All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
422 posts · page 13 of 18
Reverse Proxies Explained: Nginx, Caddy, and Traefik in Front of Your App
A reverse proxy sits between the internet and your app, handling TLS, routing, compression, and more. What reverse proxies do, how Nginx, Caddy, and Traefik differ, forwarded headers and trusting the real client IP, WebSockets and streaming, timeouts and body limits, and common 502/504 causes.
How to Resume a Claude Code Session (and What Resuming Can't Bring Back)
claude --continue and claude --resume reopen yesterday's conversation in seconds. But a resumed session restores the conversation, not the world it was working in. The commands, the habits that make resuming reliable, and the gap between conversation state and environment state.
Designing a REST API That Won't Embarrass You Later
APIs are hard to change once clients depend on them. The conventions that keep a REST API predictable — resource naming, methods, status codes, errors, pagination, validation, idempotency, and versioning — with the specific mistakes AI-generated APIs tend to make.
Why Does My App Look Broken on My Phone? Responsive Design Basics
It looks perfect on your laptop and falls apart on a phone: text too small, buttons off the edge, a page that scrolls sideways. What responsive design is, the five most common causes of broken mobile layouts, how to test properly, and what to ask your AI tool.
Replit Alternatives in 2026: What to Use Depending on Why You're Leaving
Replit bundles an AI agent, an editor, hosting, and a database. People leave for different reasons — cost, control, the agent, or outgrowing the platform — and each reason points to a different alternative. An honest guide to picking the right one.
Regular Expressions for Beginners: Reading Regex Without Panic
^[\w.+-]+@\w+\.\w{2,}$ looks like a cat walked on the keyboard. It's a regular expression, and AI tools write them constantly. The dozen symbols that cover most regex, how to read one piece by piece, how to test them, and when not to use regex at all.
Refactoring AI-Generated Code: Cleaning Up Without Breaking Things
Refactoring improves code's structure without changing what it does. When to refactor an AI-built app, how to do it safely with tests and small steps, the most valuable clean-ups, and prompts that stop the AI from rewriting everything.
Redis: When a Small App Actually Needs It (and When Postgres Is Enough)
Redis shows up in every architecture diagram, and AI tools add it by reflex. It's excellent at a few specific jobs — caching, rate limiting, ephemeral state, pub/sub — and unnecessary for many small apps. What it's for, what it isn't, and how to use it without losing data you cared about.
Prompt Injection in Coding Agents: A Threat Model
A coding agent with a shell, credentials, and network access reads text written by strangers all day. A threat model — sources, capabilities, sinks — why detection-based defences fail, and the architectural controls that actually bound the damage.
Writing a Production Dockerfile for a Node.js App
The Dockerfile an AI tool writes usually works — and ships a 1.5 GB image running as root that ignores shutdown signals and leaks build secrets into its layers. A line-by-line production Dockerfile: multi-stage builds, layer caching, non-root users, signal handling, secrets, and health checks.
Preview Environments for Every Branch: How They Work and What They Cost
A preview environment gives every branch or pull request its own live URL, so changes are reviewed running rather than read as diffs. How they work, the hard part (databases), the ways to get one, and why they matter more when an AI agent is writing the code.
Direct-to-Storage Uploads With Presigned URLs
Proxying uploads through your server wastes memory, bandwidth, and request time. How presigned URLs let browsers upload straight to S3, R2, or GCS: PUT vs POST policies, enforcing size and type, bucket CORS, confirming uploads, multipart, and serving private files.
Postgres as a Job Queue: FOR UPDATE SKIP LOCKED Done Properly
You may not need Redis or a broker for background jobs. How SKIP LOCKED makes Postgres a safe concurrent queue: claim/lease/ack, visibility timeouts and crash recovery, retries with backoff, LISTEN/NOTIFY, transactional enqueue, indexing, bloat, and its limits.
Postgres Point-in-Time Recovery: WAL Archiving, Base Backups, and Restore Drills
A nightly dump can lose a day of data. Point-in-time recovery restores to the second before the bad migration. How WAL archiving and base backups combine, the settings that matter, recovery targets and timelines, pgBackRest and WAL-G, and restore drills.
Postgres Migrations on Large Tables Without Downtime
The migration that took 40 ms in staging locked production for minutes. Postgres lock levels and the lock queue, lock_timeout with retries, which ALTER TABLE operations rewrite, CREATE INDEX CONCURRENTLY, NOT VALID constraints, safe NOT NULL, and batched backfills.
Postgres Major Version Upgrades: pg_upgrade, Logical Replication, and Minimal Downtime
Major versions change the on-disk format, so upgrading PostgreSQL isn't a package update. Dump/restore vs pg_upgrade (copy, link, clone) vs logical replication cutover; extension and collation pitfalls; sequences and DDL gaps in logical replication; statistics after upgrade; and a rehearsed runbook.
Postgres JSONB: When to Use It and When to Use Columns
JSONB lets you store flexible documents inside a relational database — and it's easy to overuse. When JSONB is the right tool, the operators you need, GIN vs expression indexes, updating nested values, validating shape with CHECK constraints, and the signs a JSONB field should become real columns.
Postgres Full-Text Search: Good Enough Before You Reach for Elasticsearch
ILIKE '%term%' doesn't scale and doesn't rank. How PostgreSQL full-text search works — tsvector, tsquery, GIN indexes, generated columns, websearch_to_tsquery, ranking, highlighting — plus pg_trgm for typo tolerance, and the point where a dedicated search engine is worth it.
Postgres Connection Pooling Explained: Why 'Too Many Connections' Happens and How to Fix It
"FATAL: sorry, too many clients already" usually appears the day an app gets popular. Why Postgres connections are expensive, how application pools and PgBouncer work, the transaction-mode caveats that break things, and how to size a pool without guessing.
How to Back Up a Postgres Database — and Prove the Backup Works
A backup you've never restored is a guess. The three kinds of Postgres backup, how to take each one, where to store them, and a restore drill you can run in fifteen minutes to find out whether yours actually work.
What Is an IP Address and a Port? localhost:3000 Explained
Every network connection goes to an address and a port — the building and the apartment number. What IP addresses and ports are, the common port numbers, what 0.0.0.0 means, why 'address already in use' happens, and why your app works on your laptop but not on the server.
How to Plan Your First App Before You Ask AI to Build It
Thirty minutes of planning saves days of AI going in circles. How to define the one problem your app solves, cut it down to a first version, describe your users' journeys and your data, and turn it all into a brief an AI tool can build from.
Password Hashing Explained: Why You Never Store Passwords
A well-built app doesn't know your password — it stores a hash. What hashing is, why fast hashes like MD5 and SHA-256 are wrong for passwords, what salts do, why bcrypt and Argon2 exist, and how to check that your AI-built app got it right.
Running Claude Code Agents in Parallel With Git Worktrees
Two agents in one checkout will overwrite each other's work. Git worktrees give each Claude Code session its own files and branch on the same repository. How to set it up, and the parts nobody warns you about: ports, databases, and dependencies.