Web security is a critical concern for any backend developer. If you’re building applications using Node.js and Express, it’s essential to safeguard your backend against common security threats such as SQL injections, cross-site scripting (XSS), cross-site request forgery (CSRF), and other vulnerabilities. This comprehensive guide explores these attacks in depth and demonstrates best practices to prevent them with practical coding examples.
Continue reading
How to Set Up Nginx on Ubuntu with Let’s Encrypt SSL and Port Forwarding
Introduction
Setting up Nginx on Ubuntu (18+) with Let’s Encrypt SSL ensures that your website or application is secure and accessible over HTTPS, providing a safe browsing experience for your users. This process not only includes the installation of the Nginx web server but also entails configuring the server to handle SSL certificates issued by Let’s Encrypt, enabling automatic renewal of these certificates to maintain uninterrupted security. By following best practices for security and performance, you can optimize your server’s settings to ensure fast loading times and reliable uptime, which are crucial for retaining visitors and improving search engine rankings. Additionally, implementing SSL helps to build trust with your audience, as it demonstrates a commitment to protecting their data and enhancing their online safety.
In this guide, we will:
- Install and configure Nginx.
- Set up port forwarding for your Node.js application.
- Obtain a free SSL certificate from Let’s Encrypt.
- Ensure proper firewall and AWS security group settings.
- Troubleshoot common issues.
Let’s get into it…
Continue reading
The Science of Better Sleep: Lessons from Huberman
The Vital Importance of Sleep
We all know sleep is important, but few of us truly grasp just how critical it is to our overall wellbeing. According to a landmark study published in the journal Science, sleep deprivation is linked to a 10-30% increase in mortality risk. Research has demonstrated that even a single night of inadequate sleep can reduce immune function by up to 70%, while chronic sleep deprivation has been directly linked to increased risk of diabetes, cardiovascular disease, and Alzheimer’s.
Perhaps most striking is a 2017 study published in Nature showing that after just one night of less than six hours of sleep, the body shows measurable signs of metabolic dysfunction, with over 700 genetic changes occurring. Sleep isn’t just about feeling rested—it’s a fundamental biological necessity for cellular repair, memory consolidation, and emotional regulation.
With sleep playing such a crucial role in our health, Dr. Andrew Huberman’s evidence-based recommendations from his popular podcast offer valuable insights for optimizing our sleep. Watch or listen to some of his episodes on this topic here.
Let’s explore these practical strategies that can transform your sleep quality and overall health.
Continue reading
Speeding Up Node & ReactJS Build Times
Speeding up Node or React build times on an EC2 instance involves optimizing your build process, leveraging the instance’s resources efficiently, and potentially tweaking your environment. Below are practical steps to reduce build times:
Continue reading
Optimize NodeJS Apps in Production on Ubuntu
Why PM2 is Essential for Applications in Production?
When deploying a Node.js application in a production environment, ensuring stability, efficiency, and reliability is crucial. This is where PM2, a powerful process manager for Node.js applications, becomes an invaluable tool. PM2 simplifies process management, enhances performance, and provides robust monitoring capabilities. In this post, we’ll explore why PM2 is essential for running Node.js applications in production.
To ensure a Node.js app keeps running smoothly in production on Linux/Ubuntu, there are many ways to achieve this, but here are some of the essential steps that will help you elevate your application’s performance to the ‘next level’:
- Regularly monitor system resource usage to prevent bottlenecks
- Implement error handling and logging to quickly diagnose and fix issues as they arise
- Utilize process managers like PM2 or Forever to automatically restart your application in case of failures
- Ensure that your dependencies are always updated and secure to avoid vulnerabilities
- A bonus step: consider employing load balancing and clustering techniques to enhance the app’s scalability and availability. Nginx is great here even if you have one instance.
1. Use a Process Manager (PM2)
PM2 is a popular process manager for Node.js applications that provides automatic restarts, logging, and monitoring.
Install PM2 globally:
npm install -g pm2
Start your application with PM2:
pm2 start app.js --name myNodeJSAppButInProd
Managing different configurations for development, testing, and production environments can be cumbersome. PM2 allows you to define environment-specific variables using an ecosystem file:
module.exports = {
apps: [{
name: "my-app",
script: "app.js",
env: {
NODE_ENV: "development",
},
env_production: {
NODE_ENV: "production",
}
}]
};
This ensures that your application loads the appropriate settings based on the environment, reducing configuration errors.
Ensure PM2 restarts on reboot:
pm2 startup
pm2 save
Top Resources to Learn JavaScript and TypeScript Effectively
JavaScript is the backbone of modern web development. TypeScript (TS)—its statically typed super-set — has rapidly gained traction in professional environments.
Whether you’re an aspiring developer or a seasoned programmer, this guide will help you level up your skills. It will assist you in navigating the learning path for JS and TS.
We’ll share various resources and courses to suit different learning styles. We will finish with three exciting project ideas to put your knowledge into practice.
Getting Started with JavaScript
Before diving into TypeScript, it’s crucial to have a solid understanding of JavaScript fundamentals.
Here are some steps and resources to get you started:
Continue reading
Why/How Senior Engineers Embrace AI Tools in Development?
How can you do better (or succeed more) with AI coding tools?
Senior engineers who use AI tools (co-pilot, claude.ai, cursor, etc.) are like master chefs who know when to use the microwave and when to actually cook with fire.
Here are some of the bold aspects I’ve noticed in the past year:
Continue reading
Endurance and Insights: My 2024 in Books and Sports
Since 2013, I’ve made it a tradition (2022, 2020, 2019, 2018, 2017, 2016, 2015, 2014, 2013) to reflect on the books I’ve read and the sports events I’ve trained for and competed in.
2024 was no exception, offering a mix of endurance and discovery through the pages of captivating stories and on the trails of challenging courses. From thought-provoking novels that broadened my horizons to intense training sessions that pushed my limits, this year added another meaningful chapter to this ongoing journey.
Here’s a look back at the highlights that made 2024.
Continue reading
Docker 101: From Development to Production – A Quick Guide
Docker has fundamentally transformed the way developers build, test, and deploy applications by introducing a consistent, lightweight, and portable runtime environment. With its ability to package applications and their dependencies into isolated containers, Docker has eliminated the age-old challenge of “it works on my machine” while enabling seamless deployment across various environments. The part of “It’s working for me” used to be funny or sad depends on the day and the hour…
Whether you’re developing locally, testing in a CI/CD pipeline, or deploying to production, Docker provides the flexibility and scalability to streamline these processes. In this guide, we’ll explore the foundational concepts of Docker, dive into its practical uses, and demonstrate how you can harness its power to simplify workflows and achieve greater efficiency in your development and operations pipelines. Whether you’re a beginner or looking to refine your Docker skills, this walkthrough will equip you with the knowledge you need to use Docker effectively.
Continue reading
Cleaner Code: The Importance of Dependency Injection in Software Development
Dependency Injection (DI) is a software design pattern that addresses the problem of managing dependencies between objects in a program. In traditional programming, objects are often tightly coupled, meaning they directly create or reference other objects they depend on.
This can lead to rigid, hard-to-maintain code that is difficult to test or reuse.
Dependency Injection solves this problem by separating the creation and configuration of dependent objects from the objects that use them.
It is a design pattern where a class receives its dependencies from external sources rather than creating them internally. Think of it as “outsourcing,” the creation and management of objects that your class needs to work on.
Instead of directly instantiating or referencing its dependencies, an object receives them through its constructor, methods, or properties.
This decoupling makes the code more flexible, testable, and maintainable.
In large-scale projects, Dependency Injection becomes especially important as the codebase grows in complexity. With many interdependent components, DI helps manage the web of dependencies, making it easier to swap out implementations, replace third-party libraries, and test individual components in isolation.
This improves the overall modularity and scalability of the system.