail-open safety at every layer:
Agency loader
One tag resolves the company from GHL itself and the active location from the URL, then calls a clean JSON config API — re-fetching automatically when the user switches locations.
One request, whole config
A shared scope resolver fetches the location/group/plan/global documents once (5 parallel queries, down from ~24 sequential) and every feature resolves against the same bundle.
Aggressive caching
Compiled CSS is LRU-cached and ETag-revalidated; language packs cache independently for a week; every save bumps a version that busts exactly the right keys.
Fail-open safety
Invalid IDs return CSS comments, unknown packs return no-op JS, DB outages serve an in-memory default theme. Each of the ten appliers is exception-isolated — one throwing can never stop the next.
Under the hood
Technical highlights
Every applier follows the same contract: ES5, self-contained, idempotent, reversible on null, and silent on error. Hard rules enforced across the codebase — every write passes a sanitizer, only repositories touch models, and every document write bumps a version, the invariant the entire caching layer hangs on.
99.9%+ delivery availability including during deploys
Ten features, one script tag, zero client-side configuration
What the client said
A note from the client
"As the technical person on our side, this is the part I respect most. One script tag, ten features, and it has never once taken down a client account — even during our own deploys. Config loads are effectively instant, and the fail-open design means a bad setting just no-ops instead of breaking someone's CRM. This is properly engineered work, not a pile of snippets." — Ryan O'Connell, CTO, Lumen SaaS. Rated 5 out of 5. Reviewed April 2025.