Intermediate guides.
For people who already ship. Claude Code workflows, deploys without downtime, Postgres in production, and the operational details that start to matter.
106 posts · page 4 of 4
Monolith vs Microservices: Why Small Teams Should Start With a Monolith
Microservices solve organisational problems most small teams don't have and add distributed-systems problems they can't afford. What each costs, the modular monolith as a middle path, the signals that justify splitting a service out, and how AI coding agents change the maths.
Load Testing Your App Before Launch Day
Find out where your app breaks before your users do. What load, stress, spike, and soak tests reveal, writing a realistic k6 scenario with thresholds, reading p95 and error rates, finding the actual bottleneck, and the safety rules for testing without taking production — or a third-party API — down.
How to Keep Claude Code Costs Down (Without Making It Worse)
Claude Code usage is driven less by how much you ask and more by how much context every request carries. Where the tokens actually go, how to see them, and the habits that cut usage — clearing between tasks, picking the right model, trimming CLAUDE.md, and planning before building.
Implementing Rate Limiting: Algorithms, Redis, and Response Headers
Fixed window, sliding window, token bucket, and GCRA — how each behaves at the edges, how to implement them atomically in Redis or Postgres, choosing keys behind proxies, fail-open vs fail-closed, headers clients can use, and layered limits for login, APIs, and AI endpoints.
HTTP Caching Headers: Cache-Control, ETags, and Getting It Right
Most caching bugs are header bugs. How Cache-Control directives actually behave (max-age, s-maxage, no-cache vs no-store, private, immutable, stale-while-revalidate), how ETags and 304s work, Vary, and a practical header policy for static assets, HTML, APIs, and personalised pages.
How to Write a CLAUDE.md That Actually Changes What Claude Does
Most CLAUDE.md files are either empty or a wall of generic advice Claude would have followed anyway. What to put in one, what to leave out, how the files load, and how to tell whether yours is working.
How Automatic SSL Actually Works (and Why It Sometimes Doesn't)
The padlock in the browser comes from a certificate that has to be issued, installed, and renewed on a schedule that keeps getting shorter. How Let's Encrypt and ACME prove you own a domain, how tools like Traefik and Caddy automate it, and the five reasons a certificate fails to issue or renew.
Handling Webhooks Reliably: Signatures, Idempotency, and Retries
Webhooks arrive late, twice, out of order, or from someone pretending to be Stripe. How to verify signatures against the raw body, acknowledge fast and process in the background, make handlers idempotent, cope with ordering, and test the whole thing locally.
GitHub Codespaces Alternatives in 2026: An Honest Shortlist
Codespaces is a strong product, but not the right fit for everyone — usage billing, GitHub lock-in, and no path from dev environment to running app. The alternatives worth considering in 2026, what each is actually good at, and which ones have quietly changed direction.
Set Up CI With GitHub Actions in Ten Minutes
Continuous integration runs your checks on every push and pull request, so broken code is caught before it merges — whoever, or whatever, wrote it. A working GitHub Actions workflow for a Node project, what each line does, how to make checks required, and the mistakes that make CI slow or insecure.
Feature Flags for Small Teams: Ship Code Without Shipping Features
Feature flags separate deploying code from releasing it: merge unfinished work safely, try features yourself first, roll out gradually, and switch things off without a redeploy. A simple implementation, when to use a service, and how to stop flags becoming clutter.
Docker Volumes vs Bind Mounts: Where Your Data Actually Lives
Containers are meant to be thrown away. Your database, uploads, and certificates are not. The three ways Docker stores data — the container layer, named volumes, and bind mounts — what survives what, the command that silently deletes your database, and how to back a volume up.
Docker Compose for Local Development: App, Postgres, and Redis in One Command
A compose.yaml that starts your whole stack — app, database, cache, and workers — with one command. Services, networking by service name, volumes for data and code, health-checked startup order, env files, profiles, watch mode for live reload, and the pitfalls on macOS and Windows.
Database Transactions Explained: ACID, Isolation Levels, and Race Conditions
Transactions make several changes succeed or fail together — but they don't automatically prevent race conditions. ACID in practice, PostgreSQL's isolation levels, lost updates and write skew, SELECT FOR UPDATE, serializable retries, and the transaction mistakes that cause outages.
Database Indexes: Why Your App Got Slow and How to Fix It
The app was fast with 100 rows and crawls with 100,000. The fix is usually an index. How indexes work, how to find the slow queries, how to read EXPLAIN ANALYZE, which columns to index (including the foreign keys ORMs forget), and what indexes cost.
CSRF Explained: Cross-Site Request Forgery and How Modern Apps Prevent It
CSRF tricks a logged-in user's browser into making a request they didn't intend. How the attack works, what SameSite cookies do and don't cover, CSRF tokens, Origin and Fetch Metadata checks, framework defaults, and why token-in-header APIs are different.
Content Security Policy: A Practical Guide to CSP Headers
A Content Security Policy tells the browser which scripts, styles, and connections your page may use, turning many XSS bugs into blocked requests. The directives that matter, nonce-based strict CSP, Report-Only rollout, Next.js specifics, and mistakes that make CSP useless.
Claude Code Subagents: When to Split the Work (and When Not To)
Subagents give Claude Code a second context window: a helper that does a noisy job — running tests, searching a codebase, reading logs — and hands back only the summary. How they work, how to write your own, and the tasks where they help versus the ones where they just add cost.
Claude Code Skills: Turn the Prompts You Keep Retyping Into Commands
If you've pasted the same instructions into Claude Code more than twice, it should be a skill. How skills work, how they differ from CLAUDE.md, how to write one with arguments and live context, and four skills worth having in almost any project.
Claude Code Settings Explained: settings.json Scopes, Precedence, and a Team Setup
Claude Code reads settings from managed, command-line, local, project, and user files. Where each lives, which wins, how permission lists merge, what belongs in the committed project file vs your personal one, and a practical team configuration with permissions, hooks, and environment variables.
Claude Code Plan Mode: Make It Think Before It Types
The most expensive Claude Code mistakes happen in the first five minutes, when it confidently heads in the wrong direction. Plan mode makes it research and propose before touching anything. How to use it, how to review a plan properly, and when it's overkill.
Connecting MCP Servers to Claude Code: Setup, Scopes, and the Security Question
MCP servers let Claude Code talk to your issue tracker, database, error monitoring, and docs. Adding one is a single command. Choosing which ones to trust is the harder part. How to connect them, where the configuration lives, and how to keep a useful integration from becoming a data leak.
Using Claude Code on a Large Codebase
On a big repository, Claude Code's quality depends on what's in its context. How to structure CLAUDE.md files across a monorepo, point it at the right code, delegate exploration to subagents, keep sessions focused, give it fast feedback loops, and plan multi-step changes that span many files.
Claude Code Hooks: Rules the Agent Can't Forget
CLAUDE.md tells Claude Code what you'd like. Hooks make it happen, every time — blocking edits to protected files, formatting after every change, refusing to stop while tests fail. Five practical hooks, how they work, and the honest limits of what a hook can enforce.
Running Claude Code Headless: claude -p in Scripts, Cron, and CI
Add -p and Claude Code stops being a chat and becomes a command: pipe input in, get text or JSON out, exit with a status code. How print mode works, how to control what it's allowed to do and spend, authentication for CI, and where headless runs still need somewhere to live.
How to Use Claude Code From Your Phone: Every Option Compared
You can check on — and steer — a Claude Code session from your phone in at least four different ways. They differ in where the code runs, what happens when your laptop sleeps, and how much you can actually do on a small screen.
Claude Code --dangerously-skip-permissions: When It's Safe, and What to Use Instead
An agent that stops to ask permission can't work while you're away. An agent that never asks can delete things. How Claude Code's permission modes and allow/deny rules work, when skipping prompts is reasonable, and what has to be true of the environment first.
Claude Code Checkpoints: How /rewind Works and What It Can't Undo
Press Esc twice and Claude Code rewinds its file edits to any earlier prompt. It's a genuine safety net — with holes shaped exactly like the mistakes that hurt most: shell commands, database changes, and anything outside the working tree. What's covered, what isn't, and what to use for the rest.
Your App Needs Background Jobs. Here's the Simplest Way to Add Them.
Sending emails, processing uploads, calling slow AI models, and nightly cleanups don't belong in the middle of a web request. What background jobs and scheduled tasks are, the simplest reliable way to add them — often your existing Postgres database — and the mistakes that make jobs fail silently.
API Pagination: Offset vs Cursor (Keyset) and When Each Breaks
Returning every row works until it doesn't. How offset pagination works and why it gets slow and skips rows, how cursor (keyset) pagination fixes both, how to encode cursors and index for them, tie-breakers, total counts, and a response shape clients can rely on.
Leaving Gitpod: Where Cloud Dev Environments Went in 2026
Gitpod Classic shut down in October 2025 and the product became Ona, an AI-agent platform on a new runtime. If that broke your workflow, here's an honest map of the alternatives and what to check before you migrate.
Why Your AI Agent Keeps Forgetting (And Why Bigger Context Windows Won't Fix It)
Your coding agent works brilliantly for twenty minutes, then forgets the architecture you explained. That's not a bug you can prompt your way out of — and million-token windows won't save you. What actually helps.
The Real Cost of a Cloud Development Environment
Sticker price is the smallest part of what a cloud development environment costs — and the laptop it replaces was never free either. A model for working out whether the numbers actually favour you.
Why AI Coding Agents Need Persistent Workspaces
Stateless sandboxes make AI agents repeat themselves, lose context, and guess at results they could have measured. Persistent workspaces fix the feedback loop — here's the mechanism, and what it costs to build.