Infrastructure
What sits under an app: servers, containers, storage, backups, and the plumbing that decides whether it stays up.
45 posts · page 2 of 2
Postgres Connection Pooling Explained: Why 'Too Many Connections' Happens and How to Fix It
"FATAL: sorry, too many clients already" usually appears the day an app gets popular. Why Postgres connections are expensive, how application pools and PgBouncer work, the transaction-mode caveats that break things, and how to size a pool without guessing.
How to Back Up a Postgres Database — and Prove the Backup Works
A backup you've never restored is a guess. The three kinds of Postgres backup, how to take each one, where to store them, and a restore drill you can run in fifteen minutes to find out whether yours actually work.
What Is an IP Address and a Port? localhost:3000 Explained
Every network connection goes to an address and a port — the building and the apartment number. What IP addresses and ports are, the common port numbers, what 0.0.0.0 means, why 'address already in use' happens, and why your app works on your laptop but not on the server.
npm Supply Chain Security: Install Scripts, Release Cooldowns, Provenance, and Trusted Publishing
Compromised maintainer accounts and self-propagating worms made npm installs an attack surface. The threat model, disabling install scripts, release cooldowns in npm, pnpm, Yarn, and Bun, lockfile discipline, provenance, trusted publishing, and isolating installs.
Monolith vs Microservices: Why Small Teams Should Start With a Monolith
Microservices solve organisational problems most small teams don't have and add distributed-systems problems they can't afford. What each costs, the modular monolith as a middle path, the signals that justify splitting a service out, and how AI coding agents change the maths.
Load Testing Your App Before Launch Day
Find out where your app breaks before your users do. What load, stress, spike, and soak tests reveal, writing a realistic k6 scenario with thresholds, reading p95 and error rates, finding the actual bottleneck, and the safety rules for testing without taking production — or a third-party API — down.
How to Know When Your App Is Down (Before Your Users Tell You)
Most small apps find out about outages from an annoyed email. Three cheap layers — an uptime check, error tracking, and logs you can search — mean you hear first, and usually know why. What each one does, how to set it up in an afternoon, and how to avoid alerts you'll learn to ignore.
Implementing Rate Limiting: Algorithms, Redis, and Response Headers
Fixed window, sliding window, token bucket, and GCRA — how each behaves at the edges, how to implement them atomically in Redis or Postgres, choosing keys behind proxies, fail-open vs fail-closed, headers clients can use, and layered limits for login, APIs, and AI endpoints.
HTTP Caching Headers: Cache-Control, ETags, and Getting It Right
Most caching bugs are header bugs. How Cache-Control directives actually behave (max-age, s-maxage, no-cache vs no-store, private, immutable, stale-while-revalidate), how ETags and 304s work, Vary, and a practical header policy for static assets, HTML, APIs, and personalised pages.
How Automatic SSL Actually Works (and Why It Sometimes Doesn't)
The padlock in the browser comes from a certificate that has to be issued, installed, and renewed on a schedule that keeps getting shorter. How Let's Encrypt and ACME prove you own a domain, how tools like Traefik and Caddy automate it, and the five reasons a certificate fails to issue or renew.
Firecracker vs gVisor vs Containers: Choosing Isolation for Untrusted Code
Containers share a kernel; gVisor intercepts it; Firecracker gives each workload its own. How the three isolation models actually work, what each costs in performance and compatibility, and how to match the boundary to the threat — for AI agents, multi-tenant platforms, and code execution.
Docker Volumes vs Bind Mounts: Where Your Data Actually Lives
Containers are meant to be thrown away. Your database, uploads, and certificates are not. The three ways Docker stores data — the container layer, named volumes, and bind mounts — what survives what, the command that silently deletes your database, and how to back a volume up.
Database Indexes: Why Your App Got Slow and How to Fix It
The app was fast with 100 rows and crawls with 100,000. The fix is usually an index. How indexes work, how to find the slow queries, how to read EXPLAIN ANALYZE, which columns to index (including the foreign keys ORMs forget), and what indexes cost.
Containers vs Virtual Machines: The Difference, Simply Explained
Both let one physical computer act like many. A virtual machine pretends to be a whole computer; a container is an isolated group of processes sharing one operating system. How each works, the trade-offs in speed, size, and isolation, and when to use which.
Container Networking Internals: veth, Bridges, NAT, and Embedded DNS
What happens when a container sends a packet: network namespaces, veth pairs, bridges, NAT for egress and published ports, why published ports bypass firewalls like ufw, Docker's embedded DNS, inter-container isolation, and debugging with nsenter and tcpdump.
How Container CPU and Memory Limits Actually Work
docker run --cpus 2 --memory 4g looks simple. Underneath, it's cgroup v2 files with behaviour that surprises people: CPU limits that throttle rather than slow, memory limits that count page cache, and tools inside the container that report the host's resources. How to read the real numbers.
What Is Caching? A Beginner's Guide to Making Apps Faster
Caching means keeping a copy of something so you don't have to fetch or compute it again. The caches between your user and your database — browser, CDN, server, database — what each is good for, why 'hard refresh' fixes things, and the one hard problem: stale data.
Preventing Cache Stampedes: Coalescing, Locks, Early Expiration, and Stale Serving
When a hot cache key expires, hundreds of requests miss at once and all hit the database. How stampedes happen, and the fixes: singleflight coalescing, distributed locks, probabilistic early recomputation (XFetch), stale-while-revalidate, TTL jitter, and negative caching.
Your App Needs Background Jobs. Here's the Simplest Way to Add Them.
Sending emails, processing uploads, calling slow AI models, and nightly cleanups don't belong in the middle of a web request. What background jobs and scheduled tasks are, the simplest reliable way to add them — often your existing Postgres database — and the mistakes that make jobs fail silently.
Egress Control for AI Agents: Designing an Allowlist Proxy
Restricting where an agent can send data is the most reliable defence against exfiltration, and easy to get subtly wrong. Network-layer enforcement, SNI vs TLS interception, DNS as a covert channel, allowlisted domains as leak paths, credential brokering, and testing.
Docker vs Linux Users for Multi-Tenant Workspace Isolation
Separate Linux users look like a cheap way to isolate tenants until you try to enforce a CPU limit. A walkthrough of why containers win for multi-tenant development workspaces — and how to verify the limits are real.