Both the network and disk access permissions are granular, which means you can allow-write only to your logs folder, and allow net access only to your DB's address.
iptables + namespaces gives you the rest.
NodeJS is also working on policies (1) which allows you to change permission to single modules or files.
But indeed, if there is a separate user account for the application, then chmod can be used for some control to its access to files and directories.