What do you want to do?

Pick a goal. Each path is a short, ordered route through the tutorials that get you there, with one line on what each step adds. Every tutorial also stands alone.

I build Spring Boot apps and want to know what happens to a request

From java -jar to a response: Spring Boot, Tomcat, NGINX and Spring Security, one request at a time. 8 steps

  1. Port, Socket, Reverse Proxy, JVM, Pod, SIGTERM: Backend Words Before the Deep Dives Optional: the words (port, socket, reverse proxy, JVM) if any are new.
  2. What Spring Boot Actually Does After java -jar (Startup to Graceful Shutdown) What starts when you run java -jar, and how it shuts down.
  3. What Apache Tomcat Actually Does With Your Request (Startup, Request, Shutdown) Tomcat, the server Spring Boot embeds (shown standalone): one request from socket to servlet.
  4. What NGINX Does Before Your App Sees a Request (and Where 502 vs 504 Come From) What sits in front of it, and where 502 and 504 come from.
  5. Tomcat vs NGINX: What Each Does and Why Spring Boot May Need Both Which layer broke: 413 on upload, a chunked AI stream, 60 seconds of silence.
  6. Why Your WebSocket Disconnects After 60 Seconds: Spring Boot Behind NGINX WebSockets behind NGINX: missing headers, 60 seconds of quiet, and 1006.
  7. Why Spring Security Returns 401 or 403: One Request Through the Filter Chain Why a request is rejected with 401 or 403 before your controller.
  8. Why Your Spring Boot Redis Cache Never Expires: Hits, Misses, TTL and Eviction as a State Machine Caching the answer: hits, misses, TTL and eviction.

All of How It Actually Works →

I deploy to Azure and Kubernetes and need to know why traffic or secrets fail

Subnets and routes from the ground up; packets through NSGs and Azure Firewall, then out to on-premises over VPN or ExpressRoute; secrets into an AKS pod; sign-in with Entra ID. 9 steps

  1. Azure CIDR & Subnets: Why You Can Use Only 251 of 256 IPs in a /24 Start here: CIDR, the 5 reserved IPs, routes and DNS.
  2. How Azure NSGs Allow or Deny a Packet: 6 Real Packets, Rule by Rule How an NSG allows or denies one packet, rule by rule.
  3. Azure Subnet NSG vs NIC NSG: Why the Packet Still Got Denied Two NSGs on one path: why the packet was still denied.
  4. Azure Route Tables and NVAs: Why the Reply Took a Different Path Route tables and NVAs: why the reply took another path.
  5. How Azure Firewall Decides: 5 Packets Through a Hub and Spoke, Rule by Rule How Azure Firewall decides in a hub and spoke.
  6. Why Your Azure VM Can't Reach On-Premises: VPN vs ExpressRoute, Packet by Packet Leaving Azure: VPN vs ExpressRoute, and which route wins.
  7. Base64 Is Not Encryption: Kubernetes Secrets, Key Vault and Redis Cache Words Explained Optional: Secrets, Key Vault and cache words first.
  8. Pod Stuck in ContainerCreating? How Secrets Reach a Pod in AKS (Key Vault CSI Driver) How a secret reaches a pod, and why it gets stuck in ContainerCreating.
  9. Sign In with Microsoft Entra ID in Spring Boot: OIDC, OAuth 2.0, PKCE, Client Credentials, SAML Signing users in with Entra ID from Spring Boot.

All of Azure Networking, Packet by Packet →

I use AI coding tools and want to know how they actually work

Tokens, context, tool calls, MCP and the agent loop: what Claude Code and its peers do under the chat box. 9 steps

  1. How Claude Works: A 5-Layer Mental Model for Developers The map: a five-layer mental model of the Claude stack.
  2. How LLM Tokens Work — And Why They Explain Your AI Bill Tokens: the unit of everything, including the bill.
  3. How Claude's Context Window Works: Limits, Costs, and Overflow What the model can see at once, and what happens when it overflows.
  4. How Claude Tool Calling Actually Works: The Request-Execute Model Tool calling: the model asks, your code runs.
  5. What Is MCP (Model Context Protocol) and How It Works MCP: one standard way to plug tools in.
  6. How Claude Code's Agent Loop Works (and Why It Breaks) The agent loop, and why it breaks.
  7. Claude Code Hooks Explained: Deterministic Guards for the Agent Loop Hooks: guards that run every time, not just when the model remembers.
  8. What Is Context Rot and Why AI Agents Degrade Over Time Why long sessions get worse.
  9. Context Engineering: What the Model Sees Is What You Design Designing what the model sees, on purpose.

The full How Claude Actually Works course →

I'm adding AI to a Java / Spring Boot application

Spring AI from the first ChatClient call to RAG, tools, MCP, tests and a production blueprint. 10 steps

  1. What Is Spring AI? The Enterprise Java Framework for Calling Any AI Model What Spring AI is, and where it fits in a Spring Boot app.
  2. Spring AI ChatClient Explained: prompt → model → response, and reading token usage The first call: prompt, model, response, token usage.
  3. Structured Output in Spring AI: Turn Model Text Into Typed Java Records with .entity() Model text into typed Java records.
  4. RAG with Spring AI: Documents → Chunks → Embeddings → Vector Store → Grounded Answers Grounding answers in your documents.
  5. Tool Calling in Spring AI 2.0: @Tool, ChatClient.tools(), and the Full Round Trip Letting the model call your Java methods.
  6. MCP with Spring AI: Connect AI to Tools the Standard Way (Spring AI 2.0.0) Connecting tools the standard way.
  7. What Spring AI Does Between chatClient.prompt() and the Answer (Memory, RAG, Tool Loop) Deep dive: everything between chatClient.prompt() and the answer.
  8. Observability for Spring AI: Logging, Metrics, and Tracing Every Model Call Logging, metrics and tracing every model call.
  9. Spring AI Evaluation & Guardrails: RelevancyEvaluator, FactCheckingEvaluator, and CI Release Gates Testing AI output before release.
  10. Spring AI Production Blueprint: ChatClient + RAG + Tools + Security + Observability in One Service All of it in one production service.

All of Spring AI for Enterprise Java →

I need to secure an AI system

The attack surface, prompt injection, RAG and MCP risks, agent permissions, and a secured architecture. 10 steps

  1. The AI Attack Surface Explained: The Mental Model for Securing AI The mental model: where an AI system can be attacked.
  2. How to Threat Model an AI System: ATLAS, OWASP, MAESTRO & NIST Which framework to use: ATLAS, OWASP, MAESTRO, NIST.
  3. Prompt Injection: The Attack Flow Every AI Developer Must Know The attack every AI developer meets first.
  4. Direct vs Indirect Prompt Injection: The One That Rides In on a Web Page The version that arrives inside a web page or document.
  5. RAG Security: Why Your RAG Pipeline Retrieves a Backdoor When your retrieval pipeline fetches the attack.
  6. The AI Supply Chain & Securing MCP (Model Context Protocol) Models, packages and MCP servers you did not write.
  7. Excessive Agency: When an AI Agent Does Too Much Agents that can do too much.
  8. AI Agent Identity: IAM for Non-Human Actors Giving an agent an identity and least privilege.
  9. Zero Trust for AI: The 5 Guardrail Principles The guardrail principles.
  10. The Architecture of a Secured AI System (Capstone) Capstone: a secured AI system, end to end.

All 35 parts of Securing AI →

My AI bill is too high

Where tokens and dollars go, and the levers that cut them: caching, model tiering, cheaper loops. 7 steps

  1. What Is a Token in AI? How AI Coding Tools Are Priced What a token is and how AI tools are priced.
  2. Why AI Agent API Costs Are So Much Higher Than Chatbots Why agents cost far more than chat.
  3. How Claude Token Billing Works: Input, Output, and Cache Costs Input, output and cache costs, line by line.
  4. How Prompt Caching Cuts Your AI Bill ~90% (and the Floor Trap) Prompt caching, and the floor that catches people.
  5. Why Is Your Cache Never Hitting? Prompt Cache Prefix Rules Why your cache never hits.
  6. How to Reduce AI Coding Costs 40-60% with Model Tiering Model tiering.
  7. The Cheapest Way to Cut Agent Cost: Model Routing and Cheaper Loops Routing and cheaper loops for agents.

All of The Hidden Cost of AI Coding →

I'm preparing for the Claude Certified Architect exam

The exam map, a study guide, and one anchor lesson per domain before the 50 scenario questions. 7 steps

  1. Claude Certified Architect (CCA) Exam Guide: All Five Domains on One Diagram All five domains on one diagram.
  2. CCA-F Exam Study Guide: Claude Certified Architect Foundations What to study, in what order.
  3. The Agent Loop Explained: Why Ignoring Tool Results Breaks Your Agent Agentic architecture: the loop and its tool results.
  4. MCP Explained on One Diagram: The USB-C Port for AI Tools Tool design and MCP.
  5. Instructions or a Hook — Which Runs Every Time? CLAUDE.md vs Hooks Claude Code configuration: instructions vs hooks.
  6. How Do You Guarantee Valid JSON? Forcing Structured Output Prompting and structured output.
  7. It Forgot Your First Instruction: Lost-in-the-Middle and Context Rot Context management and reliability.

All 53 lessons and scenario questions →

Looking for something else? Browse by series or search all tutorials.