The Daily
A note a day on APIs and the realities of shipping web applications. Stuff I've actually learned across 25 years of doing the work.
Docker Healthchecks That Actually Mean Something
Your container says healthy. Your app is throwing 500s. Here's why that happens and how to write healthchecks that actually gate traffic.
Your container is . Your app is throwing 500s on every request. Your load balancer is happily routing traffic into the void. Welcome to the false confidence of a default Docker healthcheck. I've debugged this exact situation more than once. Most recently on a Laravel app running behind Traefik for a healthcare client…
Read the daily →SSE over nginx + PHP-FPM: the buffering problem nobody warns you about
Server-Sent Events look dead simple until nginx and PHP-FPM start swallowing your stream. Here's what actually happens and how to fix it.
Every SSE tutorial on the internet shows you the same 15 lines of PHP and calls it done. What they don't show you is the part where you deploy to a real nginx + PHP-FPM stack and your beautifully streaming events arrive in one giant blob — or not at all — because three different layers are buffering your output…
Read the daily →Laravel Sanctum SPA Auth Across Subdomains Will Bite You
Sanctum's subdomain cookie auth looks simple until CORS and session config conspire to ruin your day. Here's the config that actually works.
Sanctum's documentation makes subdomain SPA authentication look like a ten-minute job. It is not a ten-minute job. I've set this up across probably a dozen projects now — e-commerce frontends on hitting APIs on , healthcare portals, a real estate dashboard — and every single time there's a moment where the cookie just…
Read the daily →The nginx directive that cuts PHP-FPM overhead in half
One keepalive line in your nginx upstream block and you stop paying TCP handshake tax on every PHP request. Here's why it's off by default and how to tune it.
I've tuned a lot of nginx configs over the years and I kept seeing the same thing: servers handling two or three hundred PHP requests per second with perfectly healthy CPU and memory numbers, but p99 latency sitting higher than it should be. The culprit, more often than not, was sitting right in the upstream block…
Read the daily →Pipedream vs. a webhook relay you own: when trust gets expensive
Pipedream is genuinely good until your payload contains PHI or a signing secret. Here's where I draw the line.
Pipedream is one of those tools I recommend without hesitation — right up until I can't. The line isn't arbitrary. It's the moment a payload contains something I'm not allowed to hand to a third party, or the moment the business logic is complex enough that I'm fighting the platform instead of using it. Let me walk…
Read the daily →