Skip to content

Remote Validation

Remote Validation sits at the heart of security in Module Federation. This guide walks through the concept step by step, with examples, a cheatsheet, and common mistakes to avoid.

Remote Validation Overview

At its core, remote validation is about doing one thing well inside your Module Federation project. Once you understand the pattern, you can apply it consistently across features and teams.

Good remote validation pays off across the whole codebase: fewer surprises, easier testing, and smoother onboarding. The snippet below is a solid starting point.

// remote (webpack.config.js)
const { ModuleFederationPlugin } = require('webpack').container;

module.exports = {
  plugins: [
    new ModuleFederationPlugin({
      name: 'catalog',
      filename: 'remoteEntry.js',
      exposes: {
        './ProductList': './src/ProductList',
      },
      shared: ['react', 'react-dom'],
    }),
  ],
};

A remote exposes modules through remoteEntry.js so hosts can load them at runtime.

Remote Validation Example

new ModuleFederationPlugin({
  name: 'app',
  filename: 'remoteEntry.js',
  exposes: { './Widget': './src/Widget' },
  remotes: { other: 'other@http://host/remoteEntry.js' },
  shared: { react: { singleton: true } },
});
  • Start from a minimal Remote Validation example and grow it only as needed.
  • Keep configuration explicit so Remote Validation behaves the same in every environment.
  • Name things clearly so teammates understand your Remote Validation at a glance.
  • Add tests around Remote Validation early to lock in expected behaviour.

Module Federation Cheatsheet

Key Module Federation settings related to remote validation.

Option Example Purpose
name name: 'shell' Unique container name
filename filename: 'remoteEntry.js' Remote entry manifest
exposes exposes: { './X': './src/X' } Modules a remote shares
remotes remotes: { app: 'app@url' } Remotes a host consumes
shared shared: { react: { singleton: true } } Deduplicate libraries
lazy load import('remote/Module') Load remotes on demand
Suspense <Suspense fallback={...}> Handle async loading

How Remote Validation Works in Module Federation

Remote Validation builds on Module Federation's ability to load code from another independently built and deployed application at runtime. Each app can be a host, a remote, or both.

A remote exposes modules through remoteEntry.js so hosts can load them at runtime.

  • Remotes expose modules through a remoteEntry.js manifest.
  • Hosts declare remotes and import exposed modules dynamically.
  • Shared dependencies are deduplicated, ideally as singletons.
  • Each micro frontend builds and deploys on its own schedule.

Practical Guidance for Remote Validation

In production, remote validation needs careful version management and graceful failure handling. Align shared dependency versions and always render a fallback when a remote cannot load.

Concern Recommendation
Shared versions Use singletons with requiredVersion
Runtime errors Wrap remotes in error boundaries and fallbacks
Deployment Resolve remotes from a runtime manifest
Performance Lazy-load remotes and cache remoteEntry.js

Common Mistakes

  • Skipping error handling and edge cases when wiring up remote validation.
  • Leaving remote validation untested, so regressions slip into production.
  • Over-engineering remote validation before you actually need the extra flexibility.
  • Ignoring documentation, which makes remote validation hard for the next developer to change.

Key Takeaways

  • Remote Validation is a core part of working effectively with Module Federation.
  • Start small and keep remote validation focused on a single responsibility.
  • Apply consistent patterns so remote validation scales across your project.
  • Test and document remote validation to keep it maintainable over time.

Pro Tip

Bookmark this remote validation pattern and reuse it. Consistency across your Module Federation codebase is worth more than clever one-off solutions.