All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
422 posts · page 15 of 18
How to Write Good Prompts for AI Coding Tools
The difference between an AI tool that builds what you want and one that goes in circles is usually the prompt. A simple structure for asking — goal, context, constraints, and how you'll know it's done — with before-and-after examples you can copy.
How Much Does It Cost to Run an App? A Realistic Monthly Budget
Hosting, database, domain, email, AI usage, storage, and the tools around them. What each costs for a small app, what's free, where surprise bills come from, and three example budgets — from a side project to a small business with paying customers.
How Automatic SSL Actually Works (and Why It Sometimes Doesn't)
The padlock in the browser comes from a certificate that has to be issued, installed, and renewed on a schedule that keeps getting shorter. How Let's Encrypt and ACME prove you own a domain, how tools like Traefik and Caddy automate it, and the five reasons a certificate fails to issue or renew.
How to Keep API Keys Out of an AI-Built App
AI-generated code hardcodes API keys all the time — and 'put it in an environment variable' isn't enough if the variable ends up in the browser. Which keys are safe to expose, which never are, and how to fix a key that's already leaked.
Handling Webhooks Reliably: Signatures, Idempotency, and Retries
Webhooks arrive late, twice, out of order, or from someone pretending to be Stripe. How to verify signatures against the raw body, acknowledge fast and process in the background, make handlers idempotent, cope with ordering, and test the whole thing locally.
How to Hand Off an AI-Built App to a Client
Freelancers and agencies are shipping client apps faster than ever with AI. The handoff is where projects go wrong: accounts in the wrong name, no documentation, and an open-ended support expectation. A checklist for handing over cleanly — and keeping the relationship profitable.
GraphQL vs REST: What's the Difference?
REST gives you many endpoints that each return a fixed shape; GraphQL gives you one endpoint where the client asks for exactly the fields it wants. How each works, over-fetching and under-fetching, the costs GraphQL adds, and why most small apps should start with REST.
What Is .gitignore? Keeping Secrets and Junk Out of Git
A .gitignore file tells Git which files never to save — your .env secrets, node_modules, build output, and OS clutter. How it works, the pattern syntax, a starter file for JavaScript projects, and what to do if you already committed something you shouldn't have.
How Much Does GitHub Codespaces Actually Cost?
Codespaces bills by the hour for compute and by the GB-month for storage, with a free allowance on personal accounts. How the meter works, three worked examples from occasional to full-time use, and the settings that stop the bill surprising you.
GitHub Codespaces Alternatives in 2026: An Honest Shortlist
Codespaces is a strong product, but not the right fit for everyone — usage billing, GitHub lock-in, and no path from dev environment to running app. The alternatives worth considering in 2026, what each is actually good at, and which ones have quietly changed direction.
Set Up CI With GitHub Actions in Ten Minutes
Continuous integration runs your checks on every push and pull request, so broken code is caught before it merges — whoever, or whatever, wrote it. A working GitHub Actions workflow for a Node project, what each line does, how to make checks required, and the mistakes that make CI slow or insecure.
Git Branches Explained for Beginners
A branch is a safe parallel copy of your project where you can try something without touching the working version. What branches are, the commands to create, switch, and merge them, a simple workflow for solo builders, and why branches matter when an AI agent is editing your code.
Git and GitHub for Beginners: The Undo Button for Your Whole Project
If you build with AI, git is the single most useful thing you can learn — it lets you save your project at good moments and go back when the AI breaks something. What git and GitHub are, the six commands you need, and a simple routine to follow.
GDPR Basics for App Builders: What a Small App Actually Needs
If anyone in the EU or UK uses your app, GDPR probably applies. What personal data is, the principles in plain English, lawful bases, the rights users have (access, deletion), what to do about third-party services and data breaches, and a practical checklist for a small app. Not legal advice.
Frontend vs Backend: What's the Difference?
Every app has a part that runs in your browser and a part that runs on a server. Knowing which is which explains why secret keys leak, why some apps need a server and others don't, and what your AI tool actually built. A plain-English guide with a restaurant analogy that actually holds up.
Form Validation Explained: Client-Side, Server-Side, and Why You Need Both
Validation checks that what users type makes sense before you save it. The difference between browser-side and server-side validation, why only the server's counts for security, built-in HTML validation, sharing rules with a schema, and writing error messages people understand.
Firecracker vs gVisor vs Containers: Choosing Isolation for Untrusted Code
Containers share a kernel; gVisor intercepts it; Firecracker gives each workload its own. How the three isolation models actually work, what each costs in performance and compatibility, and how to match the boundary to the threat — for AI agents, multi-tenant platforms, and code execution.
File Paths Explained: Absolute, Relative, and Why 'File Not Found' Happens
Cannot find module './components/Button'? ENOENT: no such file or directory? Most of the time it's a path problem. How file paths work on Mac, Linux, and Windows, absolute vs relative paths, ./ and ../, the working directory, case sensitivity, and import aliases like @/.
Feature Flags for Small Teams: Ship Code Without Shipping Features
Feature flags separate deploying code from releasing it: merge unfinished work safely, try features yourself first, roll out gradually, and switch things off without a redeploy. A simple implementation, when to use a service, and how to stop flags becoming clutter.
Evals for Coding Agents: Measuring Whether Your Agent Setup Actually Works
Changing a CLAUDE.md, model, skill, or MCP server changes agent behaviour, usually untested. How to build an eval suite for coding-agent workflows: task selection, hermetic environments, graders, pass@k vs pass^k, cost and trajectory metrics, and running headless in CI.
What Is an Environment Variable? .env Files Explained
Environment variables are how an app gets its settings and secrets — database passwords, API keys, the site's URL — without writing them into the code. What they are, how .env files work, why they must never reach GitHub, and the prefix that quietly makes a 'secret' public.
Does My App Need a Privacy Policy? A Plain-English Guide
If your app collects so much as an email address, the answer is almost certainly yes — and app stores, Google sign-in, and payment providers may require one anyway. What a privacy policy must cover, the other legal pages you'll need, cookie banners, and the practical obligations that come with them.
Docker Volumes vs Bind Mounts: Where Your Data Actually Lives
Containers are meant to be thrown away. Your database, uploads, and certificates are not. The three ways Docker stores data — the container layer, named volumes, and bind mounts — what survives what, the command that silently deletes your database, and how to back a volume up.
Docker Compose for Local Development: App, Postgres, and Redis in One Command
A compose.yaml that starts your whole stack — app, database, cache, and workers — with one command. Services, networking by service name, volumes for data and code, health-checked startup order, env files, profiles, watch mode for live reload, and the pitfalls on macOS and Windows.