8 parts · 13 chapters
Backend Disciplines
The backend mirror of the Disciplines course: the practices that cut across every service and every team, and that decide whether a backend is trustworthy. Each one is a habit with checks you can automate, not a document nobody reads.
Eight parts: application security in two halves (the OWASP API Security Top 10, then injection, SSRF, unsafe deserialisation and secrets in code); performance as a discipline with budgets and regression gates; observability as a discipline; data privacy, retention and deletion under Nigeria's NDPA and the GDPR; cost engineering; reliability habits; and accessible API docs with internationalisation on the server.
securityAuthorisation per object, input as data, secrets out of code.
performanceBudgets, benchmarks in CI, regressions caught before release.
observabilityLogs, metrics and traces with conventions every service follows.
privacyMinimise, retain on schedule, delete for real, record the basis.
costUnit costs per request and per customer, owned by teams.
reliabilityTimeouts, retries, limits and drills as defaults.
00
Application Security I: OWASP API Security Top 10
The most common API flaw · The ten, grouped
2 ch · ~12 min01Application Security II: Injection, SSRF, Deserialisation, Secrets
Input is data, never code · SSRF · Secrets in code
3 ch · ~18 min02Performance as a Discipline
Budgets with gates
1 ch · ~8 min03Observability as a Discipline
Conventions every service follows
1 ch · ~8 min04Data Privacy, Retention and Deletion (NDPA, GDPR)
The law in engineering terms · Deleting for real
2 ch · ~12 min05Cost Engineering
Unit costs, owned by teams
1 ch · ~8 min06Reliability Habits
Defaults that prevent incidents
1 ch · ~8 min07Accessible APIs and Docs, Internationalisation on the Server
Docs and errors people can use · Internationalisation on the server
2 ch · ~12 minBuilt on Auth, Diagnosis and SREUses the Auth course for identity, Backend Diagnosis for performance tooling, and SRE for reliability practice.