Infrastructure
What sits under an app: servers, containers, storage, backups, and the plumbing that decides whether it stays up.
81 posts · page 1 of 3
What Is Object Storage? S3, Buckets, and Where Your Files Should Live
Object storage keeps files as objects in buckets, reachable over HTTP — Amazon S3 is the original, and dozens of services speak the same API. How it differs from a hard disk, what buckets, keys and presigned URLs are, what it costs, and when your app needs it.
What Is Nginx? The Web Server in Front of Half the Internet
Nginx ("engine-x") is a web server that serves files, forwards requests to your app, handles HTTPS and balances load. What it does, what a basic config looks like, where the files live, the commands you'll need, and whether you need it at all.
What Is eBPF? Safe Programs Inside the Linux Kernel, Explained
eBPF lets you run small, verified programs inside the Linux kernel at hook points — syscalls, network packets, function entry — without kernel modules. How it works (verifier, JIT, maps, hooks), what it powers, bpftrace one-liners, and its limits and security implications.
What Is a Load Balancer? Spreading Traffic Across Servers
A load balancer sits in front of several copies of your app and spreads requests between them, skipping any that are unhealthy. How it works, the common algorithms, sticky sessions, health checks, and why a small app probably doesn't need one yet.
UFW Firewall Basics: Lock Down a Linux Server in Five Commands
A firewall decides which network traffic can reach your server. UFW makes Linux's firewall simple: allow SSH, HTTP and HTTPS, deny the rest. The commands, how not to lock yourself out, why your database port should never be open, and the Docker gotcha that bypasses UFW.
The TLS 1.3 Handshake Explained: What Happens Before the First Byte
What actually happens when a browser connects over HTTPS: ClientHello, key shares, the server's certificate and signature, Finished messages, one round trip instead of two, 0-RTT resumption and its replay risk, SNI and ECH, certificate chain validation, and how to inspect it all with openssl.
How to Secure a New VPS: The First 30 Minutes
A fresh server is scanned within minutes of going online. The essential hardening steps for a new Ubuntu VPS: updates, a non-root user, SSH keys only, firewall, automatic security patches, fail2ban, safe service binding, backups and monitoring — in order, with commands.
Postgres Read Replicas: Streaming Replication, Lag, and Read-Your-Writes
How Postgres physical streaming replication works, sync vs async, measuring replication lag, query conflicts and hot_standby_feedback, routing reads in your app without breaking read-your-writes, replication slots that fill disks, and when a replica is the wrong fix.
PID 1 in Containers: Signals, Zombies, and Why Your Container Won't Stop
Inside a container your app is PID 1, and PID 1 is special: the kernel won't apply default signal handlers to it and it must reap orphaned children. Why docker stop takes 10 seconds, why shell-form CMD swallows SIGTERM, zombies, and the fixes: exec form, tini/--init, signal handling.
"No Space Left on Device": Finding and Freeing Disk Space on a Server
When a server's disk fills up, databases stop writing, deploys fail and apps crash with ENOSPC. How to find what's using space with df and du, the usual culprits (logs, Docker, journald, old releases, deleted-but-open files), inode exhaustion, and how to stop it happening again.
Message Queues Explained: When You Need One and Which to Use
A message queue lets one part of your system hand work to another without waiting. Queues vs pub/sub vs event streams, delivery guarantees, dead-letter queues, and an honest comparison of Postgres, Redis, RabbitMQ, SQS and Kafka for a small team.
Linux Namespaces Explained: The Kernel Feature Containers Are Made Of
A container is a process with its own namespaces. What each of the eight Linux namespaces isolates — mount, PID, network, UTS, IPC, user, cgroup, time — how to build a container-like process by hand with unshare, inspect one with nsenter and /proc, and what namespaces do not protect against.
HTTP/1.1 vs HTTP/2 vs HTTP/3: What Changed and Whether You Should Care
HTTP/2 multiplexed requests over one TCP connection; HTTP/3 moved to QUIC over UDP to escape TCP's head-of-line blocking and speed up handshakes. How each works, what they fix, what they break, how browsers discover HTTP/3, and what to actually configure for your app.
Docker Image Layers and OverlayFS: How Container Filesystems Really Work
A Docker image is a stack of read-only layers merged by OverlayFS, with a thin writable layer per container. How layers are built and cached, content addressing and digests, copy-up and whiteouts, why deleting files doesn't shrink images, and the performance traps for databases.
How to Deploy a Node.js App to a VPS, Step by Step
From an empty Ubuntu server to your Node.js app running on your own domain with HTTPS: create a user, install Node, clone and build, keep it running with PM2 or systemd, put Caddy or Nginx in front, and set up redeploys.
How to Deploy a FastAPI App to Production
Running uvicorn main:app --reload is for development. A production FastAPI deploy needs worker processes, a process manager or container, a reverse proxy with HTTPS, proper settings, migrations, and health checks. Step-by-step options for a VPS and Docker.
What Is Linux? A Beginner's Guide for People Building Apps
Linux runs most of the world's servers — including, probably, the one your app will live on. What Linux is, kernels vs distributions, Ubuntu vs Debian vs Alpine, how it differs from Windows and macOS, and the handful of Linux facts that prevent deploy bugs.
What Is Latency? Why Distance Makes Your App Feel Slow
Latency is the delay before data arrives; bandwidth is how much can arrive at once. What latency is, why physical distance sets a floor on it, why round trips multiply it, latency vs bandwidth vs throughput, and practical ways to make an app feel faster for faraway users.
What Is a VPS? Virtual Private Servers Explained for Beginners
A VPS is your own slice of a physical server, with its own operating system and full control. What a VPS is, how it compares with shared hosting, PaaS and dedicated servers, what you're responsible for when you run one, and when a managed server is the better fit.
What Is a DDoS Attack? A Plain-English Guide for Website Owners
A DDoS attack floods a website with traffic until real visitors can't get through. How DDoS attacks work, the main types, how likely a small site is to be hit, what DDoS protection actually does, and the cheap steps that protect a small app.
SSH Port Forwarding Explained: Local, Remote, and Dynamic Tunnels
SSH tunnels let you reach a database or web app on a server as if it were on localhost — without opening ports to the internet. Local (-L), remote (-R) and dynamic (-D) forwarding with practical examples, background tunnels, and the security caveats.
The SSH Config File Explained: Stop Typing Long SSH Commands
~/.ssh/config turns ssh -i ~/.ssh/key -p 2222 deploy@203.0.113.10 into ssh prod. Where the file lives on each OS, the options worth knowing, multiple GitHub accounts, jump hosts, keep-alives, and the precedence rule that trips people up.
How to Reduce Docker Image Size: From 1.5 GB to Under 200 MB
Big Docker images are slow to build, push, pull and deploy. The techniques that actually shrink them: slim base images, multi-stage builds, .dockerignore, production-only dependencies, layer ordering, cache cleanup — with Node.js and Python examples and a way to see what's taking space.
Postgres VACUUM and Table Bloat: How It Works and How to Keep It Under Control
Why Postgres tables bloat, what VACUUM and autovacuum actually do, tuning autovacuum for large tables, what blocks cleanup (long transactions, replication slots), transaction ID wraparound, and how to reclaim space without VACUUM FULL's exclusive lock.