Frontend Engineer
Every concept a frontend engineer meets, in the order you actually need it.
Junior
Build UI that works, ship small changes safely, ask good questions.
Core: start here
- Null / None / nilA value meaning "nothing here", and the source of countless crashes.
- Truthy and FalsyNon-boolean values that act as true or false in conditions.
- undefinedJavaScript's value for a variable or property that was never assigned.
- DestructuringUnpacking values from arrays or objects into variables.
- Mutable vs ImmutableWhether a value can be changed after it's created.
- Shallow vs Deep CopyCopying only the top level vs copying everything nested inside.
- Spread / Rest SyntaxExpanding or collecting elements with ... (or * and ** in Python).
- ClosureA function that remembers variables from the place it was defined.
- Stack TraceThe chain of function calls that led to an error.
- async / awaitSyntax for writing asynchronous code that reads like synchronous code.
- Promise / FutureAn object representing a value that will be available later.
- .gitignoreFiles Git should never track, like build output and .env.
- AmendChanging the most recent commit's content or message.
- BranchA movable pointer to a line of commits, for isolated work.
- CloneCopying a remote repository, with its full history, to your machine.
- CommitA snapshot of changes with a message explaining them.
- Commit MessageA summary line plus a body explaining why a change was made.
- DiffSeeing exactly what changed between commits, branches or your working copy.
- GitThe distributed version control system almost everyone uses.
- Log and HistoryBrowsing and filtering commit history.
- Merge ConflictTwo branches changed the same lines and Git needs you to decide.
- RebaseReplaying commits on top of another base for a linear history.
- Code ReviewTeammates reading your change to catch bugs and share knowledge.
- PR DescriptionExplaining what changed, why, and how to test it.
- Pull RequestA proposal to merge a branch, with discussion and review.
- Receiving Code ReviewTaking feedback without defensiveness and resolving it clearly.
- Self-ReviewReading your own diff before asking others to.
- Small Pull RequestsKeeping changes small so they're reviewed faster and better.
- Browser DevToolsThe browser's built-in tools for inspecting DOM, network, console and performance.
- DebuggerA tool to pause code, inspect variables and step through execution.
- DebuggingSystematically finding why code doesn't do what you expect.
- Minimal Reproducible ExampleThe smallest code that still shows the bug.
- Network TabInspecting every HTTP request a page makes.
- Reading Error MessagesActually reading the error: the first and most skipped debugging step.
- Reproducing a BugGetting the bug to happen reliably before trying to fix it.
- Rubber Duck DebuggingExplaining the problem out loud until you spot the bug.
- Component TestingTesting a UI component in isolation with user-like interactions.
- MockA test double that verifies how it was called.
- Test Runner / Test FrameworkTools like pytest, JUnit, Jest or Vitest that find, run and report tests.
- Testing Library PhilosophyTesting UI the way users use it, by role and text rather than internals.
- Unit TestA fast test of one small piece of code in isolation.
- Clean CodeCode that's easy to read, change and trust.
- Code SmellA surface sign that the design may have a deeper problem.
- DRY (Don't Repeat Yourself)Every piece of knowledge should have one authoritative place.
- KISS (Keep It Simple)Prefer the simplest solution that works.
- ReadabilityCode is read far more often than it's written.
- Technical DebtThe future cost of shortcuts taken now.
- YAGNI (You Aren't Gonna Need It)Don't build things before you need them.
- RefactoringChanging code's structure without changing its behavior.
- Development Environment SetupGetting a project running locally from a fresh machine.
- FormatterA tool that rewrites code to a consistent style automatically.
- LinterA tool that flags likely bugs and style issues.
- LockfileA record of exact dependency versions so every install is identical.
- Package ManagerA tool for installing and versioning dependencies, like npm, pip or cargo.
- Reading DocumentationGoing to the official docs first, and knowing how to navigate them.
- Searching EffectivelyFinding answers fast in error messages, issues, docs and forums.
- Learning While Using AIUsing AI without skipping the understanding a junior needs to build.
- Reviewing AI-Generated CodeReading and testing AI output as critically as a stranger's PR.
- MarkdownThe plain-text formatting syntax used for READMEs, docs and PRs.
- READMEThe front page of a project: what it is, how to run it, how to contribute.
- CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
- HTTPThe request-response protocol of the web.
- HTTP MethodsGET, POST, PUT, PATCH, DELETE and what each one means.
- HTTP Status CodesThree-digit codes grouped 1xx–5xx describing the result.
- HTTPSHTTP encrypted with TLS.
- Path vs Query Parameters/users/42 vs /users?id=42, and when to use each.
- Same-Origin PolicyThe browser rule that isolates content from different origins.
- URLThe address of a resource: scheme, host, path, query and fragment.
- EndpointA specific URL and method an API exposes, like POST /orders.
- JSONThe text data format most APIs speak.
- Request and Response BodyThe payload sent with a request or returned in a response, usually JSON.
- RESTAn API style built on resources, URLs and HTTP methods.
- DOMThe browser's tree of objects representing the page.
- localStorageSimple, persistent key-value storage in the browser.
- What Happens When You Type a URLDNS, TCP, TLS, HTTP, parsing, rendering: the classic end-to-end question.
- Form ValidationChecking input in the browser and, always, again on the server.
- FormsInputs, labels, validation and submission.
- Semantic HTMLUsing elements for their meaning, like <nav>, <main> and <button>.
- Box ModelContent, padding, border and margin around every element.
- CSS GridTwo-dimensional layout with rows and columns.
- CSS Unitspx, rem, em, %, vw and vh, and when to use each.
- FlexboxOne-dimensional layout along a row or a column.
- Media QueryApplying styles based on screen size or user preferences.
- Responsive DesignLayouts that adapt to any screen size.
- SelectorThe pattern that chooses which elements a rule applies to.
- SpecificityThe rules deciding which conflicting CSS declaration wins.
- == vs ===Loose equality with coercion vs strict equality.
- DebounceWaiting until events stop before acting, e.g. for search boxes.
- DOM ManipulationReading and changing page elements with JavaScript.
- ES Modulesimport and export: JavaScript's standard module system.
- Event HandlingResponding to clicks, key presses and other user actions.
- Fetch APIThe built-in way to make HTTP requests from JavaScript.
- TypeScriptJavaScript with static types.
- var, let and constJavaScript's three ways to declare variables, and how they're scoped.
- Client-Side RoutingChanging pages without full reloads.
- ComponentA reusable, self-contained piece of UI.
- Component StateData a component owns that changes over time.
- Controlled vs Uncontrolled InputsWhether the framework or the DOM owns an input's value.
- HooksReact functions like useState and useEffect for state and side effects.
- Keys in ListsStable identifiers so the framework can track list items.
- Lifting State UpMoving state to a common parent so siblings can share it.
- PropsInputs passed from a parent component to a child.
- UI FrameworkLibraries like React, Vue, Svelte and Angular for building interfaces.
- useEffect and Side EffectsRunning code after render, and the bugs that come from misusing it.
State Management & Data Fetching
- Derived StateComputing values from state instead of storing duplicates.
- Loading, Error and Empty StatesDesigning every state of async UI, not just success.
- Image OptimizationThe right size, modern formats like WebP and AVIF, and compression.
- Lazy LoadingDeferring images and code until they're needed.
- Accessibility (a11y)Making software usable by people with disabilities.
- Alt TextText describing an image for people who can't see it.
- Color ContrastEnough contrast between text and background to be readable.
- Keyboard NavigationEverything must work without a mouse.
- BundlerA tool that combines modules into files browsers can load, like Vite, webpack or esbuild.
- Frontend Environment VariablesBuild-time variables, and why they're never secret in the browser.
- npm ScriptsProject commands defined in package.json.
- package.jsonThe manifest of a JavaScript project: its dependencies and scripts.
- Source MapA mapping from built code back to the original source, for debugging.
- Design HandoffTurning a designer's mockups into implemented UI.
- Double SubmissionA user clicking twice and creating two orders, and how to prevent it.
Authentication & Authorization
- Authentication vs AuthorizationAuthentication proves who you are; authorization decides what you may do.
- CookieA small piece of data the server asks the browser to store and send back automatically on later requests.
- JWT (JSON Web Token)A signed, self-contained token carrying claims like user ID and expiry, verifiable without a database lookup.
- Secrets in GitWhy passwords and keys must never be committed, and what to do when one is.
- Cross-Site Scripting (XSS)Injecting scripts into pages other users view.
- Never Trust the ClientAnything from the browser can be forged, so validate on the server.
- Platforms (Vercel, Netlify, Render, Fly)Hosts that deploy straight from Git with little setup.
- Continuous IntegrationAutomatically building and testing every change.
- DeploymentPutting a new version into an environment.
- Error TrackingTools like Sentry that group and report exceptions.
- Reading Production LogsFinding the few lines that matter among millions, by request ID, time and level.
- Acceptance CriteriaThe conditions a story must meet to be done.
- Definition of DoneThe team's checklist for when work is truly finished.
- Ticket / IssueA tracked unit of work in Jira, Linear or GitHub Issues.
- Writing a Bug ReportSteps to reproduce, expected vs actual behavior, and environment.
- Breaking Down TasksSplitting work into pieces small enough to finish and estimate.
- EstimationPredicting how long work will take, and communicating the uncertainty.
- Asking Good QuestionsSharing what you tried, what you expected and what happened.
- Status UpdatesProactively telling people where things stand.
- When to Ask for HelpNot too soon, not too late: time-box before asking.
- Clarifying TicketsAsking questions before building the wrong thing.
- Following Team ConventionsMatching the existing style even when you'd do it differently.
- Making Mistakes in ProductionOwning up quickly when you break something.
- Productive StruggleStruggling long enough to learn, but not so long you waste days.
- Reading an Unfamiliar CodebaseStarting from entry points, tests and data flow.
- Testing Your Own WorkChecking that your change works before calling it done.
- Understand Before You ChangeKnowing why code exists before you modify it.
- Your First WeeksSetting up, meeting people, and shipping something small early.
- Brag DocumentA running record of your accomplishments.
491 more junior concepts
- ASCIIThe original 7-bit character set that UTF-8 is backward compatible with.
- Base CaseThe condition that stops recursion.
- Block Scope vs Function ScopeWhether a variable lives until the end of its block or of the whole function.
- BooleanA true/false value.
- Boolean Flag ArgumentsPassing true/false to switch a function's behavior, and why it hurts readability.
- Character EncodingHow characters map to bytes: ASCII, UTF-8, UTF-16.
- Code CommentText for humans in code, best used to explain why rather than what.
- Conditional (if/else)Running different code depending on a condition.
- ConstantA name bound to a value that cannot be reassigned.
- Control FlowThe order in which statements execute: branches, loops, returns.
- Data TypeThe kind of value something is, which determines what operations are valid on it.
- Dates and TimesTime zones, UTC, ISO 8601, and why date bugs are everywhere.
- Default ParameterA parameter value used when the caller omits it.
- Expression vs StatementAn expression produces a value; a statement performs an action.
- Floating-Point NumberA binary approximation of real numbers, and why 0.1 + 0.2 != 0.3.
- FunctionA named, reusable block of code that takes inputs and returns an output.
- Global VariableA variable visible everywhere, and why it makes code hard to reason about.
- IntegerA whole-number type, usually with a fixed size and range.
- ISO 8601The standard text format for dates and times, like 2026-10-10T09:00:00Z.
- IterationStepping through the items of a collection one at a time.
- LoopRepeating code with for, while, do-while or for-each.
- Magic NumberAn unexplained literal in code that should be a named constant.
- Naming ThingsChoosing names that reveal intent; one of the hardest parts of programming.
- Off-by-One ErrorA loop or index that runs one step too many or too few.
- OperatorA symbol that performs an operation on values, like +, == or &&.
- Operator PrecedenceThe rules for which operators bind first in an expression.
- Parameter vs ArgumentParameters are in the definition; arguments are the values passed at the call.
- Primitive TypeA built-in basic type such as integer, float, boolean or character.
- RecursionA function solving a problem by calling itself on smaller inputs.
- Regular ExpressionA pattern language for matching and extracting text.
- Return ValueThe result a function hands back to its caller.
- ScopeThe region of code where a name is visible.
- ShadowingAn inner variable hiding an outer one with the same name.
- Short-Circuit Evaluation&& and || stopping as soon as the result is known.
- Stack OverflowCrashing when the call stack runs out of space, usually from runaway recursion.
- StringA sequence of characters, usually immutable.
- String InterpolationEmbedding values directly inside a string literal.
- Switch / MatchChoosing between many branches based on a value.
- Ternary OperatorA compact inline if/else expression.
- Time ZoneOffsets from UTC that change with location and daylight saving.
- Type CoercionImplicit conversion by the language, like "5" + 1 in JavaScript.
- Type ConversionTurning a value of one type into another, explicitly or implicitly.
- UnicodeThe universal character set, and why string length is trickier than it looks.
- Unix TimestampSeconds since 1970-01-01 UTC; a simple, unambiguous point in time.
- UTF-8The dominant variable-length encoding of Unicode.
- VariableA named reference to a value stored in memory.
- Variadic FunctionA function that accepts any number of arguments.
- ArrayAn ordered, indexed collection of elements.
- Dictionary / MapA collection of key-value pairs with fast lookup by key.
- Equality vs IdentitySame value vs same object in memory.
- IndexingAccessing elements by position, usually starting at zero.
- ListAn ordered collection; a dynamic array or a linked list depending on the language.
- Map, Filter, ReduceThe three core operations for transforming collections.
- Pass by Value vs ReferenceWhether a function receives a copy or a reference to the caller's data.
- SetAn unordered collection of unique values.
- SlicingTaking a sub-range of a sequence.
- Sorting with a Key or ComparatorSorting by a custom key or comparison function.
- TupleA fixed-size, ordered group of values, often of different types.
- AbstractionExposing what something does while hiding how it does it.
- Access Modifierspublic, private and protected: who may see a member.
- ClassA blueprint for creating objects.
- ConstructorThe method that initializes a new object.
- EncapsulationHiding internal state behind a public interface.
- Field / PropertyA piece of data stored on an object.
- Getters and SettersMethods controlling access to a field.
- InheritanceA class reusing and extending another class.
- MethodA function that belongs to an object or class.
- Method OverridingA subclass replacing a parent class's method.
- ObjectAn instance of a class holding its own state.
- Object-Oriented ProgrammingOrganizing code around objects that bundle data and behavior.
- PolymorphismOne interface with many implementations chosen at runtime.
- Static MemberA field or method that belongs to the class rather than an instance.
- this / selfThe reference to the current object inside a method.
- Arrow FunctionJavaScript's concise function syntax with lexical this.
- Declarative vs ImperativeDescribing what you want vs spelling out how to do it.
- First-Class FunctionsFunctions treated as values that can be stored, passed and returned.
- Higher-Order FunctionA function that takes or returns other functions.
- Lambda / Anonymous FunctionA function without a name, defined inline.
- Pure FunctionSame input, same output, and no side effects.
- Side EffectAnything a function does besides returning a value: I/O, mutation, logging.
- AssertionA check that crashes when an assumption turns out to be false.
- Error HandlingAnticipating, detecting and responding to things going wrong.
- ExceptionAn object signalling an error that unwinds the call stack until caught.
- Guard ClauseReturning early on invalid cases to avoid deep nesting.
- Swallowing ErrorsCatching an error and ignoring it, which hides bugs.
- Throwing / RaisingSignalling an error explicitly.
- try / catch / finallyCatching exceptions and running cleanup code regardless.
- any vs unknownTypeScript's escape hatches, and why unknown is the safe one.
- EnumA type with a fixed set of named values.
- Nullable TypeA type that explicitly allows null, forcing you to handle it.
- Static vs Dynamic TypingTypes checked at compile time vs at runtime.
- Strong vs Weak TypingHow willingly a language converts between types implicitly.
- Type AliasA new name for an existing type.
- Type AnnotationExplicitly declaring the type of a variable or parameter.
- Type SystemThe rules a language uses to assign and check types.
- Union TypeA value that can be one of several types.
- CallbackA function passed in to be called when work finishes.
- Callback HellDeeply nested callbacks that make async code unreadable.
- Promise.all, race and allSettledWaiting on many promises at once with different failure behavior.
- Compiled vs InterpretedTranslating to machine code ahead of time vs executing source at runtime.
- Atomic CommitOne commit doing one logical thing, easy to review and revert.
- BlameSeeing who last changed each line and in which commit.
- Branch Naming ConventionsNames like feat/login-page that tell people what a branch is for.
- Conventional CommitsA commit message convention like "feat:" and "fix:" that tools can parse.
- Detached HEADChecking out a commit directly instead of a branch.
- Force PushOverwriting remote history; use --force-with-lease and never on shared branches.
- ForkYour own copy of someone else's repository, for contributing via pull requests.
- Git ConfigYour name, email, aliases and defaults, at global or repository level.
- HEADGit's pointer to the commit you currently have checked out.
- MergeCombining the histories of two branches.
- Push, Pull, FetchSending commits, downloading and merging, or only downloading.
- RemoteAnother copy of the repository, usually "origin" on GitHub or GitLab.
- RepositoryA project's files plus their complete history.
- ResetMoving a branch pointer back, in soft, mixed or hard mode.
- RevertCreating a new commit that undoes an earlier one.
- SquashCombining several commits into one.
- Staging AreaWhere you choose which changes go into the next commit.
- StashTemporarily shelving uncommitted changes.
- TagA named pointer to a commit, usually marking a release.
- Version ControlTracking every change to code so you can review, revert and collaborate.
- ChangelogA human-readable list of notable changes per release.
- Feature BranchA short-lived branch for one change.
- GitHub FlowBranch from main, open a PR, merge back to main.
- HotfixAn urgent fix shipped outside the normal release cycle.
- Protected BranchA branch that requires reviews and passing checks before merging.
- Semantic VersioningMAJOR.MINOR.PATCH, and what each number promises about compatibility.
- Approve vs Request ChangesThe review states and what each one signals.
- Draft PRA PR opened early for feedback, not yet ready to merge.
- Labels and Issue HygieneLabeling, linking and closing issues so work stays findable.
- NitsMinor, optional review comments, labeled so they don't block.
- Pair ProgrammingTwo people working on the same code at the same time.
- BreakpointA place where the debugger pauses execution.
- Divide and Conquer DebuggingHalving the search space until the cause is isolated.
- Print DebuggingAdding temporary output to see what code is doing.
- Step Over, Into, OutMoving through code one line or one call at a time.
- API TestingCalling endpoints and checking status codes, bodies and side effects.
- Arrange, Act, AssertThe standard three-part structure of a test.
- End-to-End TestA test of the whole system through its real interface.
- Flaky TestA test that passes and fails without any code change.
- Functional TestingTesting that features do what the requirements say, from the outside.
- Integration TestA test of several components working together.
- Manual / Exploratory TestingA human exploring the product to find what automation misses.
- Regression TestA test ensuring a fixed bug doesn't come back.
- Smoke TestA quick check that the most basic things work after a deploy.
- Snapshot TestComparing output to a saved snapshot.
- Software TestingChecking code behaves as intended, automatically and repeatably.
- StubA test double that returns canned answers.
- Test AssertionThe check that decides whether a test passes.
- Test Case and Test SuiteA single scenario being checked, and a group of them run together.
- Test CoverageThe share of code executed by tests, and why 100% isn't the goal.
- Test FixtureSetup data or state that tests rely on.
- Test IsolationTests that don't depend on each other or on shared state.
- Boy Scout RuleLeave the code a little cleaner than you found it.
- ConsistencyDoing similar things the same way across a codebase.
- Dead CodeCode that never runs and should be deleted.
- Deep NestingToo many levels of ifs and loops; flatten them with guard clauses.
- Long MethodA function doing too much; one of the most common smells.
- Premature OptimizationOptimizing before you know where the real bottleneck is.
- Separation of ConcernsEach part of the program handles one distinct concern.
- Structured ProgrammingBuilding programs from sequence, selection and loops instead of goto.
- Extract FunctionPulling a block of code into a well-named function.
- IDE Refactoring ToolsLetting the IDE perform renames and extractions safely.
- Inline Function / VariableReplacing an unnecessary indirection with its body.
- RenameChanging a name everywhere it's used, safely.
- Cargo Cult ProgrammingCopying code or rituals without understanding why they work.
- Spaghetti CodeTangled control flow that's impossible to follow.
- Build ToolAutomating compile, test and package steps, like Make, Gradle or Vite.
- curlThe command-line tool for making HTTP requests.
- DependencyExternal code your project relies on.
- Editor ShortcutsLearning your editor's shortcuts and multi-cursor editing to work faster.
- EditorConfigA shared config for indentation and line endings across editors.
- Environment VariableA key-value setting passed to processes from their environment.
- Getting Help (man, --help, tldr)Reading a command's built-in documentation.
- Go to Definition / Find ReferencesNavigating code by symbol instead of searching text.
- grep / ripgrepSearching text across files from the terminal.
- HTTP Client Toolscurl, HTTPie, Postman or Bruno for calling APIs by hand.
- IDE / Code EditorYour main tool for editing, navigating, refactoring and debugging.
- Language Version ManagerTools like nvm, pyenv or mise for switching language versions.
- PATHThe list of directories the shell searches for commands.
- Pipes and RedirectionChaining commands with a pipe and sending output to files with >.
- Pre-commit HooksRunning linters and formatters automatically before each commit.
- Regex TestersTools for building and testing regular expressions interactively.
- ShellThe program interpreting your commands: bash, zsh, fish.
- SSH KeysKey pairs for passwordless authentication to servers and Git hosts.
- Task Runner / Project ScriptsNamed project commands, like npm scripts or a justfile.
- Terminal / Command LineControlling your computer and tools through text commands.
- Terminal Text Editors (Vim, Nano)Editing files on a server where there's no IDE, and how to quit Vim.
- AI Coding AssistantTools like Copilot, Cursor or Claude Code that suggest and write code.
- HallucinationAn AI confidently producing APIs, facts or code that don't exist.
- Prompting for CodeGiving an AI enough context and constraints to produce useful code.
- Vibe CodingAccepting AI code without reading it: fine for prototypes, risky in production.
- Docstrings / JSDocDocumenting functions and modules right next to the code.
- Technical WritingWriting clearly for other engineers.
- Binary TreeA tree where each node has at most two children.
- Data StructureA way of organizing data so certain operations are efficient.
- Dynamic ArrayAn array that grows by reallocating, with amortized O(1) appends.
- Hash FunctionA function mapping data of any size to a fixed-size value.
- Hash TableKey-value storage with average O(1) lookup via a hash function.
- Linked ListNodes pointing to the next node: fast inserts, slow random access.
- QueueA first-in, first-out collection.
- StackA last-in, first-out collection.
- TreeA hierarchy of nodes with one root and no cycles.
- AlgorithmA step-by-step procedure for solving a problem.
- Best, Worst and Average CaseDifferent inputs can make the same algorithm fast or slow.
- Big O NotationDescribing how runtime or memory grows with input size.
- Binary SearchFinding an item in sorted data by halving the range each step.
- Brute ForceTrying every possibility; the baseline before optimizing.
- Coding Interview ProblemsAlgorithm puzzles used in hiring, and how they relate to real work.
- Common Complexity ClassesO(1), O(log n), O(n), O(n log n), O(n²), O(2ⁿ) and what they feel like in practice.
- Linear SearchChecking every element in turn.
- Sorting AlgorithmsBubble, insertion, merge, quick and heap sort, and their trade-offs.
- Space ComplexityHow memory use grows with input size.
- Time ComplexityHow the number of steps grows with input size.
- Binary and HexadecimalBase-2 and base-16 number systems.
- Bits and BytesThe basic units of data, and KB vs KiB.
- Boolean LogicAND, OR, NOT and De Morgan's laws.
- LogarithmsWhy repeatedly halving something gives O(log n).
- ModuloThe remainder after division; used for wraparound and hashing.
- Rounding and MoneyNever store money as a float; use integers or decimals.
- 32-bit vs 64-bitThe size of numbers and addresses a CPU handles natively.
- CPUThe processor that executes instructions.
- CPU CoreAn independent processing unit; modern CPUs have several.
- RAMFast, temporary memory for running programs.
- SSD vs HDDStorage types and their very different speeds.
- Exit CodeThe number a program returns when it ends; 0 means success.
- File PermissionsRead, write and execute rights for user, group and others.
- File SystemHow files and directories are stored and organized.
- Operating SystemSoftware that manages hardware and runs programs.
- stdin, stdout, stderrThe three standard streams every process starts with.
- Symbolic LinkA file that points to another path.
- Programming ParadigmsStyles of programming: imperative, object-oriented, functional, declarative.
- Syntax vs SemanticsWhat code looks like vs what it means.
- TranspilerA compiler from one high-level language to another, like TypeScript to JavaScript.
- DNSThe internet's phone book, turning names into IP addresses.
- Domain NameA human-readable address like example.com.
- IP AddressA numeric address identifying a device on a network.
- Latency vs BandwidthHow long data takes to arrive vs how much can flow at once.
- localhost / 127.0.0.1The address that always means "this machine".
- PortA number identifying a specific service on a host.
- 2xx Success Codes200 OK, 201 Created, 204 No Content and friends.
- 3xx Redirects301, 302, 307, 308 and when to use each one.
- 4xx Client Errors400, 404, 409, 422, 429: the client did something wrong.
- 5xx Server Errors500, 502, 503, 504: the server failed.
- Content-TypeThe header declaring a body's format, like application/json.
- HTTP HeadersMetadata attached to requests and responses.
- HTTP RequestA method, URL, headers and an optional body.
- HTTP ResponseA status code, headers and a body.
- OriginScheme + host + port: the browser's security boundary.
- Query StringKey-value parameters after the ? in a URL.
- RedirectSending a client to a different URL.
- URL EncodingEscaping special characters in URLs as %XX.
- User-AgentThe header identifying the client software.
- Let's EncryptA free, automated certificate authority.
- TLS CertificateA file proving a server controls a domain, signed by a trusted authority.
- APIAn interface that lets programs talk to each other.
- Resource NamingPlural nouns, nested paths and consistent URL design.
- SerializationConverting objects to bytes or text for storage or transfer.
- YAMLA human-friendly data format common in configuration files.
- Browser CacheThe browser storing responses so it doesn't download them again.
- Browser CompatibilityMaking sure features work across browsers, e.g. by checking caniuse.
- Browser StorageCookies, localStorage, sessionStorage and IndexedDB.
- PolyfillCode that adds a missing feature to older browsers.
- sessionStorageKey-value storage that's cleared when the tab closes.
- Web BrowserThe program that fetches, renders and runs web pages.
- PollingAsking the server repeatedly whether something changed.
- async and deferLoading scripts without blocking page rendering.
- AttributeExtra information on an element, like href or alt.
- Data AttributesCustom data-* attributes for storing extra info on elements.
- Element and TagThe building blocks of HTML, like <p> and <a>.
- Head and Meta TagsTitle, description, viewport and other page metadata.
- HTMLThe markup language that structures web pages.
- HTML EntitiesEscaped characters like & and <.
- Input Typesemail, number, date and others, with the keyboards and validation they bring.
- Open Graph TagsMetadata controlling how links preview on social media.
- SVGVector graphics described in markup.
- Viewport Meta TagThe tag that makes pages scale correctly on phones.
- BEMA class naming convention: block__element--modifier.
- box-sizingWhether an element's width includes its padding and border.
- CSSThe language that styles web pages.
- CSS InheritanceProperties like color passing down to child elements.
- CSS Reset / NormalizeRemoving differences between browsers' default styles.
- Custom Properties (CSS Variables)Reusable values defined in CSS that can change at runtime.
- Dark ModeSupporting a dark color scheme with prefers-color-scheme or a toggle.
- displayblock, inline, inline-block, flex, grid and none.
- Mobile-FirstDesigning for small screens first, then enhancing for larger ones.
- Positioningstatic, relative, absolute, fixed and sticky.
- Pseudo-classesStates like :hover, :focus and :nth-child.
- Pseudo-elements::before and ::after for styling parts of an element.
- Sass / CSS PreprocessorsLanguages adding variables, nesting and mixins that compile to CSS.
- The CascadeHow origin, specificity and order combine to resolve styles.
- TransformsMoving, scaling and rotating elements without affecting layout.
- TransitionsSmoothly animating between property values.
- Utility-First CSS (Tailwind)Styling with small single-purpose classes directly in markup.
- ECMAScriptThe standard JavaScript implements, with a new version every year.
- Event Bubbling and CapturingEvents travelling up (and down) the DOM tree.
- Event DelegationOne listener on a parent handling events for many children.
- HoistingDeclarations behaving as if moved to the top of their scope.
- JavaScriptThe programming language of the web.
- JSON.parse and JSON.stringifyConverting between JSON text and JavaScript values.
- Node.jsA JavaScript runtime for servers and tooling.
- Optional Chaining and Nullish Coalescing?. and ?? for handling missing values safely.
- preventDefault and stopPropagationCancelling default browser behavior or further event propagation.
- Template LiteralsBacktick strings with interpolation.
- this in JavaScriptHow this is determined by the way a function is called.
- ThrottleActing at most once per interval, e.g. for scroll handlers.
- Web APIsThe browser's built-in APIs: clipboard, geolocation, notifications and more.
- Component LibraryReady-made components like MUI, shadcn/ui or Radix.
- Component LifecycleMounting, updating and unmounting.
- Dependency ArrayThe list that decides when an effect or memo reruns.
- File-Based RoutingRoutes defined by the folder structure.
- JSXHTML-like syntax inside JavaScript.
- Prop DrillingPassing props through many layers that don't use them.
- Re-renderingA component running again because its state or props changed.
- RefsDirect references to DOM nodes or values that persist across renders.
State Management & Data Fetching
- Local vs Global StateKeeping state close to where it's used unless it's truly shared.
- Single Source of TruthEach piece of data has exactly one authoritative owner.
- State ManagementDeciding where data lives in an app and how it changes.
- Client-Side Rendering (CSR)The browser builds the page with JavaScript.
- Multi-Page Application (MPA)Traditional sites where each page is a full load.
- SEOMaking pages discoverable and well ranked by search engines.
- Single-Page Application (SPA)One HTML page whose content changes through JavaScript.
- sitemap.xml and robots.txtTelling crawlers what to index and what to skip.
- Static Site Generation (SSG)Building HTML once, at build time.
- Bundle SizeHow much JavaScript users have to download.
- LighthouseGoogle's tool for auditing performance, accessibility and SEO.
- MinificationShrinking code by removing whitespace and shortening names.
- Skeleton ScreenPlaceholder shapes shown while content loads.
- Web PerformanceHow fast pages load and respond.
- Accessible FormsLabels, error messages and instructions that are announced correctly.
- Screen ReaderSoftware that reads the interface aloud for blind and low-vision users.
- Visible FocusNever removing the focus outline without a replacement.
- Dev ServerA local server that rebuilds as you edit.
- Hot Module ReplacementSwapping changed modules into the running app without a reload.
- node_modulesWhere installed packages live, and why it gets so big.
- Static AssetsImages, fonts and files served as-is.
- ViteA fast dev server and bundler for modern frontends.
- Empty StateWhat to show when there's no data yet.
- Error MessagesMessages that say what went wrong and how to fix it.
- Locale-Aware FormattingFormatting numbers, currencies and dates per locale with Intl.
- Pixel Perfect vs Good EnoughKnowing when to match a design exactly and when to push back.
- UX BasicsUsability, feedback, affordances and consistency.
- BackendThe server side: business logic, data and integrations.
- Business LogicThe rules that make your product what it is.
- ConfigurationSettings that change between environments, kept out of code.
- Environments (dev, staging, prod)Separate deployments for development, testing and real users.
- File UploadsAccepting, validating and storing files from users.
- Filtering and SortingLetting clients narrow down and order results.
- Input ValidationChecking every input at the boundary before using it.
- Log LevelsDEBUG, INFO, WARN and ERROR, and when to use each.
- LoggingRecording what the application does so you can debug it later.
- MVCModel-View-Controller: separating data, presentation and input handling.
- PaginationReturning large result sets one page at a time.
- TimeoutsNever waiting forever on a network call.
- Web FrameworkLibraries like Express, Django, Spring or FastAPI for building web apps.
- Web ServerSoftware that accepts HTTP requests and returns responses.
- Web Servers (Nginx, Apache, Caddy)The common servers that sit in front of applications.
- 429 Too Many RequestsThe status returned when a client goes over a rate limit.
- API Naming ConventionsConsistent casing, plurals and verbs across endpoints.
- Breaking ChangeA change that forces clients to update.
- CRUDCreate, Read, Update, Delete: the four basic data operations.
- DatabaseOrganized, persistent storage for data.
- Database Client / GUITools like psql, DBeaver or TablePlus for exploring databases.
- Database SchemaThe structure of tables, columns and relationships.
- Foreign KeyA column referencing another table's primary key.
- JOINCombining rows from several tables.
- NULL in SQLThree-valued logic, and why NULL = NULL isn't true.
- One-to-Many and Many-to-ManyThe basic kinds of relationship and how to model them.
- PostgreSQL, MySQL and SQLiteThe common relational databases and where each one fits.
- Primary KeyA column that uniquely identifies each row.
- Relational DatabaseData stored in tables with rows, columns and relationships.
- SELECT, WHERE, ORDER BYReading, filtering and sorting rows.
- SQLThe language for querying relational databases.
- Table, Row, ColumnThe basic structure of relational data.
- Database IndexA lookup structure that speeds up queries at the cost of slower writes.
- N+1 Query ProblemOne query for a list, then one more query for every item in it.
- NoSQLDatabases not built on the relational table model.
- Object StorageStoring files as objects, as in S3.
- Seed DataInitial data loaded for development or tests.
- Cache Hit and MissWhether the requested data was found in the cache.
- CachingKeeping copies of data somewhere faster to avoid repeated work.
- TTL (Time to Live)How long a cached item stays valid.
- CSV Import / ExportMoving tabular data in and out, with all its edge cases.
- File StorageWhere uploaded files live: local disk, object storage or a CDN.
- MIME TypeThe standard label for a file's format, like image/png.
- Sign-Up and Email VerificationCreating accounts and confirming the user owns the email address.
- Slugs and Readable URLsTurning titles into URL-safe identifiers, and handling duplicates and renames.
- Client-Server ModelClients make requests; servers respond.
- MonolithOne deployable application containing all the features.
- CDNA network of edge servers serving content close to users.
- Load BalancerDistributing traffic across servers.
- Static Content HostingServing files straight from storage or a CDN instead of your app.
- BackupsCopies of data for restoring, and why untested backups don't count.
- LatencyThe time a single operation takes.
Authentication & Authorization
- 401 Unauthorized vs 403 Forbidden401 means "I don't know who you are"; 403 means "I know who you are, and you can't do this."
- API KeyA long random secret identifying a calling application rather than a user.
- Basic AuthenticationSending a username and password with every request, Base64-encoded.
- Bearer TokenA token that grants access to whoever presents it, sent in the Authorization header.
- CredentialAnything used to prove identity: a password, key, token or certificate.
- SessionServer-side memory of a logged-in user, referenced by a random ID the browser sends on each request.
- IDORReaching other users' data by changing an ID; a missing authorization check.
- Input SanitizationCleaning untrusted input, and why validation and escaping matter more.
- Output Encoding / EscapingEscaping data for the context it's inserted into.
- SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.
- Base64An encoding of bytes as text; not encryption.
- Don't Roll Your Own CryptoUse vetted libraries; homemade cryptography is almost always broken.
- Encryption in TransitEncrypting data as it travels, with TLS.
- Hashing vs Encryption vs EncodingA one-way fingerprint vs reversible with a key vs just a different format.
- Keeping Sensitive Data Out of LogsNever logging passwords, tokens or personal data.
- Phishing and Social EngineeringAttacks that trick people instead of breaking code.
- Principle of Least PrivilegeGive every user and service only the access it needs.
- PIIPersonally identifiable information that needs special care.
- Archiving and Compression (tar, gzip, zip)Bundling and compressing files.
- Basic Shell Commandsls, cd, cp, mv, rm, cat, less and find.
- LinuxThe operating system most servers run.
- OS Package Managers (apt, dnf, brew)Installing system software.
- sudo and rootRunning commands with administrator privileges.
- Virtual MachineA fully emulated computer running on shared hardware.
- ContainerA lightweight, isolated package of an app and its dependencies.
- Container LogsReading a container's stdout and stderr.
- Container RegistryWhere images are stored and pulled from.
- Container vs Virtual MachineSharing the host kernel vs emulating a full machine.
- DockerThe most common tool for building and running containers.
- Docker ComposeRunning multi-container setups from one YAML file.
- DockerfileThe recipe for building an image.
- Ephemeral Container FilesystemAnything written inside a container disappears when it's removed.
- ImageA read-only template that containers are created from.
- Port MappingExposing a container's port on the host.
- VolumePersistent storage that outlives a container.
- AWS, GCP and AzureThe three biggest cloud providers.
- Cloud ComputingRenting computing resources on demand.
- IaaS, PaaS, SaaSHow much of the stack the provider manages for you.
- S3 / Blob StorageCheap, durable object storage.
- ServerA machine, or a program on one, that provides a service to clients.
- Build ArtifactThe packaged output of a build, deployed as-is.
- CI PipelineThe sequence of automated build, test and deploy steps.
- GitHub ActionsGitHub's built-in CI/CD.
- Preview EnvironmentA temporary deployment for each pull request.
- RollbackReturning to the previous version when a deploy goes wrong.
- Staging EnvironmentA production-like environment for final testing.
- DashboardA visual display of key metrics.
- MonitoringWatching known metrics and alerting when they go wrong.
- Uptime MonitoringChecking from the outside that a site responds.
- IncidentAn unplanned event that disrupts or degrades service.
- Large Language ModelA model trained on huge amounts of text to understand and generate language.
- AgileDelivering in small increments and adapting to feedback.
- BacklogThe prioritized list of work that hasn't started yet.
- Backlog RefinementClarifying and sizing upcoming work.
- Daily StandupA short daily sync on progress and blockers.
- EpicA large body of work split into smaller stories.
- KanbanVisualizing work on a board and limiting work in progress.
- RetrospectiveA regular meeting to reflect on how the team works and improve it.
- ScrumAn agile framework with sprints, roles and ceremonies.
- Software Development LifecycleThe stages from idea to production to maintenance.
- SprintA fixed period, often two weeks, to deliver planned work.
- Sprint PlanningChoosing the work for the next sprint.
- Sprint Review / DemoShowing what was built to stakeholders.
- User Story"As a user, I want… so that…": a requirement from the user's point of view.
- WaterfallSequential phases from requirements to release.
- Planning PokerEstimating as a team by revealing guesses at the same time.
- Story PointsRelative effort estimates instead of hours.
- TimeboxingFixing the time and adjusting the scope.
- 1:1 MeetingsRegular private conversations with your manager.
- Giving a DemoShowing your work clearly to an audience.
- Receiving FeedbackListening, asking for specifics, and acting on it.
- Working with DesignersCollaborating on how it should look and behave.
- Working with QACollaborating with testers to ship quality.
- Writing ClearlyLead with the point, be specific, keep it short.
- Edge CasesUnusual inputs and situations that break naive code.
- RequirementsWhat the software must do.
- User EmpathyRemembering a real person uses what you build.
- Context Switching CostWhy jumping between tasks destroys productivity.
- Deep Work / Focus TimeLong, uninterrupted blocks for hard problems.
- Done Is Better Than PerfectShipping working software instead of polishing forever.
- Finding a MentorGetting guidance from someone more experienced.
- Fundamentals over FrameworksFrameworks change; the concepts underneath them don't.
- Impostor SyndromeFeeling you don't belong despite the evidence.
- Keeping an Engineering JournalWriting down what you learn, decide and get stuck on.
- Learning How to LearnDeliberate practice, spaced repetition and building things.
- Onboarding YourselfUsing code, docs and history to learn a new codebase.
- Time ManagementPlanning your day, protecting focus time and finishing what you start.
- Tutorial HellEndlessly following tutorials without building anything on your own.
- Behavioral Interview (STAR)Answering with Situation, Task, Action and Result.
- BurnoutChronic work stress, and how to notice and prevent it.
- Career LadderThe levels and expectations from junior to principal.
- Contributing to Open SourceFinding issues, following the guidelines and opening PRs.
- Job SearchResumes, portfolios, applications and referrals.
- Junior EngineerLearning to deliver well-defined tasks with guidance.
- Performance ReviewA periodic assessment of your work.
- Side ProjectsBuilding outside work to learn and to show your skills.
- Sustainable PaceWorking at a pace you can keep up for years.
- Technical InterviewsCoding, system design and behavioral rounds.
Mid-level
Own a feature end to end without hand-holding.
Core: start here
- Discriminated UnionA union whose members are told apart by a tag field.
- GenericsCode that works over many types while keeping type safety.
- Runtime ValidationChecking that untrusted data matches a type at runtime, e.g. with Zod or Pydantic.
- Type NarrowingRefining a broad type to a specific one through checks.
- Utility TypesBuilt-in TypeScript type transformers like Partial, Pick and Record.
- Event LoopA single thread running tasks from a queue, as in JavaScript and asyncio.
- Race ConditionA bug where the result depends on unpredictable timing.
- Merge vs RebasePreserving history as it happened vs rewriting it to be linear.
- Giving Code ReviewReviewing others' code helpfully: priorities, tone and turnaround.
- Root Cause AnalysisFinding the underlying reason, not just the symptom.
- Testing PyramidMany unit tests, fewer integration tests, few end-to-end tests.
- Visual Regression TestDetecting unintended UI changes by comparing screenshots.
- CohesionHow closely the parts of a module belong together; more is better.
- CouplingHow much modules depend on each other's internals; less is better.
- SOLID PrinciplesFive object-oriented design principles for maintainable code.
- HTTP CachingCache-Control, ETag and Last-Modified for reusing responses.
- Container QueryStyling a component by the size of its container instead of the screen.
- z-index and Stacking ContextHow elements layer, and why z-index: 9999 sometimes does nothing.
- Microtasks vs MacrotasksWhy promise callbacks run before setTimeout callbacks.
- ContextSharing values across a component tree without prop drilling.
- Custom HookExtracting reusable stateful logic into a hook.
- HydrationAttaching interactivity to server-rendered HTML.
- memo, useMemo and useCallbackSkipping work when inputs haven't changed.
- Meta-FrameworkFrameworks like Next.js, Nuxt, SvelteKit and Remix that add routing and rendering.
- Unnecessary Re-rendersRenders that change nothing, and how to avoid them.
State Management & Data Fetching
- Data Fetching LibrariesTools like TanStack Query and SWR that cache and sync server data.
- Form State ManagementValues, touched fields, errors and submission state.
- Global StoreA central container for shared app state, like Redux or Zustand.
- Optimistic UpdateUpdating the UI before the server confirms, and rolling back on failure.
- Server State vs Client StateCached copies of server data vs purely UI state.
- URL as StateKeeping filters, tabs and pagination in the URL so it can be shared.
- CSR vs SSR vs SSGChoosing a rendering strategy for SEO, speed and complexity.
- Server-Side Rendering (SSR)The server builds HTML for each request.
- Code SplittingLoading code only for the page or feature being used.
- Core Web VitalsGoogle's metrics for loading, interactivity and visual stability.
- Cumulative Layout Shift (CLS)How much the page jumps around while it loads.
- Interaction to Next Paint (INP)How quickly the page responds to user input.
- Largest Contentful Paint (LCP)When the main content becomes visible.
- Tree ShakingRemoving unused code from bundles.
- Accessible NameThe text assistive technology announces for an element.
- ARIAAttributes that add accessibility information when HTML alone isn't enough.
- First Rule of ARIAUse a native HTML element instead of ARIA whenever possible.
- Focus ManagementMoving focus sensibly in modals, route changes and dynamic content.
- WCAGThe Web Content Accessibility Guidelines and their A, AA and AAA levels.
- Design SystemShared components, tokens and guidelines for consistent UI.
- Design TokensNamed values for color, spacing and type shared across platforms.
- Internationalization (i18n)Preparing software for many languages and regions.
- Feature FlagsTurning features on and off without deploying.
Authentication & Authorization
- CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
- OAuth 2.0A framework for letting an app act on a user's behalf without seeing their password.
- Refresh TokenA long-lived credential used only to get new short-lived access tokens without logging in again.
- Content Security PolicyA header restricting which scripts and resources a page may load.
- PrioritizationDeciding what to do first: impact vs effort, urgent vs important.
- Giving FeedbackFeedback that's specific, timely, kind and actionable.
- Product ThinkingUnderstanding the user problem behind the ticket.
- ImpactOutcomes that matter to the business, not just output.
- OwnershipTaking responsibility for outcomes, not just tasks.
538 more mid-level concepts
- Bitwise OperationOperating on individual bits: AND, OR, XOR and shifts.
- Pattern MatchingBranching on the shape of data and destructuring it at the same time.
- Tail RecursionRecursion where the call is the last action, which some languages turn into a loop.
- GeneratorA function that lazily yields a sequence of values.
- IteratorAn object that yields items one at a time from a sequence.
- Lazy EvaluationComputing values only when they're actually needed.
- Abstract ClassA class that can't be instantiated and leaves some methods to subclasses.
- Composition over InheritanceBuilding behavior by combining objects instead of deep class hierarchies.
- InterfaceA contract of methods a type promises to implement.
- Method OverloadingSeveral methods with the same name but different parameters.
- Mixin / TraitReusable behavior added to classes without inheritance.
- Prototypal InheritanceJavaScript's model where objects inherit directly from other objects.
- CurryingTurning a multi-argument function into a chain of single-argument ones.
- Function CompositionCombining functions so the output of one feeds the next.
- Functional ProgrammingBuilding programs from pure functions and immutable data.
- ImmutabilityNever changing data after creation, producing new values instead.
- MemoizationCaching a function's results for inputs it has already seen.
- Option / Maybe TypeA type that explicitly represents "a value or nothing".
- Partial ApplicationFixing some arguments of a function to get a new function.
- Result / Either TypeA type that represents success or failure without exceptions.
- Custom ExceptionA domain-specific error type carrying meaningful context.
- Defensive ProgrammingWriting code that guards against invalid inputs and states.
- Error BoundaryA UI component that catches rendering errors in its children.
- Error Values vs ExceptionsReturning errors as values vs throwing them.
- Fail FastStopping loudly on problems instead of continuing in a bad state.
- Graceful DegradationLosing non-critical features instead of failing completely.
- Duck TypingIf it has the right methods, it's the right type.
- Finite State MachineA model with a fixed set of states and allowed transitions, e.g. an order going from paid to shipped.
- Intersection TypeA type combining all the members of several types.
- Structural vs Nominal TypingCompatible by shape vs compatible by declared name.
- Type GuardA check that tells the type checker a value's specific type.
- Type InferenceThe compiler working out types without annotations.
- Blocking vs Non-blocking I/OWhether waiting for I/O stops the thread.
- CancellationStopping in-flight async work cleanly, e.g. with AbortController or a context.
- Check-Then-Act Race (TOCTOU)Checking a condition and acting on it as two steps, so something changes in between.
- Concurrency vs ParallelismDealing with many things at once vs doing many things at once.
- CoroutineA function that can pause and resume; the basis of async/await.
- Web WorkerRunning JavaScript on a background thread in the browser.
- Garbage CollectionAutomatic reclamation of memory that's no longer reachable.
- Language Runtime / VMThe environment that executes your code: JVM, V8, CPython, CLR.
- Memory LeakMemory that's never released, growing until the program slows or crashes.
- Stack vs HeapShort-lived call frames vs dynamically allocated, longer-lived memory.
- BisectBinary-searching history to find the commit that introduced a bug.
- Cherry-PickApplying one specific commit onto another branch.
- Fast-Forward vs Merge CommitMoving a branch pointer ahead vs recording a merge commit.
- Git HooksScripts that run on Git events, like linting before a commit.
- Git LFSStoring large binary files outside normal Git history.
- Interactive RebaseRewriting commits: squash, reorder, edit, drop.
- MonorepoMany projects living in one repository.
- ReflogGit's log of where HEAD has been; your undo history after disasters.
- Removing Secrets from Git HistoryPurging a committed secret with git filter-repo, and why you must rotate it anyway.
- Rewriting Shared HistoryWhy rebasing or force-pushing shared branches breaks teammates.
- Signed CommitsCryptographically proving who authored a commit.
- SubmoduleA repository embedded inside another at a fixed commit.
- Branching StrategyThe team's rules for how branches are created and merged.
- Git FlowA model with develop, feature, release and hotfix branches.
- Long-Lived BranchA branch kept for weeks, and the painful merges that follow.
- Release BranchA branch stabilized for shipping a specific version.
- Release NotesA user-facing explanation of what changed in a release.
- Trunk-Based DevelopmentEveryone merges small changes to main frequently.
- AI-Assisted Code ReviewUsing AI reviewers as a first pass, not a replacement for human review.
- CODEOWNERSA file that assigns required reviewers by path.
- CONTRIBUTING GuideA file explaining how to propose changes to a project.
- Merge Commit vs Squash vs Rebase MergeHow a PR lands on main and what history it leaves behind.
- Mob ProgrammingA whole team working on one problem together.
- Review TurnaroundHow quickly reviews happen, and why it matters to team speed.
- Conditional BreakpointPausing only when a condition is true.
- Five WhysAsking "why" repeatedly to get from a symptom to its root cause.
- HeisenbugA bug that disappears when you try to observe it.
- ProfilerA tool that measures where time or memory goes.
- Remote DebuggingAttaching a debugger to code running somewhere else.
- Acceptance TestVerifying a feature meets the agreed requirements.
- Behavior-Driven DevelopmentSpecifying behavior as plain-language scenarios shared with non-developers.
- Deterministic TestsControlling time, randomness and network so tests always behave the same.
- FakeA working but simplified implementation, like an in-memory database.
- Given / When / ThenDescribing tests as context, action and expected outcome.
- Mock ServerA fake API that returns canned responses, for testing clients in isolation.
- Over-MockingMocking so much that tests check implementation instead of behavior.
- Performance TestingMeasuring speed and resource use; load, stress, soak and spike tests.
- Red, Green, RefactorThe three-step TDD cycle.
- SpyA test double that records calls to a real or fake function.
- Test Data Builder / FactoryHelpers that create valid test objects with sensible defaults.
- Test DoubleAny stand-in for a real dependency in tests.
- Test-Driven DevelopmentWriting a failing test first, then the code to pass it, then refactoring.
- Testing TrophyA frontend-oriented model that favors integration tests.
- Broken Windows TheorySmall neglected messes invite bigger ones.
- Chesterton's FenceDon't remove something until you know why it was put there.
- Command-Query SeparationA method should either change state or return data, not both.
- Convention over ConfigurationSensible defaults so you only configure what's unusual.
- Cyclomatic ComplexityA count of independent paths through code; a rough complexity measure.
- Dependency Inversion Principle (D)Depend on abstractions, not concrete implementations.
- Encapsulate What VariesIsolating the parts that change from the parts that stay the same.
- Feature EnvyA method more interested in another class's data than its own.
- God ObjectA class that knows and does too much.
- IdempotenceDoing something twice has the same effect as doing it once.
- Interface Segregation Principle (I)Clients shouldn't depend on methods they don't use.
- Law of DemeterOnly talk to your immediate neighbors; avoid a.b().c().d().
- Liskov Substitution Principle (L)Subtypes must work anywhere their parent type is expected.
- Open/Closed Principle (O)Open for extension, closed for modification.
- Premature AbstractionGeneralizing before you have enough examples, creating the wrong abstraction.
- Primitive ObsessionUsing raw strings and ints where a small domain type belongs.
- Principle of Least AstonishmentCode and APIs should behave the way people expect.
- Program to an InterfaceDepending on what something does rather than which class it is.
- Rule of ThreeTolerating duplication until the third time, to avoid the wrong abstraction.
- Shotgun SurgeryOne change requiring edits in many scattered places.
- Single Responsibility Principle (S)A module should have one reason to change.
- Tell, Don't AskTell objects what to do instead of querying their state and deciding for them.
- Characterization TestA test that captures current behavior before you change legacy code.
- Extract ClassSplitting a class that does too much.
- Introduce Parameter ObjectGrouping parameters that travel together into one object.
- Legacy CodeCode without tests that you're afraid to change.
- Replace Conditional with PolymorphismSwapping a type switch for subclasses or strategies.
- AdapterWrapping an interface to make it match another.
- Anti-PatternA common solution that looks right but causes problems.
- BuilderConstructing complex objects step by step.
- Chain of ResponsibilityPassing a request along handlers until one deals with it; how middleware works.
- CommandTurning a request into an object you can queue, log or undo.
- CompositeTreating individual objects and groups of them uniformly, as a tree.
- DecoratorAdding behavior to an object by wrapping it.
- Dependency InjectionPassing dependencies in instead of creating them inside.
- Design PatternA named, reusable solution to a recurring design problem.
- FacadeA simple interface over a complex subsystem.
- Factory MethodLetting subclasses or functions decide which class to instantiate.
- Gang of FourThe 1994 book that catalogued 23 classic patterns.
- Inversion of ControlA framework calls your code rather than your code calling it.
- Iterator PatternTraversing a collection without exposing its internals.
- MiddlewareA pipeline of functions wrapped around request handling.
- Null ObjectA do-nothing object used instead of null checks.
- ObserverNotifying subscribers when something changes.
- ProxyA stand-in that controls access to another object.
- Publish-SubscribeSenders publish to topics; receivers subscribe without knowing each other.
- SingletonEnsuring a class has exactly one instance; often an anti-pattern.
- StateChanging an object's behavior when its internal state changes.
- StrategySwapping algorithms behind a common interface.
- Template MethodA base algorithm whose steps subclasses fill in.
- Code GenerationGenerating boilerplate from schemas or templates.
- Dependency HellConflicting version requirements that can't all be satisfied.
- Dev ContainersA reproducible development environment defined as a container.
- DotfilesYour personal config files, often kept in Git.
- jqA command-line JSON processor.
- Language Server ProtocolThe protocol that gives editors autocomplete and diagnostics for any language.
- MakefileA classic way to define project tasks and their dependencies.
- Reading Library Source CodeReading a library's code when its docs don't answer your question.
- Shell ScriptingAutomating tasks with shell scripts.
- SSHSecurely logging into and running commands on remote machines.
- Static AnalysisFinding bugs by analyzing code without running it.
- Transitive DependencyA dependency of one of your dependencies.
- Agent Instruction FilesRepository files like CLAUDE.md or AGENTS.md that tell AI agents the project's conventions.
- Coding AgentAn AI that plans, edits across files and runs commands on its own.
- Context WindowHow much text a model can consider at once.
- Model Context Protocol (MCP)A standard for connecting AI assistants to tools and data.
- API DocumentationReference docs for an API's endpoints, parameters and errors.
- Architecture DiagramA box-and-arrow picture of a system's components and data flow.
- Class DiagramA diagram of classes, their fields and relationships.
- Diagrams as CodeWriting diagrams as text, with tools like Mermaid or PlantUML.
- Docs as CodeKeeping docs in the repository and reviewing them like code.
- Onboarding DocumentationDocs that get a new teammate productive quickly.
- RunbookStep-by-step instructions for operating or fixing a system.
- Sequence DiagramA diagram of messages passed between components over time.
- State DiagramA diagram of states and the transitions between them.
- UMLA standard visual language for software diagrams.
- Adjacency List vs MatrixTwo ways to store a graph's edges.
- Binary Search TreeA binary tree ordered so each lookup can halve the search.
- DequeA double-ended queue that adds and removes at both ends.
- Directed Acyclic Graph (DAG)A graph with directed edges and no cycles, as in build systems and pipelines.
- Doubly Linked ListA linked list with pointers in both directions.
- GraphNodes connected by edges; models networks, dependencies and maps.
- Hash CollisionTwo keys hashing to the same slot, and how tables handle it.
- HeapA tree that keeps the min or max at the root; backs priority queues.
- LRU CacheA cache evicting the least recently used item, built from a hash map and a linked list.
- Priority QueueA queue that always returns the highest-priority item first.
- Tree TraversalVisiting tree nodes in pre-order, in-order, post-order or level order.
- TrieA tree of characters for fast prefix lookups.
- Amortized AnalysisThe average cost per operation over a sequence of operations.
- BacktrackingTrying choices and undoing them when they lead nowhere.
- Big Omega and Big ThetaLower bounds and tight bounds, alongside Big O's upper bound.
- Breadth-First SearchExploring a graph level by level; finds shortest unweighted paths.
- Depth-First SearchExploring a graph as deep as possible before backtracking.
- Divide and ConquerSplitting a problem into smaller ones and combining the results.
- Dynamic ProgrammingSolving overlapping subproblems once and reusing the answers.
- Greedy AlgorithmTaking the locally best choice at each step.
- Merge SortSplit in half, sort each half, merge: a stable O(n log n) sort.
- QuicksortPartitioning around a pivot; fast in practice, O(n²) in the worst case.
- Sliding WindowMaintaining a moving range over a sequence.
- Stable SortA sort that keeps equal elements in their original order.
- Topological SortOrdering tasks so every dependency comes first.
- Two PointersWalking two indexes through data to avoid nested loops.
- CombinatoricsCounting arrangements and combinations, e.g. how many IDs a format allows.
- Discrete MathLogic, sets, graphs and combinatorics: the math of computing.
- Percentiles (p50, p95, p99)The value below which a given share of measurements fall; the right way to read latency.
- Probability BasicsReasoning about chance, for sampling, A/B tests and failure rates.
- Set TheoryUnions, intersections and differences; the basis of SQL.
- Statistics for EngineersMean, median, percentiles and variance.
- CPU CacheSmall, very fast memory close to the CPU (L1, L2, L3).
- GPUA processor for massively parallel work like graphics and ML.
- How a CPU Executes ProgramsFetch, decode, execute: how instructions actually run.
- Instruction Set (x86, ARM)The machine instructions a CPU family understands.
- Latency Numbers Every Programmer Should KnowRough costs of cache, memory, disk and network access.
- Out of Memory (OOM)Running out of memory, and the OOM killer that ends processes.
- Abstract Syntax Tree (AST)A tree of code's structure that linters, formatters and compilers work on.
- CompilerA program that translates source code into another form.
- Decorators / AnnotationsSyntax for attaching behavior or metadata to functions and classes.
- InterpreterA program that executes source code directly.
- ParserTurning text into a structured representation.
- ReflectionA program inspecting its own structure at runtime.
- Connect Timeout vs Read TimeoutWaiting to establish a connection vs waiting for data on it.
- DNS Record TypesA, AAAA, CNAME, MX, TXT, NS and what each one does.
- DNS TTL and PropagationHow long DNS answers are cached, and why changes take time to spread.
- FirewallRules that allow or block network traffic.
- IPv4 vs IPv632-bit vs 128-bit addresses, and why IPv6 exists.
- Keep-Alive ConnectionsReusing one connection for many requests.
- OSI ModelA seven-layer model of how network communication is structured.
- PacketA unit of data sent over a network.
- Round-Trip Time (RTT)The time for a message to go out and a reply to come back.
- SocketAn endpoint for sending and receiving data over a network.
- TCPReliable, ordered, connection-based transport.
- TCP Three-Way HandshakeSYN, SYN-ACK, ACK: how a TCP connection starts.
- TCP/IP ModelThe practical four-layer model the internet actually runs on.
- ThroughputHow much work or data gets through per unit of time.
- UDPFast, connectionless transport with no delivery guarantees.
- VPNAn encrypted tunnel into another network.
- Cache-ControlThe header that directs how responses may be cached.
- Content NegotiationClient and server agreeing on format and language through Accept headers.
- ETagA version identifier used for conditional requests and caching.
- HSTSA header telling browsers to always use HTTPS for a site.
- HTTP Compressiongzip and Brotli shrinking responses on the wire.
- HTTP ProxyAn intermediary that forwards HTTP requests.
- HTTP/1.1The text-based HTTP version with one request at a time per connection.
- HTTP/2Binary framing and many requests multiplexed over one connection.
- Long PollingHolding a request open until the server has news.
- multipart/form-dataThe encoding used to upload files from forms.
- Preflight RequestThe OPTIONS request a browser sends before certain cross-origin calls.
- Safe and Idempotent MethodsWhich HTTP methods shouldn't change state, and which can be retried safely.
- Server-Sent EventsA one-way stream of events from server to browser over HTTP.
- Synchronous vs Asynchronous APIsReturning the result in the response vs accepting work and reporting later.
- WebhookAn HTTP callback: a service calls your URL when something happens.
- Webhooks vs PollingBeing notified when something changes vs repeatedly asking.
- WebSocketA persistent, two-way connection between browser and server.
- Certificate AuthorityAn organization trusted to sign certificates.
- Certificate ExpiryExpired certificates as a classic cause of outages, and automating renewal.
- Self-Signed CertificateA certificate not signed by a trusted authority, used in development.
- TLSThe protocol that encrypts and authenticates network connections.
- API Client / SDKA library wrapping an API so callers don't hand-write HTTP.
- GraphQLA query language that lets clients ask for exactly the data they need.
- GraphQL Schema and ResolversTypes describing the data, and functions that fetch each field.
- JSON SchemaA vocabulary for validating the structure of JSON.
- OpenAPIA standard format for describing REST APIs.
- Resource ModelingDeciding what your API's resources are and how they relate.
- REST ConstraintsStatelessness, uniform interface, cacheability and REST's other rules.
- RPCCalling a function on another machine as if it were local.
- tRPCEnd-to-end type-safe APIs for TypeScript without a schema language.
- XMLA verbose markup format still common in enterprise and legacy systems.
- Browser ExtensionsAdd-ons that change browser behavior, and how they can break your site.
- Critical Rendering PathThe steps from HTML bytes to pixels on screen.
- CSSOMThe browser's tree of parsed styles.
- Feature Detection vs Browser SniffingChecking whether a feature exists instead of guessing from the browser's name.
- IndexedDBAn asynchronous database built into browsers.
- JavaScript EngineThe component that runs JavaScript, like V8 or SpiderMonkey.
- Layout / ReflowComputing the position and size of every element.
- Render TreeThe combination of DOM and CSSOM that actually gets drawn.
- Service WorkerA script between the page and the network, for offline support and caching.
- Real-Time CommunicationPushing updates to clients as they happen.
- Real-Time Pub/SubBroadcasting events to subscribed clients through a broker.
- CanvasA drawable bitmap surface controlled from JavaScript.
- dialog ElementThe native modal and non-modal dialog.
- iframeEmbedding one page inside another.
- Responsive Images (srcset, picture)Serving the right image size for each screen.
- :has() SelectorSelecting a parent based on its children.
- CSS ModulesLocally scoped class names generated at build time.
- CSS-in-JSWriting styles in JavaScript alongside components.
- Keyframe AnimationsMulti-step animations defined with @keyframes.
- Logical Propertiesmargin-inline and friends, which adapt to writing direction.
- Native CSS NestingNesting selectors directly in plain CSS.
- Web FontsLoading custom fonts without layout shifts or invisible text.
- Web TypographyFonts, line height, line length and readable text.
- CommonJSNode's older require/module.exports module system.
- Deno and BunNewer JavaScript runtimes with built-in tooling.
- History APIChanging the URL without reloading; the basis of client-side routing.
- Intersection ObserverDetecting when elements enter the viewport, e.g. for lazy loading.
- Resize ObserverReacting to an element changing size.
- structuredCloneThe built-in deep copy for JavaScript values.
- Component CompositionBuilding UIs from children and slots instead of configuration flags.
- Headless ComponentsComponents that provide behavior and accessibility without styles.
- Higher-Order ComponentA function that wraps a component to add behavior.
- Hydration MismatchServer and client HTML differing, causing errors or flicker.
- PortalsRendering a child into a different part of the DOM, e.g. for modals.
- ReactivityAutomatically updating the UI when data changes.
- ReconciliationHow a framework works out what changed between renders.
- Render Props / SlotsPassing render functions or content into components.
- SignalsFine-grained reactive values that update only what depends on them.
- StorybookDeveloping and documenting components in isolation.
- Virtual DOMAn in-memory UI tree diffed to find the minimal real DOM updates.
State Management & Data Fetching
- Client Cache InvalidationKnowing when cached server data is out of date.
- Flux / Redux PatternOne-way data flow with actions, reducers and a single store.
- ReducerA pure function from (state, action) to the new state.
- Stale-While-RevalidateShowing cached data immediately while fetching fresh data in the background.
- Canonical URLTelling search engines which URL is the original.
- Hypermedia-Driven Apps (htmx)Swapping server-rendered HTML fragments instead of building a SPA.
- Progressive EnhancementA baseline that works without JavaScript, enhanced when it's available.
- Progressive Web AppA web app that can be installed and used offline like a native one.
- Rendering StrategiesWhere and when HTML gets generated.
- First Contentful PaintWhen anything first appears on screen.
- List VirtualizationRendering only the visible rows of huge lists.
- Long TasksJavaScript running over 50 ms and blocking the main thread.
- Main ThreadThe single browser thread that runs JavaScript, layout and paint.
- Perceived PerformanceMaking waits feel shorter with skeletons and instant feedback.
- Preload, Prefetch, PreconnectHints telling the browser what to fetch early.
- Real User Monitoring (RUM)Measuring performance from real users' browsers.
- Render-Blocking ResourcesCSS and scripts that delay the first paint.
- Synthetic MonitoringMeasuring with scripted visits from controlled locations.
- Time to First Byte (TTFB)How long until the first byte of the response arrives.
- Accessibility TestingAutomated checks like axe plus manual keyboard and screen reader testing.
- LandmarksRegions like header, nav and main that screen readers can jump between.
- Reduced MotionRespecting users who ask for less animation.
- Skip LinkA link that jumps past navigation to the main content.
- Asset FingerprintingContent hashes in file names so caches update correctly.
- Babel / SWCTools that transform modern JavaScript and JSX for older targets.
- BrowserslistThe config declaring which browsers your build supports.
- Keeping Dependencies UpdatedUpgrading regularly, with tools like Dependabot or Renovate.
- npm vs pnpm vs YarnJavaScript package managers and their trade-offs.
- Peer DependencyA dependency the host project must provide, like React for a component library.
- webpackThe long-dominant, highly configurable JavaScript bundler.
- A/B TestingComparing two variants with real users to see which performs better.
- Dark PatternsDeceptive UI that tricks users, and why to refuse to build it.
- Localization (l10n)Translating and adapting software for a specific locale.
- MicrointeractionsSmall animations and feedback that make UI feel responsive.
- Pluralization and ICU MessagesHandling plural rules that differ between languages.
- Product AnalyticsTracking how people use features to inform decisions.
- Spacing ScaleA consistent set of spacing values.
- Visual HierarchySize, weight and spacing guiding the eye.
- DTOA plain object for moving data between layers or over the wire.
- Layered ArchitectureControllers, services and data access as separate layers.
- Offset vs Cursor PaginationSimple page numbers vs stable, scalable cursors.
- Payments IntegrationUsing providers like Stripe safely, with webhooks and idempotency.
- Serverless FunctionsRunning code per request without managing servers.
- The Twelve-Factor AppTwelve practices for building deployable, scalable web services.
- Third-Party IntegrationsCalling payment, email and other external APIs reliably.
- Unbounded Result SetsQueries and APIs that return "everything", until everything is a million rows.
- API ContractThe agreed shape and behavior of an API.
- API DesignDesigning interfaces that are clear, consistent and hard to misuse.
- API GatewayA single entry point handling routing, auth and rate limits for many services.
- API VersioningEvolving an API without breaking existing clients.
- Backward CompatibilityNew versions that still work with old clients.
- DeprecationMarking something for removal and giving users time to migrate.
- Error Response FormatA consistent shape for API errors, like RFC 9457 Problem Details.
- Idempotency KeyA client-supplied ID that makes retried requests safe.
- OAuth Scopes and PermissionsLimiting what a token can do, e.g. read-only access.
- Rate LimitingLimiting how many requests a client can make.
- Data ModelingDesigning how your data is structured and related.
- GROUP BY and AggregatesSummarizing rows with COUNT, SUM and AVG.
- HAVINGFiltering groups after aggregation.
- INNER, LEFT, RIGHT and FULL JOINWhich rows each kind of join keeps.
- SubqueryA query nested inside another query.
- UUID vs Auto-Increment IDsSequential integers vs globally unique IDs, and their trade-offs.
Transactions & Concurrency Control
- Optimistic LockingDetecting conflicts with a version number at write time.
- Embedded DatabaseA database that runs inside your app, like SQLite.
- SQL vs NoSQLChoosing a database by data shape, consistency needs and access patterns.
- Vector DatabaseStoring embeddings for similarity search.
- Cache InvalidationRemoving stale data from a cache; famously one of the hard problems.
- Cache Key DesignChoosing keys so different data never collides.
- CDN CachingCaching content on edge servers near users.
- Retry with Exponential BackoffRetrying with growing delays so you don't hammer a failing service.
- Notification PreferencesLetting users choose which messages they get, on which channel.
- Push NotificationsSending alerts to phones and browsers through APNs, FCM or Web Push.
- Data ExportLetting users download their data, often as a background job.
- Image ProcessingResizing, cropping and converting images on upload.
- PDF GenerationProducing PDFs like invoices and reports.
- Presigned URLA temporary URL letting clients upload or download directly from storage.
- Account DeletionDeleting or anonymizing a user across every table and system.
- Approval WorkflowsMulti-step approvals modeled as explicit states and transitions.
- Entitlements and Plan LimitsDeciding which features and quotas each plan unlocks.
- InvitationsInviting people into an organization or team with expiring, single-use links.
- Organizations, Teams and MembershipsModeling accounts that many users share, with roles per membership.
- Subscription BillingPlans, trials, renewals, failed payments and dunning.
- User-Facing Activity LogShowing users who changed what and when.
- MicroservicesMany small, independently deployable services.
- N-Tier ArchitectureSeparating presentation, logic and data into tiers.
- Non-Functional RequirementsRequirements about how well a system works rather than what it does.
- Serverless ArchitectureBuilding from managed functions and services without running servers.
- Software ArchitectureThe high-level structure of a system and the decisions that are expensive to change.
- Ubiquitous LanguageOne shared vocabulary between developers and domain experts.
- Value ObjectA domain object defined only by its values, and immutable.
- Clarifying RequirementsAsking what the system must do, and at what scale, before designing it.
- Forward ProxyA proxy acting on behalf of clients.
- Reverse ProxyA server in front of your app that handles TLS, routing and caching.
- ScalabilityHandling more load by adding resources.
- System DesignDesigning the components, data flow and trade-offs of a whole system.
- System Design InterviewThe interview format, and how it differs from real design work.
- CAP TheoremDuring a network partition, you must choose consistency or availability.
- Eventual ConsistencyReplicas converge once updates stop, but reads may be stale in the meantime.
- AvailabilityThe share of time a system is usable, often measured in "nines".
- Handling Dependency FailuresDeciding what happens when something you call is down.
- Nines (99.9%, 99.99%)How much downtime each level of availability allows.
- RedundancyExtra components so a single failure isn't fatal.
- ReliabilityA system doing what it should, even when things fail.
- Single Point of FailureOne component whose failure takes everything down.
- BatchingGrouping work to reduce per-item overhead.
- BenchmarkingMeasuring performance under controlled conditions.
- BottleneckThe component that limits overall throughput.
- Cold StartThe delay when a serverless function or container starts fresh.
- Payload SizeSending fewer bytes over the wire.
- PerformanceHow fast and efficiently a system does its work.
- EventA record that something happened.
- Unix PhilosophySmall tools that do one thing well and compose through pipes.
- Chatty I/OMany small network or database calls where one bigger one would do.
- Over-FetchingRetrieving far more data than an operation needs.
Authentication & Authorization
- Access TokenA short-lived token sent with each API request to prove the caller is authenticated.
- Identity Provider (IdP)The service that authenticates users for other apps, like Okta, Auth0 or Google.
- Multi-Factor Authentication (MFA)Requiring two or more kinds of proof: something you know, have, or are.
- OpenID Connect (OIDC)An identity layer on top of OAuth 2.0 that adds login and a standard ID token.
- Password Reset FlowDesigning reset links that are single-use, short-lived and don't leak account existence.
- PKCEAn OAuth extension that stops stolen authorization codes from being exchanged by attackers.
- SameSite CookiesA cookie attribute controlling whether cookies are sent on cross-site requests.
- Token ExpiryChoosing how long tokens live, and handling what happens when they run out.
- Bot Protection and CAPTCHATelling humans apart from automated abuse.
- Broken Access ControlThe #1 OWASP risk: users acting outside their permissions.
- ClickjackingTricking users into clicking hidden elements inside an iframe.
- DDoSOverwhelming a service with traffic from many sources.
- File Upload SecurityValidating the type, size and content of uploaded files.
- Open RedirectA redirect parameter abused to send users to malicious sites.
- OWASP Top 10The ten most critical web application security risks.
- Security HeadersHTTP headers that harden browsers against attacks.
- Security MisconfigurationDefault passwords, verbose errors and exposed admin panels.
- Stored, Reflected and DOM XSSThe three kinds of XSS and where each comes from.
- Subresource IntegrityVerifying that third-party scripts haven't been tampered with.
- Trust BoundaryWhere data crosses from untrusted to trusted; validate there.
- Cryptographic Hash (SHA-256)A hash where finding collisions is infeasible.
- CryptographyThe math of keeping data secret and verifying it.
- Digital SignatureProving who created data and that it hasn't been changed.
- Public-Key CryptographyA public key encrypts or verifies; a private key decrypts or signs.
- Secure Random NumbersCryptographically secure randomness for tokens and keys.
- Symmetric EncryptionOne shared key both encrypts and decrypts, as with AES.
- Attack SurfaceEvery point where an attacker could try to get in.
- CVEA public identifier for a known vulnerability.
- Defense in DepthSeveral layers of security, so one failure isn't fatal.
- Dependency ScanningFinding known vulnerabilities in your dependencies.
- SASTStatic analysis that looks for security bugs in source code.
- Secrets ManagementKeeping API keys and passwords in a vault, not in code.
- TyposquattingMalicious packages named like popular ones.
- Zero-DayA vulnerability exploited before a fix exists.
- Cookie ConsentAsking permission before non-essential tracking.
- CopyleftLicenses that require derivative work to stay open source.
- Data MinimizationCollecting only the data you actually need.
- GDPRThe EU regulation on personal data: consent, access and deletion rights.
- Open Source LicensesMIT, Apache, GPL, and what each one lets you do.
- Text Processing (sed, awk, cut, sort)Command-line tools for slicing and transforming text.
- Bind Mounts vs VolumesMounting a host directory vs Docker-managed storage.
- ENTRYPOINT and CMDWhat runs when a container starts.
- Hot Reloading in ContainersSeeing code changes instantly while developing in Docker.
- Image Layers and Build CacheHow images are built from cached layers, and how to order steps.
- Image Tags and DigestsNaming image versions, and why :latest is risky.
- Multi-Stage BuildBuilding in one stage and shipping a small final image.
- Functions as a Service (Lambda)Running code in response to events without servers.
- IAMIdentity and access management for cloud resources.
- Regions and Availability ZonesGeographic locations, and isolated data centers within them.
- Infrastructure as CodeDefining infrastructure in versioned files instead of clicking in consoles.
- App Store ReleasesWhy mobile releases can't be rolled back instantly.
- Blue-Green DeploymentSwitching traffic between two identical environments.
- Build CachingReusing previous build outputs to make CI fast.
- Canary ReleaseReleasing to a small share of users first.
- Continuous Delivery / DeploymentKeeping every change releasable, or releasing it automatically.
- Deploy vs ReleaseShipping code vs exposing it to users.
- Deployment FreezeA period when deploys are paused, like around holidays.
- Roll ForwardFixing a bad deploy with a new deploy instead of reverting.
- Secrets in CIHandling credentials safely in pipelines.
- Alert FatigueSo many alerts that people start ignoring them.
- AlertingNotifying people when something needs attention.
- APMApplication performance monitoring tools.
- Correlation / Request IDAn ID passed through every service to tie one request's logs together.
- Logs, Metrics and TracesThe three main kinds of telemetry.
- MetricsNumeric measurements over time.
- ObservabilityUnderstanding a system's internal state from its outputs.
- Structured LoggingLogging key-value fields instead of free text.
- Blameless PostmortemFocusing on systems rather than individuals when things go wrong.
- Emergency Change ProcessShipping urgent fixes safely under pressure.
- EscalationKnowing when and how to pull in more help.
- Incident ResponseHow a team detects, coordinates, fixes and communicates during an incident.
- Incident Severity LevelsSEV1 to SEV4: how bad an incident is.
- Mitigate First, Fix LaterStopping the bleeding before hunting for the root cause.
- On-CallBeing responsible for responding to production issues.
- PagingAlerts that wake someone up.
- PostmortemA written review of an incident: what happened and how to prevent it.
- SLAA service level agreement: a promise to customers, with consequences.
- Status PagePublic communication about outages.
- Feature Flag CleanupRemoving flags once rollout is done so they don't pile up as debt.
- Launch ChecklistMonitoring, rollback, docs and support readiness before something goes live.
- On-Call HandoverPassing open issues and context to the next person on call.
- Reproducing Production Issues LocallyRecreating a production bug with realistic, anonymized data.
- Analytics Event TrackingRecording user actions for later analysis.
- Deep LearningNeural networks with many layers.
- Machine LearningSoftware that learns patterns from data instead of following explicit rules.
- ModelThe learned function that turns inputs into predictions.
- Neural NetworkLayers of weighted connections that learn from data.
- Supervised LearningLearning from labeled examples.
- Training vs InferenceBuilding a model vs using it to make predictions.
- AI AgentA model that plans and takes actions with tools in a loop.
- EmbeddingsNumeric vectors representing meaning, used for similarity search.
- How LLMs WorkTokens in, next-token prediction out: a mental model of what's happening.
- Multimodal ModelsModels that handle images, audio and text together.
- Prompt EngineeringWriting instructions that get reliable results from a model.
- Prompt InjectionUntrusted text hijacking a model's instructions.
- Retrieval-Augmented Generation (RAG)Giving a model relevant documents so it answers from your data.
- Semantic SearchSearching by meaning instead of keywords.
- Streaming ResponsesShowing model output token by token as it's generated.
- Structured OutputGetting models to return valid JSON matching a schema.
- System PromptInstructions that set a model's behavior for a conversation.
- TemperatureA setting controlling how random a model's output is.
- TokenThe unit of text a model reads and writes, and what you pay for.
- Tool Use / Function CallingLetting a model call your functions and APIs.
- Continuous Improvement (Kaizen)Small, ongoing improvements to how the team works.
- Definition of ReadyWhat a ticket needs before work on it starts.
- Iterative DeliveryShipping a thin working slice first, then improving it.
- MVPThe smallest product that tests whether an idea works.
- TriageSorting incoming bugs and requests by urgency and impact.
- VelocityHow much work a team finishes per sprint, and how it gets misused.
- Vertical SliceA feature built through every layer, end to end.
- WIP LimitCapping how many tasks are in progress at once.
- Buffers and UnknownsAccounting for the work you can't see yet.
- Hofstadter's LawIt always takes longer than you expect, even when you account for this.
- MilestoneA significant checkpoint in a project.
- Ninety-Ninety RuleThe last 10% of the work takes the other 90% of the time.
- Scope CreepRequirements growing while a project is underway.
- SpikeA time-boxed investigation to reduce uncertainty.
- T-Shirt SizingRough S/M/L/XL estimates for early planning.
- Async CommunicationWriting so people can respond on their own time.
- Effective MeetingsAgendas, notes, clear decisions, and fewer meetings.
- Explaining to Non-EngineersTranslating technical trade-offs into business terms.
- Making Work Visible RemotelyOver-communicating when nobody can see you working.
- Saying NoDeclining or pushing back on work constructively.
- Working with Product ManagersCollaborating on what to build and why.
- DogfoodingUsing your own product.
- Functional vs Non-Functional RequirementsWhat it does vs how well it does it.
- Handling Support EscalationsInvestigating issues reported by customers.
- Career ConversationsDiscussing goals and growth with your manager.
- Compensation and NegotiationSalary, equity and bonuses, and negotiating offers.
- Mid-Level EngineerDelivering features independently.
- PromotionShowing next-level scope before you get the title.
- T-Shaped SkillsBroad knowledge with deep expertise in one area.
Senior
Own an app's architecture, performance, and failure modes.
Core: start here
- Contract TestingVerifying that services agree on the API contract between them.
- Hyrum's LawWith enough users, every observable behavior becomes something someone depends on.
- Architecture Decision Record (ADR)A short document recording a decision, its context and its consequences.
- Design DocumentA written proposal of how to build something, reviewed before building it.
- CSS ArchitectureOrganizing styles so a large codebase stays maintainable.
- Choosing a FrameworkChoosing between React, Vue, Svelte and Angular based on team and product needs.
- Islands ArchitectureStatic pages with small interactive islands.
- Server ComponentsComponents that render on the server and ship no JavaScript.
State Management & Data Fetching
- Offline-FirstApps that work without a network and sync later.
- State Machines for UIModeling UI as explicit states and transitions, e.g. with XState.
- Streaming SSRSending HTML in chunks as it becomes ready.
- Layout ThrashingAlternating layout reads and writes, forcing many reflows.
- Performance BudgetAgreed limits on size and timing that builds must meet.
- Inclusive DesignDesigning for the full range of human ability from the start.
- Live RegionsAnnouncing dynamic updates to screen reader users.
- Architectural Trade-offsEvery architecture decision gives something up; naming what.
- Micro-FrontendsSplitting a frontend into independently deployed parts.
- One-Way vs Two-Way DoorsMoving fast on reversible decisions and carefully on irreversible ones.
- Threat ModelingSystematically asking what could go wrong and how to prevent it.
- Distributed TracingFollowing a single request across many services.
- SLOA service level objective: the target for an SLI.
- Handling AmbiguityMaking progress when the problem isn't well defined.
- ScopeHow big and ambiguous the problems you own are.
- Managing Technical DebtTracking, prioritizing and paying down debt deliberately.
- MentoringHelping less experienced engineers grow.
- Technical Decision MakingGathering input, weighing trade-offs, deciding, and recording why.
228 more senior concepts
- Integer OverflowA value exceeding its type's range and wrapping around or failing.
- MonadA pattern for chaining computations that carry context, like Option or Promise.
- Referential TransparencyAn expression can be replaced by its value without changing behavior.
- Algebraic Data TypesComposing types from "and" (products) and "or" (sums).
- Covariance and ContravarianceHow subtyping of generic types follows their type parameters.
- BackpressureA slow consumer signalling a fast producer to slow down.
- DeadlockTwo or more tasks waiting on each other forever.
- ProcessA running program with its own memory space.
- ThreadAn execution path within a process that shares its memory.
- BytecodeAn intermediate instruction format run by a virtual machine.
- JIT CompilationCompiling hot code to machine code while the program runs.
- Object PoolingReusing objects to avoid the cost of allocating new ones.
- Reference CountingFreeing an object when nothing refers to it anymore.
- Weak ReferenceA reference that doesn't keep its object alive.
- Git InternalsBlobs, trees, commits and refs: what Git actually stores.
- Monorepo vs PolyrepoOne repository for everything vs one per project.
- Patch FilesSharing changes as diff files instead of branches.
- WorktreeSeveral working directories checked out from one repository.
- Stacked PRsA chain of dependent pull requests, each reviewable on its own.
- Debugging in ProductionFinding issues with logs, traces and metrics when you can't attach a debugger.
- Flame GraphA visualization of where a program spends its time.
- FuzzingFeeding random inputs to find crashes and vulnerabilities.
- Load TestingMeasuring behavior under expected traffic.
- Mutation TestingChanging code on purpose to check that the tests notice.
- Property-Based TestingGenerating many inputs to check that properties always hold.
- Soak TestRunning under load for hours to find leaks and slow degradation.
- Stress TestingPushing beyond capacity to find the breaking point.
- Testing in ProductionValidating safely with real traffic using flags, canaries and monitoring.
- Functional Core, Imperative ShellPure logic in the middle, side effects at the edges.
- Gall's LawComplex systems that work evolved from simple systems that worked.
- Keep Framework Code at the EdgesKeeping business logic free of framework details so it survives framework changes.
- Postel's LawBe conservative in what you send and liberal in what you accept.
- Big Bang RewriteReplacing a whole system at once, and why it usually fails.
- Parallel Change (Expand-Contract)Add the new way, migrate callers, then remove the old way.
- SeamA place where you can change behavior without editing the code there.
- Strangler Fig PatternGradually replacing a legacy system by routing pieces to new code.
- Abstract FactoryCreating families of related objects without naming concrete classes.
- BridgeSeparating an abstraction from its implementation so both can vary.
- FlyweightSharing common state among many small objects to save memory.
- MediatorCentralizing communication between objects.
- MementoCapturing state so it can be restored later, as in undo.
- PrototypeCreating objects by cloning an existing one.
- Service LocatorA registry for looking up dependencies, often seen as an anti-pattern.
- Type ObjectDefining "kinds" of things as data instead of subclasses.
- VisitorAdding operations to a structure without changing its classes.
- C4 ModelDiagramming software at four zoom levels: context, containers, components, code.
- DiátaxisOrganizing docs into tutorials, how-to guides, reference and explanation.
- B-TreeA wide, shallow tree optimized for disks; how database indexes work.
- Balanced TreeTrees like AVL or red-black that stay shallow for guaranteed O(log n).
- Bloom FilterA compact structure answering "definitely not" or "probably yes" for set membership.
- Persistent Data StructureAn immutable structure that shares unchanged parts between versions.
- Ring BufferA fixed-size buffer that wraps around.
- Classic Hard ProblemsKnapsack, traveling salesman and others, and how to recognize them in disguise.
- Diff AlgorithmsComputing the minimal set of changes between two sequences.
- Dijkstra's AlgorithmFinding shortest paths in a graph with non-negative weights.
- Huffman CodingCompressing data by giving frequent symbols shorter codes.
- Minimum Spanning TreeConnecting all nodes with the least total edge weight (Prim's, Kruskal's).
- P vs NP / NP-CompleteProblems with no known efficient solution, and why some tasks stay hard.
- String SearchingAlgorithms like KMP and Rabin-Karp for finding substrings.
- Amdahl's LawThe speedup from parallelism is limited by the part that stays sequential.
- Linear Algebra BasicsVectors and matrices, the foundation of graphics and ML.
- Cache LocalityAccessing memory that's close together is much faster.
- KernelThe core of the OS with full access to the hardware.
- Domain-Specific LanguageA small language built for one problem, like SQL or regex.
- Lexer / TokenizerSplitting source text into tokens.
- MetaprogrammingCode that writes or modifies code.
- WebAssemblyA portable binary format that runs near-native code in browsers and beyond.
- Head-of-Line BlockingOne slow item holding up everything queued behind it.
- QUICA UDP-based transport behind HTTP/3, with faster handshakes.
- Chunked Transfer EncodingStreaming a response in pieces without knowing its total size.
- Conditional RequestIf-None-Match and If-Match for caching and concurrency control.
- HTTP/3HTTP running over QUIC.
- Range RequestsFetching part of a resource, for resumable downloads and video.
- Certificate ChainLeaf, intermediate and root certificates linking to a trusted root.
- TLS HandshakeHow client and server agree on keys before sending data.
- DataLoader / N+1 in GraphQLBatching resolver lookups so nested queries don't explode.
- MessagePackA compact binary alternative to JSON.
- REST vs GraphQL vs gRPCChoosing an API style for the clients and teams you have.
- Richardson Maturity ModelLevels of REST maturity, from one endpoint to hypermedia.
- Schema EvolutionChanging data formats so old and new readers and writers keep working.
- Paint and CompositeFilling in pixels and assembling layers on the GPU.
- CRDTData structures that merge concurrent edits without conflicts, used in collaborative editors.
- Operational TransformationTransforming concurrent edits so they apply consistently, as in Google Docs.
- PresenceShowing who is online or viewing something right now.
- WebRTCPeer-to-peer audio, video and data in the browser.
- Shadow DOMEncapsulated DOM and styles for a component.
- template and slotInert HTML fragments and placeholders for components.
- Web ComponentsBrowser-native custom elements with encapsulated styles.
- Cascade Layers (@layer)Controlling cascade priority between groups of styles.
- Critical CSSInlining just the CSS needed for the first screen.
- Mutation ObserverWatching for changes to the DOM.
- Proxy and ReflectIntercepting operations on objects; how some reactivity systems work.
- SymbolA unique, non-string property key.
- Concurrent RenderingInterruptible rendering that keeps the UI responsive.
- SuspenseDeclaratively showing fallbacks while data or code loads.
- Edge RenderingRendering close to users on CDN edge servers.
- Incremental Static RegenerationRebuilding static pages in the background after deploy.
- Right-to-Left SupportSupporting languages like Arabic and Hebrew.
- Context PropagationCarrying request IDs, deadlines and trace context across threads and services.
- API-First DesignDesigning the API contract before implementing it.
- Backend for Frontend (BFF)A backend tailored to one frontend's needs.
- Bulk OperationsEndpoints that act on many items in one request.
- HATEOASResponses that include links to the possible next actions.
- Long-Running OperationsReturning 202 Accepted and a status URL for slow work.
- Public vs Internal APIsWhy public APIs need much more care about stability.
- Sparse FieldsetsLetting clients choose which fields they receive.
- Faceted SearchFiltering search results by categories with counts.
- Fuzzy SearchMatching despite typos and spelling variations.
- Geospatial DataStoring and querying locations: nearby search, distances, geohashes.
- Cache ConsistencyKeeping cached data in line with the source of truth.
- JitterRandomizing retry delays so clients don't all retry in sync.
- Video Streaming (HLS)Serving video as adaptive chunks.
- Multi-Currency HandlingStoring, converting and displaying money in several currencies.
- Recurring EventsRepeating schedules, RRULE, and their time zone edge cases.
- Clean ArchitectureConcentric layers whose dependencies point inward to the domain.
- Event-Driven ArchitectureServices communicating by publishing and reacting to events.
- Hexagonal ArchitecturePorts and adapters that isolate core logic from infrastructure.
- Modular MonolithA monolith with strong internal module boundaries.
- Monolith vs MicroservicesWeighing simplicity against independent scaling and deployment.
- Peer-to-PeerNodes that act as both client and server.
- Plugin ArchitectureA core extended by independently developed plugins.
- Quality Attributes (the "-ilities")Scalability, availability, maintainability and other non-functional goals.
- Bounded ContextA boundary inside which a model and its terms have one meaning.
- Domain-Driven DesignModeling software closely on the business domain and its language.
- Event StormingA workshop for discovering a domain through its events.
- Back-of-the-Envelope EstimationRough math for traffic, storage and bandwidth.
- CQRSSeparating the write model from the read model.
- Designing a Chat SystemReal-time messaging, presence and message storage.
- Designing AutocompleteTries, ranking and caching for type-ahead search.
- Push vs Pull CDNUploading content to the CDN vs letting it fetch on demand.
- Read-Your-Writes ConsistencyUsers always seeing their own updates.
- Consistency ModelsLinearizable, sequential, causal, eventual: what readers are allowed to see.
- Distributed SystemMany machines cooperating over an unreliable network.
- Fallacies of Distributed ComputingEight false assumptions, starting with "the network is reliable".
- Idempotency in Distributed SystemsMaking retries safe when you can't know whether the first attempt worked.
- Request CoalescingCollapsing identical concurrent requests into one.
- Strong ConsistencyEvery read sees the latest write.
- Blast RadiusHow much breaks when something fails.
- Cascading FailureOne failure triggering failures in the systems that depend on it.
- Circuit BreakerStopping calls to a failing service so it can recover.
- Degraded ModesServing reduced functionality when dependencies fail.
- Fault ToleranceContinuing to work when components fail.
- Retry StormRetries multiplying the load on an already failing system.
- Tail LatencyThe slowest requests (p99), which users notice most.
- Event BusA channel through which events reach their subscribers.
- Gateway AggregationOne gateway call that fans out to many services and combines the results.
Authentication & Authorization
- Account EnumerationLeaking whether an email is registered through login, signup or reset responses.
- Passkeys (WebAuthn)Phishing-resistant login with device-bound key pairs instead of passwords.
- Refresh Token RotationIssuing a new refresh token on every refresh and invalidating the old one, so reuse of an old token reveals theft.
- Single Sign-On (SSO)Logging in once with an identity provider and accessing many apps.
- Business Logic VulnerabilitiesAbusing legitimate features in unintended ways.
- Prototype PollutionInjecting properties into JavaScript's Object prototype.
- ReDoSRegular expressions that take exponential time on crafted input.
- End-to-End EncryptionOnly the communicating users can read the data, not the server.
- Bug BountyPaying outside researchers to report vulnerabilities.
- CVSSA score rating how severe a vulnerability is.
- DASTTesting a running app for vulnerabilities from the outside.
- Penetration TestingAuthorized simulated attacks to find vulnerabilities.
- Responsible DisclosureReporting vulnerabilities privately before going public.
- SBOMA software bill of materials listing every component.
- Security ReviewReviewing a design or change specifically for security risks.
- Shift-Left SecurityFinding security issues early in development.
- Software Supply Chain SecurityProtecting against compromised dependencies and build pipelines.
- STRIDEA way to categorize threats: spoofing, tampering, repudiation, disclosure, denial of service, elevation.
- Privacy by DesignBuilding privacy in from the start.
- KubernetesThe dominant container orchestration platform.
- Cloud Cost Management (FinOps)Understanding and controlling cloud spending.
- Edge ComputingRunning code near users at CDN locations.
- Managed vs Self-HostedPaying for convenience vs running it yourself.
- Vendor Lock-InDepending on one provider's proprietary services.
- Dark LaunchRunning new code in production without users seeing it.
- Deployment FrequencyHow often a team ships; a key DevOps metric.
- Progressive DeliveryGradual rollouts with automatic checks at each step.
- Release TrainShipping on a fixed schedule with whatever is ready.
- Actionable AlertsAlerting only on symptoms that need a human to act.
- OpenTelemetryThe vendor-neutral standard for collecting telemetry.
- SamplingRecording only a fraction of traces or logs to control cost.
- Customer Communication in IncidentsTelling users what's happening, honestly and promptly.
- Error BudgetHow much unreliability an SLO allows, used to balance speed and stability.
- Incident CommanderThe person coordinating an incident response.
- MTTR / MTTDMean time to recover, and to detect.
- SLIA service level indicator: a measured aspect of service quality.
- Classification vs RegressionPredicting categories vs predicting numbers.
- OverfittingA model memorizing its training data instead of generalizing.
- Recommendation SystemSuggesting items based on behavior and similarity.
- Train / Test SplitHolding out data to evaluate a model honestly.
- Unsupervised LearningFinding structure in unlabeled data.
- AI Product UXDesigning interfaces for uncertain, streaming, sometimes-wrong AI output.
- Choosing a ModelTrading off quality, speed and cost across model sizes and providers.
- EvalsSystematically measuring the quality of LLM output.
- Fine-TuningFurther training a model on your own examples.
- GuardrailsChecks on model inputs and outputs for safety and correctness.
- LLM Cost and LatencyManaging tokens, model choice and caching.
- LLM-as-JudgeUsing one model to grade another model's output.
- Cycle Time and Lead TimeHow long work takes from start, or from request, until it's done.
- Lean Software DevelopmentEliminating waste and optimizing the flow of work.
- Shape UpBasecamp's six-week cycles with shaped, fixed-time bets.
- Cone of UncertaintyEstimates get more accurate as work progresses.
- Critical PathThe chain of tasks that determines the earliest finish date.
- Cross-Team DependenciesWork blocked on other teams, and how to manage it.
- OKRsObjectives and key results for setting goals.
- Project KickoffAligning everyone on goals, scope and roles at the start.
- RICE and MoSCoWFrameworks for prioritizing work.
- RoadmapA plan of what to build over the coming months.
- Disagree and CommitVoicing disagreement, then fully backing the decision.
- PresentingCommunicating ideas to a group.
- Psychological SafetyFeeling safe to take risks and admit mistakes on a team.
- Resolving ConflictWorking through disagreements productively.
- Stakeholder ManagementKeeping the people affected by your work informed and aligned.
- Build vs BuyDeciding whether to build something or use an existing product.
- Business MetricsRevenue, retention, conversion: what the business measures.
- Experimentation CultureTesting ideas with data before committing to them.
- Feature AdoptionWhether users actually use what you shipped.
- User ResearchLearning what users actually need.
- Generalist vs SpecialistThe trade-offs between breadth and depth.
- Glue WorkEssential but invisible work that keeps teams running.
- IC vs Management TrackTwo parallel career paths, and how to choose between them.
- Senior EngineerOwning systems and raising the team around you.
- Tech LeadLeading a team's technical direction while still writing code.
- Writing and Speaking PubliclyBlogs, talks and sharing what you learn.
- Boring Technology / Innovation TokensSpending novelty sparingly and choosing proven tools by default.
- DelegationHanding off work in a way that grows others.
- Developer ExperienceHow easy and pleasant it is for engineers to do their work.
- HiringInterviewing and selecting engineers.
- Interviewing CandidatesRunning fair interviews that produce real signal.
- Managing UpKeeping your manager informed and aligned.
- Onboarding New EngineersHelping new teammates become productive.
- Technical LeadershipGuiding technical direction through influence and example.
Staff
Shape how many teams build, across apps.
- Conway's LawSystems mirror the communication structure of the organizations that build them.
- RFCA request for comments: proposing a significant change for wide review.
- Architecture Fitness FunctionAutomated checks that an architecture keeps its intended qualities.
- Architecture ReviewReviewing designs across teams before they're built.
- Evolutionary ArchitectureDesigning systems to change incrementally over time.
- Multi-Region ArchitectureRunning in several regions for lower latency and resilience.
- Performance vs CostDeciding how much speed is worth paying for.
- Security ChampionAn engineer on each team who advocates for security.
- DORA MetricsFour delivery metrics: deploy frequency, lead time, change failure rate and recovery time.
- Production Readiness ReviewA checklist before a service goes live.
- Influence Without AuthorityGetting things done across teams you don't manage.
- Writing CultureTeams that make and record decisions through written documents.
- Cost of DelayWhat it costs to ship something later.
- North Star MetricThe single metric that best captures the value you deliver.
- Engineering ManagerLeading people: hiring, growth, delivery and team health.
- Staff ArchetypesTech lead, architect, solver and right hand.
- Staff EngineerTechnical leadership across teams.
- Building ConsensusBringing people with different views to an agreement.
- Communicating with ExecutivesShort, decision-focused updates for leadership.
- Developer Productivity MetricsSPACE, DORA, and the danger of measuring the wrong thing.
- Engineering CultureThe shared values and habits that shape how a team builds.
- Evaluating New TechnologySeparating hype from what's worth adopting.
- Leading Large MigrationsMoving many teams off an old system.
- Platform ThinkingBuilding shared capabilities that make other teams faster.
- Risk ManagementIdentifying and mitigating what could derail a project.
- Setting Engineering StandardsDefining practices that many teams follow.
- SponsorshipUsing your influence to create opportunities for others.
- Team Cognitive LoadLimiting how much a team must understand to own its systems.
- Team TopologiesStream-aligned, platform, enabling and complicated-subsystem teams.
- Technical VisionA picture of where the technology should be in a few years.
Principal
Set technical direction for the organization.
- Principal EngineerTechnical direction for a whole organization.
- Budget and HeadcountPlanning people and spending.
- Inverse Conway ManeuverDesigning team structure to get the architecture you want.
- Long-Term ThinkingMaking decisions whose payoff comes years later.
- Organization DesignStructuring teams and reporting lines.
- Technical Due DiligenceAssessing another company's technology, as in an acquisition.
- Technical StrategyA plan for reaching the vision under real constraints.