All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
217 posts · page 5 of 9
Postgres Point-in-Time Recovery: WAL Archiving, Base Backups, and Restore Drills
A nightly dump can lose a day of data. Point-in-time recovery restores to the second before the bad migration. How WAL archiving and base backups combine, the settings that matter, recovery targets and timelines, pgBackRest and WAL-G, and restore drills.
Postgres Migrations on Large Tables Without Downtime
The migration that took 40 ms in staging locked production for minutes. Postgres lock levels and the lock queue, lock_timeout with retries, which ALTER TABLE operations rewrite, CREATE INDEX CONCURRENTLY, NOT VALID constraints, safe NOT NULL, and batched backfills.
Postgres Major Version Upgrades: pg_upgrade, Logical Replication, and Minimal Downtime
Major versions change the on-disk format, so upgrading PostgreSQL isn't a package update. Dump/restore vs pg_upgrade (copy, link, clone) vs logical replication cutover; extension and collation pitfalls; sequences and DDL gaps in logical replication; statistics after upgrade; and a rehearsed runbook.
Postgres JSONB: When to Use It and When to Use Columns
JSONB lets you store flexible documents inside a relational database — and it's easy to overuse. When JSONB is the right tool, the operators you need, GIN vs expression indexes, updating nested values, validating shape with CHECK constraints, and the signs a JSONB field should become real columns.
Postgres Full-Text Search: Good Enough Before You Reach for Elasticsearch
ILIKE '%term%' doesn't scale and doesn't rank. How PostgreSQL full-text search works — tsvector, tsquery, GIN indexes, generated columns, websearch_to_tsquery, ranking, highlighting — plus pg_trgm for typo tolerance, and the point where a dedicated search engine is worth it.
Postgres Connection Pooling Explained: Why 'Too Many Connections' Happens and How to Fix It
"FATAL: sorry, too many clients already" usually appears the day an app gets popular. Why Postgres connections are expensive, how application pools and PgBouncer work, the transaction-mode caveats that break things, and how to size a pool without guessing.
How to Back Up a Postgres Database — and Prove the Backup Works
A backup you've never restored is a guess. The three kinds of Postgres backup, how to take each one, where to store them, and a restore drill you can run in fifteen minutes to find out whether yours actually work.
What Is an IP Address and a Port? localhost:3000 Explained
Every network connection goes to an address and a port — the building and the apartment number. What IP addresses and ports are, the common port numbers, what 0.0.0.0 means, why 'address already in use' happens, and why your app works on your laptop but not on the server.
How to Plan Your First App Before You Ask AI to Build It
Thirty minutes of planning saves days of AI going in circles. How to define the one problem your app solves, cut it down to a first version, describe your users' journeys and your data, and turn it all into a brief an AI tool can build from.
Password Hashing Explained: Why You Never Store Passwords
A well-built app doesn't know your password — it stores a hash. What hashing is, why fast hashes like MD5 and SHA-256 are wrong for passwords, what salts do, why bcrypt and Argon2 exist, and how to check that your AI-built app got it right.
Running Claude Code Agents in Parallel With Git Worktrees
Two agents in one checkout will overwrite each other's work. Git worktrees give each Claude Code session its own files and branch on the same repository. How to set it up, and the parts nobody warns you about: ports, databases, and dependencies.
Open Source Licences Explained for People Building Apps
Your app is built on hundreds of open-source packages, each with a licence that says what you may do with it. What open source means, the difference between permissive licences like MIT and 'copyleft' ones like GPL and AGPL, and how to check your app isn't using something it shouldn't.
How to Get a New Developer Productive on Day One
The first week of a new developer's job is often spent installing things and fighting a setup guide that stopped being true a year ago. What a day-one-ready project looks like — a reproducible environment, seed data, a short honest README — and how to test it without hiring anyone.
npm Supply Chain Security: Install Scripts, Release Cooldowns, Provenance, and Trusted Publishing
Compromised maintainer accounts and self-propagating worms made npm installs an attack surface. The threat model, disabling install scripts, release cooldowns in npm, pnpm, Yarn, and Bun, lockfile discipline, provenance, trusted publishing, and isolating installs.
What Are npm and package.json? A Beginner's Guide
Every JavaScript project has a package.json and a giant node_modules folder, and AI tools run npm commands constantly. What packages are, what npm install actually does, what the lockfile is for, and the handful of commands and warnings you need to understand.
The N+1 Query Problem: How to Spot It and Fix It
The most common performance bug in ORM-based apps: one query for a list, then one more per item. How N+1 happens in Prisma, Drizzle, Django, Rails, and GraphQL resolvers, how to detect it from logs and pg_stat_statements, and the fixes — eager loading, batching, joins, and DataLoader.
Multi-Tenant SaaS on Postgres: Shared Schema + RLS vs Schema-per-Tenant vs Database-per-Tenant
The tenancy model is the hardest SaaS decision to reverse. Shared schema with RLS vs schema-per-tenant vs database-per-tenant — isolation, migrations, pooling, per-tenant restore — plus the owner-bypass, pooling, and foreign-key traps that silently break row-level security.
How to Move a Replit App to Your Own Hosting
Replit is a great place to build and a reasonable place to host — until the bill, the limits, or the lock-in start to matter. How to get your code and data out, where to put them, and the Replit-specific things that break on the way.
Monorepo or Separate Repos? A Practical Guide for Small Teams
Should your frontend, backend, and shared code live in one repository or several? The real trade-offs — atomic changes, tooling cost, deploy independence, access control — how monorepo tooling like workspaces and Turborepo helps, and why AI agents tip the balance.
Monolith vs Microservices: Why Small Teams Should Start With a Monolith
Microservices solve organisational problems most small teams don't have and add distributed-systems problems they can't afford. What each costs, the modular monolith as a middle path, the signals that justify splitting a service out, and how AI coding agents change the maths.
Merge Conflicts Explained: What They Are and How to Fix Them
CONFLICT (content): Merge conflict in app.js looks alarming, but it's Git asking you a simple question. Why conflicts happen, how to read the <<<<<<< and >>>>>>> markers, how to resolve one in VS Code or with an AI tool, how to back out safely, and how to avoid most of them.
Load Testing Your App Before Launch Day
Find out where your app breaks before your users do. What load, stress, spike, and soak tests reveal, writing a realistic k6 scenario with thresholds, reading p95 and error rates, finding the actual bottleneck, and the safety rules for testing without taking production — or a third-party API — down.
Linters and Formatters Explained: ESLint, Prettier, Biome, and Ruff
A formatter makes code look consistent; a linter catches likely bugs. What each does, the common tools for JavaScript and Python, how to run them automatically on save and before every commit, and why they matter even more when an AI is writing the code.
I Leaked an API Key. What Now? A Step-by-Step Response
You pushed a .env file to GitHub, pasted a key in a screenshot, or found your secret key in your app's frontend code. What to do in the next ten minutes, the next hour, and the next day — revoke, rotate, check for abuse, clean up — and how to stop it happening again.