Architecture
How the pieces of an app fit together — frontends and backends, APIs, databases, queues and caches — and how to choose between designs.
84 posts · page 2 of 4
Structured Output From LLMs: Getting Reliable JSON Every Time
How to get a language model to return JSON your code can trust: why "respond in JSON" isn't enough, schema-constrained structured outputs with Claude and Zod, strict tool use, validation, handling refusals and truncation, and designing schemas models fill well.
Is SQLite Good Enough for Production? When It Works and When It Doesn't
SQLite now runs real production apps. When a single-file database is a great choice, the settings you must change (WAL mode, busy timeout, foreign keys), backups with Litestream, the single-writer limit, and the hosting setups where SQLite will lose your data.
Session Cookies vs JWTs: Which Should Your App Use for Authentication?
Server-side sessions and JWTs both keep users logged in, with very different trade-offs. How each works, revocation and logout, where to store tokens (cookies vs localStorage), the hybrid access/refresh pattern, and a clear default for web apps.
Server-Sent Events vs WebSockets: Which for Real-Time Features and AI Streaming?
SSE streams updates from server to browser over plain HTTP; WebSockets open a two-way channel. How each works, code for both, why AI chat responses use SSE-style streaming, proxy buffering and connection-limit gotchas, and a decision guide including plain polling.
Role-Based Access Control (RBAC) for Your App: A Practical Guide
How to add roles and permissions to a web app without making a mess: roles vs permissions, a simple database schema, checking permissions on the server, multi-tenant roles per organisation, enforcing in the UI and the API, and testing it.
Python vs JavaScript: Which Should a Beginner Choose?
Python and JavaScript are the two most popular first languages. How they differ in what they're for, how they look, speed, jobs and AI support — and a simple way to choose based on what you actually want to build.
Postgres Table Partitioning: When It Helps, When It Hurts, and How to Do It
Declarative partitioning in PostgreSQL: range, list and hash partitions, partition pruning, primary key and unique constraint rules, dropping old data instantly, automating new partitions, converting an existing table, and the cases where partitioning makes things slower.
Postgres Advisory Locks: Distributed Locking Without Redis
Advisory locks let your application lock arbitrary things — a job, a customer, a migration — using Postgres. Session vs transaction locks, blocking vs try-locks, turning strings into lock keys, the connection-pooler trap, and patterns for singleton cron jobs and per-entity mutexes.
Password Reset and Email Verification Flows Done Right
Password resets are one of the most attacked parts of any app. How to build reset and email-verification flows securely: token generation and hashing, expiry, account enumeration, host header poisoning, invalidating sessions, and the UX details that reduce support tickets.
Magic Link Login: How Passwordless Email Sign-In Works (and Its Pitfalls)
Magic links let people log in by clicking a link in their email — no password. How they work, when they're a good fit, the security details that matter (expiry, single use, token hashing), and the real-world problems: spam filters, email scanners and phones vs laptops.
What Is IDOR? The Security Bug Where Users Can See Each Other's Data
IDOR (insecure direct object reference) is when changing an ID in a URL shows you someone else's data. How it happens, why it's the most common serious bug in AI-built apps, how to test for it in five minutes, and the one-line habit that prevents it.
Idempotency Keys: Making POST Requests Safe to Retry
A timeout on "create payment" — did it go through or not? Idempotency keys let clients retry safely without double-charging. How the Idempotency-Key header works, a Postgres-backed implementation, handling concurrent duplicates, fingerprint mismatches, expiry, and what to store.
Horizontal vs Vertical Scaling: How Apps Handle More Users
Vertical scaling means a bigger server; horizontal scaling means more servers. How each works, what load balancers do, why databases are the hard part, what has to change in your app to scale out, and why most small apps should scale up first.
Health Check Endpoints: What /health Should (and Shouldn't) Check
A health check endpoint tells load balancers, orchestrators and monitors whether your app can serve traffic. Liveness vs readiness, what to check and what not to, response formats, timeouts, security, and examples for Express, Next.js and Docker.
Do You Need Kubernetes? (Probably Not Yet — Here's How to Tell)
Kubernetes runs containers across many machines and is everywhere in job ads. What it actually does, what it costs to operate, the signs you might need it, and the simpler options that serve almost every small app and startup better.
What Is an API? Explained Without the Jargon
APIs are how apps talk to each other — how your app takes a payment, sends an email, or asks an AI model a question. What an API actually is, what requests and responses look like, what an API key does, and the few terms you'll keep running into.
What Is a Webhook? Explained for Beginners
A webhook is how another service tells your app that something happened — a payment went through, a form was submitted, a file finished processing. How webhooks differ from normal API calls, what you need to receive one, and the three safety rules every webhook handler must follow.
What Is a Tech Stack? How to Choose One When AI Writes the Code
Your tech stack is the set of tools your app is built from: language, framework, database, and hosting. Even if AI writes the code, the choice matters — for how well the AI performs, what it costs, and who can help you later. A beginner's guide with a safe default.
What Is a Framework? React, Next.js, and Friends Explained
React, Next.js, Vue, Svelte, Django, Laravel — the names come up constantly and blur together. What a framework is, how it differs from a library, how the popular ones relate to each other, and why AI tools keep choosing the same few.
What Are WebSockets? Real-Time Features Explained
Chat, live notifications, multiplayer cursors, and dashboards that update themselves all need the server to push data to the browser. How WebSockets work, the simpler alternatives (polling and server-sent events), hosted real-time services, and what real-time needs from your hosting.
Web App vs Mobile App: Which Should You Build First?
Should your idea be a website, an iPhone app, an Android app, or all three? The real differences in cost, distribution, app store rules, updates, and capabilities — plus progressive web apps and cross-platform tools like React Native and Flutter — and why most first products start on the web.
Validating Input With Zod: One Schema for Forms, APIs, and Types
Every trust boundary — request bodies, query strings, webhooks, environment variables, AI output — needs runtime validation TypeScript can't provide. Using Zod schemas at each boundary, sharing them between client and server, stripping unknown keys, and useful errors.
The Transactional Outbox Pattern: Reliable Events Without Dual Writes
Writing to your database and publishing an event can't be made atomic, so one eventually happens without the other. How the transactional outbox fixes it: polling relays vs CDC, ordering, at-least-once delivery, idempotent consumers with an inbox, cleanup, and monitoring.
Static vs Dynamic Websites: What's the Difference?
A static site is the same files for everyone; a dynamic site builds pages per request. What each means, where single-page apps and server rendering fit, why it matters for hosting, speed, SEO, and cost — and how to tell which one your AI tool built.