All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
422 posts · page 12 of 18
Stuck in an AI Fix Loop? How to Break Out
You ask the AI to fix a bug. It says it's fixed. It isn't. Three rounds later, two other things are broken too. Why AI tools get stuck in loops, how to recognise one early, and a step-by-step way out that works far better than asking again.
Structured Logging: Logs You Can Actually Search
console.log('user saved') is useless at 3am when you need every request user 4812 made in the last hour. How structured logs work, what fields to include, request IDs that tie a request together, log levels that mean something, what never to log, and how logs make AI agents better debuggers.
How to Stop Bots From Running Up Your AI App's Bill
If your app calls an AI model on a user's behalf, every request costs you money — and a bot, a scraper, or one determined user can make thousands of them overnight. Rate limits, usage caps, provider spending limits, and the architecture that keeps a surprise bill from happening.
How to Stop an AI Agent From Deleting Your Production Database
In July 2025 an AI coding agent deleted a company's production database during a code freeze. It wasn't a freak event — it was the predictable result of giving an agent production credentials. Six controls that make it structurally impossible, not just unlikely.
Static vs Dynamic Websites: What's the Difference?
A static site is the same files for everyone; a dynamic site builds pages per request. What each means, where single-page apps and server rendering fit, why it matters for hosting, speed, SEO, and cost — and how to tell which one your AI tool built.
SSH Keys Explained: Set Them Up Once, Properly
SSH keys are how you log into servers and push to GitHub without passwords. What the two halves of a key pair do, how to create a modern one, using ssh-agent and a config file so you stop retyping things, and the habits that matter: passphrases, one key per device, never sharing a private key.
SQL vs NoSQL: Which Database Should a Beginner Choose?
Postgres or MongoDB? Supabase or Firebase? The real difference between SQL and NoSQL databases, what 'relational' and 'document' mean, where each shines, the myths about scale and flexibility, and why most new apps should start with SQL.
SQL Injection Explained: The Classic Attack and the One-Line Fix
SQL injection lets an attacker rewrite your database queries by typing into a form. How it works with a simple example, what damage it can do, why parameterized queries and ORMs prevent it, the places AI-generated code still gets it wrong, and how to check your app.
SQL for Beginners: The Queries You Need to Understand Your App's Data
You don't need to become a database expert to read your own data. The handful of SQL queries — SELECT, WHERE, ORDER BY, COUNT, JOIN — that let you answer real questions about your app, plus the two commands to be very careful with.
Soft Deletes and Audit Logs: Keeping History Without Making a Mess
Deleting rows is irreversible; hiding them has costs too. When to use soft deletes, how to implement them without leaking 'deleted' data (partial indexes, unique constraints, views, RLS), the privacy tension with erasure requests, and how to build an audit log with triggers or application events.
Social Preview Images: Make Your Links Look Good When Shared
When someone shares your app's link on Slack, X, LinkedIn, or iMessage, the preview card comes from Open Graph tags. What they are, the exact tags to add, the right image size, how to generate images per page in Next.js, how to test, and why your preview isn't updating.
"Sign in with Google" Explained: OAuth for Beginners
Social login lets users skip creating a password. How 'Sign in with Google' (and GitHub, Apple, Microsoft) actually works, what OAuth and OpenID Connect are, what redirect URIs and client secrets are, and why it breaks when you move from localhost to your real domain.
Should You Still Learn to Code If AI Writes It?
AI can now build working apps from a description, so is learning to code still worth it? An honest answer: what AI has genuinely made unnecessary, the skills that matter more than ever, and a practical learning path for people who build with AI.
SEO Basics for Your App: How to Get Found on Google
A beautiful app that search engines can't read is invisible. The fundamentals that matter for a small app or product site — titles and descriptions, crawlable pages, a sitemap, speed, and link previews — plus the single-page-app problem that hides many AI-built sites from Google.
How to Send Email From Your App Without Landing in Spam
Password resets, receipts, and sign-up confirmations that land in spam — or never arrive — are one of the most common launch-week problems. What SPF, DKIM, and DMARC actually do, how to set them up for your domain, and why your app should never send mail itself.
Semantic Versioning Explained: What 2.4.1 Actually Means
Version numbers like 2.4.1 follow a convention: major.minor.patch. What each number promises, what ^ and ~ mean in package.json, why '0.x' versions are different, how lock files fit in, and how to version your own app or library.
Self-Hosted Cloud IDEs in 2026: code-server, Coder, and What Running One Really Takes
You can run VS Code in a browser on your own server in ten minutes. Running it well — for a team, securely, with backups — is a different project. An honest map of the self-hosted options, from a single code-server to Coder and Eclipse Che, and the work each one hands you.
Self-Hosting Next.js Without Vercel: What Works, What Breaks, What to Configure
Next.js runs anywhere Node.js does, and on a single server almost everything just works. The surprises: build-time environment variables, caching across instances, streaming behind a proxy, and a few Vercel-only conveniences. A practical guide to running Next.js on your own infrastructure.
Securing MCP Servers: Threats and Controls for Tool-Connected Agents
An MCP server turns a model's text into real actions against real systems. The threat model — tool poisoning, prompt injection via tool output, confused deputies, token passthrough, DNS rebinding on local servers, over-broad scopes — and the controls for building and deploying MCP servers safely.
Secrets Management Beyond .env Files
.env files are fine on a laptop and fragile everywhere else. Where secrets should live in production and CI, secret managers vs platform env vars, OIDC to remove long-lived CI credentials, rotation, least privilege, keeping secrets out of logs and AI agent context, and a practical maturity path.
How to Run AI-Generated Code Safely
AI-generated code is usually well-intentioned and occasionally destructive, and the packages it installs are a supply-chain risk of their own. A practical, layered approach — what the code can see, reach, consume, and outlive — with a hardened Docker command you can use today.
How to Run Claude Code on a Remote Server (and Keep It Running)
Running Claude Code on a server instead of your laptop means sessions survive a closed lid, a dropped connection, and a flat battery. A practical setup guide — the server, the session, the security — and what you take on by doing it yourself.
Rootless Containers and User Namespaces: What They Actually Protect
Root in a container is root on the host unless something remaps it. How user namespaces work, subuid/subgid ranges, Docker userns-remap vs rootless mode vs Podman, Kubernetes hostUsers: false, the file-ownership and networking costs, and where rootless fits.
How to Review a Pull Request Written by an AI Agent
AI-written pull requests are tidy, confident, and plausible — which makes them harder to review, not easier. The failure modes that differ from human code, the order to read a PR in, and a checklist that catches what skimming misses.