← Back

The Glossary of Backend Engineering

Concurrency & Execution Models

Process vs. Thread — A process is an independently executing program with its own memory space; a thread is a lighter-weight unit of execution within a process that shares memory with its siblings. Backend servers juggle both to serve concurrent requests.

Event Loop — A single-threaded construct (as in Node.js) that continuously pulls tasks off a queue and executes them, enabling non-blocking I/O without spawning a thread per request.

Non-Blocking I/O / Async-Await — A model where a thread issues an I/O operation (disk, network, database) and moves on to other work instead of waiting idle for it to complete, resuming via a callback, promise, or await once the result is ready.

Thread Pool / Worker Pool — A fixed set of reusable threads or processes that pick up incoming work items, avoiding the overhead of creating a new thread for every request or task.

Race Condition — A bug where the correctness of a program depends on the unpredictable timing or ordering of concurrent operations, often surfacing only under load.

Mutex / Lock — A synchronization primitive that ensures only one thread can access a critical section of code or shared resource at a time.

Deadlock — A state where two or more threads or processes are each waiting on a resource the other holds, so none can proceed.

Coroutine / Green Thread — A lightweight, cooperatively-scheduled unit of execution managed by a language runtime rather than the OS, allowing thousands of concurrent tasks with far less overhead than OS threads.


Request Lifecycle & API Design

Middleware — A function or layer that sits in the request/response pipeline, able to inspect, modify, short-circuit, or log a request before it reaches the route handler (or the response before it reaches the client).

Serialization / Deserialization — Converting an in-memory object into a transmittable format like JSON, XML, or Protocol Buffers (serialization), and reconstructing it back into an object on the receiving end (deserialization).

Content Negotiation — The mechanism by which a client and server agree on the format (JSON, XML, etc.) and language of a response, typically via Accept and Content-Type headers.

Pagination (Offset vs. Cursor) — Strategies for returning large result sets in pages. Offset-based pagination skips N records and returns the next M; cursor-based pagination returns records after a stable pointer, avoiding skew when data changes mid-pagination.

API Versioning — A strategy (URL path, header, or query param based) for evolving an API's contract over time without breaking existing consumers.

Session Management — Tracking a user's state across multiple requests, either server-side (a session store keyed by a cookie ID) or client-side (a self-contained token), each with different trade-offs around statelessness and revocation.


Databases & Data Modeling

Normalization / Denormalization — Normalization structures data to eliminate redundancy across related tables; denormalization intentionally duplicates data to reduce joins and speed up reads, trading storage and write complexity for read performance.

Indexing — A data structure (commonly a B-tree or hash index) that lets a database look up rows without scanning the entire table, dramatically speeding up reads at the cost of slower writes and extra storage.

Query Execution Plan — The step-by-step strategy a database's query planner chooses to execute a query (which indexes to use, join order, etc.), inspectable via EXPLAIN and central to diagnosing slow queries.

Transaction Isolation Levels — The degree to which concurrent transactions are shielded from each other's intermediate state (Read Uncommitted, Read Committed, Repeatable Read, Serializable), trading consistency guarantees for throughput.

Optimistic vs. Pessimistic Locking — Pessimistic locking blocks other transactions from touching a row until the current one finishes; optimistic locking allows concurrent access and only checks for conflicts (e.g., via a version number) at commit time.

OLTP vs. OLAP — OLTP (Online Transaction Processing) systems handle many small, fast read/write operations (e.g., an order system); OLAP (Online Analytical Processing) systems handle complex aggregate queries over large historical datasets (e.g., a data warehouse).

NoSQL Data Models — Non-relational storage models suited to specific access patterns: document stores (nested JSON-like records), key-value stores (simple lookups), wide-column stores (sparse, column-oriented rows), and graph databases (nodes and relationships).

Write-Ahead Log (WAL) — A durability mechanism where changes are recorded in an append-only log before being applied to the actual data files, allowing a database to recover its state after a crash.


Messaging & Asynchronous Processing

Message Queue — An intermediary (e.g., RabbitMQ, SQS) that holds messages produced by one service until a consumer is ready to process them, decoupling producers from consumers in time and pace.

Pub/Sub (Publish/Subscribe) — A messaging pattern where publishers broadcast events to a topic and any number of subscribers receive a copy, without either side knowing about the other directly.

Dead Letter Queue (DLQ) — A holding queue for messages that repeatedly fail processing, so they can be inspected or retried later instead of blocking or silently vanishing.

Background Job / Worker — A unit of work executed outside the request/response cycle (sending an email, resizing an image, generating a report), typically picked up by a dedicated worker process from a job queue.

Cron Job / Scheduled Task — A task configured to run automatically at fixed intervals or specific times, independent of any user-triggered request.

Outbox Pattern — A technique for reliably publishing an event alongside a database write by first writing both to the same transaction, then having a separate process relay the event, avoiding the dual-write problem.

Delivery Guarantees — The contract a messaging system offers about how many times a message might be delivered: at-most-once (may be lost), at-least-once (may be duplicated), or exactly-once (neither, but hardest to guarantee in practice).


Scalability & Reliability

Horizontal vs. Vertical Scaling — Vertical scaling adds more resources (CPU, RAM) to a single machine; horizontal scaling adds more machines running the same service, which usually requires the service to be stateless.

Statelessness — Designing a service so no request depends on data stored in that specific server instance's memory, allowing any instance to handle any request — a prerequisite for easy horizontal scaling.

Health Check — An endpoint or probe a service exposes to report whether it's alive and ready to serve traffic, used by load balancers and orchestrators to route around unhealthy instances.

Graceful Shutdown — Allowing a service to finish in-flight requests and clean up resources before terminating, rather than dropping connections abruptly during a deploy or scale-down.

Bulkhead Pattern — Isolating resources (thread pools, connection pools) per dependency so that failure or saturation in one doesn't starve the entire system, named after ship compartments that contain flooding.

Failover — The automatic switch to a standby system or replica when the primary fails, intended to minimize downtime.

Retry with Backoff — Reattempting a failed operation after a delay that increases with each retry (exponential backoff), often with randomized jitter, to avoid overwhelming a recovering system with synchronized retries.


Security (Backend-Specific)

Hashing vs. Encryption — Hashing is a one-way transformation used to verify data (like passwords) without storing the original; encryption is reversible and used to protect data that must later be decrypted.

Salting — Appending a unique random value to data before hashing (typically passwords) so identical inputs don't produce identical hashes, defeating precomputed rainbow-table attacks.

Secrets Management — Storing and distributing sensitive credentials (API keys, database passwords, certificates) via a dedicated system (Vault, AWS Secrets Manager) rather than hardcoding them in source or config files.

Principle of Least Privilege — Granting a service, user, or process only the minimum permissions necessary to do its job, limiting the damage from a compromised credential or component.

SQL Injection — An attack where untrusted input is concatenated directly into a SQL query, letting an attacker manipulate or exfiltrate data; mitigated with parameterized queries or prepared statements.

Input Validation / Sanitization — Checking incoming data against expected shape, type, and bounds (validation) and stripping or encoding dangerous content (sanitization) before it's processed or stored.


Observability & Operations

Log Levels — A hierarchy (DEBUG, INFO, WARN, ERROR, FATAL) used to categorize log messages by severity, letting teams filter noise in production while retaining detail for debugging.

Metrics — Numeric measurements collected over time (request rate, error rate, latency, CPU usage) that can be aggregated, graphed, and alerted on to track system health.

Distributed Tracing — Following a single request as it hops across multiple services, correlating spans with a shared trace ID to visualize where time is spent and where failures occur.

APM (Application Performance Monitoring) — Tooling that combines logs, metrics, and traces into a unified view of an application's runtime behavior and performance bottlenecks.

SLA / SLO / SLI — An SLI (Service Level Indicator) is a measured metric (e.g., uptime); an SLO (Objective) is the internal target for that metric (e.g., 99.9% uptime); an SLA (Agreement) is the external, often contractual, commitment made to customers.

On-Call / Alerting — The practice of routing automated alerts (triggered when metrics breach a threshold) to a rotating set of engineers responsible for responding to production incidents.

written with Claude Sonnet 5