Contents

Track:Backend EngineerData AnalystData EngineerFrontend Engineer

Backend Engineer

Every concept a backend engineer meets, in the order you actually need it.

1928 concepts, 254 of them core · jump toJuniorMid-levelSeniorStaffPrincipal

Junior

Write correct code, ship small changes safely, ask good questions.

Core: start here

Programming Basics

  • Dates and TimesTime zones, UTC, ISO 8601, and why date bugs are everywhere.
  • Floating-Point NumberA binary approximation of real numbers, and why 0.1 + 0.2 != 0.3.
  • Naming ThingsChoosing names that reveal intent; one of the hardest parts of programming.
  • Null / None / nilA value meaning "nothing here", and the source of countless crashes.
  • Time ZoneOffsets from UTC that change with location and daylight saving.

Collections

Error Handling

  • Guard ClauseReturning early on invalid cases to avoid deep nesting.
  • Stack TraceThe chain of function calls that led to an error.

Concurrency & Async

  • async / awaitSyntax for writing asynchronous code that reads like synchronous code.
  • Promise / FutureAn object representing a value that will be available later.

Version Control (Git)

  • .gitignoreFiles Git should never track, like build output and .env.
  • AmendChanging the most recent commit's content or message.
  • BranchA movable pointer to a line of commits, for isolated work.
  • CloneCopying a remote repository, with its full history, to your machine.
  • CommitA snapshot of changes with a message explaining them.
  • Commit MessageA summary line plus a body explaining why a change was made.
  • DiffSeeing exactly what changed between commits, branches or your working copy.
  • GitThe distributed version control system almost everyone uses.
  • Log and HistoryBrowsing and filtering commit history.
  • Merge ConflictTwo branches changed the same lines and Git needs you to decide.
  • RebaseReplaying commits on top of another base for a linear history.

Pull Requests & Code Review

Debugging

Testing

  • API TestingCalling endpoints and checking status codes, bodies and side effects.
  • Integration TestA test of several components working together.
  • MockA test double that verifies how it was called.
  • Regression TestA test ensuring a fixed bug doesn't come back.
  • Test CoverageThe share of code executed by tests, and why 100% isn't the goal.
  • Test Runner / Test FrameworkTools like pytest, JUnit, Jest or Vitest that find, run and report tests.
  • Unit TestA fast test of one small piece of code in isolation.

Clean Code & Principles

Refactoring

  • RefactoringChanging code's structure without changing its behavior.

Developer Tooling

  • Development Environment SetupGetting a project running locally from a fresh machine.
  • Environment VariableA key-value setting passed to processes from their environment.
  • FormatterA tool that rewrites code to a consistent style automatically.
  • LinterA tool that flags likely bugs and style issues.
  • LockfileA record of exact dependency versions so every install is identical.
  • Package ManagerA tool for installing and versioning dependencies, like npm, pip or cargo.
  • Reading DocumentationGoing to the official docs first, and knowing how to navigate them.
  • Searching EffectivelyFinding answers fast in error messages, issues, docs and forums.
  • SSHSecurely logging into and running commands on remote machines.

AI-Assisted Development

Documentation & Writing

  • MarkdownThe plain-text formatting syntax used for READMEs, docs and PRs.
  • READMEThe front page of a project: what it is, how to run it, how to contribute.

Data Structures

  • Hash TableKey-value storage with average O(1) lookup via a hash function.

Algorithms

Networking Fundamentals

  • DNSThe internet's phone book, turning names into IP addresses.
  • IP AddressA numeric address identifying a device on a network.
  • PortA number identifying a specific service on a host.

HTTP

  • HTTPThe request-response protocol of the web.
  • HTTP HeadersMetadata attached to requests and responses.
  • HTTP MethodsGET, POST, PUT, PATCH, DELETE and what each one means.
  • HTTP Status CodesThree-digit codes grouped 1xx–5xx describing the result.
  • HTTPSHTTP encrypted with TLS.
  • Path vs Query Parameters/users/42 vs /users?id=42, and when to use each.
  • URLThe address of a resource: scheme, host, path, query and fragment.

API Styles & Formats

  • EndpointA specific URL and method an API exposes, like POST /orders.
  • JSONThe text data format most APIs speak.
  • Request and Response BodyThe payload sent with a request or returned in a response, usually JSON.
  • RESTAn API style built on resources, URLs and HTTP methods.

How Browsers Work

Backend Basics

  • ConfigurationSettings that change between environments, kept out of code.
  • Environments (dev, staging, prod)Separate deployments for development, testing and real users.
  • Input ValidationChecking every input at the boundary before using it.
  • Log LevelsDEBUG, INFO, WARN and ERROR, and when to use each.
  • LoggingRecording what the application does so you can debug it later.
  • ORMMapping database tables to objects in code.
  • PaginationReturning large result sets one page at a time.
  • RoutingMapping URLs and methods to handler code.
  • TimeoutsNever waiting forever on a network call.
  • Web FrameworkLibraries like Express, Django, Spring or FastAPI for building web apps.

API Design

  • Double SubmissionA user clicking twice and creating two orders, and how to prevent it.

Relational Databases & SQL

Indexing & Query Performance

  • Database IndexA lookup structure that speeds up queries at the cost of slower writes.
  • N+1 Query ProblemOne query for a list, then one more query for every item in it.

Transactions & Concurrency Control

  • TransactionA group of operations that succeed or fail together.

Schema Migrations

Caching

  • CachingKeeping copies of data somewhere faster to avoid repeated work.

Queues & Async Processing

Authentication & Authorization

  • 401 Unauthorized vs 403 Forbidden401 means "I don't know who you are"; 403 means "I know who you are, and you can't do this."
  • Authentication vs AuthorizationAuthentication proves who you are; authorization decides what you may do.
  • Password HashingStoring a one-way, deliberately slow fingerprint of a password instead of the password itself.
  • Secrets in GitWhy passwords and keys must never be committed, and what to do when one is.
  • SessionServer-side memory of a logged-in user, referenced by a random ID the browser sends on each request.

Web Application Security

  • Cross-Site Scripting (XSS)Injecting scripts into pages other users view.
  • IDORReaching other users' data by changing an ID; a missing authorization check.
  • Never Trust the ClientAnything from the browser can be forged, so validate on the server.
  • SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.

Secure Development

Linux & Servers

Containers

  • DockerThe most common tool for building and running containers.

CI/CD & Deployment

Observability

Incidents & SRE

  • IncidentAn unplanned event that disrupts or degrades service.

Working in Production

Agile & Delivery Process

Estimation & Planning

  • Breaking Down TasksSplitting work into pieces small enough to finish and estimate.
  • EstimationPredicting how long work will take, and communicating the uncertainty.

Communication

Junior Habits & First Job

Career Growth

446 more junior concepts

Programming Basics

  • ASCIIThe original 7-bit character set that UTF-8 is backward compatible with.
  • Base CaseThe condition that stops recursion.
  • Block Scope vs Function ScopeWhether a variable lives until the end of its block or of the whole function.
  • BooleanA true/false value.
  • Boolean Flag ArgumentsPassing true/false to switch a function's behavior, and why it hurts readability.
  • Character EncodingHow characters map to bytes: ASCII, UTF-8, UTF-16.
  • Code CommentText for humans in code, best used to explain why rather than what.
  • Conditional (if/else)Running different code depending on a condition.
  • ConstantA name bound to a value that cannot be reassigned.
  • Control FlowThe order in which statements execute: branches, loops, returns.
  • Data TypeThe kind of value something is, which determines what operations are valid on it.
  • Default ParameterA parameter value used when the caller omits it.
  • Expression vs StatementAn expression produces a value; a statement performs an action.
  • FunctionA named, reusable block of code that takes inputs and returns an output.
  • Global VariableA variable visible everywhere, and why it makes code hard to reason about.
  • IntegerA whole-number type, usually with a fixed size and range.
  • ISO 8601The standard text format for dates and times, like 2026-10-10T09:00:00Z.
  • IterationStepping through the items of a collection one at a time.
  • LoopRepeating code with for, while, do-while or for-each.
  • Magic NumberAn unexplained literal in code that should be a named constant.
  • Off-by-One ErrorA loop or index that runs one step too many or too few.
  • OperatorA symbol that performs an operation on values, like +, == or &&.
  • Operator PrecedenceThe rules for which operators bind first in an expression.
  • Parameter vs ArgumentParameters are in the definition; arguments are the values passed at the call.
  • Primitive TypeA built-in basic type such as integer, float, boolean or character.
  • RecursionA function solving a problem by calling itself on smaller inputs.
  • Regular ExpressionA pattern language for matching and extracting text.
  • Return ValueThe result a function hands back to its caller.
  • ScopeThe region of code where a name is visible.
  • ShadowingAn inner variable hiding an outer one with the same name.
  • Short-Circuit Evaluation&& and || stopping as soon as the result is known.
  • Stack OverflowCrashing when the call stack runs out of space, usually from runaway recursion.
  • StringA sequence of characters, usually immutable.
  • String InterpolationEmbedding values directly inside a string literal.
  • Switch / MatchChoosing between many branches based on a value.
  • Ternary OperatorA compact inline if/else expression.
  • Truthy and FalsyNon-boolean values that act as true or false in conditions.
  • Type CoercionImplicit conversion by the language, like "5" + 1 in JavaScript.
  • Type ConversionTurning a value of one type into another, explicitly or implicitly.
  • UnicodeThe universal character set, and why string length is trickier than it looks.
  • Unix TimestampSeconds since 1970-01-01 UTC; a simple, unambiguous point in time.
  • UTF-8The dominant variable-length encoding of Unicode.
  • VariableA named reference to a value stored in memory.
  • Variadic FunctionA function that accepts any number of arguments.

Collections

  • ArrayAn ordered, indexed collection of elements.
  • DestructuringUnpacking values from arrays or objects into variables.
  • Dictionary / MapA collection of key-value pairs with fast lookup by key.
  • Equality vs IdentitySame value vs same object in memory.
  • IndexingAccessing elements by position, usually starting at zero.
  • ListAn ordered collection; a dynamic array or a linked list depending on the language.
  • Map, Filter, ReduceThe three core operations for transforming collections.
  • SetAn unordered collection of unique values.
  • Shallow vs Deep CopyCopying only the top level vs copying everything nested inside.
  • SlicingTaking a sub-range of a sequence.
  • Sorting with a Key or ComparatorSorting by a custom key or comparison function.
  • Spread / Rest SyntaxExpanding or collecting elements with ... (or * and ** in Python).
  • TupleA fixed-size, ordered group of values, often of different types.

Object-Oriented Programming

Functional Programming

Error Handling

Type Systems

Concurrency & Async

  • CallbackA function passed in to be called when work finishes.
  • Callback HellDeeply nested callbacks that make async code unreadable.

Memory & Runtime

Version Control (Git)

  • Atomic CommitOne commit doing one logical thing, easy to review and revert.
  • BlameSeeing who last changed each line and in which commit.
  • Branch Naming ConventionsNames like feat/login-page that tell people what a branch is for.
  • Conventional CommitsA commit message convention like "feat:" and "fix:" that tools can parse.
  • Detached HEADChecking out a commit directly instead of a branch.
  • Force PushOverwriting remote history; use --force-with-lease and never on shared branches.
  • ForkYour own copy of someone else's repository, for contributing via pull requests.
  • Git ConfigYour name, email, aliases and defaults, at global or repository level.
  • HEADGit's pointer to the commit you currently have checked out.
  • MergeCombining the histories of two branches.
  • Push, Pull, FetchSending commits, downloading and merging, or only downloading.
  • RemoteAnother copy of the repository, usually "origin" on GitHub or GitLab.
  • RepositoryA project's files plus their complete history.
  • ResetMoving a branch pointer back, in soft, mixed or hard mode.
  • RevertCreating a new commit that undoes an earlier one.
  • SquashCombining several commits into one.
  • Staging AreaWhere you choose which changes go into the next commit.
  • StashTemporarily shelving uncommitted changes.
  • TagA named pointer to a commit, usually marking a release.
  • Version ControlTracking every change to code so you can review, revert and collaborate.

Branching & Releases

  • ChangelogA human-readable list of notable changes per release.
  • Feature BranchA short-lived branch for one change.
  • GitHub FlowBranch from main, open a PR, merge back to main.
  • HotfixAn urgent fix shipped outside the normal release cycle.
  • Protected BranchA branch that requires reviews and passing checks before merging.
  • Semantic VersioningMAJOR.MINOR.PATCH, and what each number promises about compatibility.

Pull Requests & Code Review

Debugging

Testing

Clean Code & Principles

Refactoring

Design Patterns

Developer Tooling

AI-Assisted Development

  • AI Coding AssistantTools like Copilot, Cursor or Claude Code that suggest and write code.
  • HallucinationAn AI confidently producing APIs, facts or code that don't exist.
  • Prompting for CodeGiving an AI enough context and constraints to produce useful code.
  • Vibe CodingAccepting AI code without reading it: fine for prototypes, risky in production.

Documentation & Writing

Data Structures

  • Binary TreeA tree where each node has at most two children.
  • Data StructureA way of organizing data so certain operations are efficient.
  • Dynamic ArrayAn array that grows by reallocating, with amortized O(1) appends.
  • Hash FunctionA function mapping data of any size to a fixed-size value.
  • Linked ListNodes pointing to the next node: fast inserts, slow random access.
  • QueueA first-in, first-out collection.
  • StackA last-in, first-out collection.
  • TreeA hierarchy of nodes with one root and no cycles.

Algorithms

Math for Programmers

Computer Architecture

  • 32-bit vs 64-bitThe size of numbers and addresses a CPU handles natively.
  • CPUThe processor that executes instructions.
  • CPU CoreAn independent processing unit; modern CPUs have several.
  • RAMFast, temporary memory for running programs.
  • SSD vs HDDStorage types and their very different speeds.

Operating Systems

Compilers & Languages

Networking Fundamentals

HTTP

TLS & Certificates

  • Let's EncryptA free, automated certificate authority.
  • TLS CertificateA file proving a server controls a domain, signed by a trusted authority.

API Styles & Formats

  • APIAn interface that lets programs talk to each other.
  • Resource NamingPlural nouns, nested paths and consistent URL design.
  • SerializationConverting objects to bytes or text for storage or transfer.
  • YAMLA human-friendly data format common in configuration files.

How Browsers Work

  • Web BrowserThe program that fetches, renders and runs web pages.

Real-Time Communication

  • PollingAsking the server repeatedly whether something changed.

HTML

  • AttributeExtra information on an element, like href or alt.
  • Element and TagThe building blocks of HTML, like <p> and <a>.
  • Form ValidationChecking input in the browser and, always, again on the server.
  • FormsInputs, labels, validation and submission.
  • Head and Meta TagsTitle, description, viewport and other page metadata.
  • HTMLThe markup language that structures web pages.
  • HTML EntitiesEscaped characters like &amp; and &lt;.
  • Semantic HTMLUsing elements for their meaning, like <nav>, <main> and <button>.

CSS

  • CSSThe language that styles web pages.

JavaScript & TypeScript

State Management & Data Fetching

Rendering Strategies

Accessibility

Frontend Build Tooling

  • Dev ServerA local server that rebuilds as you edit.
  • node_modulesWhere installed packages live, and why it gets so big.
  • npm ScriptsProject commands defined in package.json.
  • package.jsonThe manifest of a JavaScript project: its dependencies and scripts.
  • Source MapA mapping from built code back to the original source, for debugging.
  • Static AssetsImages, fonts and files served as-is.

Backend Basics

API Design

Relational Databases & SQL

NoSQL & Other Data Stores

  • Document DatabaseStoring JSON-like documents, as in MongoDB.
  • Key-Value StoreStoring values by key, as in Redis or DynamoDB.
  • NoSQLDatabases not built on the relational table model.
  • Object StorageStoring files as objects, as in S3.
  • RedisAn in-memory data store used for caching, queues and more.

Schema Migrations

  • Migration ToolsTools like Flyway, Alembic, Prisma Migrate and Rails migrations.
  • Seed DataInitial data loaded for development or tests.

Caching

Queues & Async Processing

  • MessageA self-contained unit of data sent from one component to another through a broker.

Email & Notifications

Files & Media

  • CSV Import / ExportMoving tabular data in and out, with all its edge cases.
  • File StorageWhere uploaded files live: local disk, object storage or a CDN.
  • MIME TypeThe standard label for a file's format, like image/png.

Product Building Blocks

Architecture Styles

System Design Fundamentals

Reliability & Resilience

  • BackupsCopies of data for restoring, and why untested backups don't count.

Performance & Scalability

  • LatencyThe time a single operation takes.

Authentication & Authorization

  • API KeyA long random secret identifying a calling application rather than a user.
  • Basic AuthenticationSending a username and password with every request, Base64-encoded.
  • bcryptA widely supported password hashing algorithm with a tunable cost factor.
  • Bearer TokenA token that grants access to whoever presents it, sent in the Authorization header.
  • CookieA small piece of data the server asks the browser to store and send back automatically on later requests.
  • CredentialAnything used to prove identity: a password, key, token or certificate.
  • JWT (JSON Web Token)A signed, self-contained token carrying claims like user ID and expiry, verifiable without a database lookup.
  • SaltA random value added to each password before hashing so identical passwords get different hashes.

Web Application Security

Cryptography Basics

Secure Development

Privacy & Compliance

  • PIIPersonally identifiable information that needs special care.

Linux & Servers

Containers

Cloud Computing

CI/CD & Deployment

Observability

Data Engineering Foundations

Collection & Instrumentation

Storage, Formats & Lakehouse

  • CSVThe simplest tabular format, and its quoting, encoding and type pitfalls.

Stream Processing

LLM & AI Engineering

Agile & Delivery Process

  • AgileDelivering in small increments and adapting to feedback.
  • BacklogThe prioritized list of work that hasn't started yet.
  • Backlog RefinementClarifying and sizing upcoming work.
  • Daily StandupA short daily sync on progress and blockers.
  • EpicA large body of work split into smaller stories.
  • KanbanVisualizing work on a board and limiting work in progress.
  • RetrospectiveA regular meeting to reflect on how the team works and improve it.
  • ScrumAn agile framework with sprints, roles and ceremonies.
  • Software Development LifecycleThe stages from idea to production to maintenance.
  • SprintA fixed period, often two weeks, to deliver planned work.
  • Sprint PlanningChoosing the work for the next sprint.
  • Sprint Review / DemoShowing what was built to stakeholders.
  • User Story"As a user, I want… so that…": a requirement from the user's point of view.
  • WaterfallSequential phases from requirements to release.

Estimation & Planning

Communication

Product Thinking

Junior Habits & First Job

Career Growth

Mid-level

Own a feature end to end without hand-holding.

Core: start here

Object-Oriented Programming

Concurrency & Async

Version Control (Git)

  • BisectBinary-searching history to find the commit that introduced a bug.
  • Interactive RebaseRewriting commits: squash, reorder, edit, drop.
  • Merge vs RebasePreserving history as it happened vs rewriting it to be linear.

Pull Requests & Code Review

Debugging

Testing

Clean Code & Principles

Design Patterns

HTTP

  • CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
  • HTTP CachingCache-Control, ETag and Last-Modified for reusing responses.

TLS & Certificates

  • TLSThe protocol that encrypts and authenticates network connections.

Backend Basics

API Design

Relational Databases & SQL

  • Data ModelingDesigning how your data is structured and related.
  • EXPLAINShowing how the database plans to run a query.
  • NormalizationOrganizing tables to reduce duplication: 1NF, 2NF, 3NF.

Indexing & Query Performance

Transactions & Concurrency Control

  • ACIDAtomicity, Consistency, Isolation, Durability.
  • Optimistic LockingDetecting conflicts with a version number at write time.
  • Pessimistic LockingLocking rows before changing them, e.g. with SELECT ... FOR UPDATE.

NoSQL & Other Data Stores

  • SQL vs NoSQLChoosing a database by data shape, consistency needs and access patterns.

Caching

  • Cache InvalidationRemoving stale data from a cache; famously one of the hard problems.
  • Cache-AsideThe app checks the cache, then the database, then fills the cache.

Queues & Async Processing

Architecture Styles

System Design Fundamentals

Distributed Systems

  • CAP TheoremDuring a network partition, you must choose consistency or availability.
  • Eventual ConsistencyReplicas converge once updates stop, but reads may be stale in the meantime.

Authentication & Authorization

  • CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
  • OAuth 2.0A framework for letting an app act on a user's behalf without seeing their password.
  • OpenID Connect (OIDC)An identity layer on top of OAuth 2.0 that adds login and a standard ID token.
  • RBACRole-Based Access Control: permissions are granted to roles, and users are given roles.
  • Refresh TokenA long-lived credential used only to get new short-lived access tokens without logging in again.

Web Application Security

  • OWASP Top 10The ten most critical web application security risks.

Secure Development

Containers

Kubernetes & Orchestration

  • KubernetesThe dominant container orchestration platform.

Cloud Computing

  • IAMIdentity and access management for cloud resources.

Infrastructure as Code

CI/CD & Deployment

Observability

Incidents & SRE

  • On-CallBeing responsible for responding to production issues.
  • PostmortemA written review of an incident: what happened and how to prevent it.

Estimation & Planning

  • PrioritizationDeciding what to do first: impact vs effort, urgent vs important.

Communication

Product Thinking

Career Growth

  • ImpactOutcomes that matter to the business, not just output.
  • OwnershipTaking responsibility for outcomes, not just tasks.
646 more mid-level concepts

Programming Basics

  • Bitwise OperationOperating on individual bits: AND, OR, XOR and shifts.
  • Integer OverflowA value exceeding its type's range and wrapping around or failing.
  • Pattern MatchingBranching on the shape of data and destructuring it at the same time.
  • Tail RecursionRecursion where the call is the last action, which some languages turn into a loop.

Collections

  • GeneratorA function that lazily yields a sequence of values.
  • IteratorAn object that yields items one at a time from a sequence.
  • Lazy EvaluationComputing values only when they're actually needed.

Object-Oriented Programming

  • Abstract ClassA class that can't be instantiated and leaves some methods to subclasses.
  • InterfaceA contract of methods a type promises to implement.
  • Mixin / TraitReusable behavior added to classes without inheritance.
  • Special MethodsMethods the language calls implicitly, like __eq__ or toString.

Functional Programming

Error Handling

Type Systems

  • Discriminated UnionA union whose members are told apart by a tag field.
  • Duck TypingIf it has the right methods, it's the right type.
  • Finite State MachineA model with a fixed set of states and allowed transitions, e.g. an order going from paid to shipped.
  • GenericsCode that works over many types while keeping type safety.
  • Runtime ValidationChecking that untrusted data matches a type at runtime, e.g. with Zod or Pydantic.
  • Type InferenceThe compiler working out types without annotations.
  • Type NarrowingRefining a broad type to a specific one through checks.
  • Union TypeA value that can be one of several types.

Concurrency & Async

Memory & Runtime

  • BytecodeAn intermediate instruction format run by a virtual machine.
  • Garbage CollectionAutomatic reclamation of memory that's no longer reachable.
  • Language Runtime / VMThe environment that executes your code: JVM, V8, CPython, CLR.
  • Memory LeakMemory that's never released, growing until the program slows or crashes.
  • PointerA variable that holds a memory address.
  • Stack vs HeapShort-lived call frames vs dynamically allocated, longer-lived memory.

Version Control (Git)

Branching & Releases

Pull Requests & Code Review

Debugging

Testing

Clean Code & Principles

Refactoring

Design Patterns

  • Active RecordObjects that know how to save themselves to the database.
  • AdapterWrapping an interface to make it match another.
  • Anti-PatternA common solution that looks right but causes problems.
  • BuilderConstructing complex objects step by step.
  • Chain of ResponsibilityPassing a request along handlers until one deals with it; how middleware works.
  • CommandTurning a request into an object you can queue, log or undo.
  • CompositeTreating individual objects and groups of them uniformly, as a tree.
  • DecoratorAdding behavior to an object by wrapping it.
  • Design PatternA named, reusable solution to a recurring design problem.
  • FacadeA simple interface over a complex subsystem.
  • Factory MethodLetting subclasses or functions decide which class to instantiate.
  • Gang of FourThe 1994 book that catalogued 23 classic patterns.
  • Inversion of ControlA framework calls your code rather than your code calling it.
  • Iterator PatternTraversing a collection without exposing its internals.
  • Null ObjectA do-nothing object used instead of null checks.
  • ObserverNotifying subscribers when something changes.
  • ProxyA stand-in that controls access to another object.
  • Publish-SubscribeSenders publish to topics; receivers subscribe without knowing each other.
  • Repository PatternA collection-like interface over data storage.
  • SingletonEnsuring a class has exactly one instance; often an anti-pattern.
  • StateChanging an object's behavior when its internal state changes.
  • StrategySwapping algorithms behind a common interface.
  • Template MethodA base algorithm whose steps subclasses fill in.
  • Transaction ScriptOrganizing business logic as one procedure per request.

Developer Tooling

AI-Assisted Development

Documentation & Writing

  • API DocumentationReference docs for an API's endpoints, parameters and errors.
  • Architecture DiagramA box-and-arrow picture of a system's components and data flow.
  • Class DiagramA diagram of classes, their fields and relationships.
  • Diagrams as CodeWriting diagrams as text, with tools like Mermaid or PlantUML.
  • Docs as CodeKeeping docs in the repository and reviewing them like code.
  • Onboarding DocumentationDocs that get a new teammate productive quickly.
  • RunbookStep-by-step instructions for operating or fixing a system.
  • Sequence DiagramA diagram of messages passed between components over time.
  • State DiagramA diagram of states and the transitions between them.
  • UMLA standard visual language for software diagrams.

Data Structures

  • Adjacency List vs MatrixTwo ways to store a graph's edges.
  • B-TreeA wide, shallow tree optimized for disks; how database indexes work.
  • Binary Search TreeA binary tree ordered so each lookup can halve the search.
  • DequeA double-ended queue that adds and removes at both ends.
  • Directed Acyclic Graph (DAG)A graph with directed edges and no cycles, as in build systems and pipelines.
  • Doubly Linked ListA linked list with pointers in both directions.
  • GraphNodes connected by edges; models networks, dependencies and maps.
  • Hash CollisionTwo keys hashing to the same slot, and how tables handle it.
  • HeapA tree that keeps the min or max at the root; backs priority queues.
  • LRU CacheA cache evicting the least recently used item, built from a hash map and a linked list.
  • Priority QueueA queue that always returns the highest-priority item first.
  • Tree TraversalVisiting tree nodes in pre-order, in-order, post-order or level order.
  • TrieA tree of characters for fast prefix lookups.

Algorithms

Math for Programmers

Computer Architecture

Operating Systems

Compilers & Languages

  • Abstract Syntax Tree (AST)A tree of code's structure that linters, formatters and compilers work on.
  • CompilerA program that translates source code into another form.
  • Decorators / AnnotationsSyntax for attaching behavior or metadata to functions and classes.
  • InterpreterA program that executes source code directly.
  • ParserTurning text into a structured representation.
  • ReflectionA program inspecting its own structure at runtime.
  • TranspilerA compiler from one high-level language to another, like TypeScript to JavaScript.

Networking Fundamentals

HTTP

  • Cache-ControlThe header that directs how responses may be cached.
  • Content NegotiationClient and server agreeing on format and language through Accept headers.
  • ETagA version identifier used for conditional requests and caching.
  • HSTSA header telling browsers to always use HTTPS for a site.
  • HTTP Compressiongzip and Brotli shrinking responses on the wire.
  • HTTP ProxyAn intermediary that forwards HTTP requests.
  • HTTP/1.1The text-based HTTP version with one request at a time per connection.
  • HTTP/2Binary framing and many requests multiplexed over one connection.
  • Long PollingHolding a request open until the server has news.
  • multipart/form-dataThe encoding used to upload files from forms.
  • OriginScheme + host + port: the browser's security boundary.
  • Preflight RequestThe OPTIONS request a browser sends before certain cross-origin calls.
  • Safe and Idempotent MethodsWhich HTTP methods shouldn't change state, and which can be retried safely.
  • Same-Origin PolicyThe browser rule that isolates content from different origins.
  • Server-Sent EventsA one-way stream of events from server to browser over HTTP.
  • Synchronous vs Asynchronous APIsReturning the result in the response vs accepting work and reporting later.
  • Webhooks vs PollingBeing notified when something changes vs repeatedly asking.
  • WebSocketA persistent, two-way connection between browser and server.

TLS & Certificates

API Styles & Formats

  • API Client / SDKA library wrapping an API so callers don't hand-write HTTP.
  • GraphQLA query language that lets clients ask for exactly the data they need.
  • GraphQL Schema and ResolversTypes describing the data, and functions that fetch each field.
  • gRPCA fast RPC framework built on HTTP/2 and Protocol Buffers.
  • JSON SchemaA vocabulary for validating the structure of JSON.
  • OpenAPIA standard format for describing REST APIs.
  • Protocol BuffersA compact, schema-based binary serialization format.
  • Resource ModelingDeciding what your API's resources are and how they relate.
  • REST ConstraintsStatelessness, uniform interface, cacheability and REST's other rules.
  • RPCCalling a function on another machine as if it were local.
  • XMLA verbose markup format still common in enterprise and legacy systems.

How Browsers Work

Real-Time Communication

JavaScript & TypeScript

  • CommonJSNode's older require/module.exports module system.
  • Deno and BunNewer JavaScript runtimes with built-in tooling.
  • ECMAScriptThe standard JavaScript implements, with a new version every year.
  • Microtasks vs MacrotasksWhy promise callbacks run before setTimeout callbacks.

State Management & Data Fetching

Rendering Strategies

Web Performance

Frontend Build Tooling

UI/UX for Engineers

Backend Basics

API Design

Relational Databases & SQL

Indexing & Query Performance

Transactions & Concurrency Control

NoSQL & Other Data Stores

Schema Migrations

Database Operations

Caching

Queues & Async Processing

Email & Notifications

  • Email DeliverabilityBounces, spam complaints, sender reputation and staying out of spam folders.
  • Notification PreferencesLetting users choose which messages they get, on which channel.
  • Push NotificationsSending alerts to phones and browsers through APNs, FCM or Web Push.
  • SMS DeliverySending text messages through providers, and the cost and fraud pitfalls.
  • SMTPThe protocol for sending email between servers.
  • SPF, DKIM and DMARCDNS records that prove your email is really from you, so it doesn't land in spam.

Files & Media

Product Building Blocks

Architecture Styles

Domain-Driven Design

  • EntityA domain object defined by its identity.
  • Ubiquitous LanguageOne shared vocabulary between developers and domain experts.
  • Value ObjectA domain object defined only by its values, and immutable.

System Design Fundamentals

Distributed Systems

  • BASEBasically Available, Soft state, Eventual consistency: the counterpart to ACID.

Reliability & Resilience

Performance & Scalability

Events & Integration

  • ETL / ELTExtracting, transforming and loading data between systems.
  • EventA record that something happened.
  • Unix PhilosophySmall tools that do one thing well and compose through pipes.

Cloud Design Patterns

Authentication & Authorization

  • Access TokenA short-lived token sent with each API request to prove the caller is authenticated.
  • Account EnumerationLeaking whether an email is registered through login, signup or reset responses.
  • Argon2The current recommended password hashing algorithm; memory-hard to resist GPU cracking.
  • Identity Provider (IdP)The service that authenticates users for other apps, like Okta, Auth0 or Google.
  • JWT ClaimsThe fields inside a JWT payload, such as sub, exp, iat, iss and aud, and which to check.
  • JWT Signing AlgorithmsHS256 (shared secret) vs RS256/ES256 (key pair), and when each fits.
  • Login Rate LimitingSlowing or blocking repeated login attempts to stop password guessing.
  • Multi-Factor Authentication (MFA)Requiring two or more kinds of proof: something you know, have, or are.
  • Password Reset FlowDesigning reset links that are single-use, short-lived and don't leak account existence.
  • PKCEAn OAuth extension that stops stolen authorization codes from being exchanged by attackers.
  • SameSite CookiesA cookie attribute controlling whether cookies are sent on cross-site requests.
  • Token ExpiryChoosing how long tokens live, and handling what happens when they run out.
  • TOTPTime-based one-time passwords, the 6-digit codes from authenticator apps.

Web Application Security

Cryptography Basics

Secure Development

  • Attack SurfaceEvery point where an attacker could try to get in.
  • Audit LoggingRecording who did what and when, for accountability.
  • CVEA public identifier for a known vulnerability.
  • Defense in DepthSeveral layers of security, so one failure isn't fatal.
  • Dependency ScanningFinding known vulnerabilities in your dependencies.
  • SASTStatic analysis that looks for security bugs in source code.
  • TyposquattingMalicious packages named like popular ones.
  • Zero-DayA vulnerability exploited before a fix exists.

Privacy & Compliance

  • CopyleftLicenses that require derivative work to stay open source.
  • Data MinimizationCollecting only the data you actually need.
  • GDPRThe EU regulation on personal data: consent, access and deletion rights.
  • Open Source LicensesMIT, Apache, GPL, and what each one lets you do.

Linux & Servers

Containers

Kubernetes & Orchestration

  • ConfigMap and SecretConfiguration and sensitive values injected into pods.
  • Container OrchestrationAutomating the deployment, scaling and healing of containers.
  • CrashLoopBackOffA pod that keeps crashing and restarting.
  • DeploymentDeclares how many replicas of a pod should run and how to update them.
  • HelmA package manager for Kubernetes.
  • IngressRouting external HTTP traffic into the cluster.
  • Job and CronJobRunning one-off and scheduled tasks in Kubernetes.
  • kubectlThe command-line tool for Kubernetes.
  • Liveness and Readiness ProbesHow Kubernetes checks whether a container is healthy.
  • NamespaceDividing cluster resources between teams or apps.
  • NodeA machine in the cluster that runs pods.
  • PodThe smallest deployable unit in Kubernetes: one or more containers.
  • ReplicaSetKeeps a set number of identical pods running.
  • ServiceA stable network address for a set of pods.

Cloud Computing

Infrastructure as Code

CI/CD & Deployment

Observability

Incidents & SRE

Working in Production

Collection & Instrumentation

Ingestion

Serving & Analytics

  • Data APIsServing data to applications through an API instead of direct database access.

Data Engineering Basics

Machine Learning Basics

LLM & AI Engineering

Agile & Delivery Process

Estimation & Planning

Communication

Product Thinking

Career Growth

Senior

Own a system, its failure modes, and its trade-offs.

Core: start here

Clean Code & Principles

  • Hyrum's LawWith enough users, every observable behavior becomes something someone depends on.

Documentation & Writing

Transactions & Concurrency Control

  • Isolation LevelsRead uncommitted, read committed, repeatable read and serializable.

Schema Migrations

Caching

Queues & Async Processing

Architecture Styles

Domain-Driven Design

System Design Fundamentals

Distributed Systems

Reliability & Resilience

Performance & Scalability

Authentication & Authorization

  • Refresh Token RotationIssuing a new refresh token on every refresh and invalidating the old one, so reuse of an old token reveals theft.

Secure Development

  • Threat ModelingSystematically asking what could go wrong and how to prevent it.

Observability

Incidents & SRE

  • Error BudgetHow much unreliability an SLO allows, used to balance speed and stability.
  • SLOA service level objective: the target for an SLI.

Career Growth

  • Handling AmbiguityMaking progress when the problem isn't well defined.
  • ScopeHow big and ambiguous the problems you own are.

Technical Leadership

501 more senior concepts

Functional Programming

  • CurryingTurning a multi-argument function into a chain of single-argument ones.
  • MonadA pattern for chaining computations that carry context, like Option or Promise.
  • Referential TransparencyAn expression can be replaced by its value without changing behavior.

Error Handling

Type Systems

Concurrency & Async

  • Actor ModelConcurrency through isolated actors that communicate by messages.
  • BackpressureA slow consumer signalling a fast producer to slow down.
  • ChannelA typed pipe for passing values between concurrent tasks.
  • Green Threads / GoroutinesLightweight threads scheduled by the runtime rather than the OS.
  • LivelockTasks keep reacting to each other without making progress.
  • SemaphoreA counter limiting how many tasks can use a resource at once.
  • StarvationA task never gets the resources it needs to run.

Memory & Runtime

Version Control (Git)

  • Git InternalsBlobs, trees, commits and refs: what Git actually stores.
  • Monorepo vs PolyrepoOne repository for everything vs one per project.
  • Patch FilesSharing changes as diff files instead of branches.
  • WorktreeSeveral working directories checked out from one repository.

Pull Requests & Code Review

  • Stacked PRsA chain of dependent pull requests, each reviewable on its own.

Debugging

  • Core DumpA snapshot of a crashed process's memory for later analysis.
  • Debugging in ProductionFinding issues with logs, traces and metrics when you can't attach a debugger.
  • Flame GraphA visualization of where a program spends its time.

Testing

  • Contract TestingVerifying that services agree on the API contract between them.
  • FuzzingFeeding random inputs to find crashes and vulnerabilities.
  • Mutation TestingChanging code on purpose to check that the tests notice.
  • Property-Based TestingGenerating many inputs to check that properties always hold.
  • Soak TestRunning under load for hours to find leaks and slow degradation.
  • Stress TestingPushing beyond capacity to find the breaking point.
  • Testing in ProductionValidating safely with real traffic using flags, canaries and monitoring.

Clean Code & Principles

Refactoring

Design Patterns

  • Abstract FactoryCreating families of related objects without naming concrete classes.
  • BridgeSeparating an abstraction from its implementation so both can vary.
  • Data MapperA separate layer moving data between objects and the database.
  • Domain ModelOrganizing business logic as objects that hold both data and behavior.
  • FlyweightSharing common state among many small objects to save memory.
  • Identity MapEnsuring each database row is loaded into only one object per session.
  • MediatorCentralizing communication between objects.
  • MementoCapturing state so it can be restored later, as in undo.
  • Patterns of Enterprise Application ArchitectureFowler's catalog: transaction script, domain model, data mapper and more.
  • PrototypeCreating objects by cloning an existing one.
  • Service LocatorA registry for looking up dependencies, often seen as an anti-pattern.
  • Type ObjectDefining "kinds" of things as data instead of subclasses.
  • Unit of WorkTracking changes and committing them in one transaction.
  • VisitorAdding operations to a structure without changing its classes.

Documentation & Writing

  • C4 ModelDiagramming software at four zoom levels: context, containers, components, code.
  • DiátaxisOrganizing docs into tutorials, how-to guides, reference and explanation.

Data Structures

  • Balanced TreeTrees like AVL or red-black that stay shallow for guaranteed O(log n).
  • Bloom FilterA compact structure answering "definitely not" or "probably yes" for set membership.
  • HyperLogLogEstimating the number of distinct items with tiny memory.
  • K-D TreeA tree for searching points in multi-dimensional space.
  • Merkle TreeA tree of hashes that verifies large data efficiently.
  • Persistent Data StructureAn immutable structure that shares unchanged parts between versions.
  • Ring BufferA fixed-size buffer that wraps around.
  • Segment TreeA tree for fast range queries over arrays.
  • Skip ListA layered linked list with O(log n) search.
  • Union-FindTracking which elements belong to the same group.

Algorithms

Math for Programmers

  • Amdahl's LawThe speedup from parallelism is limited by the part that stays sequential.
  • Linear Algebra BasicsVectors and matrices, the foundation of graphics and ML.
  • Little's LawItems in a system = arrival rate × time each spends in it.

Computer Architecture

  • Cache LocalityAccessing memory that's close together is much faster.
  • InterruptA signal that makes the CPU pause and handle an event.
  • RegistersThe tiny, fastest storage inside the CPU.

Operating Systems

Compilers & Languages

Networking Fundamentals

  • AnycastOne IP address served from many locations, sending users to the nearest.
  • ARPFinding the hardware address behind an IP on a local network.
  • Head-of-Line BlockingOne slow item holding up everything queued behind it.
  • MTUThe largest packet size a network link can carry.
  • Network PartitionPart of a network becoming unreachable from the rest.
  • Packet Capture (tcpdump, Wireshark)Recording and inspecting raw network traffic.
  • QUICA UDP-based transport behind HTTP/3, with faster handshakes.
  • RoutingHow packets find their way across networks.

HTTP

TLS & Certificates

  • Certificate ChainLeaf, intermediate and root certificates linking to a trusted root.
  • SNITelling the server which hostname you want during the TLS handshake.
  • TLS HandshakeHow client and server agree on keys before sending data.

API Styles & Formats

Real-Time Communication

  • CRDTData structures that merge concurrent edits without conflicts, used in collaborative editors.
  • PresenceShowing who is online or viewing something right now.
  • WebRTCPeer-to-peer audio, video and data in the browser.

Rendering Strategies

Web Performance

Backend Basics

  • Choosing a Backend LanguageWeighing ecosystem, performance and team skills.
  • Context PropagationCarrying request IDs, deadlines and trace context across threads and services.
  • Let It CrashRestarting a failed component cleanly instead of handling every error inside it.
  • Multi-TenancyServing many customers from one system while keeping their data apart.
  • Steady StateDesigning systems to clean up after themselves: purging data, rotating logs.
  • Worker and Process ModelsPre-fork workers, threads or an event loop: how a server handles many requests at once.

API Design

Relational Databases & SQL

Indexing & Query Performance

Transactions & Concurrency Control

Database Internals

NoSQL & Other Data Stores

Schema Migrations

Database Operations

Caching

Queues & Async Processing

Email & Notifications

Files & Media

Product Building Blocks

Architecture Styles

Domain-Driven Design

System Design Fundamentals

Distributed Systems

Reliability & Resilience

Performance & Scalability

Events & Integration

Cloud Design Patterns

  • AmbassadorA helper proxy that handles networking concerns for a service.
  • Busy DatabasePushing too much processing into the database.
  • Claim CheckPutting a large payload in storage and sending only a reference through the queue.
  • GatekeeperA dedicated host that validates requests before they reach trusted services.
  • Gateway AggregationOne gateway call that fans out to many services and combines the results.
  • Gateway OffloadingMoving TLS, auth and other shared concerns into the gateway.
  • Index TableA separate table that indexes data by a field the main store can't query efficiently.
  • Noisy NeighborOne tenant or workload hogging shared resources and slowing others down.
  • Priority Queue PatternProcessing urgent messages before others.
  • Queue-Based Load LevelingA queue absorbing traffic spikes so a service sees steady load.
  • Scheduler Agent SupervisorCoordinating a multi-step job and recovering steps that fail.
  • Sequential ConvoyProcessing related messages in order while unrelated ones run in parallel.

Authentication & Authorization

  • ABACAttribute-Based Access Control: decisions based on attributes of user, resource and context.
  • Client Credentials FlowThe OAuth 2.0 flow for machine-to-machine calls with no user involved.
  • Credential StuffingAutomated logins using username/password pairs leaked from other sites.
  • DAC, MAC and PBACOwner-controlled, centrally mandated and policy-based access control.
  • JWKSJSON Web Key Set: a published endpoint of public keys used to verify signed tokens.
  • mTLSMutual TLS: both client and server present certificates, common for service-to-service auth.
  • Passkeys (WebAuthn)Phishing-resistant login with device-bound key pairs instead of passwords.
  • ReBACRelationship-Based Access Control, as in Google Zanzibar: access follows relationships like owner or member.
  • SAMLAn older XML-based standard for enterprise SSO, still common in B2B.
  • Session FixationAn attack where the attacker sets a victim's session ID before login; fixed by rotating the ID on login.
  • Signing Key RotationReplacing token signing keys regularly without invalidating every live token.
  • Single Sign-On (SSO)Logging in once with an identity provider and accessing many apps.
  • Token RevocationStrategies for invalidating tokens before they expire: denylists, versioning, short lifetimes.

Web Application Security

  • Business Logic VulnerabilitiesAbusing legitimate features in unintended ways.
  • Insecure DeserializationDeserializing untrusted data in a way that executes code.
  • ReDoSRegular expressions that take exponential time on crafted input.
  • SSRFTricking a server into making requests to internal systems.
  • XXEXML parsers fetching external entities and leaking files.

Cryptography Basics

Secure Development

  • Bug BountyPaying outside researchers to report vulnerabilities.
  • Container SecurityMinimal images, non-root users and image scanning.
  • CVSSA score rating how severe a vulnerability is.
  • DASTTesting a running app for vulnerabilities from the outside.
  • Penetration TestingAuthorized simulated attacks to find vulnerabilities.
  • Responsible DisclosureReporting vulnerabilities privately before going public.
  • SBOMA software bill of materials listing every component.
  • Secret RotationRegularly replacing credentials.
  • Security ReviewReviewing a design or change specifically for security risks.
  • Shift-Left SecurityFinding security issues early in development.
  • Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
  • STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.

Privacy & Compliance

Linux & Servers

Containers

  • Minimal Base ImagesAlpine, distroless and scratch images for a smaller attack surface.
  • OCIThe open standards for container images and runtimes.
  • Union FilesystemStacking read-only image layers with a writable layer on top.

Kubernetes & Orchestration

Cloud Computing

Infrastructure as Code

CI/CD & Deployment

Observability

  • Actionable AlertsAlerting only on symptoms that need a human to act.
  • CardinalityThe number of unique label combinations, and why high cardinality gets expensive.
  • Counter, Gauge, HistogramThe basic metric types.
  • OpenTelemetryThe vendor-neutral standard for collecting telemetry.
  • RED MethodRate, errors and duration for request-driven services.
  • SamplingRecording only a fraction of traces or logs to control cost.
  • SpanOne timed operation within a trace.
  • USE MethodUtilization, saturation and errors for resources.

Incidents & SRE

Working in Production

  • Break-Glass AccessEmergency elevated access that is logged, time-limited and reviewed afterwards.

Collection & Instrumentation

  • Telemetry PipelineThe path from emitted logs, metrics and events to where they're stored and queried.

Serving & Analytics

Data Engineering Basics

Machine Learning Basics

LLM & AI Engineering

  • Choosing a ModelTrading off quality, speed and cost across model sizes and providers.
  • ChunkingSplitting documents into pieces for embedding and retrieval.
  • EvalsSystematically measuring the quality of LLM output.
  • Fine-TuningFurther training a model on your own examples.
  • GuardrailsChecks on model inputs and outputs for safety and correctness.
  • LLM Cost and LatencyManaging tokens, model choice and caching.
  • LLM-as-JudgeUsing one model to grade another model's output.
  • Prompt CachingReusing processed prompt prefixes to save cost and time.
  • RerankingRe-ordering retrieved results with a stronger model.

Agile & Delivery Process

Estimation & Planning

Communication

Product Thinking

Career Growth

Technical Leadership

Staff

Shape how many teams build, across systems.

Clean Code & Principles

  • Conway's LawSystems mirror the communication structure of the organizations that build them.

Documentation & Writing

  • RFCA request for comments: proposing a significant change for wide review.

API Design

Architecture Styles

Domain-Driven Design

System Design Fundamentals

Reliability & Resilience

Performance & Scalability

Events & Integration

Cloud Design Patterns

  • Deployment StampsDeploying many independent copies of a whole system, e.g. one per region or customer group.
  • GeodesServing any request from any region, with data replicated everywhere.

Authentication & Authorization

  • Auth System MigrationMoving users to a new identity system or hashing scheme without forcing everyone to log in again.
  • Build vs Buy for IdentityDeciding between an in-house auth system and a provider like Auth0, Keycloak or Cognito.
  • Identity ArchitectureDesigning how identity, sessions and permissions work across many services and teams.
  • Zero TrustTreating every request as untrusted regardless of network location, verifying identity everywhere.

Secure Development

Privacy & Compliance

Kubernetes & Orchestration

Cloud Computing

  • Multi-CloudUsing several cloud providers, and whether it's worth it.

CI/CD & Deployment

  • DORA MetricsFour delivery metrics: deploy frequency, lead time, change failure rate and recovery time.

Observability

  • Wide EventsRich, high-cardinality events instead of pre-aggregated metrics.

Incidents & SRE

Data Engineering Basics

  • Reverse ETLSyncing warehouse data back into operational tools.

Communication

Product Thinking

Career Growth

Technical Leadership

Principal

Set technical direction for the organization.

Concurrency & Async

Design Patterns

Data Structures

  • Suffix ArrayA sorted array of a string's suffixes for fast substring search.

Algorithms

  • Maximum FlowFinding the most that can flow through a network (Ford-Fulkerson).

Computer Architecture

  • SIMDOne instruction operating on multiple data values at once.

Networking Fundamentals

  • BGPThe protocol that routes traffic between the internet's networks.

Real-Time Communication

Database Internals

Distributed Systems

  • Byzantine FaultNodes that behave arbitrarily or maliciously.
  • Fencing TokenA counter that stops stale lock holders from writing.
  • Hedged RequestsSending a duplicate request when the first is slow, to cut tail latency.
  • LinearizabilityOperations appear to happen instantly, in real-time order.
  • Logical ClocksLamport and vector clocks for ordering events without real time.
  • PaxosThe classic, notoriously hard-to-understand consensus algorithm.
  • Total Order BroadcastDelivering the same messages in the same order to every node.

Performance & Scalability

Cryptography Basics

Linux & Servers

  • eBPFRunning safe, sandboxed programs inside the Linux kernel for tracing and networking.

Career Growth

Technical Leadership