Knowledge hub
We publish how we build.
Real engineering depth, written by people who ship it. Each guide is a citeable reference, organized by the layer it belongs to.

Search the library

Featured · 00
CI/CD governance for a small senior team
Every change travels one short, governed path from branch to production, and the pipeline enforces the rules for free. Why boring delivery is the IP that lets four people out ship forty.
Open guide ▶
35 guides · 10 layers
Layer 004
Engineering pipeline & governance

CI/CD governance for a small senior team
Every change travels one short, governed path from branch to production, and the pipeline enforces the rules for free. Why boring delivery is the IP that lets four people out ship forty.
Read guide ▶
Push to deploy, with GitHub as the only source of truth
When git history and production can disagree, they eventually will. Closing that gap so every deploy has a commit, a diff, and a one step rollback.
Read guide ▶
Centralized secrets with Infisical machine identities
One source for every credential, a scoped identity per workload, rotation in a single screen, and a self hostable path for data residency.
Read guide ▶
Grounding AI assisted code in live documentation
The failure mode of AI development is confident code against an API that changed. Grounding the model in current docs turns plausible wrong answers into compiled right ones.
Read guide ▶Layer 014
Edge, compute & hosting

Choosing a host for the workload, not the logo
There is no single best host. A decision map for placing each workload, web app, edge media, always on worker, heavy compute, where its shape fits.
Read guide ▶
Always on workers and cron with Render
Serverless is a poor home for work that must stay awake. Where queue consumers, scheduled jobs, and persistent connections belong, and how to define the schedule as infrastructure.
Read guide ▶
Zero egress media with Cloudflare R2
Most object storage bills you when data leaves, which is fastest when you succeed. Storing media where popularity does not raise the invoice, served through an image pipeline.
Read guide ▶
Building front ends for low bandwidth
Build for a mid range phone on a metered network and the fast case takes care of itself. Shipping less, right sizing images, and degrading honestly.
Read guide ▶Layer 025
Data & state

A database per pull request with Neon
Shared staging databases rot. Branching the database the way you branch the code, so every pull request gets an isolated, instantly forked, scale to zero copy.
Read guide ▶
Multi tenant isolation with Supabase row level security
The most expensive bug is tenant A seeing tenant B's data. Pushing the boundary into the database, where forgetting a where clause cannot cause a breach.
Read guide ▶
Rate limiting and queues at the edge with Upstash
The edge needs state but cannot hold a heavy connection. HTTP Redis for the rate limit that protects everything downstream and the queue that moves slow work off the request.
Read guide ▶
Search you already pay for, in Postgres
Most products do not need a search cluster. Ranked full text search with no new infrastructure, filterable by your ordinary columns, and how to combine it with semantic search.
Read guide ▶
Cheap, joinable RAG with pgvector
Keeping embeddings inside the Postgres you already pay for, joinable with business data in one query, and when that beats a managed vector database.
Read guide ▶Layer 035
AI & intelligence

Vendor neutral AI with the AI SDK and Gateway
One code interface across providers, with fallback chains and a cost dashboard. Why provider choice should be configuration, not code, and why neutrality wins proposals.
Read guide ▶
Provider fallback chains and a cost ceiling
A single model provider is a single point of failure. Ordering a chain by capability and cost, timing out aggressively, and logging which step actually answered.
Read guide ▶
Getting reliable structured output from a model
If you parse a model's prose you will eventually parse it wrong. Constraining output to a schema at the call, so the model returns typed, validated data instead of hopeful text.
Read guide ▶
Self hosted and fine tuned models with Hugging Face
When residency, a underserved language, or sheer volume make a self hosted or fine tuned open model the right call, kept behind the same uniform interface as the hosted providers.
Read guide ▶
Multilingual voice, including Swahili and Sheng
Voice is the accessible interface for users that text leaves behind. Text to speech and speech to text in the user's real language, wired to the channels that reach a basic phone.
Read guide ▶Layer 043
Identity & secrets

Multi tenant auth with Clerk organizations
Auth is the part you should almost never build yourself. Modeling organizations and roles directly, and pairing managed identity with an enforced database boundary.
Read guide ▶
Verifying webhooks so you can trust them
A webhook is an unauthenticated public POST until you prove otherwise. Verifying the signature over the raw body, comparing in constant time, and making the handler idempotent.
Read guide ▶
HIPAA and data residency on a modern stack
Compliance is an architecture, not a checkbox. Keeping protected data inside a boundary, enforcing access at the database, building real audit trails, and not overclaiming.
Read guide ▶Layer 054
Payments & monetization

Stripe subscriptions and the edge cases that bite
The happy path is easy; the declines, upgrades, refunds, and disputes are the product. Treating the webhook as the source of truth and reconciling against your own ledger.
Read guide ▶
Reconciling a dual rail ledger, M-Pesa and Stripe
Two rails that behave nothing alike, normalized into one internal ledger keyed on an external reference, with a nightly job that proves the money matches.
Read guide ▶
Idempotency keys for payments and callbacks
The network will deliver your important request twice. Making an operation safe to repeat with a unique key and the database as the atomic referee.
Read guide ▶
M-Pesa Daraja, done correctly
Phone normalization, integer KES, proactive token refresh, and idempotent callbacks. Treating mobile money as a first class rail rather than a plugin.
Read guide ▶Layer 063
Communications & engagement

USSD, reaching feature phones with no data
The users you most want to reach may not have a smartphone. How a USSD session works, designing for the tiny screen and short timeout, and where it fits with SMS and voice.
Read guide ▶
The WhatsApp Business 24 hour window
The platform's hard line between replying and messaging out of the blue shapes the whole integration. Session messages inside the window, approved templates outside it, consent throughout.
Read guide ▶
Transactional email that actually lands
Email only works if it reaches the inbox. Authenticating the sending domain with SPF, DKIM, and DMARC, the split nameserver trap, and matching the message to the right channel.
Read guide ▶Layer 073
Design & experience

Design to code in both directions with Figma
Design and code drift apart unless something keeps them together. Reading tokens and structure into code, pushing components back, and closing the loop with Code Connect.
Read guide ▶
Data driven brand graphics with Canva
On brand images at volume without a designer in the loop each time. Brand templates filled by autofill, driven by the data you already have, with the look in one place.
Read guide ▶
Per device responsive images on a budget
A desktop image on a phone is bytes the user paid for and never saw. Letting the browser choose with srcset and sizes, the CDN handle format and width, and width only meaning no crop.
Read guide ▶Layer 082
Observability, docs & ops
Production failures that arrive with a stack trace
A silent error is churn you cannot explain. Capturing the full trace and context, adding what makes triage fast without leaking sensitive data, and acting on volume.
Read guide ▶
From spec to ticket in Notion
Knowledge in people's heads leaves when they do. Writing a short decisive spec first, deriving tickets from it, and capturing decisions so they are not relitigated.
Read guide ▶Layer 092
Domains & brand portfolio

Programmatic DNS and subdomain plays
DNS clicked by hand cannot be reviewed or reproduced. Scripting records, reading them back to verify, the split nameserver trap, and short TTLs while you change things.
Read guide ▶
A domain portfolio strategy for a family of brands
Once you ship more than one product, domains become strategy. Umbrella versus independent brands, defending variants, permanent canonical redirects, and governing it like infrastructure.
Read guide ▶Have a build that needs this depth?
Tell us what you are building. We respond within two business days.