YouTube2Text

1. Roadmap for backend from first principles — Transcript

by Sriniously · 5,502 words · 872 segments · language en · Watch on YouTube

Full transcript

  1. 0:00backend engineering is a very wide scope
  2. 0:03and when I say backend engineering it is
  3. 0:07much more than building a set of crud
  4. 0:09apis the way I think backend engineering
  5. 0:12is about building reliable scalable fall
  6. 0:15tolerant and maintainable code bases and
  7. 0:19efficient
  8. 0:20systems and if one were to start today
  9. 0:25to learn back in development there are a
  10. 0:27lot of resources and
  11. 0:30at least 1,00
  12. 0:31resources but how do you decide what to
  13. 0:34learn how do you prioritize how do you
  14. 0:36see the big picture when and how all
  15. 0:39these different concepts come together
  16. 0:41and this is the reason it takes people
  17. 0:43years to get their head around a lot of
  18. 0:45these Concepts and principles because
  19. 0:48people primarily start with a limited
  20. 0:50scope of training uh whether it is from
  21. 0:52a college or a boot camp or a simple cop
  22. 0:56course and they eventually build onp top
  23. 1:00of that with trial and error and with
  24. 1:01help of other developers over time now I
  25. 1:04am a backend engineer and I have faced
  26. 1:08this struggle initially when I started
  27. 1:10out I had to constantly search for
  28. 1:12resources learn from other developers I
  29. 1:15have read a lot of books on backend
  30. 1:16development I have studied hundreds of
  31. 1:19open- source code bases to see how
  32. 1:22people in the industry are building
  33. 1:23stuff and it was a very timec consuming
  34. 1:26procedure and the second problem is
  35. 1:29people start with backend development
  36. 1:31from a particular language or Frameworks
  37. 1:34point of view it could be Express or
  38. 1:37spring boot or Ruby on Rails and the
  39. 1:41problem with that is you look at the
  40. 1:43problems that you solve with the lens of
  41. 1:45your particular language and ecosystem
  42. 1:48and there are blind spots in that let's
  43. 1:50imagine you have to switch to a
  44. 1:52different language let's say you were
  45. 1:54working with rubyan rails for years and
  46. 1:56one day your company decided to migrate
  47. 1:58to golang for performance reasons in
  48. 2:00that situation how much of your
  49. 2:02knowledge can you transfer if you don't
  50. 2:05understand the underlying systems so
  51. 2:08here I have decided to put together a
  52. 2:10comprehensive list of videos which are
  53. 2:13based on foundational concepts of a
  54. 2:15backend system and these are from
  55. 2:17various books that I've read over the
  56. 2:18years the open source code base we'll
  57. 2:20start with a very high level
  58. 2:22understanding of how backend systems
  59. 2:24work behind the scenes we'll look at how
  60. 2:27request from browser flows through
  61. 2:29different hops the network firewalls
  62. 2:31over the internet and how it is routed
  63. 2:34to our backend server that is situated
  64. 2:36in a remote AWS server and how it
  65. 2:39responds to that request and we'll look
  66. 2:41at what the response looks like and that
  67. 2:44should give us a pretty vivid idea of
  68. 2:47how systems communicate how a client
  69. 2:49communicates with a server and how the
  70. 2:51server responds from there we'll move to
  71. 2:53understanding HTTP protocol what is the
  72. 2:56role it plays and how the communication
  73. 2:59is established through HTTP and how HTTP
  74. 3:03raw messages look like and what are the
  75. 3:05HTTP headers what are the role of the
  76. 3:07headers the different types of headers
  77. 3:09like request headers or representational
  78. 3:12headers General headers and security
  79. 3:14headers and we'll look at different
  80. 3:16types of HTTP methods like get method
  81. 3:18post put delete and when to use them and
  82. 3:21what are the semantics and what are the
  83. 3:23principles behind them we'll look at
  84. 3:25what is the cost flow and how does it
  85. 3:28work we'll look at how simple request
  86. 3:30defers from a pre-flight request and how
  87. 3:33a pre-flight request FL looks like from
  88. 3:35our browser to the server and back to
  89. 3:36our browser we'll look at HTTP responses
  90. 3:39the structure of it and different status
  91. 3:41codes that server returns and when to
  92. 3:44return which type of code and what are
  93. 3:46the most commonly used HTTP status codes
  94. 3:49then we'll look at HTTP caching what are
  95. 3:51the different types of caching
  96. 3:53techniques using HTTP we have eags we
  97. 3:55have uh max age headers then we'll look
  98. 3:58at the differences between http 1. 1 and
  99. 4:00HTTP 2.0 and HTTP 3.0 and what are the
  100. 4:03differences between them we will look at
  101. 4:05how content negotiation looks like
  102. 4:07between client and server using
  103. 4:08different headers we'll see how
  104. 4:10persistent connections work in HTTP
  105. 4:12we'll look at HTTP compression different
  106. 4:14types of compression techniques like
  107. 4:15gzip and deflate and BR and which is the
  108. 4:19commonly used technique we'll see the
  109. 4:21security aspect of it the SSL TLS and
  110. 4:24htps then we'll move on to routing how
  111. 4:26routing Maps URLs to server side logic
  112. 4:29and what is the connection between
  113. 4:30routing and HTTP methods different
  114. 4:32components of routes like path
  115. 4:34parameters and query parameters
  116. 4:36different types of routes static routes
  117. 4:38Dynamic routes nested routes
  118. 4:40hierarchical routes catchall Wild Card
  119. 4:42routes and regular expression based
  120. 4:44routes how to do API versioning using
  121. 4:46HTTP different types of versioning
  122. 4:48techniques we'll see what is the best
  123. 4:49way to deprecate it outout and what are
  124. 4:51the best practices in the industry we
  125. 4:53look at the benefits of Route grouping
  126. 4:55and how it helps with versioning
  127. 4:57permissions and shared middleware we'll
  128. 4:59see how to secure routes how to optimize
  129. 5:02route matching performance then we'll
  130. 5:04move on to serialization and der
  131. 5:05serialization this basically means how
  132. 5:08before sending it over to the network
  133. 5:10our server translates the data into a
  134. 5:12particular format and after receiving
  135. 5:14the data from uh let's say client over
  136. 5:17the internet and how and how it
  137. 5:19translates the data received from the
  138. 5:21client over the internet to its own
  139. 5:22native format that is called DC
  140. 5:24realization and we will see what is the
  141. 5:26need of it and how it helps with the
  142. 5:28interoperability standard the different
  143. 5:30formats that are used in serialization
  144. 5:33der serialization we have text based
  145. 5:34formats which is Json or XML we have
  146. 5:37binary formats which is prot off and
  147. 5:40what are the performance differences
  148. 5:41between these two and when to use which
  149. 5:44one we'll look at how different
  150. 5:45programming languages Implement
  151. 5:46serialization and der serialization we
  152. 5:48will explore a popular text based format
  153. 5:50for serialization and der serialization
  154. 5:52which is Json the structure of Json the
  155. 5:54different data types like strings
  156. 5:55numbers booleans arrays and objects how
  157. 5:58realization of nested objects and
  158. 5:59collections are handled in Json how DC
  159. 6:02serializing into data structures the
  160. 6:04native data structures works like in
  161. 6:06let's say python dictionary or goang
  162. 6:08structs or JavaScript object what are
  163. 6:11the common errors while dealing with
  164. 6:12Json like handling missing or extra
  165. 6:14Fields dealing with null values or date
  166. 6:17serialization issues and time zone
  167. 6:19issues and how to implement custom
  168. 6:22serialization while before sending or
  169. 6:24serializing data into Json we'll look at
  170. 6:27error handling and serialization der
  171. 6:28serialization for example invalid data
  172. 6:31data conversion errors unknown Fields
  173. 6:33look at the security concerns if it like
  174. 6:34injection attacks why to do validation
  175. 6:37before DC realization and validating
  176. 6:39Json schemas before processing data
  177. 6:42using Json schema validation we'll see
  178. 6:44the performance aspect of it like
  179. 6:46reducing the serialized data through
  180. 6:47compression and eliminating unnecessary
  181. 6:50Fields like serialization performance
  182. 6:52between text based and binary formats
  183. 6:54like Json versus protuff the tradeoffs
  184. 6:57between readability and performance
  185. 6:58because in text based format you can
  186. 7:00easily check the payload and see that
  187. 7:03does not work the same in binary formats
  188. 7:05but binary formats are faster so when
  189. 7:07you you use a binary format and when you
  190. 7:09use a text Bas format that is a valid
  191. 7:11trade-off then we'll move to
  192. 7:12authentication and authorization why do
  193. 7:14we use it different types of
  194. 7:16authentication like State full State L
  195. 7:18we have basic authentication better
  196. 7:21token authentications we'll look at
  197. 7:22sessions jws cookies we'll Deep dive on
  198. 7:25oo protocol and open ID connect we'll
  199. 7:28see how API keys work how multiactor
  200. 7:30authentications work what is salting
  201. 7:33hashing and different cryptographic
  202. 7:34techniques used in authorization we'll
  203. 7:37explore aack rback reback we'll look at
  204. 7:40what are the best practices in security
  205. 7:42like securing cookies avoiding csrf xss
  206. 7:46mitm like audit logging which basically
  207. 7:49means recording authentication
  208. 7:51authorization events for Audits and
  209. 7:54monitoring failed login attempts
  210. 7:55privilege escalation and access to
  211. 7:57sensitive resources we'll look at a
  212. 7:59skating authenticated related error
  213. 8:01messages preventing information leakage
  214. 8:03to attackers through detailed error
  215. 8:04messages like handling edge cases for
  216. 8:07example consistency in responses across
  217. 8:09different failure modes like rate
  218. 8:10limiting and account lockout we'll see
  219. 8:12how to avoid timing attacks for example
  220. 8:14attackers can exploit time differences
  221. 8:16in error responses to infer valid
  222. 8:19credentials for example an error for a
  223. 8:21wrong password might take longer than an
  224. 8:23error for a valid username because to
  225. 8:25check for a password you have to do some
  226. 8:28kind of hashing uh or uh some use some
  227. 8:31kind of cryptographic technique which
  228. 8:32takes a little bit of time so people can
  229. 8:35General the tiny bit of timing
  230. 8:38difference between them and guess
  231. 8:40passwords even though that's very
  232. 8:42difficult but we don't want to keep any
  233. 8:44security Halls then the next topic we'll
  234. 8:46explore is validation and transformation
  235. 8:48the different types of validation like
  236. 8:49syntactic validation for example
  237. 8:51checking whether resting is a email or
  238. 8:53not whether it is a valid phone number
  239. 8:55or not or whether it is a valid date
  240. 8:57format or not there is semantic valid
  241. 8:59for example a date uh a date of birth
  242. 9:02cannot be in the future or the age of a
  243. 9:06person should be between one and 120
  244. 9:08these are called semantic validations
  245. 9:10then we have type validation for example
  246. 9:13checking the input values match expected
  247. 9:15types whether it is a string or not
  248. 9:17whether it is an integer or not whether
  249. 9:19it is an array or not whether it is an
  250. 9:20object or not these types of checks are
  251. 9:22called type validation we'll see what
  252. 9:24are the best practices for validation
  253. 9:26what is the difference between client
  254. 9:28side validation and what is the of
  255. 9:29server side validation the importance of
  256. 9:31server side validation even if client
  257. 9:33side validation is already implemented
  258. 9:35because client side validation improves
  259. 9:37user experience by providing instant
  260. 9:39feedback but server side validation is
  261. 9:41the true security implementation because
  262. 9:43that is the gateway to your business
  263. 9:45logic we'll look at the importance of
  264. 9:47failing fast by reducing unnecessary
  265. 9:49processing by returning early and we'll
  266. 9:51look at uh why to keep consistency
  267. 9:53between front end validation and backend
  268. 9:55validation then there is Transformations
  269. 9:58for example type casting converting
  270. 9:59string to number or number to string
  271. 10:01because uh in query parameters or path
  272. 10:04parameters whatever we receive is a
  273. 10:05string but let's say we are expecting an
  274. 10:08ID field which is a number so before we
  275. 10:10send it to our handlers we have to
  276. 10:11convert that string into a number so
  277. 10:13that step is called a transformation
  278. 10:15which we have to take care of in our
  279. 10:17validation Pipeline and different date
  280. 10:19formats for example the front end might
  281. 10:22send a different format or we might be
  282. 10:23expecting a time stamp so that also has
  283. 10:26to taken care of in the validation
  284. 10:28pipeline then there is normalization for
  285. 10:31example converting an email to lower
  286. 10:32case or trimming white space from a
  287. 10:34string or adding country code to a phone
  288. 10:37number these are called normalizations
  289. 10:39then there is sanitization for security
  290. 10:41issues for example we have to sanitize a
  291. 10:44string that is submitted by the user to
  292. 10:46prevent attacks like SQL injection then
  293. 10:49there is complex validation Logic for
  294. 10:51example relationships let's say User
  295. 10:53submitted a form and it has two Fields
  296. 10:55one is password and another is confirm
  297. 10:57password so we have to check whether the
  298. 10:59two strings are the same or not so that
  299. 11:01is a relationship based validation then
  300. 11:04there is conditional validation so let's
  301. 11:05say in the form there are two Fields one
  302. 11:08is partner name and the second is
  303. 11:11married which is a Boolean true or false
  304. 11:14so a partner field might only be
  305. 11:16required if the married is true so that
  306. 11:18is a conditional validation so these
  307. 11:20kinds of checks we have to do then there
  308. 11:22is chain validation like converting a
  309. 11:23string to lower case then roving special
  310. 11:26characters and then checking its length
  311. 11:28then we'll look at error handling in
  312. 11:29validation like sending meaningful error
  313. 11:31messages to front end so that the user
  314. 11:33can fix them and aggregating all
  315. 11:35validation errors in one response for
  316. 11:37client side display or Aus skating error
  317. 11:40messages so instead of saying invalid
  318. 11:42password we'll have to say invalid
  319. 11:43credentials to prevent different types
  320. 11:45of attacks then we will see how to
  321. 11:47gracefully handle failed Transformations
  322. 11:49for example an invalid Json and a failed
  323. 11:52date conversion and how to let the user
  324. 11:54know in a meaningful message then we'll
  325. 11:56look at the performance trade-offs of
  326. 11:58validation and how to optimize it by
  327. 12:00returning early avoiding redundant
  328. 12:02validations then our next topic is going
  329. 12:05to be middleware we'll look at what is a
  330. 12:08middleware and when to use them what are
  331. 12:10the common use cases of middlewares the
  332. 12:12role of a middleware in a request cycle
  333. 12:14for example a pre-quest middleware or a
  334. 12:17post response middleware the flow of
  335. 12:19middlewares for example techniques like
  336. 12:21chaining a middleware is executed in a
  337. 12:23sequence passing control to the next
  338. 12:24middleware until request reaches its
  339. 12:26final Handler how to order middleware is
  340. 12:28appropriate for example we have to go in
  341. 12:30this order we have to log the request we
  342. 12:32have to check whether the user is
  343. 12:34authenticated or not we have to do
  344. 12:36validation and we have to do route
  345. 12:38handling and then we have to do error
  346. 12:40handling so this order matters in
  347. 12:42middleware flow we'll see how the next
  348. 12:44function Works in middleware and exiting
  349. 12:47middleware early how middleware can SE
  350. 12:50circuit the request pipeline by handling
  351. 12:51404 errors we'll look at some of the
  352. 12:54common middlewares like security
  353. 12:55middlewares which add security headers
  354. 12:57like X content type or strict Transport
  355. 13:00Security or content security policy or
  356. 13:02middlewares which add appropriate course
  357. 13:05headers to every single request or
  358. 13:07response and middleware to avoid csrf
  359. 13:10attack middleware to rate limit then we
  360. 13:12have authentication middleware to reuse
  361. 13:15the route protecting logic across our
  362. 13:18apps then we have logging and monitoring
  363. 13:20middlewares for request logging or
  364. 13:21structur logging for observability or
  365. 13:24easier debugging in production then we
  366. 13:26have error handling middlewares which
  367. 13:28catches and form mats application Level
  368. 13:30errors for consistent API responses then
  369. 13:32we have compression or performance
  370. 13:34related middlewares which basically
  371. 13:35compresses response bodies to reduce the
  372. 13:37size of data sent over the networks then
  373. 13:39we have data passing middleware passing
  374. 13:41incoming request bodies like Json URL
  375. 13:43encoded forms and file uploads handles
  376. 13:45multiplatform data for the file uploads
  377. 13:48then we'll look at the performance and
  378. 13:49scalability aspect of middleware like
  379. 13:52what are the best practices to keep
  380. 13:53middlewares lightweight and efficient
  381. 13:55ensuring middleware is applied in the
  382. 13:57correct order or how how middleware
  383. 13:59order can affect the performance and
  384. 14:01security of the application the next
  385. 14:03topic is going to be request context
  386. 14:05request context basically means the
  387. 14:07metadata that is often passed through
  388. 14:10application middlewares controllers and
  389. 14:12services it is kind of a request coped
  390. 14:15State right the state is only valid for
  391. 14:18that request so here we'll explore the
  392. 14:20life cycle of a request maintaining
  393. 14:22State for the duration of a request
  394. 14:24sharing data across different layers of
  395. 14:26the application without coupling how
  396. 14:28context provides a temporary request
  397. 14:29scoped State we look at what are the
  398. 14:31different components of a request
  399. 14:33context the request metadata for example
  400. 14:35the HTTP method the URL headers the
  401. 14:37query parameters and the body and there
  402. 14:39is the session and user information for
  403. 14:41example in the authentication middleware
  404. 14:43we fetch the user information and then
  405. 14:45we add it to the request context so for
  406. 14:47that request scope the users information
  407. 14:50is injected into the context then we
  408. 14:52have tracking and loging information
  409. 14:53like unique request IDs or Trace IDs
  410. 14:56then we have request specific data like
  411. 14:58custom data in injected during the
  412. 14:59request life cycle like caching data
  413. 15:01permission checks we'll look at what are
  414. 15:02the use cases for example authentication
  415. 15:05rate limiting tracing logging we'll
  416. 15:07explore the connection between
  417. 15:08middlewares and request contexts we'll
  418. 15:09see what are the different types of
  419. 15:11timeouts the request timeouts custom
  420. 15:13timeouts cancellation signals we'll see
  421. 15:15what are the best practices like keeping
  422. 15:17it lightweight to prevent memory
  423. 15:18overhead ensuring context data is
  424. 15:20cleaned up after request life cycle to
  425. 15:22prevent memory leaks avoiding tightly
  426. 15:24coupling components through context or
  427. 15:26over relying on it for passing data then
  428. 15:28we'll move to handlers and controllers
  429. 15:30the MVC pattern and what handlers and
  430. 15:32controllers and services the
  431. 15:34responsibilities of all of them and
  432. 15:36reducing code with middleware then we
  433. 15:38have centralized error handling in
  434. 15:39handlers and consistent success and
  435. 15:42error message formats and how to
  436. 15:43implement them in controllers then we'll
  437. 15:46look at the different types of crud
  438. 15:47operations like how cud operations map
  439. 15:50HTTP methods and what are the common
  440. 15:52apis associated with each method for
  441. 15:54example post method is usually used for
  442. 15:56creation and submissions and the status
  443. 15:59code is usually 2011 created or a400 if
  444. 16:03it's a bad request and get requests are
  445. 16:05usually associated with fetching a list
  446. 16:07of resources or fetching a single
  447. 16:08resource and we have put and Patch to
  448. 16:11update resources and delete to delete
  449. 16:14resources we look at how to implement
  450. 16:16pagination and how to implement a search
  451. 16:19API how to do sorting and how to do
  452. 16:21filtering and we'll see what are the
  453. 16:23best practices for example strict
  454. 16:25validation consistent response
  455. 16:26formatting limiting payload redacting
  456. 16:29sensitive Fields error handling
  457. 16:31authentication and authorization then
  458. 16:33we'll explore what is the restful
  459. 16:34architecture and what are the best
  460. 16:36practices for implementing rest apis the
  461. 16:39principle of Designing apis around
  462. 16:41resources and sticking to sttp semantics
  463. 16:44and best practices for filtering and
  464. 16:46pagination uh what are the different
  465. 16:48types of versioning like URI versioning
  466. 16:50header versioning query string media
  467. 16:52type we'll see how to design apis with
  468. 16:54open API spec in mind you'll see content
  469. 16:57negotiation capturing exceptions and
  470. 16:59providing meaningful messages supporting
  471. 17:02client side caching e taxs and
  472. 17:04optimizing large requests and responses
  473. 17:06after that we'll move on to a very
  474. 17:08important topic which are databases in
  475. 17:10databases we'll look at relational and
  476. 17:12non-relational what are the differences
  477. 17:14and to when to use which we look at some
  478. 17:16of the theoretical Concepts like acid
  479. 17:18and cap theorem we'll take a look at
  480. 17:20basic quering and joints and database
  481. 17:22design best practices like schema design
  482. 17:25indexing we look at different
  483. 17:26optimization methods like query
  484. 17:28optimization caching connection pooling
  485. 17:30then we have data Integrity like
  486. 17:33constraints and validations transactions
  487. 17:35and concurrency we'll see how ORS work
  488. 17:39whether to use an orm what are the
  489. 17:40tradeoffs and we'll look at what are
  490. 17:42database migrations that we'll move on
  491. 17:44to business logic layer which is also
  492. 17:46called BL what is the role of it what
  493. 17:48are the different layers of a request
  494. 17:50cycle for example we have validation
  495. 17:52layer we have routing we have
  496. 17:53middlewares and we have handl and
  497. 17:55controls which all of them fall under
  498. 17:57presentation layer because they they
  499. 17:59deal with users data whether it is
  500. 18:01accepting users data or sending a user
  501. 18:04data so those are part of a presentation
  502. 18:06layer after that we have business logic
  503. 18:09layer which is the middle one which
  504. 18:11deals with our Core Business logic and
  505. 18:14after that we have the data access layer
  506. 18:17which deals with databases perform
  507. 18:19squaring or inserts or deletions and
  508. 18:21business logic layer uses the data
  509. 18:23access layer behind the scenes we'll
  510. 18:24look at different design principles like
  511. 18:26separation of concerns single
  512. 18:28responsibility open close dependency
  513. 18:30inversion what are the components of a
  514. 18:31business logic layer for example we have
  515. 18:33Services we have domain models which
  516. 18:35represent core entities like a user or
  517. 18:37an order then we have business tools
  518. 18:40then we have business validation logic
  519. 18:42we'll look at service layer design best
  520. 18:43practices we'll look at how to handle
  521. 18:45errors properly and how to propagate
  522. 18:47those errors from our service layer to
  523. 18:50our presentation layer after that we
  524. 18:51have caching we'll discuss what is the
  525. 18:53need of caching and how it differs from
  526. 18:55database persistence what are the
  527. 18:57different types of caching we have
  528. 18:58memory caching browser caching database
  529. 19:00caching and what is the need of client
  530. 19:02side caching and server side caching the
  531. 19:04different caching strategies for example
  532. 19:06cash aside right through right behind or
  533. 19:09right back read through the different
  534. 19:11cash eviction strategies for example lru
  535. 19:14lfu TTL and fifo need for cash
  536. 19:17invalidation like manual Cash
  537. 19:18invalidation Time To Live invalidation
  538. 19:21or event bash invalidation the different
  539. 19:23levels of caching level one which is in
  540. 19:25memory level two which is Network
  541. 19:27distributed and there is is the
  542. 19:29hierarchical caching which combines
  543. 19:32level one and level two caching
  544. 19:33strategies where frequently used data is
  545. 19:35stored in a fast small cach which is the
  546. 19:38level one cache and the less frequently
  547. 19:40used data is stored in a slower or large
  548. 19:42cach which is the level two cache we'll
  549. 19:44see how caching for web apps looks like
  550. 19:46that is caching static assets or caching
  551. 19:48API responses using headers we'll see
  552. 19:50how to cach with databases for example
  553. 19:52query caching like storing the results
  554. 19:55of heavy joints in redis and look at
  555. 19:59Cash hit and cash Miss ratio and how to
  556. 20:02optimize them after that we'll move on
  557. 20:04to transactional emails what are the use
  558. 20:06of them what are the common use cases
  559. 20:08the anatomy of a transactional email the
  560. 20:10subject the preheader the body header
  561. 20:12main content CTA footer and how to
  562. 20:14personalize with different Dynamic
  563. 20:16parameters then we have task queuing and
  564. 20:18scheduling what are the common use cases
  565. 20:21for example queuing might be used for
  566. 20:23sending emails or processing image files
  567. 20:26and third party API integration like
  568. 20:28Payment Processing or web hooks or
  569. 20:29offloading heavy computation like badge
  570. 20:31processing for example a user clicks a
  571. 20:33button to clear all my data so to clear
  572. 20:36all the users data we have to call we
  573. 20:39have to execute different queries for
  574. 20:41different tables to clear all the users
  575. 20:43data and that might take some time so
  576. 20:45instead of blocking the request we
  577. 20:46return the response instantly and we
  578. 20:48trigger a background job by pushing into
  579. 20:50the task Cube we'll look at scheduling
  580. 20:52what are the use cases for example for
  581. 20:54example running database backups
  582. 20:56recurring notifications and reminders
  583. 20:58data synchronization or maintenance
  584. 21:01related issues for example clearing logs
  585. 21:03or caches the different components of a
  586. 21:06task Q There is the producer Q consumer
  587. 21:09broker backend the flow of a task
  588. 21:11dependency for example it might be chain
  589. 21:13dependency or it might have parent child
  590. 21:16relationship we look at task groups
  591. 21:18executing multiple task concurrently and
  592. 21:20waiting for all of them to complete at
  593. 21:21the same time we look at how to handle
  594. 21:23errors and Implement retries in task use
  595. 21:26we'll look at task prioritization and
  596. 21:28and rate limiting for example giving
  597. 21:30importance to task like Payment
  598. 21:31Processing before you process task like
  599. 21:33sending notifications after that we'll
  600. 21:35move on to elastic search why do we use
  601. 21:37elastic search and how does it work
  602. 21:39behind the scenes the different
  603. 21:41techniques that are used for example
  604. 21:42inverted index term frequency and
  605. 21:44inverse document frequency segments and
  606. 21:46shards what are the use cases of elastic
  607. 21:48search for example providing a type
  608. 21:50ahead experience or log analytics or
  609. 21:53social media search for example full
  610. 21:55text search for user profiles posts
  611. 21:57comments we'll see how to create and
  612. 21:59manage indexes we'll see how to search
  613. 22:01and query different types of searching
  614. 22:03basic searching full text search
  615. 22:04relevance scoring we'll see how to
  616. 22:06optimize search performance by tweaking
  617. 22:08text versus keyword Fields understanding
  618. 22:10analyzers and boosting and pagination
  619. 22:13we'll take a look at some of the
  620. 22:14advanced search patterns for example
  621. 22:16filtering aggregation fuzzy search then
  622. 22:18we'll see how kibana works and how to
  623. 22:20use elastic search in a user friendly
  624. 22:22way and different best practices for
  625. 22:24example defining field mappings
  626. 22:26explicitly optimizing the number number
  627. 22:28of shards indexing data in batches and
  628. 22:31avoiding wild cards then we have error
  629. 22:33handling the different types of errors
  630. 22:35in our apps could be syntax errors
  631. 22:37runtime errors logical errors and
  632. 22:39different error handling strategies for
  633. 22:41example fail safe or fail fast graceful
  634. 22:44degradation or prevention of Errors
  635. 22:46different practices for error handling
  636. 22:48for example catching early not
  637. 22:49swallowing errors custom error types
  638. 22:51failing gracefully logging errors and
  639. 22:53using stack traces we'll look at how
  640. 22:56Global error handlers work we'll see how
  641. 22:57to appropriate handle user facing errors
  642. 23:00like providing friendly error messages
  643. 23:01and providing actionable feedbacks we'll
  644. 23:04see the importance of monitoring and
  645. 23:05logging in error handling and different
  646. 23:08tools like Sentry or elk stack and
  647. 23:11different error alerts like email based
  648. 23:14alerts and slack based alerts after that
  649. 23:16we have config management what is
  650. 23:18exactly config management and how does
  651. 23:20it help with flexibility and decouples
  652. 23:23environment specific settings from
  653. 23:25application logic and what are the use
  654. 23:27cases for example example different
  655. 23:29environments using config management
  656. 23:31safely managing sensitive data such as
  657. 23:33API Keys database passwords and private
  658. 23:36certificates dynamically enabling and
  659. 23:38disabling features without changing
  660. 23:40codebase what are the best practices of
  661. 23:42config management different types of
  662. 23:44configs for example static configs like
  663. 23:46DB credentials and API end points
  664. 23:49Dynamic configs like feature Flags rate
  665. 23:51limits and sensitive configs like
  666. 23:53credentials tokens secrets and different
  667. 23:56sources of configs for example it could
  668. 23:58be EnV file or Json or yaml and what are
  669. 24:01the differences between using
  670. 24:02environment variables versus command
  671. 24:05line Flags versus static files after
  672. 24:07that we have logging monitoring and
  673. 24:09observability a very important topic
  674. 24:11we'll see what are the differences
  675. 24:12between logging tracing monitoring and
  676. 24:15observability the different types of
  677. 24:16logging like system logging application
  678. 24:18access security logs the different
  679. 24:20levels of logs like debug info one error
  680. 24:24fatal and we'll see the difference
  681. 24:26between structured logging and un
  682. 24:28structure logging and the best practices
  683. 24:30for logging like centralized logging log
  684. 24:33rotation and retention contextual and
  685. 24:35meaningful logs and avoiding sensitive
  686. 24:37data like passwords and API Keys then we
  687. 24:39will look at monitoring different types
  688. 24:41of monitoring like infrastructure
  689. 24:43monitoring application performance
  690. 24:44monitoring uptime monitoring the
  691. 24:46different tools that are used in
  692. 24:47monitoring like Prometheus grafana and
  693. 24:50how to manage alerts and notifications
  694. 24:52by defining thresholds creating alerts
  695. 24:55and avoiding alert fatigue by only
  696. 24:57creating action alerts and ensuring that
  697. 24:59alerts are meaningful and necessary then
  698. 25:02we'll take a look at observability the
  699. 25:04three pillars of observability which are
  700. 25:06logs metrics and traces the best
  701. 25:08practices around it the security and
  702. 25:10compliance of log management after that
  703. 25:12we'll move on to graceful shutdown why
  704. 25:14do we need graceful shutdown and how
  705. 25:16does it work behind the scenes what are
  706. 25:18the different use cases for example you
  707. 25:20might need it when server restarts or or
  708. 25:23scaling in Cloud environments or
  709. 25:25microservices or long running jobs how
  710. 25:27it works like signal handling sigor
  711. 25:30signant and sill signals what are the
  712. 25:32different steps of graceful shutdown for
  713. 25:34example it starts with capturing a
  714. 25:36signal and then it stops accepting
  715. 25:38requests then it completes an inflight
  716. 25:41requests and then it closes external
  717. 25:43resources like database connections or
  718. 25:45any open files Etc and at last it
  719. 25:48terminates the app after that we'll move
  720. 25:50on to security the different aspects of
  721. 25:52security in a backend code base avoiding
  722. 25:54different security attacks like SQL
  723. 25:56injection no SQL injection xss csrf
  724. 25:59broken authentication insecure
  725. 26:02deserialization and principles of a
  726. 26:04secure software design for example least
  727. 26:06privilege defense in depth fail secure
  728. 26:09defaults separation of Duties security
  729. 26:11by Design then we'll look at the
  730. 26:13importance of input validation and
  731. 26:15sanitization and rate limits and content
  732. 26:17security policy course and same side
  733. 26:20cookie and the importance of monitoring
  734. 26:22events after that we have scaling and
  735. 26:24performance the different metrics of
  736. 26:26performance like response time resource
  737. 26:28utilization identifying bottlenecks
  738. 26:30caching and database optimization for
  739. 26:33example avoiding n plus1 query problems
  740. 26:35and ensuring proper use of joints and
  741. 26:38using lazy loading where appropriate
  742. 26:40then we have using database indexes to
  743. 26:42speed of read operations on frequent VAR
  744. 26:45Fields like indexing foreign keys or
  745. 26:47search Fields how to process data in
  746. 26:49batches to minimize database load and
  747. 26:51improve performance for large data sets
  748. 26:53how to avoid memory leaks like closing
  749. 26:55file handles database connections or
  750. 26:57cleaning of after a long process
  751. 26:59minimizing Network overhead by reducing
  752. 27:01payload size and using compression we'll
  753. 27:03look at how to do performance testing
  754. 27:05and profiling we look at some of the
  755. 27:07best practices for writing performant
  756. 27:08code like focusing on writing clear and
  757. 27:11maintainable code first without
  758. 27:13premature optimization and writing
  759. 27:15modular code to make it easier to
  760. 27:17optimize individual components without
  761. 27:19affecting the entire system ensuring
  762. 27:21that if a particular resources under
  763. 27:22load are unavailable the system degrades
  764. 27:25gracefully without crashing and how to
  765. 27:27offload non critical tasks like sending
  766. 27:29emails or logging to background
  767. 27:31processes or task use to free of
  768. 27:33resources for more critical operations
  769. 27:36then we have concurrency and parallelism
  770. 27:38what are the difference between
  771. 27:39concurrency and parallelism and how
  772. 27:41concurrency helps in IO bound task and
  773. 27:43how parallelism helps in CPU bound tasks
  774. 27:46then we have object storage and large
  775. 27:47files we'll look at some of the common
  776. 27:49use cases when we use object storage
  777. 27:51like awss 3 and how to manage large
  778. 27:54files with chunking and streaming and
  779. 27:57we'll look at multiart file uploads then
  780. 27:59we have realtime backend systems where
  781. 28:01we take a look at web sockets or servers
  782. 28:03and events and pubs of architecture to
  783. 28:06that we have testing and code quality
  784. 28:09here we take a look at different types
  785. 28:10of testing unit testing integration
  786. 28:12testing end to end testing functional
  787. 28:14testing regression testing performance
  788. 28:16testing load and stress testing user
  789. 28:19acceptance testing security testing
  790. 28:21we'll take a look at what is test driven
  791. 28:23development how to automate test in cicd
  792. 28:25environments how to manage code quality
  793. 28:27with external linting and formatting
  794. 28:29tools and what are the measures of code
  795. 28:31quality and coverage like quality
  796. 28:33metrics like cyclomatic complexity which
  797. 28:36measures complexity of a function by
  798. 28:37counting the number of possible paths
  799. 28:39through the code and we have
  800. 28:41maintainability index which basically
  801. 28:43quantifies how easy it is to maintain a
  802. 28:45code based on the complexity lines of
  803. 28:48code and other factors then we'll take a
  804. 28:50look at a very interesting set of
  805. 28:51principles which is called 12 Factor app
  806. 28:53after that we'll move on to open API
  807. 28:56standards what is the need of this
  808. 28:58standards and why should we stick to it
  809. 29:00what are the benefits of it what are the
  810. 29:02use cases like documentation Automation
  811. 29:04and the ecosystem surrounding it like
  812. 29:06Swagger Corden postmen and what is the
  813. 29:09history the Swagger to open API
  814. 29:12transition and what are the different
  815. 29:13versions that are currently active and
  816. 29:16what are the key concepts of open API
  817. 29:18documents for example there is API pass
  818. 29:20the request and response definition
  819. 29:23there is parameters there is schemas and
  820. 29:25what is the structure of an OPN API
  821. 29:27document there is metadata there is
  822. 29:29paths there is components there is
  823. 29:31security definitions and there is
  824. 29:33responses we'll see what are the new
  825. 29:35features of open API 3.0 and 3.1 what
  826. 29:37are the tools surrounding open API for
  827. 29:39example Swagger UI Cen Postman what are
  828. 29:42the best practices like avoiding
  829. 29:44duplication and sticking to standards
  830. 29:47we'll look at a very interesting
  831. 29:49development method which is API First
  832. 29:51Development where you define your open
  833. 29:52API standard or write your open API spec
  834. 29:55first and then you start creating the
  835. 29:57apis after that we'll move on to web
  836. 29:59hooks what are the use cases of web
  837. 30:01hooks by like sending notification third
  838. 30:03party Integrations what are the
  839. 30:04differences between API versus web hook
  840. 30:06for the same use case for example for
  841. 30:08API we might have to use polling which
  842. 30:10is client side initiated compared to web
  843. 30:12hooks which is pushing is server
  844. 30:14initiated what are the key components of
  845. 30:17web hooks for example the web hook URL
  846. 30:19event triggers payload HTTP method the
  847. 30:21response handling what are the best
  848. 30:23practices surrounding web hooks like web
  849. 30:25hook signature verification like using
  850. 30:27http PS and quick response retry logic
  851. 30:30logging how to test web hooks with enro
  852. 30:32real world use cases like STP Payment
  853. 30:34Processing GitHub web hook slack Discord
  854. 30:37TWU Etc and at last we'll take a look at
  855. 30:40what are some devops Concepts and
  856. 30:42backend engineer should be familiar with
  857. 30:44for example some of the Core Concepts
  858. 30:46like continuous integration continuous
  859. 30:48delivery continuous deployment the
  860. 30:51devops practices like infrastructure is
  861. 30:53code config management Version Control
  862. 30:56the different tools surrounding devops
  863. 30:58for example creating containers with
  864. 30:59Docker or orchestrating container with
  865. 31:01kubernetes and cicd pipelines and how to
  866. 31:05scale your service horizontal scaling
  867. 31:07versus vertical scaling and different
  868. 31:10deployment strategies like red green
  869. 31:12deployment rolling deployment Etc and
  870. 31:15that's about it this is all the concepts
  871. 31:17that we are going to cover in the next
  872. 31:1930 or 40 videos so stay tuned

About this transcript

This page contains the full transcript of 1. Roadmap for backend from first principles by Sriniously, generated from the public captions YouTube serves with the video. The transcript has 5,502 words across 872 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.