All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
217 posts · page 7 of 9
GDPR Basics for App Builders: What a Small App Actually Needs
If anyone in the EU or UK uses your app, GDPR probably applies. What personal data is, the principles in plain English, lawful bases, the rights users have (access, deletion), what to do about third-party services and data breaches, and a practical checklist for a small app. Not legal advice.
Frontend vs Backend: What's the Difference?
Every app has a part that runs in your browser and a part that runs on a server. Knowing which is which explains why secret keys leak, why some apps need a server and others don't, and what your AI tool actually built. A plain-English guide with a restaurant analogy that actually holds up.
Form Validation Explained: Client-Side, Server-Side, and Why You Need Both
Validation checks that what users type makes sense before you save it. The difference between browser-side and server-side validation, why only the server's counts for security, built-in HTML validation, sharing rules with a schema, and writing error messages people understand.
Firecracker vs gVisor vs Containers: Choosing Isolation for Untrusted Code
Containers share a kernel; gVisor intercepts it; Firecracker gives each workload its own. How the three isolation models actually work, what each costs in performance and compatibility, and how to match the boundary to the threat — for AI agents, multi-tenant platforms, and code execution.
File Paths Explained: Absolute, Relative, and Why 'File Not Found' Happens
Cannot find module './components/Button'? ENOENT: no such file or directory? Most of the time it's a path problem. How file paths work on Mac, Linux, and Windows, absolute vs relative paths, ./ and ../, the working directory, case sensitivity, and import aliases like @/.
Feature Flags for Small Teams: Ship Code Without Shipping Features
Feature flags separate deploying code from releasing it: merge unfinished work safely, try features yourself first, roll out gradually, and switch things off without a redeploy. A simple implementation, when to use a service, and how to stop flags becoming clutter.
Evals for Coding Agents: Measuring Whether Your Agent Setup Actually Works
Changing a CLAUDE.md, model, skill, or MCP server changes agent behaviour, usually untested. How to build an eval suite for coding-agent workflows: task selection, hermetic environments, graders, pass@k vs pass^k, cost and trajectory metrics, and running headless in CI.
What Is an Environment Variable? .env Files Explained
Environment variables are how an app gets its settings and secrets — database passwords, API keys, the site's URL — without writing them into the code. What they are, how .env files work, why they must never reach GitHub, and the prefix that quietly makes a 'secret' public.
Does My App Need a Privacy Policy? A Plain-English Guide
If your app collects so much as an email address, the answer is almost certainly yes — and app stores, Google sign-in, and payment providers may require one anyway. What a privacy policy must cover, the other legal pages you'll need, cookie banners, and the practical obligations that come with them.
Docker Volumes vs Bind Mounts: Where Your Data Actually Lives
Containers are meant to be thrown away. Your database, uploads, and certificates are not. The three ways Docker stores data — the container layer, named volumes, and bind mounts — what survives what, the command that silently deletes your database, and how to back a volume up.
Docker Compose for Local Development: App, Postgres, and Redis in One Command
A compose.yaml that starts your whole stack — app, database, cache, and workers — with one command. Services, networking by service name, volumes for data and code, health-checked startup order, env files, profiles, watch mode for live reload, and the pitfalls on macOS and Windows.
DNS Records Explained: A, CNAME, MX, and TXT for Beginners
Your domain's DNS settings page is a table of cryptic records. What A, AAAA, CNAME, MX, TXT, and NS records do, how subdomains work, what TTL means, why changes 'take time to propagate', and how to check what the world actually sees.
Dev, Staging, and Production Explained
Professional apps don't have one copy — they have several, so changes can be tried safely before real users see them. What development, staging, and production environments are, why they need separate databases and keys, and the simplest version that works for a small app.
How to Design Your First Database (Without a Computer Science Degree)
Before you ask an AI tool to 'build the database', spend fifteen minutes on paper. How to find your tables, choose columns and types, connect tables with foreign keys, handle one-to-many and many-to-many relationships, and avoid the mistakes that are painful to fix later.
How to Deploy a v0 App (and What to Check Before Real Users Arrive)
v0's Publish button puts your app on Vercel in one click, and for many apps that's the right answer. What you actually have, how GitHub sync changes the workflow, how to host a v0 app somewhere other than Vercel, and the production checks that apply wherever it lives.
How to Deploy a Lovable App to Production
Lovable's Publish button gets your app online in one click. Whether that's production-ready depends on your database security, your domain, and what happens when you outgrow the builder. The three deployment paths, and the checks to run before real users arrive.
How to Deploy a Bolt.new App: Bolt Hosting, Netlify, or Your Own Server
Bolt.new can publish your app in one click, to its own hosting or to Netlify. What each option actually gives you, when to export the code and host it yourself, and the checks to run before you share the link with real users.
Debugging for Beginners: A Calm, Repeatable Way to Find Bugs
Debugging isn't guessing until it works. A simple five-step method — reproduce, read, locate, hypothesise, verify — plus console.log, breakpoints, git bisect, rubber-ducking, and how to debug alongside an AI tool without getting stuck in a loop.
Dates and Time Zones in Apps: How Not to Get Them Wrong
Reminders sent an hour late, bookings on the wrong day, 'yesterday' that's actually today. Why dates are hard, the golden rule (store UTC, display local), ISO 8601, time zones vs offsets, daylight saving traps, and how to check your AI-built app handles them.
Database Transactions Explained: ACID, Isolation Levels, and Race Conditions
Transactions make several changes succeed or fail together — but they don't automatically prevent race conditions. ACID in practice, PostgreSQL's isolation levels, lost updates and write skew, SELECT FOR UPDATE, serializable retries, and the transaction mistakes that cause outages.
What Are Database Migrations? A Plain-English Guide
Migrations are how an app's database changes shape over time without losing data. What they are, why AI-built apps get them wrong, how to make a risky change safely, and the rules that stop a schema change from becoming a data-loss incident.
Database Indexes: Why Your App Got Slow and How to Fix It
The app was fast with 100 rows and crawls with 100,000. The fix is usually an index. How indexes work, how to find the slow queries, how to read EXPLAIN ANALYZE, which columns to index (including the foreign keys ORMs forget), and what indexes cost.
How to Get a Custom Email Address for Your Domain
you@yourapp.com looks far more trustworthy than yourapp.support@gmail.com. The options — Google Workspace, Microsoft 365, Zoho, Proton, Fastmail, and forwarding — how MX, SPF, DKIM, and DMARC records set it up, and how mailboxes differ from sending email from your app.
CSRF Explained: Cross-Site Request Forgery and How Modern Apps Prevent It
CSRF tricks a logged-in user's browser into making a request they didn't intend. How the attack works, what SameSite cookies do and don't cover, CSRF tokens, Origin and Fetch Metadata checks, framework defaults, and why token-in-header APIs are different.