All posts.
Every EasySpawn article, newest first — deploying AI-built apps, Claude Code, databases, security, and the infrastructure underneath.
422 posts · page 6 of 18
What Is a PWA? Progressive Web Apps Explained for Beginners
A progressive web app is a website that can be installed like an app, work offline and send notifications. What a PWA needs (manifest, service worker, HTTPS), what it can and can't do on iPhone and Android, and when it's a better first step than an app-store app.
What Is a DDoS Attack? A Plain-English Guide for Website Owners
A DDoS attack floods a website with traffic until real visitors can't get through. How DDoS attacks work, the main types, how likely a small site is to be hit, what DDoS protection actually does, and the cheap steps that protect a small app.
What Are Embeddings? How AI Turns Meaning Into Numbers
An embedding is a list of numbers that captures what a piece of text means, so a computer can find similar things. How embeddings work, what they're used for (search, RAG, recommendations), how to store them, and practical tips on models, dimensions and cost.
VS Code Remote SSH: Develop on a Remote Server as if It Were Local
The Remote - SSH extension lets VS Code edit files, run terminals and debug on a remote Linux server. How it works, setup step by step, SSH config and keys, extensions and port forwarding, and fixes for the common connection problems.
How to View Your Postgres Database: psql, GUIs, and VS Code
Want to see what's actually in your app's database? How to look inside Postgres with psql, desktop tools like pgAdmin, DBeaver and TablePlus, VS Code extensions, and your ORM's studio — plus how to connect safely to a database on a server.
UUID vs Auto-Increment IDs: Which Primary Key Should You Use?
Sequential integers or UUIDs for your primary keys? The real trade-offs — size, index performance, guessability, merging data, leaking business metrics — why UUIDv7 changes the answer, Postgres 18's uuidv7(), and the common hybrid of internal IDs plus public IDs.
Two-Factor Authentication Explained (and How to Add It to Your App)
What two-factor authentication is, how authenticator-app codes (TOTP) work, why SMS codes are the weakest option, where passkeys fit, and how to add 2FA to your own app — including recovery codes and the mistakes to avoid.
How to Turn Your Web App Into a Mobile App (Without Rebuilding It)
Three realistic paths from a web app to a phone app: make it a PWA, wrap it with Capacitor for the App Store and Google Play, or rebuild with React Native. Costs, what Apple rejects, what you need (yes, a Mac), and how to choose.
How to Transfer a Domain to Another Registrar (Without Breaking Your Site or Email)
A step-by-step domain transfer guide: what moves and what doesn't, the transfer lock and auth code, how long it takes, copying DNS records first so your site and email keep working, and the difference between transferring a domain and just changing nameservers.
Subdomain vs Subdirectory: blog.example.com or example.com/blog?
Should your blog, docs or app live on a subdomain (app.example.com) or a subdirectory (example.com/app)? The technical differences, what it means for SEO, cookies and hosting, and sensible defaults for a small product.
Structured Output From LLMs: Getting Reliable JSON Every Time
How to get a language model to return JSON your code can trust: why "respond in JSON" isn't enough, schema-constrained structured outputs with Claude and Zod, strict tool use, validation, handling refusals and truncation, and designing schemas models fill well.
Stripe vs Paddle vs Lemon Squeezy: Which Should You Use to Get Paid?
The real difference between Stripe and Paddle or Lemon Squeezy is who handles sales tax: you, or a merchant of record. What a merchant of record is, fees compared, Stripe Managed Payments, and how to choose for a SaaS or digital product.
SSH Port Forwarding Explained: Local, Remote, and Dynamic Tunnels
SSH tunnels let you reach a database or web app on a server as if it were on localhost — without opening ports to the internet. Local (-L), remote (-R) and dynamic (-D) forwarding with practical examples, background tunnels, and the security caveats.
The SSH Config File Explained: Stop Typing Long SSH Commands
~/.ssh/config turns ssh -i ~/.ssh/key -p 2222 deploy@203.0.113.10 into ssh prod. Where the file lives on each OS, the options worth knowing, multiple GitHub accounts, jump hosts, keep-alives, and the precedence rule that trips people up.
Is SQLite Good Enough for Production? When It Works and When It Doesn't
SQLite now runs real production apps. When a single-file database is a great choice, the settings you must change (WAL mode, busy timeout, foreign keys), backups with Litestream, the single-writer limit, and the hosting setups where SQLite will lose your data.
SQL Joins Explained Simply: INNER, LEFT, RIGHT, and FULL JOIN
A beginner's guide to SQL joins with one small example database: what a join does, INNER JOIN vs LEFT JOIN with real output, RIGHT and FULL joins, joining three tables, and the classic mistakes — duplicated rows and WHERE clauses that cancel a LEFT JOIN.
Spec-Driven Development With Claude Code: Write the Spec, Then Let the Agent Build
Spec-driven development means agreeing on a written specification before an AI agent writes code. What a good spec contains, a practical workflow with Claude Code (spec → plan → tasks → implement → verify), templates, and when it's overkill.
Session Cookies vs JWTs: Which Should Your App Use for Authentication?
Server-side sessions and JWTs both keep users logged in, with very different trade-offs. How each works, revocation and logout, where to store tokens (cookies vs localStorage), the hybrid access/refresh pattern, and a clear default for web apps.
Server-Sent Events vs WebSockets: Which for Real-Time Features and AI Streaming?
SSE streams updates from server to browser over plain HTTP; WebSockets open a two-way channel. How each works, code for both, why AI chat responses use SSE-style streaming, proxy buffering and connection-limit gotchas, and a decision guide including plain polling.
HTTP Security Headers Explained: HSTS, CSP, and the Rest (With a Copy-Paste Setup)
A practical guide to the HTTP security headers worth setting: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy and Permissions-Policy — what each prevents, safe values, a Next.js and Nginx config, and which old headers to drop.
Role-Based Access Control (RBAC) for Your App: A Practical Guide
How to add roles and permissions to a web app without making a mess: roles vs permissions, a simple database schema, checking permissions on the server, multi-tenant roles per organisation, enforcing in the UI and the API, and testing it.
robots.txt and sitemap.xml Explained: A Beginner's Guide
Two small files that tell search engines (and AI crawlers) what to crawl and what exists on your site. How robots.txt and sitemap.xml work, examples, the robots.txt mistake that hides your whole site, why Disallow doesn't remove pages from Google, and how to generate both in Next.js.
How to Reduce Docker Image Size: From 1.5 GB to Under 200 MB
Big Docker images are slow to build, push, pull and deploy. The techniques that actually shrink them: slim base images, multi-stage builds, .dockerignore, production-only dependencies, layer ordering, cache cleanup — with Node.js and Python examples and a way to see what's taking space.
React App Shows a Blank Page After Deploying? Here's How to Fix It
Works locally, white screen in production. The usual causes of a blank page after deploying a React or Vite app — wrong base path, missing environment variables, a JavaScript crash, routing, caching — and how to diagnose each in two minutes with DevTools.