All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
422 posts · page 16 of 18
DNS Records Explained: A, CNAME, MX, and TXT for Beginners
Your domain's DNS settings page is a table of cryptic records. What A, AAAA, CNAME, MX, TXT, and NS records do, how subdomains work, what TTL means, why changes 'take time to propagate', and how to check what the world actually sees.
Dev, Staging, and Production Explained
Professional apps don't have one copy — they have several, so changes can be tried safely before real users see them. What development, staging, and production environments are, why they need separate databases and keys, and the simplest version that works for a small app.
How to Design Your First Database (Without a Computer Science Degree)
Before you ask an AI tool to 'build the database', spend fifteen minutes on paper. How to find your tables, choose columns and types, connect tables with foreign keys, handle one-to-many and many-to-many relationships, and avoid the mistakes that are painful to fix later.
How to Deploy a v0 App (and What to Check Before Real Users Arrive)
v0's Publish button puts your app on Vercel in one click, and for many apps that's the right answer. What you actually have, how GitHub sync changes the workflow, how to host a v0 app somewhere other than Vercel, and the production checks that apply wherever it lives.
How to Deploy a Lovable App to Production
Lovable's Publish button gets your app online in one click. Whether that's production-ready depends on your database security, your domain, and what happens when you outgrow the builder. The three deployment paths, and the checks to run before real users arrive.
How to Deploy a Bolt.new App: Bolt Hosting, Netlify, or Your Own Server
Bolt.new can publish your app in one click, to its own hosting or to Netlify. What each option actually gives you, when to export the code and host it yourself, and the checks to run before you share the link with real users.
Debugging for Beginners: A Calm, Repeatable Way to Find Bugs
Debugging isn't guessing until it works. A simple five-step method — reproduce, read, locate, hypothesise, verify — plus console.log, breakpoints, git bisect, rubber-ducking, and how to debug alongside an AI tool without getting stuck in a loop.
Dates and Time Zones in Apps: How Not to Get Them Wrong
Reminders sent an hour late, bookings on the wrong day, 'yesterday' that's actually today. Why dates are hard, the golden rule (store UTC, display local), ISO 8601, time zones vs offsets, daylight saving traps, and how to check your AI-built app handles them.
Database Transactions Explained: ACID, Isolation Levels, and Race Conditions
Transactions make several changes succeed or fail together — but they don't automatically prevent race conditions. ACID in practice, PostgreSQL's isolation levels, lost updates and write skew, SELECT FOR UPDATE, serializable retries, and the transaction mistakes that cause outages.
What Are Database Migrations? A Plain-English Guide
Migrations are how an app's database changes shape over time without losing data. What they are, why AI-built apps get them wrong, how to make a risky change safely, and the rules that stop a schema change from becoming a data-loss incident.
Database Indexes: Why Your App Got Slow and How to Fix It
The app was fast with 100 rows and crawls with 100,000. The fix is usually an index. How indexes work, how to find the slow queries, how to read EXPLAIN ANALYZE, which columns to index (including the foreign keys ORMs forget), and what indexes cost.
How to Get a Custom Email Address for Your Domain
you@yourapp.com looks far more trustworthy than yourapp.support@gmail.com. The options — Google Workspace, Microsoft 365, Zoho, Proton, Fastmail, and forwarding — how MX, SPF, DKIM, and DMARC records set it up, and how mailboxes differ from sending email from your app.
CSRF Explained: Cross-Site Request Forgery and How Modern Apps Prevent It
CSRF tricks a logged-in user's browser into making a request they didn't intend. How the attack works, what SameSite cookies do and don't cover, CSRF tokens, Origin and Fetch Metadata checks, framework defaults, and why token-in-header APIs are different.
CORS Errors Explained: Why Your Frontend Can't Reach Your API
'Blocked by CORS policy: No Access-Control-Allow-Origin header' is one of the most common errors in AI-built apps. What CORS is, why the browser enforces it, how to fix it properly on the server, why the quick fixes are dangerous, and when you don't need CORS at all.
What Is a Cookie? How Websites Remember You
Cookies are how you stay logged in, keep items in a cart, and — yes — get tracked across the web. What a cookie is, how session cookies work, first- vs third-party cookies, the security settings every login cookie needs, and cookies vs local storage.
Content Security Policy: A Practical Guide to CSP Headers
A Content Security Policy tells the browser which scripts, styles, and connections your page may use, turning many XSS bugs into blocked requests. The directives that matter, nonce-based strict CSP, Report-Only rollout, Next.js specifics, and mistakes that make CSP useless.
Containers vs Virtual Machines: The Difference, Simply Explained
Both let one physical computer act like many. A virtual machine pretends to be a whole computer; a container is an isolated group of processes sharing one operating system. How each works, the trade-offs in speed, size, and isolation, and when to use which.
Container Networking Internals: veth, Bridges, NAT, and Embedded DNS
What happens when a container sends a packet: network namespaces, veth pairs, bridges, NAT for egress and published ports, why published ports bypass firewalls like ufw, Docker's embedded DNS, inter-container isolation, and debugging with nsenter and tcpdump.
Hardening Containers With Capabilities, seccomp, AppArmor, and User Namespaces
A default container shares the host kernel and starts with more privilege than most workloads need. A layer-by-layer guide: dropping capabilities, no-new-privileges, seccomp, AppArmor and SELinux, read-only filesystems, and user namespaces — and how to verify each.
How Container CPU and Memory Limits Actually Work
docker run --cpus 2 --memory 4g looks simple. Underneath, it's cgroup v2 files with behaviour that surprises people: CPU limits that throttle rather than slow, memory limits that count page cache, and tools inside the container that report the host's resources. How to read the real numbers.
How to Connect a Custom Domain to Your App: DNS Without the Jargon
Your app works at a long platform URL, and you want it at yourname.com. What DNS records actually do, A vs CNAME in plain English, the apex-domain problem, how HTTPS gets issued, and how to fix the usual errors.
Can You Really Code on an iPad or Chromebook?
The keyboard is fine. The problem is that tablets and Chromebooks can't run your project's toolchain like a laptop. The approaches that work — SSH to a remote machine, browser editors, cloud workspaces, and AI agents doing the heavy lifting — and where each falls short.
Claude Pro vs Max vs API Key for Claude Code: Which Should You Pay For?
Claude Code works with a Pro subscription, a Max subscription, or pay-as-you-go API billing. They're metered differently and suit different ways of working. How to choose, with a simple way to check your own usage.
Claude Code vs the Claude Chat App: Which Should You Use for Coding?
Both run on Claude models and come with the same subscription. The chat app is a conversation; Claude Code is an agent that works inside your project. What each does well, where each falls short, how they share usage limits, and a simple rule for when to use which.