Book 03 · Cheat sheet
Backend & APIs
Server-side services, API design and the ways software systems talk to each other.
Software Dictionary · softwaredictionary.org/categories/backend/cheat-sheet
- 01.NET
- .NET is Microsoft's free, open-source developer platform for building web, desktop, mobile, cloud and game applications, mainly in C#.
- .NET is Microsoft's open-source platform for many kinds of apps, mainly in C#.
- .NET Core in 2016 made it cross-platform; .NET 5 in 2020 unified the line.
- Code runs on the CLR, which JIT-compiles it and manages memory.
- 02APIApplication Programming Interface
- An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- An API defines how two pieces of software communicate.
- Callers don't need to know the internal implementation.
- Web APIs usually work over HTTP and return JSON.
- 03API Gateway
- An API gateway is a server that sits in front of a group of backend services and acts as the single entry point that receives, checks, and routes API requests.
- An API gateway is the single entry point for clients calling many backend services.
- It routes each request to the right service based on its path, host, or headers.
- It centralizes authentication, rate limiting, logging, and TLS.
- 04API Versioning
- API versioning is the practice of labeling and managing changes to an API so existing clients keep working while new versions add or change features.
- Versioning lets an API make breaking changes without breaking existing clients.
- Common approaches put the version in the URL path, a header, or a query parameter.
- Adding optional fields is backward compatible; removing or renaming fields is a breaking change.
- 05Backend
- The backend is the server side of an application: the code, databases and services that store data, apply business rules and answer the frontend's requests.
- The backend is the server side: data, business rules and security.
- It answers requests from the frontend and other programs through an API.
- It usually combines application code, databases, caches and queues.
- 06Background Job
- A background job is a task that a server runs outside the normal request-response cycle, so slow work like sending emails doesn't make users wait.
- Background jobs move slow work out of the request so users get fast responses.
- The app enqueues a job; separate worker processes run it later.
- Failed jobs are retried, often with exponential backoff.
- 07Backpressure
- Backpressure is a mechanism that lets a slow consumer signal a fast producer to slow down, so data doesn't pile up faster than it can be processed.
- Backpressure lets a slow consumer tell a fast producer to slow down or pause.
- Without it, unbounded buffers grow until latency spikes or memory runs out.
- Common strategies are pull-based consumption, bounded buffers that block, and load shedding.
- 08Cache
- A cache is a fast, temporary storage layer that keeps copies of frequently used data so later requests can be served quickly without repeating slow work.
- A cache keeps copies of data in fast storage to avoid repeating slow work.
- A cache hit returns stored data; a cache miss falls back to the original source.
- Caches exist in CPUs, browsers, CDNs, and applications, for example Redis.
- 09Cron Job
- A cron job is a command or script that runs automatically on a repeating schedule, such as every night at 2 a.m., defined by a five-field cron expression.
- A cron job runs a command automatically on a time-based schedule.
- Schedules have five fields: minute, hour, day of month, month, and day of week.
- 0 2 * * * means every day at 2:00; */15 * * * * means every 15 minutes.
- 10CRUDCreate, Read, Update, Delete
- CRUD stands for create, read, update and delete, the four basic operations for working with stored data in databases, APIs and most business applications.
- CRUD stands for create, read, update, and delete.
- In SQL, the operations are INSERT, SELECT, UPDATE, and DELETE.
- In REST APIs, they usually map to POST, GET, PUT or PATCH, and DELETE.
- 11Django
- Django is an open-source Python web framework that comes with an ORM, an admin panel, authentication and security protections, so teams can build quickly.
- Django is an open-source, "batteries included" Python web framework.
- Models, views and templates form its MTV structure.
- Its ORM maps Python classes to database tables.
- 12Endpoint
- An endpoint is a specific URL, combined with an HTTP method, where an API receives requests and returns responses for one particular resource or action.
- An endpoint is a URL where an API accepts requests.
- The same URL with different HTTP methods can act as different endpoints.
- Endpoint URLs combine a base URL, a resource path, and optional query parameters.
- 13Event Loop
- The event loop is a mechanism that lets a single thread handle many tasks by running callbacks one at a time as events and I/O results become ready.
- The event loop runs callbacks one at a time on a single thread.
- Slow I/O happens in the background, so the thread never sits idle waiting.
- Microtasks, like promise callbacks, run before the next task, like a setTimeout callback.
- 14Event Streaming
- Event streaming is the practice of recording events as a continuous, ordered and durable log that many applications can read, replay and process in real time.
- Events are recorded in order in a durable, append-only log.
- Many consumers read the same stream independently, each tracking its own offset.
- Streams can be replayed from any point within the retention period.
- 15Exponential Backoff
- Exponential backoff is a retry strategy that waits longer after each failed attempt, such as 1, 2, 4 and 8 seconds, so a struggling service can recover.
- Each retry waits longer than the last, usually doubling the delay.
- Random jitter keeps many clients from retrying in lockstep.
- Cap both the maximum delay and the number of attempts.
- 16ExpressExpress.js
- Express is the most widely used Node.js web framework: a minimal layer that handles routing, requests and responses through a chain of middleware functions.
- Express is a minimal web framework for Node.js, first released in 2010.
- Routes map HTTP methods and paths to handler functions.
- Middleware functions process each request in order and call next().
- 17FastAPI
- FastAPI is a modern Python API framework that uses standard type hints to validate requests, convert data and generate OpenAPI documentation automatically.
- FastAPI builds APIs in Python using standard type hints.
- Types drive request validation through Pydantic models.
- Interactive OpenAPI docs are generated automatically at /docs.
- 18Flask
- Flask is a lightweight Python web framework offering routing, request handling and templates, leaving the database and project structure to the developer.
- Flask is a lightweight Python web framework released in 2010.
- It is built on Werkzeug for HTTP and Jinja for templates.
- Routes are functions marked with decorators such as @app.route.
- 19GraphQL
- GraphQL is a query language and runtime for APIs that lets clients request exactly the data they need, often from a single endpoint in a single request.
- Clients specify exactly which fields they want in the response.
- A typed schema describes all available data and operations.
- Queries read data, mutations change it, and subscriptions stream updates.
- 20gRPC
- gRPC is an open-source framework for calling functions on a remote server as if they were local, using Protocol Buffers and HTTP/2 for fast, typed messages.
- gRPC lets clients call methods on a remote server like local functions.
- Services and messages are defined in .proto files using Protocol Buffers.
- Client and server code is generated automatically for many languages.
- 21Health Check
- A health check is a small automated test, usually an HTTP endpoint, that reports whether a service is up and able to handle requests, so failures show fast.
- A health check is a quick endpoint or command that reports whether a service is healthy.
- Load balancers and orchestrators call it regularly and reroute traffic or restart automatically.
- Liveness checks trigger restarts; readiness checks control whether traffic is sent.
- 22HTTP Caching
- HTTP caching is the reuse of stored HTTP responses by browsers, CDNs and proxies, controlled by headers like Cache-Control and ETag, to avoid repeat downloads.
- Cache-Control tells browsers and CDNs whether, and for how long, they may reuse a response.
- ETag and Last-Modified let clients revalidate with a cheap 304 Not Modified response.
- no-cache means revalidate before every use; no-store means never store.
- 23HTTP Method
- An HTTP method is the verb in an HTTP request, such as GET, POST, PUT, PATCH or DELETE, that tells the server what action to perform on the requested resource.
- The method is the verb of an HTTP request, such as GET, POST, PUT, PATCH, or DELETE.
- GET reads, POST creates or triggers actions, PUT replaces, PATCH partially updates, and DELETE removes.
- Safe methods don't change server state; idempotent methods can be repeated safely.
- 24Idempotency
- Idempotency is the property of an operation that produces the same result whether it runs once or many times, so accidentally repeating a request is safe.
- An idempotent operation has the same effect no matter how many times it runs.
- It makes retries safe after timeouts, crashes, and duplicate messages.
- GET, PUT, and DELETE are idempotent in HTTP; POST is not.
- 25JSONJavaScript Object Notation
- JSON is a lightweight, text-based format for storing and exchanging structured data as key-value pairs and lists, readable by both humans and machines.
- JSON stands for JavaScript Object Notation but works with almost every language.
- Data is written as objects ({}), arrays ([]), strings, numbers, booleans, and null.
- Keys and strings must use double quotes.
- 26KafkaApache Kafka
- Apache Kafka is a distributed event streaming platform that stores events in durable, ordered logs for many services to publish, read in real time or replay.
- Kafka stores events in durable, ordered, append-only logs called topics.
- Topics are split into partitions spread across a cluster of brokers.
- Consumers track their own offset, so they can resume or replay history.
- 27Laravel
- Laravel is a PHP framework for full web applications, with an elegant syntax and built-in routing, the Eloquent ORM, authentication, queues and migrations.
- Laravel is the most popular PHP framework, first released in 2011.
- It uses MVC with routes, controllers, Eloquent models and Blade views.
- Eloquent is an expressive active record ORM; migrations version the schema.
- 28Long Polling
- Long polling is a technique where a client sends a request that the server holds open until new data is ready, imitating real-time push over plain HTTP.
- The server holds each request open until new data is available or a timeout expires.
- The client sends a new request immediately after each response.
- It delivers updates faster, and with fewer empty responses, than regular polling.
- 29Message Queue
- A message queue is a component that stores messages from one service until another is ready to process them, so parts of a system can work asynchronously.
- Producers send messages; consumers process them later, at their own pace.
- The queue decouples services and absorbs traffic spikes.
- Consumers acknowledge messages after processing, so work isn't lost if they crash.
- 30Middleware
- Middleware is software that sits between two layers of a system, most often code that runs between an incoming request and the final response in a web server.
- Middleware runs between receiving a request and sending the response.
- Multiple middleware functions form a chain that runs in order.
- Each one can modify the request, end it early, or pass it on.
- 31Nginx
- Nginx is a fast, open-source web server that is also widely used as a reverse proxy, load balancer and HTTP cache in front of application servers.
- Nginx is an open-source web server, reverse proxy, load balancer and cache.
- An event-driven design lets it handle many thousands of connections cheaply.
- It serves static files and forwards dynamic requests to app servers.
- 32Node.js
- Node.js is an open-source JavaScript runtime that runs JavaScript outside the browser, most often to build web servers, APIs, and command-line tools.
- Node.js runs JavaScript outside the browser, on servers and developer machines.
- It is a runtime built on Chrome's V8 engine, not a language or a framework.
- A non-blocking event loop lets one process handle many concurrent connections.
- 33OpenAPI
- OpenAPI is an open standard for describing HTTP APIs in a YAML or JSON file, so people and tools can understand every endpoint, parameter, and response.
- OpenAPI describes HTTP APIs in a standard YAML or JSON document.
- It covers endpoints, parameters, request and response schemas, and authentication.
- Tools use it to generate docs, client SDKs, server stubs, mock servers, and tests.
- 34Pagination
- Pagination is the practice of splitting a large set of results into smaller pages, so an API or website returns a manageable number of items per request.
- Pagination returns large result sets in smaller pages.
- Offset pagination (limit and offset) is simple and allows jumping to any page.
- Cursor pagination continues after the last item seen and stays fast on large tables.
- 35Pub/SubPublish-Subscribe
- Pub/sub is a messaging pattern where publishers send messages to topics and every subscriber to a topic gets a copy, without either side knowing the other.
- Publishers send messages to topics, and every subscriber to a topic gets a copy.
- Publishers and subscribers don't know about each other, which keeps services loosely coupled.
- New subscribers can be added without changing the publisher.
- 36RabbitMQ
- RabbitMQ is an open-source message broker that routes producers' messages through exchanges into queues, where consumers take them and confirm when done.
- RabbitMQ is an open-source message broker written in Erlang.
- Producers send to exchanges, which route messages into queues by bindings.
- Direct, topic and fanout exchanges cover one-to-one and one-to-many delivery.
- 37Rate Limiting
- Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- Rate limiting caps how many requests a client can make in a period of time.
- Clients over the limit usually receive HTTP 429 Too Many Requests.
- Limits are typically applied per API key, user, or IP address.
- 38REST APIRepresentational State Transfer API
- A REST API is a web API that exposes data as resources identified by URLs and lets clients read or change them using standard HTTP methods.
- REST is an architectural style, not a protocol or a formal standard.
- Resources are identified by URLs, such as /users/42.
- HTTP methods (GET, POST, PUT, PATCH, DELETE) describe the action.
- 39RPCRemote Procedure Call
- RPC is a communication style in which a program calls a function that runs on another machine as if it were a local function, hiding the network in between.
- RPC makes a call to code on another machine look like a local function call.
- Client stubs serialize the arguments and send them; the server runs the function and returns the result.
- gRPC, JSON-RPC, and Apache Thrift are common RPC implementations.
- 40Ruby on Rails
- Ruby on Rails is a full-stack web framework for Ruby that favors convention over configuration, so database-backed web apps can be built quickly.
- Rails is a full-stack Ruby web framework released in 2004.
- Convention over configuration means a standard structure and fewer decisions.
- Active Record maps models to tables; migrations version the schema.
- 41Serialization
- Serialization is the process of converting in-memory data structures into a format such as JSON or bytes, so they can be stored or sent over a network.
- Serialization converts in-memory data into text or bytes for storage or transfer.
- Deserialization rebuilds the in-memory data from that format.
- JSON, XML, and YAML are text formats; Protocol Buffers and MessagePack are binary.
- 42Server-Sent Events
- Server-Sent Events is a web standard that lets a server push a continuous stream of text updates to the browser over one long-lived HTTP connection.
- SSE streams messages from server to browser over one long-lived HTTP response.
- The server sends text/event-stream data, and browsers read it with the EventSource API.
- Browsers reconnect automatically and resume using the Last-Event-ID header.
- 43Session
- A session is a way for a server to remember a user across many requests, usually by keeping their data on the server and giving the browser a session ID.
- Sessions let a server remember a user across stateless HTTP requests.
- The server stores session data and gives the client a random session ID.
- The session ID usually travels in an HttpOnly, Secure cookie.
- 44SOAPSimple Object Access Protocol
- SOAP is an XML-based messaging protocol for web services that wraps each request and response in a strict envelope, usually defined by a formal WSDL contract.
- SOAP messages are XML documents with an envelope, an optional header, and a body.
- A WSDL file formally describes the service's operations and data types.
- WS-* standards add message-level security and reliable delivery.
- 45Spring Boot
- Spring Boot is a Java framework for quickly building production-ready services on top of Spring, with auto-configuration and an embedded web server.
- Spring Boot builds production-ready Java apps on the Spring Framework.
- Starters and auto-configuration replace most manual setup.
- Apps run as a single JAR with an embedded server such as Tomcat.
- 46Web Server
- A web server is software, or the machine running it, that accepts HTTP requests from browsers and other clients and responds with pages, files, or data.
- A web server receives HTTP requests and returns responses such as HTML, files, or JSON.
- It usually listens on port 80 for HTTP and port 443 for HTTPS.
- Static files are served directly; dynamic requests are passed to application code.
- 47Webhook
- A webhook is an automated HTTP request that one application sends to a URL you provide as soon as a specific event happens, such as a completed payment.
- A webhook is an HTTP request triggered by an event.
- The sender pushes data to you, so you don't have to poll.
- You provide the URL; the other service calls it.
- 48XMLExtensible Markup Language
- XML (Extensible Markup Language) is a text format for structured data that uses nested tags you define yourself, readable by both people and machines.
- XML is a text format for structured data with self-defined tags.
- It became a W3C standard in 1998.
- XSD validates documents, XPath queries them and XSLT transforms them.