Advanced guides.
Under the hood: container isolation, cgroups, sandboxing untrusted code, and the architecture behind multi-tenant platforms.
40 posts · page 1 of 2
What Is eBPF? Safe Programs Inside the Linux Kernel, Explained
eBPF lets you run small, verified programs inside the Linux kernel at hook points — syscalls, network packets, function entry — without kernel modules. How it works (verifier, JIT, maps, hooks), what it powers, bpftrace one-liners, and its limits and security implications.
The TLS 1.3 Handshake Explained: What Happens Before the First Byte
What actually happens when a browser connects over HTTPS: ClientHello, key shares, the server's certificate and signature, Finished messages, one round trip instead of two, 0-RTT resumption and its replay risk, SNI and ECH, certificate chain validation, and how to inspect it all with openssl.
Postgres Read Replicas: Streaming Replication, Lag, and Read-Your-Writes
How Postgres physical streaming replication works, sync vs async, measuring replication lag, query conflicts and hot_standby_feedback, routing reads in your app without breaking read-your-writes, replication slots that fill disks, and when a replica is the wrong fix.
Postgres MVCC Explained: Tuples, xmin/xmax, Snapshots and Why VACUUM Exists
How PostgreSQL lets readers and writers work without blocking each other: every UPDATE writes a new row version, transactions see a snapshot, and visibility is decided by xmin and xmax. See it with real queries, and how it explains bloat, VACUUM, HOT updates, long transactions and wraparound.
Postgres Index Types: B-tree, GIN, GiST, BRIN, Hash — and When Each Wins
Postgres has more index types than most databases, and choosing well can turn a sequential scan into milliseconds. How B-tree, GIN, GiST, SP-GiST, BRIN and hash indexes work, which operators each supports, partial and expression indexes, covering indexes, and how to verify the planner uses them.
PID 1 in Containers: Signals, Zombies, and Why Your Container Won't Stop
Inside a container your app is PID 1, and PID 1 is special: the kernel won't apply default signal handlers to it and it must reap orphaned children. Why docker stop takes 10 seconds, why shell-form CMD swallows SIGTERM, zombies, and the fixes: exec form, tini/--init, signal handling.
Linux Namespaces Explained: The Kernel Feature Containers Are Made Of
A container is a process with its own namespaces. What each of the eight Linux namespaces isolates — mount, PID, network, UTS, IPC, user, cgroup, time — how to build a container-like process by hand with unshare, inspect one with nsenter and /proc, and what namespaces do not protect against.
HTTP/1.1 vs HTTP/2 vs HTTP/3: What Changed and Whether You Should Care
HTTP/2 multiplexed requests over one TCP connection; HTTP/3 moved to QUIC over UDP to escape TCP's head-of-line blocking and speed up handshakes. How each works, what they fix, what they break, how browsers discover HTTP/3, and what to actually configure for your app.
How Coding Agents Work: The Loop, the Tools, and the Context Behind Them
Under the hood, Claude Code, Codex and similar agents are a model in a loop with tools and a carefully managed context. The agent loop, tools, file editing, search, context compaction, subagents, permissions and sandboxing — and what it means for you.
Docker Image Layers and OverlayFS: How Container Filesystems Really Work
A Docker image is a stack of read-only layers merged by OverlayFS, with a thin writable layer per container. How layers are built and cached, content addressing and digests, copy-up and whiteouts, why deleting files doesn't shrink images, and the performance traps for databases.
Postgres VACUUM and Table Bloat: How It Works and How to Keep It Under Control
Why Postgres tables bloat, what VACUUM and autovacuum actually do, tuning autovacuum for large tables, what blocks cleanup (long transactions, replication slots), transaction ID wraparound, and how to reclaim space without VACUUM FULL's exclusive lock.
Postgres Table Partitioning: When It Helps, When It Hurts, and How to Do It
Declarative partitioning in PostgreSQL: range, list and hash partitions, partition pruning, primary key and unique constraint rules, dropping old data instantly, automating new partitions, converting an existing table, and the cases where partitioning makes things slower.
Reading Postgres EXPLAIN ANALYZE: A Practical Guide to Query Plans
How to read a Postgres query plan: EXPLAIN vs EXPLAIN ANALYZE, BUFFERS, costs vs actual times, loops, scan and join types, spotting bad row estimates, sorts spilling to disk — plus pg_stat_statements and auto_explain for finding the queries worth fixing.
Postgres "Deadlock Detected": Why It Happens and How to Prevent It
ERROR: deadlock detected. How Postgres deadlocks happen, how to read the log detail, the common causes — inconsistent lock ordering, batch updates, foreign keys, upserts — and the fixes: consistent ordering, shorter transactions, explicit locking, and safe retries.
Postgres Advisory Locks: Distributed Locking Without Redis
Advisory locks let your application lock arbitrary things — a job, a customer, a migration — using Postgres. Session vs transaction locks, blocking vs try-locks, turning strings into lock keys, the connection-pooler trap, and patterns for singleton cron jobs and per-entity mutexes.
Finding Memory Leaks in Node.js: Heap Snapshots, Retainers, and Common Culprits
Your Node.js server's memory climbs until it crashes. How to confirm a leak, read process.memoryUsage, capture heap snapshots in production safely, compare them in Chrome DevTools, follow retainer chains, and fix the usual causes: unbounded caches, listeners, timers and closures.
How KVM Virtualization Works: The Isolation Behind Cloud Servers
Most cloud VMs run on KVM. How hardware-assisted virtualization works — VT-x/AMD-V, the VMM, virtio, two-level page tables — what a VM boundary protects against compared with containers, the remaining risks (side channels, noisy neighbours, steal time), and what shared vs dedicated vCPUs mean.
Idempotency Keys: Making POST Requests Safe to Retry
A timeout on "create payment" — did it go through or not? Idempotency keys let clients retry safely without double-charging. How the Idempotency-Key header works, a Postgres-backed implementation, handling concurrent duplicates, fingerprint mismatches, expiry, and what to store.
Graceful Shutdown in Node.js: Handling SIGTERM Without Dropping Requests
Every deploy and restart sends your Node.js app SIGTERM. How to shut down gracefully: stop accepting traffic, fail readiness, finish in-flight requests, close keep-alive connections, drain workers, close database pools — plus the Docker PID 1 and npm start signal traps.
Context Engineering for Coding Agents: Beyond Prompt Engineering
Context engineering is designing everything an agent sees — instructions, tools, files, history — not just the prompt. Why context is a finite budget, context rot, just-in-time retrieval, progressive disclosure with skills, note-taking and compaction, subagents, and how to apply it to Claude Code.
The Transactional Outbox Pattern: Reliable Events Without Dual Writes
Writing to your database and publishing an event can't be made atomic, so one eventually happens without the other. How the transactional outbox fixes it: polling relays vs CDC, ordering, at-least-once delivery, idempotent consumers with an inbox, cleanup, and monitoring.
Securing MCP Servers: Threats and Controls for Tool-Connected Agents
An MCP server turns a model's text into real actions against real systems. The threat model — tool poisoning, prompt injection via tool output, confused deputies, token passthrough, DNS rebinding on local servers, over-broad scopes — and the controls for building and deploying MCP servers safely.
How to Run AI-Generated Code Safely
AI-generated code is usually well-intentioned and occasionally destructive, and the packages it installs are a supply-chain risk of their own. A practical, layered approach — what the code can see, reach, consume, and outlive — with a hardened Docker command you can use today.
Rootless Containers and User Namespaces: What They Actually Protect
Root in a container is root on the host unless something remaps it. How user namespaces work, subuid/subgid ranges, Docker userns-remap vs rootless mode vs Podman, Kubernetes hostUsers: false, the file-ownership and networking costs, and where rootless fits.