Foundation
Use this reference for core backend concepts that should shape most systems before advanced scaling concerns appear.
1. HTTP Protocols And Network Dynamics
Focus areas:
- Request lifecycle: DNS, load balancers, reverse proxies, firewalls, app server ingress.
- HTTP semantics: correct use of
GET,POST,PUT,PATCH,DELETE, headers, status codes, caching directives, and content negotiation. - CORS: simple vs preflight requests,
OPTIONS, origin policy, safe header configuration. - Protocol evolution: HTTP/1.1 vs HTTP/2 vs HTTP/3, multiplexing, connection reuse, and head-of-line blocking tradeoffs.
- Transport optimization: TLS, keep-alive, gzip, brotli, streaming, chunked transfer.
Agent guidance:
- Respect HTTP semantics instead of tunneling everything through
POST. - Add compression and pagination on payload-heavy endpoints.
- Use streaming for large downloads, uploads, or server-side event flows.
2. Presentation Layer And API Design
Focus areas:
- Routing patterns: static, dynamic, nested, wildcard, regex, and route precedence.
- API versioning: URI, header, query, media type; deprecation and retirement plans.
- Serialization: JSON as default, Protobuf or Avro for internal high-throughput systems.
- Validation: JSON Schema, nested object validation, nullability, enums, time zones, and date parsing.
- OpenAPI-first design for external APIs.
Agent guidance:
- Define request and response shapes first.
- Limit fields to what clients actually need.
- Prefer cursor pagination for large or changing datasets.
- Treat time zones and timestamps explicitly.
- Use deterministic sort order for paginated resources.
- Prefer partial-update semantics only when the merge behavior is unambiguous.
3. Request Lifecycle And Middleware
Recommended middleware order:
- Request ID or trace ID injection.
- Access logging.
- Security headers.
- CORS.
- Rate limiting.
- Authentication.
- Authorization.
- Body parsing with payload limits.
- Validation and normalization.
- Route handler.
- Global error handling.
Agent guidance:
- Short-circuit early on auth, validation, and rate-limit failures.
- Propagate request-scoped context through async flows.
- Honor deadlines, abort signals, and timeouts.
4. Decoupled Code Architecture
Core rules:
- Controllers own transport concerns only.
- Services own orchestration, validation beyond syntax, transactions, idempotency, and policies.
- Repositories own data access patterns and mapping to storage.
- Adapters wrap external systems such as cache, broker, payments, storage, and email.
Useful design principles:
- Single Responsibility Principle for each layer.
- Dependency Inversion so higher-level rules do not depend on frameworks.
- Separation of concerns between syntax validation and domain validation.
Validation categories:
- Syntactic: shape, required fields, types, size limits.
- Semantic: business rules, state transitions, permissions, invariants.
- Safety: sanitization, normalization, injection defense, canonicalization.
5. Database Operations And Performance
Focus areas:
- SQL vs NoSQL tradeoffs.
- ACID and transaction boundaries.
- Schema design, normalization, uniqueness, foreign keys, and indexing.
- Query plans, join costs, eager loading, batching, and pagination.
- Connection pooling, concurrency control, and migration safety.
Common backend failures to catch:
- N+1 queries.
- Missing composite indexes for real filter and sort patterns.
- Long transactions holding locks across network calls.
- Table scans hidden behind ORM convenience methods.
- Unbounded
SELECT *behavior on hot endpoints. - Offset pagination on very large tables where keyset pagination is more stable.
- Missing idempotency or uniqueness controls on transactional tables.
Agent guidance:
- Batch where possible.
- Keep transactions tight and local.
- Never call third-party APIs inside a database transaction unless the business process was explicitly designed for it.
- Explain why each new index exists.
- Call out read paths, write paths, and consistency expectations separately.
6. Caching Topologies
Patterns:
- Cache-aside for read-heavy data.
- Write-through for stronger consistency needs.
- Write-behind only with explicit tolerance for asynchronous persistence risks.
- Read-through only when cache infrastructure already supports it cleanly.
Layers:
- L1 in-process cache for low-latency hot reads in a single instance.
- L2 distributed cache such as Redis for multi-instance deployments.
Operational concerns:
- TTL selection.
- Eviction policy: LRU, LFU, FIFO.
- Cache invalidation triggers.
- Stampede protection with locks, jitter, or stale-while-revalidate.
Agent guidance:
- Name the cache key format.
- Define what causes invalidation.
- Avoid caching secrets or authorization decisions without very careful scoping.