Deployment
Getting an app from a laptop to a real address and keeping it there — hosting choices, domains, SSL, preview environments and zero-downtime releases.
54 posts · page 2 of 2
Preview Environments for Every Branch: How They Work and What They Cost
A preview environment gives every branch or pull request its own live URL, so changes are reviewed running rather than read as diffs. How they work, the hard part (databases), the ways to get one, and why they matter more when an AI agent is writing the code.
Postgres Migrations on Large Tables Without Downtime
The migration that took 40 ms in staging locked production for minutes. Postgres lock levels and the lock queue, lock_timeout with retries, which ALTER TABLE operations rewrite, CREATE INDEX CONCURRENTLY, NOT VALID constraints, safe NOT NULL, and batched backfills.
Postgres Major Version Upgrades: pg_upgrade, Logical Replication, and Minimal Downtime
Major versions change the on-disk format, so upgrading PostgreSQL isn't a package update. Dump/restore vs pg_upgrade (copy, link, clone) vs logical replication cutover; extension and collation pitfalls; sequences and DDL gaps in logical replication; statistics after upgrade; and a rehearsed runbook.
How to Back Up a Postgres Database — and Prove the Backup Works
A backup you've never restored is a guess. The three kinds of Postgres backup, how to take each one, where to store them, and a restore drill you can run in fifteen minutes to find out whether yours actually work.
How to Move a Replit App to Your Own Hosting
Replit is a great place to build and a reasonable place to host — until the bill, the limits, or the lock-in start to matter. How to get your code and data out, where to put them, and the Replit-specific things that break on the way.
Load Testing Your App Before Launch Day
Find out where your app breaks before your users do. What load, stress, spike, and soak tests reveal, writing a realistic k6 scenario with thresholds, reading p95 and error rates, finding the actual bottleneck, and the safety rules for testing without taking production — or a third-party API — down.
How to Launch Your First App: A Beginner's Launch Checklist
Your app works. Now what? A practical launch plan for first-time builders: the pre-launch checks, where to find your first users, how to launch on Product Hunt, Reddit, and Hacker News without getting ignored or banned, and what to watch in the first week.
How to Know When Your App Is Down (Before Your Users Tell You)
Most small apps find out about outages from an annoyed email. Three cheap layers — an uptime check, error tracking, and logs you can search — mean you hear first, and usually know why. What each one does, how to set it up in an afternoon, and how to avoid alerts you'll learn to ignore.
HTTP Caching Headers: Cache-Control, ETags, and Getting It Right
Most caching bugs are header bugs. How Cache-Control directives actually behave (max-age, s-maxage, no-cache vs no-store, private, immutable, stale-while-revalidate), how ETags and 304s work, Vary, and a practical header policy for static assets, HTML, APIs, and personalised pages.
How Much Does It Cost to Run an App? A Realistic Monthly Budget
Hosting, database, domain, email, AI usage, storage, and the tools around them. What each costs for a small app, what's free, where surprise bills come from, and three example budgets — from a side project to a small business with paying customers.
How Automatic SSL Actually Works (and Why It Sometimes Doesn't)
The padlock in the browser comes from a certificate that has to be issued, installed, and renewed on a schedule that keeps getting shorter. How Let's Encrypt and ACME prove you own a domain, how tools like Traefik and Caddy automate it, and the five reasons a certificate fails to issue or renew.
How to Keep API Keys Out of an AI-Built App
AI-generated code hardcodes API keys all the time — and 'put it in an environment variable' isn't enough if the variable ends up in the browser. Which keys are safe to expose, which never are, and how to fix a key that's already leaked.
How to Hand Off an AI-Built App to a Client
Freelancers and agencies are shipping client apps faster than ever with AI. The handoff is where projects go wrong: accounts in the wrong name, no documentation, and an open-ended support expectation. A checklist for handing over cleanly — and keeping the relationship profitable.
Set Up CI With GitHub Actions in Ten Minutes
Continuous integration runs your checks on every push and pull request, so broken code is caught before it merges — whoever, or whatever, wrote it. A working GitHub Actions workflow for a Node project, what each line does, how to make checks required, and the mistakes that make CI slow or insecure.
Feature Flags for Small Teams: Ship Code Without Shipping Features
Feature flags separate deploying code from releasing it: merge unfinished work safely, try features yourself first, roll out gradually, and switch things off without a redeploy. A simple implementation, when to use a service, and how to stop flags becoming clutter.
Does My App Need a Privacy Policy? A Plain-English Guide
If your app collects so much as an email address, the answer is almost certainly yes — and app stores, Google sign-in, and payment providers may require one anyway. What a privacy policy must cover, the other legal pages you'll need, cookie banners, and the practical obligations that come with them.
DNS Records Explained: A, CNAME, MX, and TXT for Beginners
Your domain's DNS settings page is a table of cryptic records. What A, AAAA, CNAME, MX, TXT, and NS records do, how subdomains work, what TTL means, why changes 'take time to propagate', and how to check what the world actually sees.
Dev, Staging, and Production Explained
Professional apps don't have one copy — they have several, so changes can be tried safely before real users see them. What development, staging, and production environments are, why they need separate databases and keys, and the simplest version that works for a small app.
How to Deploy a v0 App (and What to Check Before Real Users Arrive)
v0's Publish button puts your app on Vercel in one click, and for many apps that's the right answer. What you actually have, how GitHub sync changes the workflow, how to host a v0 app somewhere other than Vercel, and the production checks that apply wherever it lives.
How to Deploy a Lovable App to Production
Lovable's Publish button gets your app online in one click. Whether that's production-ready depends on your database security, your domain, and what happens when you outgrow the builder. The three deployment paths, and the checks to run before real users arrive.
How to Deploy a Bolt.new App: Bolt Hosting, Netlify, or Your Own Server
Bolt.new can publish your app in one click, to its own hosting or to Netlify. What each option actually gives you, when to export the code and host it yourself, and the checks to run before you share the link with real users.
What Are Database Migrations? A Plain-English Guide
Migrations are how an app's database changes shape over time without losing data. What they are, why AI-built apps get them wrong, how to make a risky change safely, and the rules that stop a schema change from becoming a data-loss incident.
Content Security Policy: A Practical Guide to CSP Headers
A Content Security Policy tells the browser which scripts, styles, and connections your page may use, turning many XSS bugs into blocked requests. The directives that matter, nonce-based strict CSP, Report-Only rollout, Next.js specifics, and mistakes that make CSP useless.
How to Connect a Custom Domain to Your App: DNS Without the Jargon
Your app works at a long platform URL, and you want it at yourname.com. What DNS records actually do, A vs CNAME in plain English, the apex-domain problem, how HTTPS gets issued, and how to fix the usual errors.
Which Database Should an AI-Built App Use?
The AI will happily pick a database for you — sometimes a file on disk that disappears on the next deploy. What the choice actually is, why Postgres is the right default for almost every app, and the mistakes that lose data.
Your App Needs Background Jobs. Here's the Simplest Way to Add Them.
Sending emails, processing uploads, calling slow AI models, and nightly cleanups don't belong in the middle of a web request. What background jobs and scheduled tasks are, the simplest reliable way to add them — often your existing Postgres database — and the mistakes that make jobs fail silently.
How to Add Stripe Payments to an AI-Built App Without Getting Burned
AI tools will happily wire up Stripe in a way that looks finished and lets anyone pay $0.01 for your product. The four rules that make payments safe — server-side prices, verified webhooks, idempotent fulfilment, and a real live-mode test — explained without the jargon.
How to Add Login to an AI-Built App (Without Building It Yourself)
Authentication is the one feature you should never let an AI write from scratch. What 'login' actually involves, the three sensible ways to add it, and the checks that tell you whether the login your AI tool built is protecting anything at all.
You Built an App With AI. Now What?
The AI wrote your app in an afternoon. Getting it online, with a real database, that doesn't leak your API keys, is where most people get stuck. A plain-English guide to what happens after the code exists.
What Is an Autonomous Development Platform?
An Autonomous Development Platform gives AI agents and developers a persistent, managed environment to build in — not just a place to generate code. Here's what separates the category from AI code generators, PaaS, and cloud IDEs.