Architecture
How the pieces of an app fit together — frontends and backends, APIs, databases, queues and caches — and how to choose between designs.
45 posts · page 1 of 2
What Is an API? Explained Without the Jargon
APIs are how apps talk to each other — how your app takes a payment, sends an email, or asks an AI model a question. What an API actually is, what requests and responses look like, what an API key does, and the few terms you'll keep running into.
What Is a Webhook? Explained for Beginners
A webhook is how another service tells your app that something happened — a payment went through, a form was submitted, a file finished processing. How webhooks differ from normal API calls, what you need to receive one, and the three safety rules every webhook handler must follow.
What Is a Tech Stack? How to Choose One When AI Writes the Code
Your tech stack is the set of tools your app is built from: language, framework, database, and hosting. Even if AI writes the code, the choice matters — for how well the AI performs, what it costs, and who can help you later. A beginner's guide with a safe default.
What Is a Framework? React, Next.js, and Friends Explained
React, Next.js, Vue, Svelte, Django, Laravel — the names come up constantly and blur together. What a framework is, how it differs from a library, how the popular ones relate to each other, and why AI tools keep choosing the same few.
What Are WebSockets? Real-Time Features Explained
Chat, live notifications, multiplayer cursors, and dashboards that update themselves all need the server to push data to the browser. How WebSockets work, the simpler alternatives (polling and server-sent events), hosted real-time services, and what real-time needs from your hosting.
Web App vs Mobile App: Which Should You Build First?
Should your idea be a website, an iPhone app, an Android app, or all three? The real differences in cost, distribution, app store rules, updates, and capabilities — plus progressive web apps and cross-platform tools like React Native and Flutter — and why most first products start on the web.
Validating Input With Zod: One Schema for Forms, APIs, and Types
Every trust boundary — request bodies, query strings, webhooks, environment variables, AI output — needs runtime validation TypeScript can't provide. Using Zod schemas at each boundary, sharing them between client and server, stripping unknown keys, and useful errors.
The Transactional Outbox Pattern: Reliable Events Without Dual Writes
Writing to your database and publishing an event can't be made atomic, so one eventually happens without the other. How the transactional outbox fixes it: polling relays vs CDC, ordering, at-least-once delivery, idempotent consumers with an inbox, cleanup, and monitoring.
Static vs Dynamic Websites: What's the Difference?
A static site is the same files for everyone; a dynamic site builds pages per request. What each means, where single-page apps and server rendering fit, why it matters for hosting, speed, SEO, and cost — and how to tell which one your AI tool built.
SQL vs NoSQL: Which Database Should a Beginner Choose?
Postgres or MongoDB? Supabase or Firebase? The real difference between SQL and NoSQL databases, what 'relational' and 'document' mean, where each shines, the myths about scale and flexibility, and why most new apps should start with SQL.
Soft Deletes and Audit Logs: Keeping History Without Making a Mess
Deleting rows is irreversible; hiding them has costs too. When to use soft deletes, how to implement them without leaking 'deleted' data (partial indexes, unique constraints, views, RLS), the privacy tension with erasure requests, and how to build an audit log with triggers or application events.
Securing MCP Servers: Threats and Controls for Tool-Connected Agents
An MCP server turns a model's text into real actions against real systems. The threat model — tool poisoning, prompt injection via tool output, confused deputies, token passthrough, DNS rebinding on local servers, over-broad scopes — and the controls for building and deploying MCP servers safely.
Reverse Proxies Explained: Nginx, Caddy, and Traefik in Front of Your App
A reverse proxy sits between the internet and your app, handling TLS, routing, compression, and more. What reverse proxies do, how Nginx, Caddy, and Traefik differ, forwarded headers and trusting the real client IP, WebSockets and streaming, timeouts and body limits, and common 502/504 causes.
Designing a REST API That Won't Embarrass You Later
APIs are hard to change once clients depend on them. The conventions that keep a REST API predictable — resource naming, methods, status codes, errors, pagination, validation, idempotency, and versioning — with the specific mistakes AI-generated APIs tend to make.
Redis: When a Small App Actually Needs It (and When Postgres Is Enough)
Redis shows up in every architecture diagram, and AI tools add it by reflex. It's excellent at a few specific jobs — caching, rate limiting, ephemeral state, pub/sub — and unnecessary for many small apps. What it's for, what it isn't, and how to use it without losing data you cared about.
Direct-to-Storage Uploads With Presigned URLs
Proxying uploads through your server wastes memory, bandwidth, and request time. How presigned URLs let browsers upload straight to S3, R2, or GCS: PUT vs POST policies, enforcing size and type, bucket CORS, confirming uploads, multipart, and serving private files.
Postgres as a Job Queue: FOR UPDATE SKIP LOCKED Done Properly
You may not need Redis or a broker for background jobs. How SKIP LOCKED makes Postgres a safe concurrent queue: claim/lease/ack, visibility timeouts and crash recovery, retries with backoff, LISTEN/NOTIFY, transactional enqueue, indexing, bloat, and its limits.
Postgres Point-in-Time Recovery: WAL Archiving, Base Backups, and Restore Drills
A nightly dump can lose a day of data. Point-in-time recovery restores to the second before the bad migration. How WAL archiving and base backups combine, the settings that matter, recovery targets and timelines, pgBackRest and WAL-G, and restore drills.
Postgres Migrations on Large Tables Without Downtime
The migration that took 40 ms in staging locked production for minutes. Postgres lock levels and the lock queue, lock_timeout with retries, which ALTER TABLE operations rewrite, CREATE INDEX CONCURRENTLY, NOT VALID constraints, safe NOT NULL, and batched backfills.
Postgres JSONB: When to Use It and When to Use Columns
JSONB lets you store flexible documents inside a relational database — and it's easy to overuse. When JSONB is the right tool, the operators you need, GIN vs expression indexes, updating nested values, validating shape with CHECK constraints, and the signs a JSONB field should become real columns.
Postgres Full-Text Search: Good Enough Before You Reach for Elasticsearch
ILIKE '%term%' doesn't scale and doesn't rank. How PostgreSQL full-text search works — tsvector, tsquery, GIN indexes, generated columns, websearch_to_tsquery, ranking, highlighting — plus pg_trgm for typo tolerance, and the point where a dedicated search engine is worth it.
Postgres Connection Pooling Explained: Why 'Too Many Connections' Happens and How to Fix It
"FATAL: sorry, too many clients already" usually appears the day an app gets popular. Why Postgres connections are expensive, how application pools and PgBouncer work, the transaction-mode caveats that break things, and how to size a pool without guessing.
The N+1 Query Problem: How to Spot It and Fix It
The most common performance bug in ORM-based apps: one query for a list, then one more per item. How N+1 happens in Prisma, Drizzle, Django, Rails, and GraphQL resolvers, how to detect it from logs and pg_stat_statements, and the fixes — eager loading, batching, joins, and DataLoader.
Multi-Tenant SaaS on Postgres: Shared Schema + RLS vs Schema-per-Tenant vs Database-per-Tenant
The tenancy model is the hardest SaaS decision to reverse. Shared schema with RLS vs schema-per-tenant vs database-per-tenant — isolation, migrations, pooling, per-tenant restore — plus the owner-bypass, pooling, and foreign-key traps that silently break row-level security.