All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
422 posts · page 14 of 18
Open Source Licences Explained for People Building Apps
Your app is built on hundreds of open-source packages, each with a licence that says what you may do with it. What open source means, the difference between permissive licences like MIT and 'copyleft' ones like GPL and AGPL, and how to check your app isn't using something it shouldn't.
How to Get a New Developer Productive on Day One
The first week of a new developer's job is often spent installing things and fighting a setup guide that stopped being true a year ago. What a day-one-ready project looks like — a reproducible environment, seed data, a short honest README — and how to test it without hiring anyone.
npm Supply Chain Security: Install Scripts, Release Cooldowns, Provenance, and Trusted Publishing
Compromised maintainer accounts and self-propagating worms made npm installs an attack surface. The threat model, disabling install scripts, release cooldowns in npm, pnpm, Yarn, and Bun, lockfile discipline, provenance, trusted publishing, and isolating installs.
What Are npm and package.json? A Beginner's Guide
Every JavaScript project has a package.json and a giant node_modules folder, and AI tools run npm commands constantly. What packages are, what npm install actually does, what the lockfile is for, and the handful of commands and warnings you need to understand.
The N+1 Query Problem: How to Spot It and Fix It
The most common performance bug in ORM-based apps: one query for a list, then one more per item. How N+1 happens in Prisma, Drizzle, Django, Rails, and GraphQL resolvers, how to detect it from logs and pg_stat_statements, and the fixes — eager loading, batching, joins, and DataLoader.
Multi-Tenant SaaS on Postgres: Shared Schema + RLS vs Schema-per-Tenant vs Database-per-Tenant
The tenancy model is the hardest SaaS decision to reverse. Shared schema with RLS vs schema-per-tenant vs database-per-tenant — isolation, migrations, pooling, per-tenant restore — plus the owner-bypass, pooling, and foreign-key traps that silently break row-level security.
How to Move a Replit App to Your Own Hosting
Replit is a great place to build and a reasonable place to host — until the bill, the limits, or the lock-in start to matter. How to get your code and data out, where to put them, and the Replit-specific things that break on the way.
Monorepo or Separate Repos? A Practical Guide for Small Teams
Should your frontend, backend, and shared code live in one repository or several? The real trade-offs — atomic changes, tooling cost, deploy independence, access control — how monorepo tooling like workspaces and Turborepo helps, and why AI agents tip the balance.
Monolith vs Microservices: Why Small Teams Should Start With a Monolith
Microservices solve organisational problems most small teams don't have and add distributed-systems problems they can't afford. What each costs, the modular monolith as a middle path, the signals that justify splitting a service out, and how AI coding agents change the maths.
Merge Conflicts Explained: What They Are and How to Fix Them
CONFLICT (content): Merge conflict in app.js looks alarming, but it's Git asking you a simple question. Why conflicts happen, how to read the <<<<<<< and >>>>>>> markers, how to resolve one in VS Code or with an AI tool, how to back out safely, and how to avoid most of them.
Load Testing Your App Before Launch Day
Find out where your app breaks before your users do. What load, stress, spike, and soak tests reveal, writing a realistic k6 scenario with thresholds, reading p95 and error rates, finding the actual bottleneck, and the safety rules for testing without taking production — or a third-party API — down.
Linters and Formatters Explained: ESLint, Prettier, Biome, and Ruff
A formatter makes code look consistent; a linter catches likely bugs. What each does, the common tools for JavaScript and Python, how to run them automatically on save and before every commit, and why they matter even more when an AI is writing the code.
I Leaked an API Key. What Now? A Step-by-Step Response
You pushed a .env file to GitHub, pasted a key in a screenshot, or found your secret key in your app's frontend code. What to do in the next ten minutes, the next hour, and the next day — revoke, rotate, check for abuse, clean up — and how to stop it happening again.
How to Launch Your First App: A Beginner's Launch Checklist
Your app works. Now what? A practical launch plan for first-time builders: the pre-launch checks, where to find your first users, how to launch on Product Hunt, Reddit, and Hacker News without getting ignored or banned, and what to watch in the first week.
How to Know When Your App Is Down (Before Your Users Tell You)
Most small apps find out about outages from an annoyed email. Three cheap layers — an uptime check, error tracking, and logs you can search — mean you hear first, and usually know why. What each one does, how to set it up in an afternoon, and how to avoid alerts you'll learn to ignore.
How to Keep Claude Code Costs Down (Without Making It Worse)
Claude Code usage is driven less by how much you ask and more by how much context every request carries. Where the tokens actually go, how to see them, and the habits that cut usage — clearing between tasks, picking the right model, trimming CLAUDE.md, and planning before building.
How to Install Claude Code on Mac, Windows, and Linux
A step-by-step guide to installing Claude Code: the recommended native installer, Homebrew, WinGet, and npm; which account you need; signing in; checking it works with claude doctor; updating; and fixing the install problems beginners hit most often.
Implementing Rate Limiting: Algorithms, Redis, and Response Headers
Fixed window, sliding window, token bucket, and GCRA — how each behaves at the edges, how to implement them atomically in Redis or Postgres, choosing keys behind proxies, fail-open vs fail-closed, headers clients can use, and layered limits for login, APIs, and AI endpoints.
HTTP Status Codes Explained: 200, 301, 404, 500 and the Rest
Every response from a server starts with a three-digit number that says how it went. What the 2xx, 3xx, 4xx, and 5xx families mean, the dozen codes you'll actually meet, what each one tells you about where a bug lives, and which ones your own API should return.
HTTP Caching Headers: Cache-Control, ETags, and Getting It Right
Most caching bugs are header bugs. How Cache-Control directives actually behave (max-age, s-maxage, no-cache vs no-store, private, immutable, stale-while-revalidate), how ETags and 304s work, Vary, and a practical header policy for static assets, HTML, APIs, and personalised pages.
HTML, CSS, and JavaScript: What Each One Does
Every web page is built from three languages with three different jobs: HTML for structure, CSS for looks, JavaScript for behaviour. What each one is, how they fit together, what they look like, and how much of each you need to understand to steer an AI tool.
How to Write a CLAUDE.md That Actually Changes What Claude Does
Most CLAUDE.md files are either empty or a wall of generic advice Claude would have followed anyway. What to put in one, what to leave out, how the files load, and how to tell whether yours is working.
How to Read an Error Message (and Fix Things Faster)
Error messages look like walls of gibberish, but they usually tell you exactly what went wrong and where. How to find the one line that matters, what common errors actually mean, where to look when there's no error at all, and what to give an AI so it can fix it first time.
How to Read a Diff: Reviewing What Your AI Tool Changed
A diff shows exactly what changed in your code: red lines removed, green lines added. How to read unified and side-by-side diffs, what the @@ lines mean, where to look them up in Git, VS Code, and GitHub, and a quick review routine for AI-generated changes.