Deployment
Getting an app from a laptop to a real address and keeping it there — hosting choices, domains, SSL, preview environments and zero-downtime releases.
54 posts · page 1 of 2
Zero-Downtime Deploys for a Small App
You don't need Kubernetes to deploy without dropping requests. What actually causes downtime during a deploy — stopping before starting, no health checks, killed requests, and database changes the old code can't handle — and the four practices that fix each one.
Why Does My App Work Locally but Not in Production?
The app runs perfectly on your machine and breaks the moment it's deployed. It's almost always one of about a dozen causes — missing environment variables, localhost URLs, a filesystem that doesn't persist. How to find which one, in the order most likely to be it.
Where Should User Uploads Go? Object Storage Explained
Profile photos that vanish after a deploy, a database bloated with images, a public bucket full of private documents. Where uploaded files should live, how object storage works, and the three decisions — public or private, who uploads, and how files are served — that keep uploads fast and safe.
What Is Web Hosting? A Plain-English Guide for First-Time App Builders
Your app has to run on a computer that's always on and connected to the internet. That's hosting. The main kinds — static hosting, app hosting, servers you manage, and managed platforms — what each is for, and how to tell which one your app needs.
What Is Serverless? (There Are Still Servers)
Serverless means you write functions and the platform runs them on demand — no servers to manage, pay per use. What serverless really is, how it differs from an always-on server, cold starts, timeouts, and the database connection problem, and when it's the wrong fit.
What Is Next.js? A Beginner's Guide
Next.js is the React framework that v0 and many AI tools produce by default. What it adds on top of React, how file-based routing works, server vs client components, API routes, what 'rendering' means, and what you need to know to deploy it.
What Is Localhost? (And Why Your Friend Can't Open Your Link)
You send someone http://localhost:3000 and it doesn't work for them. That's because localhost means 'this computer' — yours, and only yours. What localhost and ports are, how to share an app you're working on, and why localhost sneaks into apps that are supposed to be live.
What Is CI/CD? Continuous Integration and Deployment for Beginners
CI/CD means every change is automatically checked, and working changes are automatically shipped. What continuous integration, delivery, and deployment are, what a pipeline does, why it matters when AI writes your code, and the smallest useful setup for a solo builder.
What Is a CDN? Why Your Site Loads Fast (or Doesn't) Far From Home
A CDN keeps copies of your site's files on servers around the world, so a visitor in Sydney doesn't wait for a server in Virginia. What a CDN does, what it can and can't speed up, how caching fits in, and the stale-content surprise that confuses beginners.
Agent Hosting Is Becoming Free. Here's What Isn't.
Anthropic now ships ways to keep Claude Code running without your laptop — Remote Control, cloud sessions, scheduled Routines. That's good news, and it changes what's worth paying for. The session is becoming a commodity. The environment the work ships into is not.
VPS vs PaaS: Where Should a Small App Live?
A VPS is cheap and does whatever you tell it — including nothing when it breaks. A PaaS runs your app for you and bills you for the privilege, often by usage. What each one actually includes, what it quietly leaves to you, and how to decide for a side project, an AI-built app, or a small business.
A Security Checklist for Vibe-Coded Apps
AI-built apps fail security in predictable ways: open databases, keys in the browser, authorization checked only in the UI. A practical checklist for non-security people — what to check, how to test it yourself, and what to fix before real users arrive.
How to Stop Bots From Running Up Your AI App's Bill
If your app calls an AI model on a user's behalf, every request costs you money — and a bot, a scraper, or one determined user can make thousands of them overnight. Rate limits, usage caps, provider spending limits, and the architecture that keeps a surprise bill from happening.
How to Stop an AI Agent From Deleting Your Production Database
In July 2025 an AI coding agent deleted a company's production database during a code freeze. It wasn't a freak event — it was the predictable result of giving an agent production credentials. Six controls that make it structurally impossible, not just unlikely.
Static vs Dynamic Websites: What's the Difference?
A static site is the same files for everyone; a dynamic site builds pages per request. What each means, where single-page apps and server rendering fit, why it matters for hosting, speed, SEO, and cost — and how to tell which one your AI tool built.
Social Preview Images: Make Your Links Look Good When Shared
When someone shares your app's link on Slack, X, LinkedIn, or iMessage, the preview card comes from Open Graph tags. What they are, the exact tags to add, the right image size, how to generate images per page in Next.js, how to test, and why your preview isn't updating.
"Sign in with Google" Explained: OAuth for Beginners
Social login lets users skip creating a password. How 'Sign in with Google' (and GitHub, Apple, Microsoft) actually works, what OAuth and OpenID Connect are, what redirect URIs and client secrets are, and why it breaks when you move from localhost to your real domain.
SEO Basics for Your App: How to Get Found on Google
A beautiful app that search engines can't read is invisible. The fundamentals that matter for a small app or product site — titles and descriptions, crawlable pages, a sitemap, speed, and link previews — plus the single-page-app problem that hides many AI-built sites from Google.
How to Send Email From Your App Without Landing in Spam
Password resets, receipts, and sign-up confirmations that land in spam — or never arrive — are one of the most common launch-week problems. What SPF, DKIM, and DMARC actually do, how to set them up for your domain, and why your app should never send mail itself.
Self-Hosting Next.js Without Vercel: What Works, What Breaks, What to Configure
Next.js runs anywhere Node.js does, and on a single server almost everything just works. The surprises: build-time environment variables, caching across instances, streaming behind a proxy, and a few Vercel-only conveniences. A practical guide to running Next.js on your own infrastructure.
Secrets Management Beyond .env Files
.env files are fine on a laptop and fragile everywhere else. Where secrets should live in production and CI, secret managers vs platform env vars, OIDC to remove long-lived CI credentials, rotation, least privilege, keeping secrets out of logs and AI agent context, and a practical maturity path.
Reverse Proxies Explained: Nginx, Caddy, and Traefik in Front of Your App
A reverse proxy sits between the internet and your app, handling TLS, routing, compression, and more. What reverse proxies do, how Nginx, Caddy, and Traefik differ, forwarded headers and trusting the real client IP, WebSockets and streaming, timeouts and body limits, and common 502/504 causes.
Replit Alternatives in 2026: What to Use Depending on Why You're Leaving
Replit bundles an AI agent, an editor, hosting, and a database. People leave for different reasons — cost, control, the agent, or outgrowing the platform — and each reason points to a different alternative. An honest guide to picking the right one.
Writing a Production Dockerfile for a Node.js App
The Dockerfile an AI tool writes usually works — and ships a 1.5 GB image running as root that ignores shutdown signals and leaks build secrets into its layers. A line-by-line production Dockerfile: multi-stage builds, layer caching, non-root users, signal handling, secrets, and health checks.