All Topics
Browse 178 articles by topic — 23 tags across five series.
Advanced 2 articles
AI Security 9 articles
Why AI Systems Break Differently
An AI-powered application is still software — and everything you learned in Phases 0–5 still applies to it. But AI introduces something genuinely new: the…
Security · 56The OWASP Top 10 for LLM Applications
When the AI security field was new, every team faced LLM risks alone, with no shared vocabulary. Just as the classic OWASP Top 10 (2.3) gave web security a…
Security · 57Prompt Injection and Jailbreaking
Prompt injection is the defining vulnerability of the LLM era — and it is, at its heart, the exact same flaw as the SQL injection you learned in 2.4…
Security · 58Data Poisoning, Model Theft, and Training-Time Attacks
Prompt injection (6.3) attacks an AI system through its running input. But an AI system has two more things that traditional software does not — the data it…
Security · 59Securing LLM Applications and AI Agents
This is the defensive heart of Phase 6 — the page that answers “so how do I actually build an AI feature safely?” The honest situation: most teams shipping…
Security · 60Sensitive Data, Privacy, and the AI Supply Chain
AI systems have a complicated relationship with data — they are trained on it, they process it, they hold it in context, and they can leak it in ways…
Security · 61AI as a Security Tool
Part A treated AI as something to secure. This page treats AI as something to use — a tool in a security practitioner’s hands. AI genuinely helps with real…
Security · 62The AI-Augmented Security Workflow
Page 6.7 established the principle: AI is a useful tool that must be verified. This page is the practice — how to actually integrate AI into real security…
Security · 63The Threat Landscape of AI-Powered Attacks
Every tool that helps defenders helps attackers. You have learned to use AI for security work (6.7, 6.8) — and attackers are using it too. AI does not, for…
Architecture 18 articles
Middleware
The code that runs around every request. The onion model, why order is everything, short-circuiting, and the error-handling middleware everyone forgets.
Backend · 08Request Context
How to share request-scoped data down the call tree without threading it through every function signature — and how not to make a mess of it.
Backend · 09Handlers, Controllers & Services
The layered architecture every backend converges on — what belongs in each layer, why the separation pays off, and when the layers are overkill.
Backend · 11RESTful API Design
Where REST came from. Idempotency. Pagination. Response shape standards. HATEOAS.
Backend · 28Monolith vs Microservices
When to split a system, the modular monolith middle ground, and the distributed monolith trap.
Backend · 33API Gateway, Reverse Proxy & BFF
What sits in front of your services. Nginx, load balancers, the BFF pattern — the edge of your system.
Backend · 34Beyond REST — gRPC & GraphQL
Two alternatives to REST and when each one earns its place. Same problem, different trade-offs.
Backend · 38Multi-Tenancy
Building SaaS that serves many customers from one system — without leaking their data into each other.
Java · 05Classes and Objects
The blueprint and the thing built from it. Constructors, fields, methods, the static keyword, and what `new` actually does at the JVM level.
Java · 06The Four Pillars of OOP
Encapsulation, inheritance, polymorphism, abstraction — but with real examples, not the textbook version everyone has to memorise then forget.
Java · 07Abstract Classes vs Interfaces
The most-asked Java interview question. The real differences, when to pick each, and how default methods in Java 8+ blurred the lines.
Java · 09Access Modifiers and Packages
public, protected, private, and the package-private one nobody knows the name of. What each does, when to use them, and how packages organise the chaos.
Java · 11Generics and Type Erasure
How generics actually work — at compile time, anyway. Type erasure, bounded types, wildcards, and the weird things they enable and forbid.
Java · 15Inner Classes and Anonymous Classes
Classes inside classes. Static nested, inner, local, anonymous, lambdas — the spectrum from explicit to invisible, and when each is the right tool.
HLD · 04Load Balancers, CDNs & API Gateways
Load balancing, DNS and CDNs, API gateways, HTTP/1.1/2/3, WebSockets, service discovery, service mesh — the plumbing that connects every service.
HLD · 06Microservices, Circuit Breakers & Rate Limiting
Microservices vs monolith, circuit breaker, rate limiting, retry and backoff, saga, API patterns, bulkhead and timeout — the named patterns that recur in every real system.
HLD · 08Design a URL Shortener, Newsfeed & Chat
URL shortener, rate limiter, newsfeed, chat, file upload, ride-sharing, video streaming, payments, distributed ID generator — the canonical interview designs done seriously.
HLD · 09Design a Web Crawler, Autocomplete & Task Queue
Task queues, idempotency in depth, web crawler, search autocomplete, hotel/seat reservation, top-K — the topics that didn't fit cleanly into the main modules.
Async 3 articles
Task Queues & Background Jobs
Why some work doesn't belong in the request cycle. Retries, DLQs, idempotency.
Backend · 29Event-Driven Architecture
Events vs commands, pub/sub patterns, Kafka, event sourcing — decoupling services with messages.
HLD · 05Message Queues, Kafka & Event-Driven Design
Message queues, Kafka, pub/sub, notification design, stream processing, event sourcing and CQRS — the asynchronous backbone of large systems.
Career 5 articles
Building a Security Portfolio
Nobody can see the knowledge in your head. Employers and clients do not hire claims — they hire proof. A security portfolio is that proof: a visible…
Security · 65Certifications: Which Ones, and When
Certifications are doors, not destinations. They can get your résumé past automated filters, satisfy hard requirements, and signal validated knowledge to…
Security · 66Breaking Into a Security Job
Switching careers into security is not done by sending out applications and hoping — it is done with a deliberate strategy. And the centerpiece of that…
Security · 67Freelancing: Bug Bounty and Independent Security Work
Security work can be done independently, not only as an employee — and freelance security income is real. But it is also uneven, widely misunderstood, and…
Security · 68Staying Current and Going Further
Security is not a body of knowledge you finish — it is a field that never stops moving. Threats evolve, technologies change, new vulnerability classes…
CI/CD 4 articles
Continuous Integration
Automated testing on every change. The shortest feedback loop in software engineering.
DevOps · 07Continuous Delivery & Deployment
From green build to running in production. Pipelines, environments, and the difference between delivery and deployment.
DevOps · 08GitHub Actions in Depth
Workflows, matrix builds, reusable actions, OIDC, and the patterns that scale to large orgs.
DevOps · 09Build Optimization
Caching, parallelism, monorepo strategies. How to keep CI under 5 minutes as your codebase grows.
Cloud 10 articles
Cloud Computing Models
IaaS, PaaS, SaaS, serverless. Why the cloud changed everything and what it actually offers.
DevOps · 17AWS Core Services
EC2, S3, RDS, Lambda, IAM — the building blocks behind most modern infrastructure.
DevOps · 18GCP Core Services
Compute Engine, GCS, Cloud SQL, Cloud Run, IAM — Google Cloud essentials and how it differs from AWS.
DevOps · 19Cloud Networking
VPCs, peering, transit gateways, private connectivity — the network plumbing that ties cloud workloads together.
DevOps · 37On-Prem vs Cloud: What Self-Managed Infrastructure Actually Demands
On-prem is not "cloud, but in my room". A long list of things a provider used to handle silently becomes your job the moment you own the hardware…
Security · 50Cloud Security Fundamentals
The cloud did not just move servers somewhere else — it changed the fundamental rules of how systems are built, accessed, and secured. Concepts from earlier…
Security · 51Common Cloud Misconfigurations
Cloud breaches are rarely the result of a clever attack on the cloud provider’s infrastructure. Overwhelmingly, they are the result of the customer…
Security · 52Container and Kubernetes Security
Modern cloud applications are overwhelmingly packaged in containers and run at scale by orchestration platforms like Kubernetes. This is the technology of…
Security · 53Infrastructure as Code Security
Because cloud infrastructure is software-defined, it can be defined as code — written, reviewed, versioned, and deployed like any other code. This is one of…
Security · 54DevSecOps Pipelines
Modern software is built and shipped through automated pipelines — a continuous flow from code change to deployed application. DevSecOps means weaving…
Containers 4 articles
Docker — Containers from First Principles
Images, layers, networking, multi-stage builds. The technology that made 'works on my machine' obsolete.
DevOps · 11Container Image Security
Vulnerabilities, supply chain attacks, image signing — keeping your containers from becoming the entry point.
DevOps · 12Docker Compose for Local Development
Define your whole stack in one file. The fastest way to onboard new engineers.
DevOps · 41Running a Private Docker Registry On-Prem
A self-managed system that pulls every image from someone else's registry is not self-managed. The registry is the last external dependency in the…
Data 9 articles
Serialization & Deserialization
JSON vs Protobuf. Schema validation. The gotchas that bite in production.
Backend · 06Validation & Transformation
Type, semantic, and syntactic validation. Actionable error messages. Trust nothing.
Backend · 10Databases
ACID, B-trees, MVCC, query execution stages. NoSQL families. The database fundamentals.
Backend · 30File Uploads & Object Storage
S3, presigned URLs, multipart uploads — handling files without your server becoming the bottleneck.
Backend · 35Database Replication & Sharding
How databases scale beyond one machine. Read replicas, leader/follower, sharding, and the trade-offs.
Java · 04Strings Deep Dive
Why == lies. The String Pool. StringBuilder vs StringBuffer vs string concatenation in a loop. The 1000-object trap.
Java · 12Collections Framework
List, Set, Map, Queue — the interfaces and the implementations. When to pick which. How HashMap actually works inside.
Java · 14Enums
Type-safe constants. Methods on enum values. The trick of using an enum as a singleton. Java's enum is more powerful than most people realise.
HLD · 02SQL vs NoSQL, Sharding & Replication
SQL vs NoSQL, indexing, sharding, replication, object storage, NewSQL — picking the right storage for each part of a real system.
Defensive Security 14 articles
Secure Coding I: Defending Against Injection and XSS
You learned to exploit injection and XSS in Phases 2.4 and 2.5. Now you become the person who makes them impossible. Here is the most important realization…
Security · 32Secure Coding II: Authentication, Access Control, and Secrets
The bugs in 2.6, 2.7, and 2.8 — broken authentication, broken access control, request forgery — are different in nature from injection. They are not “data…
Security · 33Secure Design and Defense in Depth
Secure coding (4.1, 4.2) fixes how individual pieces are built. But a system can be made of perfectly secure pieces and still be insecure as a whole …
Security · 34Hardening Systems and Networks
Secure design (4.3) decided the architecture; hardening is the hands-on work of making real systems resistant to attack. It is the direct, practical answer…
Security · 35Blue Team Operations and the SOC
Building secure systems (4.1–4.4) is essential, but not the whole of defense. Because no defense is perfect and breach must be assumed, someone has to watch…
Security · 36Logging, Monitoring, and Detection
An attack you cannot see is an attack you cannot stop. Page 4.5 established that defenders must watch continuously; this page is the how. Detection rests on…
Security · 37Incident Response and Digital Forensics Basics
Detection (4.6) tells you an attack is underway. What happens next — in the minutes and hours after — often determines whether it is a minor event or a…
Security · 38Vulnerability Management and Security Operations
Across Phases 2 and 3 you saw that attackers overwhelmingly exploit known weaknesses — known vulnerabilities, known misconfigurations, missing patches. The…
Security · 39Defensive Walkthrough: Securing an Application End to End
Defense, like offense, must be practiced as a complete exercise — not a checklist of separate techniques. Page 2.11 had you run a full attack on an…
Security · 45The Secure Development Lifecycle
Security cannot be a final inspection bolted onto finished software — by then, flaws are baked into the design and expensive (or impossible) to remove…
Security · 46Code Review for Security
A penetration tester (Phases 2–3) attacks software from the outside, seeing only its behavior. A security code reviewer reads the source itself — and sees…
Security · 47Security Testing Automation
Manual security work — code review, pentesting, threat modeling — is essential but does not scale: it cannot run on every code change, every day, across a…
Security · 48Threat Modeling in Practice
You learned threat modeling back in Phase 1.2 as a way of thinking like an attacker. This page takes it from a personal skill to a practiced, repeatable team…
Security · 49Working with Developers
Every technical practice in Track B — secure coding standards, code review, automated testing, threat modeling — succeeds or fails on one thing: whether…
Foundation 23 articles
What is a Backend?
The mental model. HTTP request loop. Why first principles beat framework knowledge.
Backend · 02HTTP Protocol
Anatomy of requests, methods, status codes, and the headers you must know.
Backend · 03Routing
How a URL becomes a function call. Path matching, parameters, route ordering, and the bugs that come from getting the order wrong.
Backend · 25How a Request Travels the Network
DNS, packets, TCP handshake — what actually happens between typing a URL and seeing a response.
Backend · 27Distributed Systems & CAP
The 8 fallacies, CAP theorem, eventual consistency — what changes when you add a second computer.
Backend · 32Money, Time & Identity
Cents, UTC, UUIDs — the three things that bite every backend engineer eventually.
Backend · 39Internationalization (i18n) & Localization
Building software that works in every language, region, and writing system — from day one.
DevOps · 01What is DevOps, Really?
Beyond the buzzwords. The cultural shift that turned operations from a separate team into shared responsibility.
DevOps · 02Linux Fundamentals for DevOps
The terminal, processes, permissions, and signals — every cloud server you'll ever touch runs on this.
DevOps · 03Networking Essentials
IPs, ports, DNS, VPCs, firewalls — the network primitives every cloud engineer needs in their bones.
DevOps · 04Shell Scripting & Automation
Bash scripting from variables to traps. The glue that holds DevOps automation together.
Java · 01What Java Actually Is (And Why It Survived)
Origin, evolution, and the real reason Java is still everywhere in 2026 — even after every other language tried to kill it.
Java · 02The JVM, JRE, JDK — What's Actually Happening
From .java to running bytes. Class loaders, runtime memory areas, JIT, and the garbage collector — the whole machine demystified.
Java · 03Variables, Primitives, and the Memory Model
Stack vs heap. Primitives vs references. Autoboxing traps. The memory model that shapes every line of Java you'll write.
Java · 08The Object Class — equals, hashCode, toString
Every Java class secretly inherits from Object. These three methods determine whether your objects work correctly in collections, comparisons, and logs.
Java · 13Control Flow and Operators
if, while, for, switch — plus the modern switch expression and pattern matching. Operators and the precedence rules nobody memorises.
HLD · 01System Design Foundations
CAP, ACID vs BASE, latency numbers, back-of-envelope estimation, single points of failure — the vocabulary every system designer thinks in.
Security · 01How the Internet Moves Data
The internet is not magic and it is not one thing. It is millions of computers passing small envelopes of data to each other, following a few simple rules…
Security · 02The Linux Command Line for Security Work
Security work happens in a terminal. Not because terminals are cool, but because security tools need precision, automation, and the ability to be chained…
Security · 03HTTP, HTTPS, and How the Web Really Works
A huge share of all security work — employed or freelance — is finding and fixing bugs in web applications. Web apps are everywhere, they’re exposed to the…
Security · 04Networking Deeper: Services, Protocols, and the Attack Surface
A computer connected to a network is not one target — it is a collection of doors, each one a service listening on a port. Both attacking and defending begin…
Security · 05Setting Up Your Security Lab
You cannot learn to attack systems by attacking real ones — that is a crime, full stop. You also cannot learn by only reading. The answer, used by every…
Security · 06Programming for Security: Python & Scripting Basics
Pre-built tools handle the common 80% of security work. The remaining 20% — the custom, the unusual, the specific-to-this-target — is where real skill shows…
IaC 3 articles
Terraform — Infrastructure as Code
Declarative infrastructure. Providers, state, modules — and why your cloud should be defined by code review.
DevOps · 21Pulumi & CDK — Code-First IaC
When real programming languages beat Terraform's HCL. Tradeoffs, when to use each.
DevOps · 22Configuration Management — Ansible
Configuring servers idempotently. When and why you still need this in a containerized world.
Integration 3 articles
Webhooks & OpenAPI
Two halves of integration done right — webhooks for letting your API push events to others, and OpenAPI for describing your API so others can consume it without guesswork.
Backend · 36Notifications — Email, SMS & Push
Sending messages reliably at scale. Provider patterns, deliverability, unsubscribes, async always.
Backend · 37Payments & Financial Systems
Stripe-style integrations done safely. Webhooks, idempotency, reconciliation — and never storing card numbers.
Modern Practices 6 articles
GitOps with ArgoCD & Flux
Git as the source of truth for infrastructure. Continuous reconciliation, audit trails, declarative everything.
DevOps · 35Platform Engineering
Building internal developer platforms — golden paths, self-service, and the team that scales engineering.
DevOps · 36Edge Computing & CDNs
Cloudflare, edge functions, and pushing compute close to users. The new layer in the stack.
Java · 16Lambdas and Functional Interfaces
The Java 8 feature that changed everything. Method references, the standard functional interfaces, and the patterns that replaced 80% of inner-class boilerplate.
Java · 17Streams API
Filter, map, reduce — Java's functional pipeline for collections. When streams are clearer than loops, and when they aren't.
Java · 20Modern Java: Records, Sealed Classes, Pattern Matching
What's new in Java 16-21. The features that made the language feel current again. Records, sealed types, pattern matching, var, text blocks.
Observability 5 articles
Monitoring with Prometheus & Grafana
Metrics that matter, dashboards that don't lie, and alerts that fire when (and only when) things break.
DevOps · 24Logging at Scale
Structured logs, ELK, Loki, and the discipline of logging things you'll actually want at 3 AM.
DevOps · 25Distributed Tracing
OpenTelemetry, Jaeger, Tempo — seeing how a single request flows across many services.
DevOps · 26SRE Principles
SLIs, SLOs, error budgets — Google's framework for reliability without sacrificing velocity.
HLD · 10SLOs, Observability & API Security
SLOs and error budgets, the three pillars of observability, chaos engineering, disaster recovery, AuthN/AuthZ, API security — the operational concerns every system must address.
Offensive Security 23 articles
Reconnaissance: Information Gathering
Attacks are won or lost before a single exploit is fired. Reconnaissance — methodically learning everything about a target — is what separates someone who…
Security · 14Burp Suite and the Web Hacker’s Toolkit
A browser shows you what a web app wants you to see. To attack or test an app you need to see — and change — what’s actually being sent on the wire, before…
Security · 15The OWASP Top 10: The Industry’s Shared Map
Web applications fail in patterns. The same categories of vulnerability appear again and again, across companies, languages, and decades. The security…
Security · 16Injection: SQL Injection and Command Injection
The deepest flaw in all of software security is the confusion between data and code. When an application takes input that should be plain data and…
Security · 17Cross-Site Scripting (XSS)
Cross-Site Scripting is injection again — but the injected code is JavaScript, and the place it runs is not the server but the browser of an innocent victim…
Security · 18Broken Authentication and Session Attacks
Authentication is the front door of an application — and session handling is the key you keep using after you’ve walked in. When either is weak, an attacker…
Security · 19Broken Access Control and IDOR
Authentication proves who you are; authorization decides what you’re allowed to do. Broken access control is the failure of that second check — the…
Security · 20CSRF, SSRF, and Request Forgery
Some attacks don’t break into a system — they trick something trusted into acting on the attacker’s behalf. Request forgery is exactly this: making a request…
Security · 21Security Misconfiguration and Exposure
Not every breach is clever. A great many require no exploit at all — just an attacker who found a default password still in place, an admin panel left open…
Security · 22Vulnerable Components and the Software Supply Chain
Modern software is not written — it is assembled. Any application is a small amount of original code resting on a vast foundation of third-party libraries…
Security · 23Putting It Together: A Full Web App Pentest Walkthrough
Knowing vulnerabilities individually is not the same as assessing an application. A real penetration test is a methodology — a disciplined, repeatable…
Security · 24Network Scanning and Enumeration
Before you can attack infrastructure, you must see it — precisely. Phase 2’s recon mapped a web application; network scanning maps the machines and services…
Security · 25Common Network Service Attacks
A network service is a program that answers the network — and every one of them is a potential way in. Most service compromises are not the result of…
Security · 26Exploitation and Metasploit
An exploit is the bridge between “this system has a weakness” and “I now have access.” Page 2.10 established that vulnerabilities are often publicly…
Security · 27Privilege Escalation: Linux and Windows
Getting in is rarely getting control. A foothold almost always lands you as a low-privileged user — able to do little. Privilege escalation is the climb from…
Security · 28Active Directory Fundamentals and Attacks
Most organizations don’t run their computers as a loose collection of independent machines. They run them as a managed, interconnected whole — and on Windows…
Security · 29Wireless and Other Attack Surfaces
Attacks don’t only travel over cables and through web forms. They travel through the air, through physical doors, and through the growing crowd of connected…
Security · 30Capture The Flag: Structured Practice
Security is a skill, and skills are built by doing, repeatedly, against fresh challenges — not by reading. This page is different from every other in Phase…
Security · 40How Bug Bounty Actually Works
Bug bounty is the meeting point of three things you already have — offensive skill (Phases 2–3), the discipline of authorization (1.0), and professional…
Security · 41Advanced Web Exploitation
Phase 2 gave you the OWASP Top 10 — the most common, most critical web vulnerabilities. On a crowded bug bounty program, those obvious bugs are usually found…
Security · 42Recon at Scale
You can only find a vulnerability in something you have discovered. Page 2.1 taught reconnaissance as a methodology; this page scales it for bug bounty…
Security · 43Writing Reports That Get Paid
In bug bounty, you are not paid for finding a vulnerability. You are paid for communicating a vulnerability so clearly and convincingly that the company can…
Security · 44Building a Bug Bounty Practice
Skill finds bugs; a practice sustains a career. This final page of Track A is about the difference — turning the ability to find and report vulnerabilities…
Operations 9 articles
Logging, Monitoring & Observability
Logs, metrics, traces — the three pillars. Correlation IDs. What to alert on.
Backend · 2212-Factor App & Config Management
The methodology behind apps that deploy cleanly and scale predictably — what the twelve factors actually mean, how to manage config and secrets, and where the method stops applying.
Backend · 23DevOps for Backend Engineers
The slice of DevOps a backend engineer actually needs — containers, orchestration, and CI/CD — explained as the path your code takes from a commit to running in production.
DevOps · 30Deployment Strategies in Practice
Blue-green, canary, feature flags — picking the right strategy for the risk and the team.
DevOps · 31Incident Response
When things break: how good teams handle the first 60 minutes and the next 60 days.
DevOps · 32Disaster Recovery & Backups
RPO, RTO, restore drills — preparing for the day a region disappears.
DevOps · 33Cost Optimization (FinOps)
Cloud bills get expensive. The practices and tools to keep spend predictable and right-sized.
DevOps · 38Preparing Linux Nodes and Networking for a Bare-Metal Cluster
A Kubernetes node is a real machine with a real operating system underneath it, sitting on a network you designed. Prepare those two layers inconsistently…
Java · 19Build Tools and Project Structure
Maven, Gradle, the standard project layout. Dependency management, build lifecycles, and which tool to pick in 2026.
Orchestration 5 articles
Kubernetes Fundamentals
Pods, Deployments, Services — the mental model for the system that runs most modern infrastructure.
DevOps · 14Kubernetes in Practice
Helm, autoscaling, persistent volumes, RBAC — what you actually need to run production K8s.
DevOps · 15Service Mesh — When You Need One
Istio, Linkerd, Cilium — what they actually do, and when adding one helps vs hurts.
DevOps · 39Building a Multi-Node Kubernetes Cluster with k3s
A cluster stops being an abstraction the moment self-healing means a Pod moving between two machines you can physically touch. k3s is the shortest honest…
DevOps · 40On-Prem Kubernetes Storage, MetalLB and Ingress
Two things that "just work" on a managed cluster are the two that do not exist on-prem: something that turns a storage claim into a real disk, and something…
Performance 5 articles
Caching
Cache-aside. TTL vs event invalidation. Stampedes, poisoning, HTTP caching.
Backend · 18Scaling & Performance
Vertical vs horizontal. Load balancing. Read replicas. The optimization checklist.
Backend · 19Concurrency & Async
Why a server handles thousands of requests at once without thousands of threads — the event loop, the thread-pool model, race conditions, and when plain synchronous code is the right answer.
Java · 18Concurrency and Multithreading
Threads, the memory model, synchronization, volatile, atomics, ExecutorService, and why concurrency is the hardest topic in Java.
HLD · 03Caching Strategies, Redis & Invalidation
Why caching exists, the strategies (cache-aside, write-through, write-behind), Redis, eviction, invalidation, stampedes, and CDNs.
Quality 1 article
Reliability 5 articles
Error Handling
Operational vs programmer errors. Retries, circuit breakers, async pitfalls.
Backend · 17Graceful Shutdown
Why stopping a server is harder than starting one — the SIGTERM lifecycle, draining in-flight requests, and the deploy-time errors that graceful shutdown removes.
Backend · 31Idempotency & Distributed Patterns
Idempotency keys, sagas, the outbox pattern — making distributed work safe.
Java · 10Exception Handling
Checked vs unchecked. try/catch/finally. try-with-resources. The dogmatic rules everyone learns and the pragmatic ones senior developers actually follow.
HLD · 07Consensus, Quorums & Distributed Locks
Consensus (Raft and Paxos), distributed locks, quorum reads and writes, vector clocks and CRDTs, gossip, clock synchronisation — the primitives that hold distributed systems together.
Security 11 articles
Authentication & Authorization
Auth history. Sessions vs JWTs. SAML, OAuth, OIDC, RBAC — explained from the ground up.
Backend · 16Security
OWASP Top 10. SQL injection. Rate limiting. CORS. Secret management.
DevOps · 27DevSecOps — Shifting Security Left
Building security into every step instead of bolting it on at the end.
DevOps · 28Secrets Management
Vault, KMS, sealed secrets — keeping passwords and API keys out of Git and out of trouble.
DevOps · 29Cloud Security Posture
Least privilege, network policies, security baselines — defense in depth for cloud workloads.
Security · 07Rules of Engagement: Law, Ethics, and Authorization
Security is the one technical field where doing the exercise on the wrong target is not a bug — it is a crime. The exact same action — scanning a server…
Security · 08What Security Actually Means: CIA, Risk, and Trade-offs
“Make it secure” is a meaningless instruction until you answer three questions: secure what, against whom, and at what cost? Security is not a wall you build…
Security · 09Thinking Like an Attacker: Threat Modeling
You cannot defend everything, so you must know what is actually worth attacking — and that means deliberately thinking like an attacker. Threat modeling is…
Security · 10Cryptography for Practitioners
Cryptography is the math that makes confidentiality and integrity possible — and it is everywhere: every HTTPS connection, every stored password, every…
Security · 11Authentication, Authorization, and Identity
Two questions sit at the entrance of every application: “Who are you?” and “What are you allowed to do?” The first is authentication, the second is…
Security · 12The Security Landscape: Roles, Teams, and Where You Fit
“Cybersecurity” is not one job — it is a dozen distinct careers that happen to share a field. Trying to “learn cybersecurity” in general is like trying to…