Intermediate guides.
For people who already ship. Claude Code workflows, deploys without downtime, Postgres in production, and the operational details that start to matter.
106 posts · page 1 of 4
How to Test Webhooks Locally: Stripe CLI, Tunnels, and Replays
Webhook providers can't reach localhost, so local testing needs a forwarder or a tunnel. How to use provider CLIs like stripe listen, general tunnels like ngrok and Cloudflare Tunnel, request-capture tools, and fixture replays in automated tests — plus the signature-verification gotchas.
TanStack Query vs useEffect for Data Fetching in React
Fetching in useEffect looks simple until you need loading states, errors, caching, race conditions, refetching and mutations. What TanStack Query handles for you, side-by-side code, mutations with invalidation, and when server components or plain useEffect are still the right choice.
Stripe Subscriptions Explained: Products, Prices, Webhooks and Access
How Stripe Billing models subscriptions — customers, products, prices, subscriptions and invoices — which webhooks to handle, what each subscription status means for access, trials, upgrades and proration, failed payments and dunning, and the Customer Portal.
Streaming LLM Responses to the Browser: SSE, Fetch Streams, and Gotchas
Streaming makes AI features feel fast: words appear as they're generated instead of after a ten-second wait. How to stream from the Claude API on your server, forward it to the browser, read it in React, and fix the proxies and timeouts that buffer or cut off streams.
How to Secure a New VPS: The First 30 Minutes
A fresh server is scanned within minutes of going online. The essential hardening steps for a new Ubuntu VPS: updates, a non-root user, SSH keys only, firewall, automatic security patches, fail2ban, safe service binding, backups and monitoring — in order, with commands.
React State Management: useState vs Context vs Zustand vs Redux
Most React apps need less state management than they think. Sort your state into server, URL, form, local and global, then pick the lightest tool for each: useState, the URL, React Context, Zustand, Redux Toolkit or Jotai. Trade-offs, examples and common mistakes.
React Server Components Explained: "use client", "use server", and What Runs Where
Server Components render on the server and send no JavaScript; Client Components hydrate in the browser for interactivity. How the boundary works, what 'use client' and 'use server' actually mean, passing data across, common errors, and how to keep secrets and bundles where they belong.
Prompt Caching Explained: Cut LLM Costs and Latency on Repeated Prompts
If every request repeats the same long system prompt, documents or tool definitions, prompt caching lets the provider reuse that work for a fraction of the price and time. How it works, structuring prompts for cache hits, Claude's cache_control, OpenAI's automatic caching, and verifying it works.
Postgres Roles and Permissions: CREATE USER, GRANT, and Least Privilege
Most apps connect to Postgres as a superuser, so one SQL injection or rogue AI command can drop everything. How Postgres roles, privileges, schemas and default privileges work, and a practical setup with separate owner, app and read-only roles.
Playwright Tutorial: End-to-End Tests That Aren't Flaky
Playwright drives real browsers to test your app the way users use it. Install it, write your first test, use role-based locators and auto-waiting assertions, log in once and reuse the session, run against a dev server, debug with UI mode and traces, and run it in CI.
Optimistic vs Pessimistic Locking: Preventing Lost Updates
Two users edit the same record and one silently overwrites the other. Pessimistic locking (SELECT FOR UPDATE) blocks the second writer; optimistic locking (a version column) detects the conflict. How each works, code for both, atomic updates that avoid locks entirely, and how to choose.
"No Space Left on Device": Finding and Freeing Disk Space on a Server
When a server's disk fills up, databases stop writing, deploys fail and apps crash with ENOSPC. How to find what's using space with df and du, the usual culprits (logs, Docker, journald, old releases, deleted-but-open files), inode exhaustion, and how to stop it happening again.
Next.js App Router vs Pages Router: Differences and Whether to Migrate
Next.js has two routers: the older pages/ directory and the newer app/ directory built on React Server Components. How routing, data fetching, layouts and API routes differ, which one new projects should use, and a sensible incremental migration path.
Message Queues Explained: When You Need One and Which to Use
A message queue lets one part of your system hand work to another without waiting. Queues vs pub/sub vs event streams, delivery guarantees, dead-letter queues, and an honest comparison of Postgres, Redis, RabbitMQ, SQS and Kafka for a small team.
Deploy to a VPS With GitHub Actions: Push to Main, Ship to Production
Automate deploys to your own server: run tests in GitHub Actions, then SSH in and run your deploy script — or build a Docker image and pull it. Deploy keys, secrets, known_hosts, environments with approval, rollbacks, and keeping the SSH key's power limited.
ESM vs CommonJS: import vs require and the Errors Between Them
JavaScript has two module systems. CommonJS uses require and module.exports; ES modules use import and export. How Node decides which a file is, and how to fix 'Cannot use import statement outside a module', 'require is not defined', ERR_REQUIRE_ESM and __dirname is not defined.
How to Deploy a FastAPI App to Production
Running uvicorn main:app --reload is for development. A production FastAPI deploy needs worker processes, a process manager or container, a reverse proxy with HTTPS, proper settings, migrations, and health checks. Step-by-step options for a VPS and Docker.
Database Normalization Explained: 1NF, 2NF, 3NF in Plain English
Normalization means storing each fact once, so updates can't leave your data contradicting itself. What 1NF, 2NF and 3NF actually require, with one example table taken through each step, the anomalies they prevent, and when deliberately denormalizing is the right call.
The Claude Agent SDK: Building Your Own Agents on Claude Code's Engine
The Claude Agent SDK gives you the agent loop behind Claude Code as a library: file and shell tools, permissions, MCP, subagents and sessions. When to use it instead of the plain API or claude -p, a minimal TypeScript example, custom tools, permissions, and running it safely.
API Authentication Methods: API Keys, Sessions, JWTs, OAuth and mTLS
How should clients prove who they are to your API? API keys for server-to-server, session cookies for your own web app, bearer tokens for mobile and SPAs, OAuth for third-party access, HMAC signatures for webhooks, mTLS for service meshes. When to use each and how to do it safely.
VS Code Remote SSH: Develop on a Remote Server as if It Were Local
The Remote - SSH extension lets VS Code edit files, run terminals and debug on a remote Linux server. How it works, setup step by step, SSH config and keys, extensions and port forwarding, and fixes for the common connection problems.
UUID vs Auto-Increment IDs: Which Primary Key Should You Use?
Sequential integers or UUIDs for your primary keys? The real trade-offs — size, index performance, guessability, merging data, leaking business metrics — why UUIDv7 changes the answer, Postgres 18's uuidv7(), and the common hybrid of internal IDs plus public IDs.
Structured Output From LLMs: Getting Reliable JSON Every Time
How to get a language model to return JSON your code can trust: why "respond in JSON" isn't enough, schema-constrained structured outputs with Claude and Zod, strict tool use, validation, handling refusals and truncation, and designing schemas models fill well.
SSH Port Forwarding Explained: Local, Remote, and Dynamic Tunnels
SSH tunnels let you reach a database or web app on a server as if it were on localhost — without opening ports to the internet. Local (-L), remote (-R) and dynamic (-D) forwarding with practical examples, background tunnels, and the security caveats.