What do you want to do?
Pick a goal. Each path is a short, ordered route through the tutorials that get you there, with one line on what each step adds. Every tutorial also stands alone.
- I build Spring Boot apps and want to know what happens to a request
- I deploy to Azure and Kubernetes and need to know why traffic or secrets fail
- I use AI coding tools and want to know how they actually work
- I'm adding AI to a Java / Spring Boot application
- I need to secure an AI system
- My AI bill is too high
- I'm preparing for the Claude Certified Architect exam
I build Spring Boot apps and want to know what happens to a request
From java -jar to a response: Spring Boot, Tomcat, NGINX and Spring Security, one request at a time. 8 steps
- Port, Socket, Reverse Proxy, JVM, Pod, SIGTERM: Backend Words Before the Deep Dives Optional: the words (port, socket, reverse proxy, JVM) if any are new.
- What Spring Boot Actually Does After java -jar (Startup to Graceful Shutdown) What starts when you run java -jar, and how it shuts down.
- What Apache Tomcat Actually Does With Your Request (Startup, Request, Shutdown) Tomcat, the server Spring Boot embeds (shown standalone): one request from socket to servlet.
- What NGINX Does Before Your App Sees a Request (and Where 502 vs 504 Come From) What sits in front of it, and where 502 and 504 come from.
- Tomcat vs NGINX: What Each Does and Why Spring Boot May Need Both Which layer broke: 413 on upload, a chunked AI stream, 60 seconds of silence.
- Why Your WebSocket Disconnects After 60 Seconds: Spring Boot Behind NGINX WebSockets behind NGINX: missing headers, 60 seconds of quiet, and 1006.
- Why Spring Security Returns 401 or 403: One Request Through the Filter Chain Why a request is rejected with 401 or 403 before your controller.
- Why Your Spring Boot Redis Cache Never Expires: Hits, Misses, TTL and Eviction as a State Machine Caching the answer: hits, misses, TTL and eviction.
I deploy to Azure and Kubernetes and need to know why traffic or secrets fail
Subnets and routes from the ground up; packets through NSGs and Azure Firewall, then out to on-premises over VPN or ExpressRoute; secrets into an AKS pod; sign-in with Entra ID. 9 steps
- Azure CIDR & Subnets: Why You Can Use Only 251 of 256 IPs in a /24 Start here: CIDR, the 5 reserved IPs, routes and DNS.
- How Azure NSGs Allow or Deny a Packet: 6 Real Packets, Rule by Rule How an NSG allows or denies one packet, rule by rule.
- Azure Subnet NSG vs NIC NSG: Why the Packet Still Got Denied Two NSGs on one path: why the packet was still denied.
- Azure Route Tables and NVAs: Why the Reply Took a Different Path Route tables and NVAs: why the reply took another path.
- How Azure Firewall Decides: 5 Packets Through a Hub and Spoke, Rule by Rule How Azure Firewall decides in a hub and spoke.
- Why Your Azure VM Can't Reach On-Premises: VPN vs ExpressRoute, Packet by Packet Leaving Azure: VPN vs ExpressRoute, and which route wins.
- Base64 Is Not Encryption: Kubernetes Secrets, Key Vault and Redis Cache Words Explained Optional: Secrets, Key Vault and cache words first.
- Pod Stuck in ContainerCreating? How Secrets Reach a Pod in AKS (Key Vault CSI Driver) How a secret reaches a pod, and why it gets stuck in ContainerCreating.
- Sign In with Microsoft Entra ID in Spring Boot: OIDC, OAuth 2.0, PKCE, Client Credentials, SAML Signing users in with Entra ID from Spring Boot.
I use AI coding tools and want to know how they actually work
Tokens, context, tool calls, MCP and the agent loop: what Claude Code and its peers do under the chat box. 9 steps
- How Claude Works: A 5-Layer Mental Model for Developers The map: a five-layer mental model of the Claude stack.
- How LLM Tokens Work — And Why They Explain Your AI Bill Tokens: the unit of everything, including the bill.
- How Claude's Context Window Works: Limits, Costs, and Overflow What the model can see at once, and what happens when it overflows.
- How Claude Tool Calling Actually Works: The Request-Execute Model Tool calling: the model asks, your code runs.
- What Is MCP (Model Context Protocol) and How It Works MCP: one standard way to plug tools in.
- How Claude Code's Agent Loop Works (and Why It Breaks) The agent loop, and why it breaks.
- Claude Code Hooks Explained: Deterministic Guards for the Agent Loop Hooks: guards that run every time, not just when the model remembers.
- What Is Context Rot and Why AI Agents Degrade Over Time Why long sessions get worse.
- Context Engineering: What the Model Sees Is What You Design Designing what the model sees, on purpose.
I'm adding AI to a Java / Spring Boot application
Spring AI from the first ChatClient call to RAG, tools, MCP, tests and a production blueprint. 10 steps
- What Is Spring AI? The Enterprise Java Framework for Calling Any AI Model What Spring AI is, and where it fits in a Spring Boot app.
- Spring AI ChatClient Explained: prompt → model → response, and reading token usage The first call: prompt, model, response, token usage.
- Structured Output in Spring AI: Turn Model Text Into Typed Java Records with .entity() Model text into typed Java records.
- RAG with Spring AI: Documents → Chunks → Embeddings → Vector Store → Grounded Answers Grounding answers in your documents.
- Tool Calling in Spring AI 2.0: @Tool, ChatClient.tools(), and the Full Round Trip Letting the model call your Java methods.
- MCP with Spring AI: Connect AI to Tools the Standard Way (Spring AI 2.0.0) Connecting tools the standard way.
- What Spring AI Does Between chatClient.prompt() and the Answer (Memory, RAG, Tool Loop) Deep dive: everything between chatClient.prompt() and the answer.
- Observability for Spring AI: Logging, Metrics, and Tracing Every Model Call Logging, metrics and tracing every model call.
- Spring AI Evaluation & Guardrails: RelevancyEvaluator, FactCheckingEvaluator, and CI Release Gates Testing AI output before release.
- Spring AI Production Blueprint: ChatClient + RAG + Tools + Security + Observability in One Service All of it in one production service.
I need to secure an AI system
The attack surface, prompt injection, RAG and MCP risks, agent permissions, and a secured architecture. 10 steps
- The AI Attack Surface Explained: The Mental Model for Securing AI The mental model: where an AI system can be attacked.
- How to Threat Model an AI System: ATLAS, OWASP, MAESTRO & NIST Which framework to use: ATLAS, OWASP, MAESTRO, NIST.
- Prompt Injection: The Attack Flow Every AI Developer Must Know The attack every AI developer meets first.
- Direct vs Indirect Prompt Injection: The One That Rides In on a Web Page The version that arrives inside a web page or document.
- RAG Security: Why Your RAG Pipeline Retrieves a Backdoor When your retrieval pipeline fetches the attack.
- The AI Supply Chain & Securing MCP (Model Context Protocol) Models, packages and MCP servers you did not write.
- Excessive Agency: When an AI Agent Does Too Much Agents that can do too much.
- AI Agent Identity: IAM for Non-Human Actors Giving an agent an identity and least privilege.
- Zero Trust for AI: The 5 Guardrail Principles The guardrail principles.
- The Architecture of a Secured AI System (Capstone) Capstone: a secured AI system, end to end.
My AI bill is too high
Where tokens and dollars go, and the levers that cut them: caching, model tiering, cheaper loops. 7 steps
- What Is a Token in AI? How AI Coding Tools Are Priced What a token is and how AI tools are priced.
- Why AI Agent API Costs Are So Much Higher Than Chatbots Why agents cost far more than chat.
- How Claude Token Billing Works: Input, Output, and Cache Costs Input, output and cache costs, line by line.
- How Prompt Caching Cuts Your AI Bill ~90% (and the Floor Trap) Prompt caching, and the floor that catches people.
- Why Is Your Cache Never Hitting? Prompt Cache Prefix Rules Why your cache never hits.
- How to Reduce AI Coding Costs 40-60% with Model Tiering Model tiering.
- The Cheapest Way to Cut Agent Cost: Model Routing and Cheaper Loops Routing and cheaper loops for agents.
I'm preparing for the Claude Certified Architect exam
The exam map, a study guide, and one anchor lesson per domain before the 50 scenario questions. 7 steps
- Claude Certified Architect (CCA) Exam Guide: All Five Domains on One Diagram All five domains on one diagram.
- CCA-F Exam Study Guide: Claude Certified Architect Foundations What to study, in what order.
- The Agent Loop Explained: Why Ignoring Tool Results Breaks Your Agent Agentic architecture: the loop and its tool results.
- MCP Explained on One Diagram: The USB-C Port for AI Tools Tool design and MCP.
- Instructions or a Hook — Which Runs Every Time? CLAUDE.md vs Hooks Claude Code configuration: instructions vs hooks.
- How Do You Guarantee Valid JSON? Forcing Structured Output Prompting and structured output.
- It Forgot Your First Instruction: Lost-in-the-Middle and Context Rot Context management and reliability.
Looking for something else? Browse by series or search all tutorials.