1. Roadmap for backend from first principles — Transcript
Full transcript
- 0:00backend engineering is a very wide scope
- 0:03and when I say backend engineering it is
- 0:07much more than building a set of crud
- 0:09apis the way I think backend engineering
- 0:12is about building reliable scalable fall
- 0:15tolerant and maintainable code bases and
- 0:19efficient
- 0:20systems and if one were to start today
- 0:25to learn back in development there are a
- 0:27lot of resources and
- 0:30at least 1,00
- 0:31resources but how do you decide what to
- 0:34learn how do you prioritize how do you
- 0:36see the big picture when and how all
- 0:39these different concepts come together
- 0:41and this is the reason it takes people
- 0:43years to get their head around a lot of
- 0:45these Concepts and principles because
- 0:48people primarily start with a limited
- 0:50scope of training uh whether it is from
- 0:52a college or a boot camp or a simple cop
- 0:56course and they eventually build onp top
- 1:00of that with trial and error and with
- 1:01help of other developers over time now I
- 1:04am a backend engineer and I have faced
- 1:08this struggle initially when I started
- 1:10out I had to constantly search for
- 1:12resources learn from other developers I
- 1:15have read a lot of books on backend
- 1:16development I have studied hundreds of
- 1:19open- source code bases to see how
- 1:22people in the industry are building
- 1:23stuff and it was a very timec consuming
- 1:26procedure and the second problem is
- 1:29people start with backend development
- 1:31from a particular language or Frameworks
- 1:34point of view it could be Express or
- 1:37spring boot or Ruby on Rails and the
- 1:41problem with that is you look at the
- 1:43problems that you solve with the lens of
- 1:45your particular language and ecosystem
- 1:48and there are blind spots in that let's
- 1:50imagine you have to switch to a
- 1:52different language let's say you were
- 1:54working with rubyan rails for years and
- 1:56one day your company decided to migrate
- 1:58to golang for performance reasons in
- 2:00that situation how much of your
- 2:02knowledge can you transfer if you don't
- 2:05understand the underlying systems so
- 2:08here I have decided to put together a
- 2:10comprehensive list of videos which are
- 2:13based on foundational concepts of a
- 2:15backend system and these are from
- 2:17various books that I've read over the
- 2:18years the open source code base we'll
- 2:20start with a very high level
- 2:22understanding of how backend systems
- 2:24work behind the scenes we'll look at how
- 2:27request from browser flows through
- 2:29different hops the network firewalls
- 2:31over the internet and how it is routed
- 2:34to our backend server that is situated
- 2:36in a remote AWS server and how it
- 2:39responds to that request and we'll look
- 2:41at what the response looks like and that
- 2:44should give us a pretty vivid idea of
- 2:47how systems communicate how a client
- 2:49communicates with a server and how the
- 2:51server responds from there we'll move to
- 2:53understanding HTTP protocol what is the
- 2:56role it plays and how the communication
- 2:59is established through HTTP and how HTTP
- 3:03raw messages look like and what are the
- 3:05HTTP headers what are the role of the
- 3:07headers the different types of headers
- 3:09like request headers or representational
- 3:12headers General headers and security
- 3:14headers and we'll look at different
- 3:16types of HTTP methods like get method
- 3:18post put delete and when to use them and
- 3:21what are the semantics and what are the
- 3:23principles behind them we'll look at
- 3:25what is the cost flow and how does it
- 3:28work we'll look at how simple request
- 3:30defers from a pre-flight request and how
- 3:33a pre-flight request FL looks like from
- 3:35our browser to the server and back to
- 3:36our browser we'll look at HTTP responses
- 3:39the structure of it and different status
- 3:41codes that server returns and when to
- 3:44return which type of code and what are
- 3:46the most commonly used HTTP status codes
- 3:49then we'll look at HTTP caching what are
- 3:51the different types of caching
- 3:53techniques using HTTP we have eags we
- 3:55have uh max age headers then we'll look
- 3:58at the differences between http 1. 1 and
- 4:00HTTP 2.0 and HTTP 3.0 and what are the
- 4:03differences between them we will look at
- 4:05how content negotiation looks like
- 4:07between client and server using
- 4:08different headers we'll see how
- 4:10persistent connections work in HTTP
- 4:12we'll look at HTTP compression different
- 4:14types of compression techniques like
- 4:15gzip and deflate and BR and which is the
- 4:19commonly used technique we'll see the
- 4:21security aspect of it the SSL TLS and
- 4:24htps then we'll move on to routing how
- 4:26routing Maps URLs to server side logic
- 4:29and what is the connection between
- 4:30routing and HTTP methods different
- 4:32components of routes like path
- 4:34parameters and query parameters
- 4:36different types of routes static routes
- 4:38Dynamic routes nested routes
- 4:40hierarchical routes catchall Wild Card
- 4:42routes and regular expression based
- 4:44routes how to do API versioning using
- 4:46HTTP different types of versioning
- 4:48techniques we'll see what is the best
- 4:49way to deprecate it outout and what are
- 4:51the best practices in the industry we
- 4:53look at the benefits of Route grouping
- 4:55and how it helps with versioning
- 4:57permissions and shared middleware we'll
- 4:59see how to secure routes how to optimize
- 5:02route matching performance then we'll
- 5:04move on to serialization and der
- 5:05serialization this basically means how
- 5:08before sending it over to the network
- 5:10our server translates the data into a
- 5:12particular format and after receiving
- 5:14the data from uh let's say client over
- 5:17the internet and how and how it
- 5:19translates the data received from the
- 5:21client over the internet to its own
- 5:22native format that is called DC
- 5:24realization and we will see what is the
- 5:26need of it and how it helps with the
- 5:28interoperability standard the different
- 5:30formats that are used in serialization
- 5:33der serialization we have text based
- 5:34formats which is Json or XML we have
- 5:37binary formats which is prot off and
- 5:40what are the performance differences
- 5:41between these two and when to use which
- 5:44one we'll look at how different
- 5:45programming languages Implement
- 5:46serialization and der serialization we
- 5:48will explore a popular text based format
- 5:50for serialization and der serialization
- 5:52which is Json the structure of Json the
- 5:54different data types like strings
- 5:55numbers booleans arrays and objects how
- 5:58realization of nested objects and
- 5:59collections are handled in Json how DC
- 6:02serializing into data structures the
- 6:04native data structures works like in
- 6:06let's say python dictionary or goang
- 6:08structs or JavaScript object what are
- 6:11the common errors while dealing with
- 6:12Json like handling missing or extra
- 6:14Fields dealing with null values or date
- 6:17serialization issues and time zone
- 6:19issues and how to implement custom
- 6:22serialization while before sending or
- 6:24serializing data into Json we'll look at
- 6:27error handling and serialization der
- 6:28serialization for example invalid data
- 6:31data conversion errors unknown Fields
- 6:33look at the security concerns if it like
- 6:34injection attacks why to do validation
- 6:37before DC realization and validating
- 6:39Json schemas before processing data
- 6:42using Json schema validation we'll see
- 6:44the performance aspect of it like
- 6:46reducing the serialized data through
- 6:47compression and eliminating unnecessary
- 6:50Fields like serialization performance
- 6:52between text based and binary formats
- 6:54like Json versus protuff the tradeoffs
- 6:57between readability and performance
- 6:58because in text based format you can
- 7:00easily check the payload and see that
- 7:03does not work the same in binary formats
- 7:05but binary formats are faster so when
- 7:07you you use a binary format and when you
- 7:09use a text Bas format that is a valid
- 7:11trade-off then we'll move to
- 7:12authentication and authorization why do
- 7:14we use it different types of
- 7:16authentication like State full State L
- 7:18we have basic authentication better
- 7:21token authentications we'll look at
- 7:22sessions jws cookies we'll Deep dive on
- 7:25oo protocol and open ID connect we'll
- 7:28see how API keys work how multiactor
- 7:30authentications work what is salting
- 7:33hashing and different cryptographic
- 7:34techniques used in authorization we'll
- 7:37explore aack rback reback we'll look at
- 7:40what are the best practices in security
- 7:42like securing cookies avoiding csrf xss
- 7:46mitm like audit logging which basically
- 7:49means recording authentication
- 7:51authorization events for Audits and
- 7:54monitoring failed login attempts
- 7:55privilege escalation and access to
- 7:57sensitive resources we'll look at a
- 7:59skating authenticated related error
- 8:01messages preventing information leakage
- 8:03to attackers through detailed error
- 8:04messages like handling edge cases for
- 8:07example consistency in responses across
- 8:09different failure modes like rate
- 8:10limiting and account lockout we'll see
- 8:12how to avoid timing attacks for example
- 8:14attackers can exploit time differences
- 8:16in error responses to infer valid
- 8:19credentials for example an error for a
- 8:21wrong password might take longer than an
- 8:23error for a valid username because to
- 8:25check for a password you have to do some
- 8:28kind of hashing uh or uh some use some
- 8:31kind of cryptographic technique which
- 8:32takes a little bit of time so people can
- 8:35General the tiny bit of timing
- 8:38difference between them and guess
- 8:40passwords even though that's very
- 8:42difficult but we don't want to keep any
- 8:44security Halls then the next topic we'll
- 8:46explore is validation and transformation
- 8:48the different types of validation like
- 8:49syntactic validation for example
- 8:51checking whether resting is a email or
- 8:53not whether it is a valid phone number
- 8:55or not or whether it is a valid date
- 8:57format or not there is semantic valid
- 8:59for example a date uh a date of birth
- 9:02cannot be in the future or the age of a
- 9:06person should be between one and 120
- 9:08these are called semantic validations
- 9:10then we have type validation for example
- 9:13checking the input values match expected
- 9:15types whether it is a string or not
- 9:17whether it is an integer or not whether
- 9:19it is an array or not whether it is an
- 9:20object or not these types of checks are
- 9:22called type validation we'll see what
- 9:24are the best practices for validation
- 9:26what is the difference between client
- 9:28side validation and what is the of
- 9:29server side validation the importance of
- 9:31server side validation even if client
- 9:33side validation is already implemented
- 9:35because client side validation improves
- 9:37user experience by providing instant
- 9:39feedback but server side validation is
- 9:41the true security implementation because
- 9:43that is the gateway to your business
- 9:45logic we'll look at the importance of
- 9:47failing fast by reducing unnecessary
- 9:49processing by returning early and we'll
- 9:51look at uh why to keep consistency
- 9:53between front end validation and backend
- 9:55validation then there is Transformations
- 9:58for example type casting converting
- 9:59string to number or number to string
- 10:01because uh in query parameters or path
- 10:04parameters whatever we receive is a
- 10:05string but let's say we are expecting an
- 10:08ID field which is a number so before we
- 10:10send it to our handlers we have to
- 10:11convert that string into a number so
- 10:13that step is called a transformation
- 10:15which we have to take care of in our
- 10:17validation Pipeline and different date
- 10:19formats for example the front end might
- 10:22send a different format or we might be
- 10:23expecting a time stamp so that also has
- 10:26to taken care of in the validation
- 10:28pipeline then there is normalization for
- 10:31example converting an email to lower
- 10:32case or trimming white space from a
- 10:34string or adding country code to a phone
- 10:37number these are called normalizations
- 10:39then there is sanitization for security
- 10:41issues for example we have to sanitize a
- 10:44string that is submitted by the user to
- 10:46prevent attacks like SQL injection then
- 10:49there is complex validation Logic for
- 10:51example relationships let's say User
- 10:53submitted a form and it has two Fields
- 10:55one is password and another is confirm
- 10:57password so we have to check whether the
- 10:59two strings are the same or not so that
- 11:01is a relationship based validation then
- 11:04there is conditional validation so let's
- 11:05say in the form there are two Fields one
- 11:08is partner name and the second is
- 11:11married which is a Boolean true or false
- 11:14so a partner field might only be
- 11:16required if the married is true so that
- 11:18is a conditional validation so these
- 11:20kinds of checks we have to do then there
- 11:22is chain validation like converting a
- 11:23string to lower case then roving special
- 11:26characters and then checking its length
- 11:28then we'll look at error handling in
- 11:29validation like sending meaningful error
- 11:31messages to front end so that the user
- 11:33can fix them and aggregating all
- 11:35validation errors in one response for
- 11:37client side display or Aus skating error
- 11:40messages so instead of saying invalid
- 11:42password we'll have to say invalid
- 11:43credentials to prevent different types
- 11:45of attacks then we will see how to
- 11:47gracefully handle failed Transformations
- 11:49for example an invalid Json and a failed
- 11:52date conversion and how to let the user
- 11:54know in a meaningful message then we'll
- 11:56look at the performance trade-offs of
- 11:58validation and how to optimize it by
- 12:00returning early avoiding redundant
- 12:02validations then our next topic is going
- 12:05to be middleware we'll look at what is a
- 12:08middleware and when to use them what are
- 12:10the common use cases of middlewares the
- 12:12role of a middleware in a request cycle
- 12:14for example a pre-quest middleware or a
- 12:17post response middleware the flow of
- 12:19middlewares for example techniques like
- 12:21chaining a middleware is executed in a
- 12:23sequence passing control to the next
- 12:24middleware until request reaches its
- 12:26final Handler how to order middleware is
- 12:28appropriate for example we have to go in
- 12:30this order we have to log the request we
- 12:32have to check whether the user is
- 12:34authenticated or not we have to do
- 12:36validation and we have to do route
- 12:38handling and then we have to do error
- 12:40handling so this order matters in
- 12:42middleware flow we'll see how the next
- 12:44function Works in middleware and exiting
- 12:47middleware early how middleware can SE
- 12:50circuit the request pipeline by handling
- 12:51404 errors we'll look at some of the
- 12:54common middlewares like security
- 12:55middlewares which add security headers
- 12:57like X content type or strict Transport
- 13:00Security or content security policy or
- 13:02middlewares which add appropriate course
- 13:05headers to every single request or
- 13:07response and middleware to avoid csrf
- 13:10attack middleware to rate limit then we
- 13:12have authentication middleware to reuse
- 13:15the route protecting logic across our
- 13:18apps then we have logging and monitoring
- 13:20middlewares for request logging or
- 13:21structur logging for observability or
- 13:24easier debugging in production then we
- 13:26have error handling middlewares which
- 13:28catches and form mats application Level
- 13:30errors for consistent API responses then
- 13:32we have compression or performance
- 13:34related middlewares which basically
- 13:35compresses response bodies to reduce the
- 13:37size of data sent over the networks then
- 13:39we have data passing middleware passing
- 13:41incoming request bodies like Json URL
- 13:43encoded forms and file uploads handles
- 13:45multiplatform data for the file uploads
- 13:48then we'll look at the performance and
- 13:49scalability aspect of middleware like
- 13:52what are the best practices to keep
- 13:53middlewares lightweight and efficient
- 13:55ensuring middleware is applied in the
- 13:57correct order or how how middleware
- 13:59order can affect the performance and
- 14:01security of the application the next
- 14:03topic is going to be request context
- 14:05request context basically means the
- 14:07metadata that is often passed through
- 14:10application middlewares controllers and
- 14:12services it is kind of a request coped
- 14:15State right the state is only valid for
- 14:18that request so here we'll explore the
- 14:20life cycle of a request maintaining
- 14:22State for the duration of a request
- 14:24sharing data across different layers of
- 14:26the application without coupling how
- 14:28context provides a temporary request
- 14:29scoped State we look at what are the
- 14:31different components of a request
- 14:33context the request metadata for example
- 14:35the HTTP method the URL headers the
- 14:37query parameters and the body and there
- 14:39is the session and user information for
- 14:41example in the authentication middleware
- 14:43we fetch the user information and then
- 14:45we add it to the request context so for
- 14:47that request scope the users information
- 14:50is injected into the context then we
- 14:52have tracking and loging information
- 14:53like unique request IDs or Trace IDs
- 14:56then we have request specific data like
- 14:58custom data in injected during the
- 14:59request life cycle like caching data
- 15:01permission checks we'll look at what are
- 15:02the use cases for example authentication
- 15:05rate limiting tracing logging we'll
- 15:07explore the connection between
- 15:08middlewares and request contexts we'll
- 15:09see what are the different types of
- 15:11timeouts the request timeouts custom
- 15:13timeouts cancellation signals we'll see
- 15:15what are the best practices like keeping
- 15:17it lightweight to prevent memory
- 15:18overhead ensuring context data is
- 15:20cleaned up after request life cycle to
- 15:22prevent memory leaks avoiding tightly
- 15:24coupling components through context or
- 15:26over relying on it for passing data then
- 15:28we'll move to handlers and controllers
- 15:30the MVC pattern and what handlers and
- 15:32controllers and services the
- 15:34responsibilities of all of them and
- 15:36reducing code with middleware then we
- 15:38have centralized error handling in
- 15:39handlers and consistent success and
- 15:42error message formats and how to
- 15:43implement them in controllers then we'll
- 15:46look at the different types of crud
- 15:47operations like how cud operations map
- 15:50HTTP methods and what are the common
- 15:52apis associated with each method for
- 15:54example post method is usually used for
- 15:56creation and submissions and the status
- 15:59code is usually 2011 created or a400 if
- 16:03it's a bad request and get requests are
- 16:05usually associated with fetching a list
- 16:07of resources or fetching a single
- 16:08resource and we have put and Patch to
- 16:11update resources and delete to delete
- 16:14resources we look at how to implement
- 16:16pagination and how to implement a search
- 16:19API how to do sorting and how to do
- 16:21filtering and we'll see what are the
- 16:23best practices for example strict
- 16:25validation consistent response
- 16:26formatting limiting payload redacting
- 16:29sensitive Fields error handling
- 16:31authentication and authorization then
- 16:33we'll explore what is the restful
- 16:34architecture and what are the best
- 16:36practices for implementing rest apis the
- 16:39principle of Designing apis around
- 16:41resources and sticking to sttp semantics
- 16:44and best practices for filtering and
- 16:46pagination uh what are the different
- 16:48types of versioning like URI versioning
- 16:50header versioning query string media
- 16:52type we'll see how to design apis with
- 16:54open API spec in mind you'll see content
- 16:57negotiation capturing exceptions and
- 16:59providing meaningful messages supporting
- 17:02client side caching e taxs and
- 17:04optimizing large requests and responses
- 17:06after that we'll move on to a very
- 17:08important topic which are databases in
- 17:10databases we'll look at relational and
- 17:12non-relational what are the differences
- 17:14and to when to use which we look at some
- 17:16of the theoretical Concepts like acid
- 17:18and cap theorem we'll take a look at
- 17:20basic quering and joints and database
- 17:22design best practices like schema design
- 17:25indexing we look at different
- 17:26optimization methods like query
- 17:28optimization caching connection pooling
- 17:30then we have data Integrity like
- 17:33constraints and validations transactions
- 17:35and concurrency we'll see how ORS work
- 17:39whether to use an orm what are the
- 17:40tradeoffs and we'll look at what are
- 17:42database migrations that we'll move on
- 17:44to business logic layer which is also
- 17:46called BL what is the role of it what
- 17:48are the different layers of a request
- 17:50cycle for example we have validation
- 17:52layer we have routing we have
- 17:53middlewares and we have handl and
- 17:55controls which all of them fall under
- 17:57presentation layer because they they
- 17:59deal with users data whether it is
- 18:01accepting users data or sending a user
- 18:04data so those are part of a presentation
- 18:06layer after that we have business logic
- 18:09layer which is the middle one which
- 18:11deals with our Core Business logic and
- 18:14after that we have the data access layer
- 18:17which deals with databases perform
- 18:19squaring or inserts or deletions and
- 18:21business logic layer uses the data
- 18:23access layer behind the scenes we'll
- 18:24look at different design principles like
- 18:26separation of concerns single
- 18:28responsibility open close dependency
- 18:30inversion what are the components of a
- 18:31business logic layer for example we have
- 18:33Services we have domain models which
- 18:35represent core entities like a user or
- 18:37an order then we have business tools
- 18:40then we have business validation logic
- 18:42we'll look at service layer design best
- 18:43practices we'll look at how to handle
- 18:45errors properly and how to propagate
- 18:47those errors from our service layer to
- 18:50our presentation layer after that we
- 18:51have caching we'll discuss what is the
- 18:53need of caching and how it differs from
- 18:55database persistence what are the
- 18:57different types of caching we have
- 18:58memory caching browser caching database
- 19:00caching and what is the need of client
- 19:02side caching and server side caching the
- 19:04different caching strategies for example
- 19:06cash aside right through right behind or
- 19:09right back read through the different
- 19:11cash eviction strategies for example lru
- 19:14lfu TTL and fifo need for cash
- 19:17invalidation like manual Cash
- 19:18invalidation Time To Live invalidation
- 19:21or event bash invalidation the different
- 19:23levels of caching level one which is in
- 19:25memory level two which is Network
- 19:27distributed and there is is the
- 19:29hierarchical caching which combines
- 19:32level one and level two caching
- 19:33strategies where frequently used data is
- 19:35stored in a fast small cach which is the
- 19:38level one cache and the less frequently
- 19:40used data is stored in a slower or large
- 19:42cach which is the level two cache we'll
- 19:44see how caching for web apps looks like
- 19:46that is caching static assets or caching
- 19:48API responses using headers we'll see
- 19:50how to cach with databases for example
- 19:52query caching like storing the results
- 19:55of heavy joints in redis and look at
- 19:59Cash hit and cash Miss ratio and how to
- 20:02optimize them after that we'll move on
- 20:04to transactional emails what are the use
- 20:06of them what are the common use cases
- 20:08the anatomy of a transactional email the
- 20:10subject the preheader the body header
- 20:12main content CTA footer and how to
- 20:14personalize with different Dynamic
- 20:16parameters then we have task queuing and
- 20:18scheduling what are the common use cases
- 20:21for example queuing might be used for
- 20:23sending emails or processing image files
- 20:26and third party API integration like
- 20:28Payment Processing or web hooks or
- 20:29offloading heavy computation like badge
- 20:31processing for example a user clicks a
- 20:33button to clear all my data so to clear
- 20:36all the users data we have to call we
- 20:39have to execute different queries for
- 20:41different tables to clear all the users
- 20:43data and that might take some time so
- 20:45instead of blocking the request we
- 20:46return the response instantly and we
- 20:48trigger a background job by pushing into
- 20:50the task Cube we'll look at scheduling
- 20:52what are the use cases for example for
- 20:54example running database backups
- 20:56recurring notifications and reminders
- 20:58data synchronization or maintenance
- 21:01related issues for example clearing logs
- 21:03or caches the different components of a
- 21:06task Q There is the producer Q consumer
- 21:09broker backend the flow of a task
- 21:11dependency for example it might be chain
- 21:13dependency or it might have parent child
- 21:16relationship we look at task groups
- 21:18executing multiple task concurrently and
- 21:20waiting for all of them to complete at
- 21:21the same time we look at how to handle
- 21:23errors and Implement retries in task use
- 21:26we'll look at task prioritization and
- 21:28and rate limiting for example giving
- 21:30importance to task like Payment
- 21:31Processing before you process task like
- 21:33sending notifications after that we'll
- 21:35move on to elastic search why do we use
- 21:37elastic search and how does it work
- 21:39behind the scenes the different
- 21:41techniques that are used for example
- 21:42inverted index term frequency and
- 21:44inverse document frequency segments and
- 21:46shards what are the use cases of elastic
- 21:48search for example providing a type
- 21:50ahead experience or log analytics or
- 21:53social media search for example full
- 21:55text search for user profiles posts
- 21:57comments we'll see how to create and
- 21:59manage indexes we'll see how to search
- 22:01and query different types of searching
- 22:03basic searching full text search
- 22:04relevance scoring we'll see how to
- 22:06optimize search performance by tweaking
- 22:08text versus keyword Fields understanding
- 22:10analyzers and boosting and pagination
- 22:13we'll take a look at some of the
- 22:14advanced search patterns for example
- 22:16filtering aggregation fuzzy search then
- 22:18we'll see how kibana works and how to
- 22:20use elastic search in a user friendly
- 22:22way and different best practices for
- 22:24example defining field mappings
- 22:26explicitly optimizing the number number
- 22:28of shards indexing data in batches and
- 22:31avoiding wild cards then we have error
- 22:33handling the different types of errors
- 22:35in our apps could be syntax errors
- 22:37runtime errors logical errors and
- 22:39different error handling strategies for
- 22:41example fail safe or fail fast graceful
- 22:44degradation or prevention of Errors
- 22:46different practices for error handling
- 22:48for example catching early not
- 22:49swallowing errors custom error types
- 22:51failing gracefully logging errors and
- 22:53using stack traces we'll look at how
- 22:56Global error handlers work we'll see how
- 22:57to appropriate handle user facing errors
- 23:00like providing friendly error messages
- 23:01and providing actionable feedbacks we'll
- 23:04see the importance of monitoring and
- 23:05logging in error handling and different
- 23:08tools like Sentry or elk stack and
- 23:11different error alerts like email based
- 23:14alerts and slack based alerts after that
- 23:16we have config management what is
- 23:18exactly config management and how does
- 23:20it help with flexibility and decouples
- 23:23environment specific settings from
- 23:25application logic and what are the use
- 23:27cases for example example different
- 23:29environments using config management
- 23:31safely managing sensitive data such as
- 23:33API Keys database passwords and private
- 23:36certificates dynamically enabling and
- 23:38disabling features without changing
- 23:40codebase what are the best practices of
- 23:42config management different types of
- 23:44configs for example static configs like
- 23:46DB credentials and API end points
- 23:49Dynamic configs like feature Flags rate
- 23:51limits and sensitive configs like
- 23:53credentials tokens secrets and different
- 23:56sources of configs for example it could
- 23:58be EnV file or Json or yaml and what are
- 24:01the differences between using
- 24:02environment variables versus command
- 24:05line Flags versus static files after
- 24:07that we have logging monitoring and
- 24:09observability a very important topic
- 24:11we'll see what are the differences
- 24:12between logging tracing monitoring and
- 24:15observability the different types of
- 24:16logging like system logging application
- 24:18access security logs the different
- 24:20levels of logs like debug info one error
- 24:24fatal and we'll see the difference
- 24:26between structured logging and un
- 24:28structure logging and the best practices
- 24:30for logging like centralized logging log
- 24:33rotation and retention contextual and
- 24:35meaningful logs and avoiding sensitive
- 24:37data like passwords and API Keys then we
- 24:39will look at monitoring different types
- 24:41of monitoring like infrastructure
- 24:43monitoring application performance
- 24:44monitoring uptime monitoring the
- 24:46different tools that are used in
- 24:47monitoring like Prometheus grafana and
- 24:50how to manage alerts and notifications
- 24:52by defining thresholds creating alerts
- 24:55and avoiding alert fatigue by only
- 24:57creating action alerts and ensuring that
- 24:59alerts are meaningful and necessary then
- 25:02we'll take a look at observability the
- 25:04three pillars of observability which are
- 25:06logs metrics and traces the best
- 25:08practices around it the security and
- 25:10compliance of log management after that
- 25:12we'll move on to graceful shutdown why
- 25:14do we need graceful shutdown and how
- 25:16does it work behind the scenes what are
- 25:18the different use cases for example you
- 25:20might need it when server restarts or or
- 25:23scaling in Cloud environments or
- 25:25microservices or long running jobs how
- 25:27it works like signal handling sigor
- 25:30signant and sill signals what are the
- 25:32different steps of graceful shutdown for
- 25:34example it starts with capturing a
- 25:36signal and then it stops accepting
- 25:38requests then it completes an inflight
- 25:41requests and then it closes external
- 25:43resources like database connections or
- 25:45any open files Etc and at last it
- 25:48terminates the app after that we'll move
- 25:50on to security the different aspects of
- 25:52security in a backend code base avoiding
- 25:54different security attacks like SQL
- 25:56injection no SQL injection xss csrf
- 25:59broken authentication insecure
- 26:02deserialization and principles of a
- 26:04secure software design for example least
- 26:06privilege defense in depth fail secure
- 26:09defaults separation of Duties security
- 26:11by Design then we'll look at the
- 26:13importance of input validation and
- 26:15sanitization and rate limits and content
- 26:17security policy course and same side
- 26:20cookie and the importance of monitoring
- 26:22events after that we have scaling and
- 26:24performance the different metrics of
- 26:26performance like response time resource
- 26:28utilization identifying bottlenecks
- 26:30caching and database optimization for
- 26:33example avoiding n plus1 query problems
- 26:35and ensuring proper use of joints and
- 26:38using lazy loading where appropriate
- 26:40then we have using database indexes to
- 26:42speed of read operations on frequent VAR
- 26:45Fields like indexing foreign keys or
- 26:47search Fields how to process data in
- 26:49batches to minimize database load and
- 26:51improve performance for large data sets
- 26:53how to avoid memory leaks like closing
- 26:55file handles database connections or
- 26:57cleaning of after a long process
- 26:59minimizing Network overhead by reducing
- 27:01payload size and using compression we'll
- 27:03look at how to do performance testing
- 27:05and profiling we look at some of the
- 27:07best practices for writing performant
- 27:08code like focusing on writing clear and
- 27:11maintainable code first without
- 27:13premature optimization and writing
- 27:15modular code to make it easier to
- 27:17optimize individual components without
- 27:19affecting the entire system ensuring
- 27:21that if a particular resources under
- 27:22load are unavailable the system degrades
- 27:25gracefully without crashing and how to
- 27:27offload non critical tasks like sending
- 27:29emails or logging to background
- 27:31processes or task use to free of
- 27:33resources for more critical operations
- 27:36then we have concurrency and parallelism
- 27:38what are the difference between
- 27:39concurrency and parallelism and how
- 27:41concurrency helps in IO bound task and
- 27:43how parallelism helps in CPU bound tasks
- 27:46then we have object storage and large
- 27:47files we'll look at some of the common
- 27:49use cases when we use object storage
- 27:51like awss 3 and how to manage large
- 27:54files with chunking and streaming and
- 27:57we'll look at multiart file uploads then
- 27:59we have realtime backend systems where
- 28:01we take a look at web sockets or servers
- 28:03and events and pubs of architecture to
- 28:06that we have testing and code quality
- 28:09here we take a look at different types
- 28:10of testing unit testing integration
- 28:12testing end to end testing functional
- 28:14testing regression testing performance
- 28:16testing load and stress testing user
- 28:19acceptance testing security testing
- 28:21we'll take a look at what is test driven
- 28:23development how to automate test in cicd
- 28:25environments how to manage code quality
- 28:27with external linting and formatting
- 28:29tools and what are the measures of code
- 28:31quality and coverage like quality
- 28:33metrics like cyclomatic complexity which
- 28:36measures complexity of a function by
- 28:37counting the number of possible paths
- 28:39through the code and we have
- 28:41maintainability index which basically
- 28:43quantifies how easy it is to maintain a
- 28:45code based on the complexity lines of
- 28:48code and other factors then we'll take a
- 28:50look at a very interesting set of
- 28:51principles which is called 12 Factor app
- 28:53after that we'll move on to open API
- 28:56standards what is the need of this
- 28:58standards and why should we stick to it
- 29:00what are the benefits of it what are the
- 29:02use cases like documentation Automation
- 29:04and the ecosystem surrounding it like
- 29:06Swagger Corden postmen and what is the
- 29:09history the Swagger to open API
- 29:12transition and what are the different
- 29:13versions that are currently active and
- 29:16what are the key concepts of open API
- 29:18documents for example there is API pass
- 29:20the request and response definition
- 29:23there is parameters there is schemas and
- 29:25what is the structure of an OPN API
- 29:27document there is metadata there is
- 29:29paths there is components there is
- 29:31security definitions and there is
- 29:33responses we'll see what are the new
- 29:35features of open API 3.0 and 3.1 what
- 29:37are the tools surrounding open API for
- 29:39example Swagger UI Cen Postman what are
- 29:42the best practices like avoiding
- 29:44duplication and sticking to standards
- 29:47we'll look at a very interesting
- 29:49development method which is API First
- 29:51Development where you define your open
- 29:52API standard or write your open API spec
- 29:55first and then you start creating the
- 29:57apis after that we'll move on to web
- 29:59hooks what are the use cases of web
- 30:01hooks by like sending notification third
- 30:03party Integrations what are the
- 30:04differences between API versus web hook
- 30:06for the same use case for example for
- 30:08API we might have to use polling which
- 30:10is client side initiated compared to web
- 30:12hooks which is pushing is server
- 30:14initiated what are the key components of
- 30:17web hooks for example the web hook URL
- 30:19event triggers payload HTTP method the
- 30:21response handling what are the best
- 30:23practices surrounding web hooks like web
- 30:25hook signature verification like using
- 30:27http PS and quick response retry logic
- 30:30logging how to test web hooks with enro
- 30:32real world use cases like STP Payment
- 30:34Processing GitHub web hook slack Discord
- 30:37TWU Etc and at last we'll take a look at
- 30:40what are some devops Concepts and
- 30:42backend engineer should be familiar with
- 30:44for example some of the Core Concepts
- 30:46like continuous integration continuous
- 30:48delivery continuous deployment the
- 30:51devops practices like infrastructure is
- 30:53code config management Version Control
- 30:56the different tools surrounding devops
- 30:58for example creating containers with
- 30:59Docker or orchestrating container with
- 31:01kubernetes and cicd pipelines and how to
- 31:05scale your service horizontal scaling
- 31:07versus vertical scaling and different
- 31:10deployment strategies like red green
- 31:12deployment rolling deployment Etc and
- 31:15that's about it this is all the concepts
- 31:17that we are going to cover in the next
- 31:1930 or 40 videos so stay tuned
About this transcript
This page contains the full transcript of 1. Roadmap for backend from first principles by Sriniously, generated from the public captions YouTube serves with the video. The transcript has 5,502 words across 872 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.