8 parts · 13 chapters

Backend Disciplines

The backend mirror of the Disciplines course: the practices that cut across every service and every team, and that decide whether a backend is trustworthy. Each one is a habit with checks you can automate, not a document nobody reads.

Eight parts: application security in two halves (the OWASP API Security Top 10, then injection, SSRF, unsafe deserialisation and secrets in code); performance as a discipline with budgets and regression gates; observability as a discipline; data privacy, retention and deletion under Nigeria's NDPA and the GDPR; cost engineering; reliability habits; and accessible API docs with internationalisation on the server.

OWASP API Top 10 · injection, SSRF, deserialisation, secrets · performance · observability · privacy and deletion · cost · reliability habits · accessible APIs and server-side i18nmid → staff · backend engineers and tech leads
securityAuthorisation per object, input as data, secrets out of code.
performanceBudgets, benchmarks in CI, regressions caught before release.
observabilityLogs, metrics and traces with conventions every service follows.
privacyMinimise, retain on schedule, delete for real, record the basis.
costUnit costs per request and per customer, owned by teams.
reliabilityTimeouts, retries, limits and drills as defaults.
Built on Auth, Diagnosis and SREUses the Auth course for identity, Backend Diagnosis for performance tooling, and SRE for reliability practice.