Skip to main content Skip to navigation

Developer glossary

Short definitions of terms used across this blog, each linked to the post that explains it in depth.

CORS (Cross-Origin Resource Sharing)
An HTTP-header based mechanism that lets a server say which other origins a browser may load its resources from. Without it, browsers block cross-origin reads by default. Read: What is CORS
Preflight request
An OPTIONS request the browser sends before a non-simple cross-origin request, such as one using PUT or a custom header, to ask the server for permission. The answer can be cached with Access-Control-Max-Age. Read: What is CORS
HTTP security headers
Response headers such as Content-Security-Policy, Strict-Transport-Security and X-Content-Type-Options that instruct the browser to enable protections for your site. Read: How to use security headers
NAT gateway
An AWS managed service placed in a public subnet that lets resources in private subnets, such as a VPC-attached Lambda function, make outbound connections to the internet through the internet gateway. Read: Lambda function in a VPC
VPC endpoint
A private connection from a VPC to an AWS service that avoids a NAT gateway. Gateway endpoints for S3 and DynamoDB have no charge; interface endpoints are billed per hour and per GB. Read: NAT gateway vs VPC endpoint costs
Amazon CloudFront
AWS's content delivery network, which serves cached copies of static and dynamic content from edge locations. Hosting a single-page app on it needs custom error responses so client-side routes do not return 403 or 404. Read: Hosting an SPA on CloudFront
MCP (Model Context Protocol)
An open protocol, introduced by Anthropic in November 2024, that standardizes how applications provide context and tools to large language models, using JSON-RPC 2.0 between a client and a server. Read: Building an MCP server
Shamir's Secret Sharing
A cryptographic scheme that splits a secret into n shares so that any k of them can rebuild it, while k-1 shares reveal nothing about it. Read: Breaking bad habits with Shamir's Secret Sharing
git bisect
A Git command that binary-searches your commit history, asking you to mark commits good or bad, to find the exact commit that introduced a bug. Read: Git bisect
Pi-hole
A network-level DNS sinkhole, typically run on a Raspberry Pi, that blocks ads and unwanted domains for every device on your network. Read: Ad blocker for your whole network
Steganography
The practice of concealing a message inside another medium, such as text, an image, audio, video or network traffic, so that the existence of the message is hidden. Read: Steganography
SO_REUSEADDR
A socket option that lets a process bind to an address and port that is still in use in certain states. It is why Docker can appear to bind a port already used by a host process. Read: Port sharing and SO_REUSEADDR in Docker
Selenium WebDriver
A browser automation library that controls a real browser from code, used for testing and for automating repetitive web tasks. Read: Web automation with Selenium
ngrok
A tunneling service that exposes a local or home-network service, such as a Raspberry Pi web interface or SSH, to the internet through a public URL. Read: Access a Raspberry Pi with ngrok
ffmpeg.wasm
FFmpeg compiled to WebAssembly so video and audio can be converted directly in the browser without uploading files to a server. Read: Convert video to GIF with FFmpeg