START HERE Follow the main route ↓
01 · Understand the code / 1 Follow a value
Follow shared state
Follow execution
01 · Understand the code / 2 Model the possibilities
Express valid states
Give values meaning
Model the edges
Choose the abstraction
02 · Choose a structure / 1 Follow the cost
Solve self-similar data
Reuse overlapping work
02 · Choose a structure / 2 Keep things in order
Connect a sequence
Put work in order
02 · Choose a structure / 3 Find what you need
Membership & order
Compose a cache
02 · Choose a structure / 4 Use a little structure
Choose by priority
Follow a prefix
Balance and index
02 · Choose a structure / 5 Follow connections
Represent, then traverse
Track connected groups
02 · Choose a structure / 6 Work through the data
Search ordered data
Process a moving range
Meet pairs and ranges
Split, choose, and undo
Keep order across shapes
02 · Choose a structure / 7 Trade certainty for space
Estimate frequency
Estimate distinct values
03 · Shape the behavior / 1 Separate responsibilities
Draw a boundary
Supply behavior
Work with functions
Reuse language mechanisms
03 · Shape the behavior / 2 Create and own
Vary construction
Control the lifetime
03 · Shape the behavior / 3 Compose the pieces
Wrap an operation
Arrange collaborators
03 · Shape the behavior / 4 Coordinate behavior
Represent actions & state
React to a change
Choose the next behavior
Work through a structure
04 · Make it dependable / 1 Account for failure
Name a failure
Compose a result
Cross a boundary
Recover deliberately
04 · Make it dependable / 2 Check the claim
Challenge the behavior
Investigate the evidence
05 · Coordinate work & state / 1 Work over time
Own concurrent work
Control the flow
Keep effects predictable
Isolate responsibility
05 · Coordinate work & state / 2 Keep state useful
Coordinate changes
Serve a read
06 · Connect the system / 1 Define the contract
Define an external contract
Keep internals independent
Change runtime behavior
06 · Connect the system / 2 Apply the patterns
Give persistence an interface
06 · Connect the system / 3 Connect client and server
Shape a server for one UI
Shape the contract
Keep the screen current
06 · Connect the system / 4 Expect failure, measure success
Contain the damage
Decide what success means
Prove a change was worth it
06 · Connect the system / 5 Decompose the system
Follow the domain
Follow the teams
Check the lines
06 · Connect the system / 6 Organize the application
Point dependencies inward
Group by feature
Let others extend it
Compose a pipeline
06 · Connect the system / 7 Shape the frontend
Route every change
Cache what the server owns
Choose where HTML is made
Split across teams
06 · Connect the system / 8 Build for the split
Design for the network
Own the data
Make the move
06 · Connect the system / 9 Coordinate work across systems
Do it later
Accept outside events
Survive partial failure
06 · Connect the system / 10 Connect reads and change
Keep the history
Stream the changes
Separate customers
06 · Connect the system / 11 Change it while it runs
Choose the runtime
Change the schema
Replace a dependency
07 · Solve a specific problem / 1 Compare and find text
Score similar names
Explain a change
Find many patterns
Skip through long text
Filter windows with a rolling hash
Shortlist near-duplicates
07 · Solve a specific problem / 2 Find a route or a connection
Know every pair
Allow signed edges
Guide the search
Connect the network
Move capacity through a network
Group mutual reachability
Rank linked pages
07 · Solve a specific problem / 3 Choose under constraints
Choose compatible intervals
Select one percentile without sorting
Sweep crowded time windows
Match by cost
Match by preference
07 · Solve a specific problem / 4 Handle chance and a stream
Sample what arrives
Draw by weight
Summarize a stream
07 · Solve a specific problem / 5 Change a line or an image
Simplify a line
Wrap a point set
Diffuse pixel error
Find a seam to remove
07 · Solve a specific problem / 6 Use space and capacity deliberately
Refer to repeated data
Choose an owner
Limit arrivals
08 · Work with agents / 1 Enforce it
Know what each check catches
Run it every time
Let the agent run it
08 · Work with agents / 2 State the intent
Check the structure
Specify, then check
Shape one unit of work
08 · Work with agents / 3 Test without agreement
Put up the barrier
Score the suite
Find another truth
08 · Work with agents / 4 Shape the context
Mark the territory
Remove the hot file
Bound what it can do
08 · Work with agents / 5 Run several at once
Gate the merge
Keep the evidence
Leave it resumable
08 · Work with agents / 6 Keep the skill
See the shape first
Check before and after
Keep what you learned
⌑ · Security / 1 Security mindset and core vocabulary
⌑ · Security / 2 Threat modeling and secure design
⌑ · Security / 3 Web and API trust boundaries
⌑ · Security / 4 Output handling and injection
⌑ · Security / 5 Authorization and access control
⌑ · Security / 6 Authentication, credentials, and sessions
⌑ · Security / 7 Data protection and cryptography
⌑ · Security / 8 API, workflow, and abuse resistance
⌑ · Security / 9 LLM and AI application security
⌑ · Security / 10 Security testing and code review
⌑ · Security / 11 Files, uploads, and content processing
⌑ · Security / 12 Dependencies, build systems, and software supply chain
⌑ · Security / 13 Browser, frontend, and privacy security
⌑ · Security / 14 Runtime, infrastructure, and cloud security
⌑ · Security / 15 Logging, detection, and incident response
⌑ · Security / 16 Governance, assurance, and certification crosswalk
⌁ · DevOps / 1 DevOps foundations
⌁ · DevOps / 2 Version control and change flow
⌁ · DevOps / 3 Continuous integration
⌁ · DevOps / 4 Builds and artifacts
⌁ · DevOps / 5 Testing and quality gates
⌁ · DevOps / 6 Release management
⌁ · DevOps / 7 Deployment and runtime lifecycle
⌁ · DevOps / 8 Infrastructure as code
⌁ · DevOps / 9 Containers and orchestration
⌁ · DevOps / 10 Environments and configuration
⌁ · DevOps / 11 Observability and alerting
⌁ · DevOps / 12 Reliability and incident response
⌁ · DevOps / 13 Capacity, cost, and performance operations
⌁ · DevOps / 14 Data and stateful service operations
⌁ · DevOps / 15 Platform engineering and developer experience
⌁ · DevOps / 16 Delivery measurement and improvement
⌁ · DevOps / 17 Security and governance in delivery
⇄ · Networking / 1 Networking foundations
⇄ · Networking / 2 Network design and protocols
⇄ · Networking / 3 Operations and troubleshooting
∑ · Math in Practice / 1 Quantities and representation
∑ · Math in Practice / 2 Change, uncertainty, and evidence
∑ · Math in Practice / 3 Math in engineering decisions
∑ · Math in Practice / 4 Math behind AI
Values and references MAIN ROUTE Copying, identity, and equality Ownership, aliasing, and lifetimes Allocation and memory locality The call stack and execution Closures and captured state Static types and runtime validation Discriminated unions MAIN ROUTE Making illegal states unrepresentable Parse, don't validate Branded / opaque types Value objects Immutability Absence: null vs undefined vs missing Wide constructors When a generic earns its place Domain model vs. DTO Time and space complexity MAIN ROUTE Recursion Dynamic programming Dynamic array MAIN ROUTE Linked list Stack Queue and deque Ring buffer Hash map MAIN ROUTE Hash set Ordered map LRU cache Binary search tree MAIN ROUTE Binary heap Trie B+ trees and indexes Graph overview MAIN ROUTE Adjacency list Breadth-first and depth-first search Topological sort Union-find Sorting MAIN ROUTE Binary search Sliding window Two pointers and prefix sums Divide and conquer, greedy choices, and backtracking Monotonic stacks, interval problems, and string matching Bloom filter MAIN ROUTE Count-min sketch HyperLogLog Composition over inheritance MAIN ROUTE Coupling & cohesion Module Dependency direction Polymorphism Delegation Inversion of control Dependency injection Pure functions & side effects Currying & partial application Memoization Idempotence Mixin Extension Factory MAIN ROUTE Abstract factory Builder Prototype Singleton Multiton Lazy initialization Object pool Adapter MAIN ROUTE Decorator Proxy Flyweight Facade Composite Bridge Strategy MAIN ROUTE Command Memento State machine Observer Publish / subscribe Mediator Chain of responsibility Template method Null object Iterator / generator Visitor Interpreter How a function reports failure MAIN ROUTE Expected vs. unrecoverable Kinds and sentinels Class-based error hierarchies Go's error protocol Discriminated union results Result types & combinators Aggregate & partial failure Errors across a boundary Error boundaries in UI Retry, backoff & idempotency Invariants and example tests MAIN ROUTE Property-based testing Fakes, stubs, and mocks Contract and integration testing Debugging state and control flow Diagnosing concurrency bugs Designing useful benchmarks CPU and memory profiling Promises vs. goroutines & channels MAIN ROUTE Event loop vs. scheduler Structured concurrency Cancellation propagation Timeouts, deadlines & races Bounded parallelism Backpressure & queues Async iteration & streams Race conditions in UI Idempotency & at-least-once delivery Actor model Transactions and atomicity MAIN ROUTE Isolation and concurrent reads Optimistic concurrency Indexes and query plans Caching and invalidation Validation at the edge MAIN ROUTE API contracts Serialization hazards Versioning & compatibility Module boundaries The mapping layer Configuration as a boundary Feature flags & kill switches Registry MAIN ROUTE Repository pattern & its critics Client–server architecture MAIN ROUTE Backend for frontend REST, RPC, or GraphQL Polling, server-sent events, or WebSockets Local-first and sync Thinking in failure modes MAIN ROUTE Containing failure Defining success Observability across a request Baseline before you change Fitness functions Decomposing a system MAIN ROUTE Bounded contexts Who writes this data? Conway’s law and team boundaries Signs a boundary is wrong How big should a module or service be? Layered architecture MAIN ROUTE Hexagonal / ports & adapters Functional core, imperative shell Vertical slices Plugin architecture Pipes and filters State ownership in a component tree MAIN ROUTE Unidirectional data flow Server state in the client Server, static, or client rendering Micro-frontends Modular monolith MAIN ROUTE Module contracts Communication between modules Module-owned data in one database Consistency without a shared transaction Extracting a service Modular monolith vs. services Event-driven architecture MAIN ROUTE Work queues and background jobs Receiving webhooks Transactional outbox Sagas and compensation CQRS MAIN ROUTE Event sourcing Change data capture Multi-tenant data isolation Strangler fig migration MAIN ROUTE Long-running servers vs. functions Expand and contract Branch by abstraction Levenshtein distance MAIN ROUTE Jaro–Winkler similarity Myers diff Aho–Corasick matching Boyer–Moore substring search Rabin–Karp rolling-hash search MinHash and locality-sensitive hashing Dijkstra’s shortest path MAIN ROUTE Floyd–Warshall all-pairs shortest paths Bellman–Ford shortest paths A* pathfinding Kruskal’s minimum spanning tree Max flow and min cut Strongly connected components PageRank 0/1 knapsack MAIN ROUTE Weighted interval scheduling Quickselect percentile selection Sweep-line interval overlap detection Hungarian assignment Gale–Shapley stable matching Fisher–Yates shuffle MAIN ROUTE Reservoir sampling Alias method Welford’s online variance Bresenham’s line algorithm MAIN ROUTE Ramer–Douglas–Peucker simplification Convex hull Floyd–Steinberg dithering Seam carving Huffman coding MAIN ROUTE LZ77 compression Rendezvous hashing Token bucket Enforcement layer MAIN ROUTE Verification ladder Hooks as protocol Closing the loop Architecture as rules MAIN ROUTE Structure over diff Spec before code Task shape The closed circle MAIN ROUTE Information barrier Mutation testing Independent oracle Context engineering MAIN ROUTE Territory maps Generated registries Blast radius Parallel decomposition MAIN ROUTE Release gates Recorded runs Progress on disk Draft directory MAIN ROUTE Diagrams first Verify before and after Notes protocol Security goals: confidentiality, integrity, availability MAIN ROUTE Assets, actors, trust boundaries, and attack surface Threat, vulnerability, exploit, impact, and risk Authentication, authorization, and accounting Least privilege and secure defaults Defense in depth and security boundaries Fail open or fail closed Security by design versus security by obscurity Threat modeling a small feature MAIN ROUTE Data-flow diagrams and trust boundaries STRIDE and alternative threat prompts Abuse cases and business logic Security requirements and acceptance criteria Secure architecture decisions Attack surface reduction Third-party and integration trust Privacy and security design review Lightweight threat-model review in pull requests The browser is an untrusted client MAIN ROUTE Trace untrusted data end to end Parse, validate, normalize, and encode are different Allowlist validation and bounded input Integer and numeric bugs in security checks Canonicalization and double-decoding bugs HTTP security-relevant behavior Client-side versus server-side validation Error messages and information leakage Secure error handling and exception paths Reflected, stored, and DOM-based XSS MAIN ROUTE Contextual output encoding Safe DOM APIs and dangerous HTML escape hatches Framework escaping and its limits SQL injection and parameterized queries NoSQL and search-query injection OS command injection Template, expression, and code injection LDAP, XPath, and other interpreter injection Header, CRLF, and log injection Deserialization and object construction Prototype pollution ReDoS and parser complexity Deny by default and check every request MAIN ROUTE Object-level access and IDOR/BOLA Function-level and administrative authorization Horizontal and vertical privilege escalation RBAC, ABAC, and relationship-based policies Authorization policy placement Tenant isolation Mass assignment and over-posting Time-of-check/time-of-use authorization Authorization regression tests Delegated access and sharing links Password storage and verification MAIN ROUTE Login abuse and credential stuffing Multi-factor authentication and passkeys Account recovery and password reset Session identifiers and entropy Cookie flags and browser session storage Session fixation, rotation, expiry, and logout CSRF and same-site request defenses OAuth 2.0 and OpenID Connect roles OAuth flow security: PKCE, state, and redirect URIs API keys, bearer tokens, and signed tokens JWT validation pitfalls Service identities and workload credentials Sensitive-action confirmation and reauthentication Data classification and minimization MAIN ROUTE TLS, certificate validation, and trust stores Encryption at rest and field-level protection Hashing, encryption, encoding, and signing Cryptographically secure randomness Key lifecycle and key management Timing attacks and constant-time comparison Message authentication and digital signatures Nonces, IVs, and authenticated encryption Token and URL leakage Backups, deletion, and cryptographic erasure API authentication is not API authorization MAIN ROUTE Request size, pagination, and resource limits Rate limiting and abuse controls Idempotency and replay resistance Race conditions and limit overruns Workflow and business-logic abuse Price, quota, and entitlement tampering Webhook signature verification SSRF and server-side fetches Clickjacking and framing controls GraphQL and query-shape abuse WebSocket and long-lived connection security Redirects, callbacks, and deep links HTTP request smuggling and parser disagreement Web cache poisoning and cache deception Threat-model an LLM feature MAIN ROUTE Direct and indirect prompt injection Untrusted model output and dangerous sinks Data exfiltration through rendered output Tool calls as untrusted requests Agent permissions and excessive agency MCP and tool server security Human approval for high-impact actions Retrieval authorization and tenant isolation Poisoned and hostile retrieved content Vector stores, embeddings, and sensitive data System prompts are not secrets Conversation state and agent memory isolation AI provider data handling and privacy Model, dataset, and plugin supply-chain risk Unbounded token use, loops, and cost abuse LLM security evaluations and regression tests Red-team an AI feature safely AI security incident response Turn a threat into a test MAIN ROUTE Negative authorization tests Unit, integration, and end-to-end security tests Regression tests for vulnerabilities Static analysis and lint rules Dynamic and interactive application testing Fuzzing parsers and validators Dependency and container scanning Secure code review checklist False positives, false negatives, and test coverage Security test environments and safe fixtures Secure file upload pipeline MAIN ROUTE MIME type and extension validation Safe file names and storage locations Malware scanning and quarantine workflow Archive extraction and path traversal Image, document, and media parser risks Content-Disposition and download safety Import, export, and CSV formula injection XML external entities and unsafe XML features Rich text sanitization and safe rendering Dependency inventory and transitive risk MAIN ROUTE Vulnerability advisories and triage Lockfiles, registries, and package confusion Dependency updates and patch policy Secrets committed to source control Typosquatting and malicious packages Build isolation and reproducibility SBOMs and component provenance Artifact signing and verification CI/CD secret exposure Pipeline permissions and workflow injection Third-party actions, plugins, and build extensions Coordinated vulnerability disclosure and patch response Same-origin policy and origin model MAIN ROUTE CORS preflight and credentialed requests postMessage and cross-window messaging Browser storage trade-offs Content Security Policy deployment Subresource Integrity and third-party scripts Referrer, permissions, and security headers DOM clobbering and unsafe URL schemes Cross-site leaks and side channels Privacy-preserving telemetry Consent, retention, deletion, and export Security configuration and hardened defaults MAIN ROUTE Least privilege for application processes Memory safety and unsafe code Environment variables and secret stores Containers and image hygiene Network segmentation and egress control Cloud IAM and workload identity Database account and network security Production and non-production separation Backups, restore, and ransomware resilience Patch management and exposed services Infrastructure as code review Security event logging MAIN ROUTE Authentication and authorization signals Log integrity, access, and retention Alert quality and operational ownership Vulnerability triage and severity Incident response roles and first steps Credential and key compromise Security incident retrospectives Vulnerability disclosure handling Tabletop exercises and response readiness Security policies versus implemented controls MAIN ROUTE Secure development lifecycle OWASP ASVS as a verification catalog OWASP Top 10 and common risk taxonomies NIST SSDF practices in a small team Evidence, audit trails, and control ownership Risk acceptance and exceptions Security roles and shared responsibility CompTIA Security+ crosswalk CompTIA CySA+ crosswalk Exam objective versioning Jurisdiction- and standard-specific compliance DevOps as a way of working MAIN ROUTE The delivery value stream Small batches and fast feedback Work in progress and flow Continuous delivery and continuous deployment Local feedback loops Shared ownership and operational readiness Trunk-based development MAIN ROUTE Short-lived branches and pull requests Commit and change-set design Merge queues and serialized integration Branch protection and required checks Code ownership and review routing Reverting a change safely Pipeline as code MAIN ROUTE Pipeline stages and dependency graphs Fast-fail checks and feedback order Build matrix and targeted test selection Ephemeral CI workers Pipeline caching and cache keys Concurrency controls and cancellation Pipeline secrets and permission scope Pipeline observability and failure diagnosis Pinned toolchains and dependency inputs MAIN ROUTE Reproducible and hermetic builds Build once, promote the same artifact Artifact naming and version identity Artifact retention and cleanup Build metadata and release manifests Supply-chain attestations in delivery Test layers in a delivery pipeline MAIN ROUTE Service and API contract checks Integration environments and test dependencies Test data lifecycle Flaky test diagnosis and quarantine Parallel tests and resource contention Smoke tests after deployment Static checks and quality thresholds Database change verification Release versioning and changelogs MAIN ROUTE Deployment versus release Feature flags as release controls Progressive delivery Canary analysis Blue-green deployment Rollback and roll-forward decisions Release approvals and separation of duties Release notes and customer communication Deployment strategies and workload replacement MAIN ROUTE Startup, readiness, and liveness probes Graceful shutdown and connection draining Zero-downtime rollout prerequisites Health checks that do not amplify failure Background worker lifecycle Scheduled jobs and missed executions Deployment hooks and post-deploy verification Declarative desired state MAIN ROUTE Infrastructure plans and human review State, locking, and collaboration Drift detection and reconciliation Reusable modules and module boundaries Environment separation and promotion Idempotent provisioning and safe retries Destroy plans and data-bearing resources Infrastructure changes in CI Container image layers and build context MAIN ROUTE Multi-stage image builds Non-root containers and filesystem permissions Image tagging and immutability Resource requests, limits, and saturation Autoscaling signals and bounds Service discovery and internal traffic Jobs, workers, and scheduled workloads Orchestrator rollouts and disruption budgets Environment purpose and parity MAIN ROUTE Immutable deployment inputs Configuration validation at startup Configuration schema and defaults Secret injection and rotation boundaries Feature configuration versus feature flags Local development dependencies Ephemeral preview environments Service-level indicators and objectives MAIN ROUTE Metrics, logs, and traces in operations Dashboards for operational questions Actionable alert design Alert grouping, deduplication, and routing Telemetry cardinality and cost Synthetic checks and black-box monitoring Change markers and deployment correlation Log retention and useful context Error budgets and release decisions MAIN ROUTE On-call readiness and escalation Incident roles and communication Runbooks and operational procedures Triage and evidence gathering Incident mitigation and recovery Blameless learning reviews Game days and recovery exercises Disaster recovery objectives Capacity planning from demand patterns MAIN ROUTE Load tests as operational evidence Autoscaling and cold-start trade-offs Capacity headroom and safety margin Cost allocation and ownership Budget alerts and cost anomaly response Ephemeral resource cleanup Production performance regression detection Performance versus reliability trade-offs Backup scope and recovery point MAIN ROUTE Restore drills and recovery verification Point-in-time recovery Database migration rollout coordination Connection pool sizing and exhaustion Replication lag and failover readiness Storage growth and retention policy Stateful workload maintenance windows Internal platforms as products MAIN ROUTE Golden paths and paved roads Self-service infrastructure and delivery Service templates and scaffolding Platform APIs and capability boundaries Platform adoption and developer feedback Platform reliability and support model Platform migration and deprecation Delivery performance measures MAIN ROUTE Lead time and deployment frequency Change failure and recovery time Value stream bottleneck analysis Operational toil and automation choices Improvement experiments and outcome checks Metric misuse and team-level comparison Security checks in the software pipeline MAIN ROUTE Least-privilege pipeline identities Policy checks for infrastructure changes Audit trails for deployment decisions Separation of duties without delivery bottlenecks Security incident and release coordination What a network does MAIN ROUTE Layers, encapsulation, and decapsulation Frames, MAC addresses, and local delivery IPv4 addresses, prefixes, and subnetting IPv6 address structure and neighbor discovery ICMP and ping Ports, sockets, and endpoint identity Byte order and wire formats TCP and UDP TCP connection lifecycle DNS lookup path DHCP and address configuration Common network services Physical media and wireless basics Routing and forwarding MAIN ROUTE Switching, VLANs, and broadcast domains NAT and port forwarding Firewalls, ACLs, and packet filtering Flow control, congestion, and head-of-line blocking HTTP request and response path TLS and certificate validation mTLS and service identity HTTP/2, HTTP/3, and QUIC CORS and browser network rules Real-time transports Proxies, reverse proxies, and load balancers HTTP caching and CDNs VPNs and network segmentation Cloud and virtual networks Container and Kubernetes networking Wireless network behavior A repeatable network troubleshooting method MAIN ROUTE Connection refused, reset, and timed out Read route, interface, and neighbor tables DNS, DHCP, and address-conflict diagnosis Latency, bandwidth, throughput, loss, and jitter Timeouts, keepalives, and connection pooling Traceroute, MTU, and path diagnosis Inspecting HTTP from the client Packet capture and protocol inspection Network monitoring and baselines Network documentation and change control Units, dimensions, and conversions MAIN ROUTE Ratios, rates, and proportions Linear interpolation and scaling Percentages and percentage points Powers of two and logarithms Binary, hexadecimal, and bit operations Boolean logic, sets, and predicates Counting and combinatorics Signed numbers, overflow, and fixed-width values Floating point and rounding Modular arithmetic Text, Unicode, and encoded bytes Entropy and bits of strength Linear, exponential, and logarithmic growth MAIN ROUTE Sums and series Probability and expected value Collisions and the birthday problem Conditional probability and Bayes’ rule Precision, recall, and the confusion matrix Sampling and selection bias Randomness and random number generators Mean, median, variance, and percentiles Distributions and long tails Moving averages and smoothing (EWMA) Confidence, variability, and repeated measurements Error bars and uncertainty communication Weighted averages and aggregation Back-of-envelope estimation MAIN ROUTE Queue growth and Little’s Law intuition Availability and failure probability Tail latency under fan-out Retry amplification and backoff Rate limiting math Cache hit rate and break-even cost SLOs, error budgets, and burn rate Load distribution and hashing Capacity, headroom, and saturation Network subnet planning Vectors and dot products MAIN ROUTE Similarity and distance Matrices as transformations Derivatives, gradients, and the chain rule Gradient descent and learning rate Exponentials, softmax, and temperature Log-probabilities and information theory Sampling strategies (greedy, top-k, top-p) Normalization High-dimensional intuition Quantization and numeric precision Token and cost arithmetic KEEP BUILDING Put the ideas to work.