Intermediate guides.
For people who already ship. Claude Code workflows, deploys without downtime, Postgres in production, and the operational details that start to matter.
106 posts · page 2 of 4
The SSH Config File Explained: Stop Typing Long SSH Commands
~/.ssh/config turns ssh -i ~/.ssh/key -p 2222 deploy@203.0.113.10 into ssh prod. Where the file lives on each OS, the options worth knowing, multiple GitHub accounts, jump hosts, keep-alives, and the precedence rule that trips people up.
Is SQLite Good Enough for Production? When It Works and When It Doesn't
SQLite now runs real production apps. When a single-file database is a great choice, the settings you must change (WAL mode, busy timeout, foreign keys), backups with Litestream, the single-writer limit, and the hosting setups where SQLite will lose your data.
Spec-Driven Development With Claude Code: Write the Spec, Then Let the Agent Build
Spec-driven development means agreeing on a written specification before an AI agent writes code. What a good spec contains, a practical workflow with Claude Code (spec → plan → tasks → implement → verify), templates, and when it's overkill.
Session Cookies vs JWTs: Which Should Your App Use for Authentication?
Server-side sessions and JWTs both keep users logged in, with very different trade-offs. How each works, revocation and logout, where to store tokens (cookies vs localStorage), the hybrid access/refresh pattern, and a clear default for web apps.
Server-Sent Events vs WebSockets: Which for Real-Time Features and AI Streaming?
SSE streams updates from server to browser over plain HTTP; WebSockets open a two-way channel. How each works, code for both, why AI chat responses use SSE-style streaming, proxy buffering and connection-limit gotchas, and a decision guide including plain polling.
HTTP Security Headers Explained: HSTS, CSP, and the Rest (With a Copy-Paste Setup)
A practical guide to the HTTP security headers worth setting: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy and Permissions-Policy — what each prevents, safe values, a Next.js and Nginx config, and which old headers to drop.
Role-Based Access Control (RBAC) for Your App: A Practical Guide
How to add roles and permissions to a web app without making a mess: roles vs permissions, a simple database schema, checking permissions on the server, multi-tenant roles per organisation, enforcing in the UI and the API, and testing it.
How to Reduce Docker Image Size: From 1.5 GB to Under 200 MB
Big Docker images are slow to build, push, pull and deploy. The techniques that actually shrink them: slim base images, multi-stage builds, .dockerignore, production-only dependencies, layer ordering, cache cleanup — with Node.js and Python examples and a way to see what's taking space.
PM2 vs systemd: How to Keep a Node.js App Running on a Server
When you run node app.js over SSH and log out, your app dies. How PM2 and systemd keep it running, restart it after crashes and reboots, handle logs and environment variables — with working configs for both, and where Docker fits.
pgvector Tutorial: Vector Search in Postgres for RAG and Semantic Search
Add semantic search and RAG to your app without a separate vector database. A hands-on pgvector guide: install the extension, store embeddings, query by cosine distance, add HNSW indexes, filter results correctly, choose dimensions and halfvec, and know when you've outgrown it.
Password Reset and Email Verification Flows Done Right
Password resets are one of the most attacked parts of any app. How to build reset and email-verification flows securely: token generation and hashing, expiry, account enumeration, host header poisoning, invalidating sessions, and the UX details that reduce support tickets.
Health Check Endpoints: What /health Should (and Shouldn't) Check
A health check endpoint tells load balancers, orchestrators and monitors whether your app can serve traffic. Liveness vs readiness, what to check and what not to, response formats, timeouts, security, and examples for Express, Next.js and Docker.
Git Rebase vs Merge: What's the Difference and When to Use Each
Merge and rebase both bring changes from one branch into another, but they shape history differently. How each works, fast-forward and squash merges, interactive rebase, the golden rule of rebasing, resolving conflicts during a rebase, and a sensible team policy.
Codespaces vs Coder vs Ona: Cloud Development Environments Compared (2026)
An honest comparison of the main cloud development environments in 2026 — GitHub Codespaces, Coder, Ona (formerly Gitpod) and DevPod-style tools — by who runs them, pricing model, environment definition, persistence, and what each is actually for.
Claude Code GitHub Actions: Set Up @claude on Issues and Pull Requests
How to set up the Claude Code GitHub Action so you can mention @claude on issues and PRs: quick setup with /install-github-app, manual setup, API key vs subscription token, interactive vs automation mode, scheduled runs, cost controls, and security.
Claude Code /compact vs /clear: Managing Context Without Losing Your Place
When to compact, when to clear, and when to let auto-compaction handle it. What /compact actually does, custom compaction instructions, the auto-compact window and /autocompact, why compacting a huge session is itself expensive, and a workflow that keeps sessions sharp.
Zero-Downtime Deploys for a Small App
You don't need Kubernetes to deploy without dropping requests. What actually causes downtime during a deploy — stopping before starting, no health checks, killed requests, and database changes the old code can't handle — and the four practices that fix each one.
Getting AI to Write Tests That Actually Catch Bugs
Ask an AI for tests and you'll get plenty: tests that mock everything, assert nothing useful, and pass no matter what the code does. How to get tests that fail when behaviour breaks — what to test, how to prompt, how to check a test is real, and how tests become the agent's safety net.
What Is a Dev Container? devcontainer.json Explained
A dev container defines your development environment as code — the tools, versions, services, and settings a project needs — so it runs the same on every machine and in the cloud. What goes in devcontainer.json, how it differs from a Dockerfile, and where it falls short.
Agent Hosting Is Becoming Free. Here's What Isn't.
Anthropic now ships ways to keep Claude Code running without your laptop — Remote Control, cloud sessions, scheduled Routines. That's good news, and it changes what's worth paying for. The session is becoming a commodity. The environment the work ships into is not.
VPS vs PaaS: Where Should a Small App Live?
A VPS is cheap and does whatever you tell it — including nothing when it breaks. A PaaS runs your app for you and bills you for the privilege, often by usage. What each one actually includes, what it quietly leaves to you, and how to decide for a side project, an AI-built app, or a small business.
Validating Input With Zod: One Schema for Forms, APIs, and Types
Every trust boundary — request bodies, query strings, webhooks, environment variables, AI output — needs runtime validation TypeScript can't provide. Using Zod schemas at each boundary, sharing them between client and server, stripping unknown keys, and useful errors.
Why TypeScript Makes AI-Generated Code Safer
Types turn a whole class of AI mistakes — invented properties, wrong arguments, forgotten null checks — into errors caught before the code runs. How TypeScript acts as a feedback loop for agents, the settings that matter, and the escape hatches AI uses to switch it off.
A tmux Cheat Sheet for Long-Running Sessions (and AI Agents)
tmux keeps terminal sessions running after you disconnect — which is exactly what you want for a build, a dev server, or an AI agent working on a remote machine. The twenty commands that cover almost everything, a small config that makes it pleasant, and the habits for running agents inside it.