- Knowledge
- technology
- OOP
- Tips
- Programming
- Tips
- Tutorial
- SEO
- Ranking
- Knowledge
- Special Day
- Seo
- Bug
- Data science
- Seo
- artificial intelligence
- Machine Learning
- Robotics
- happyNewYear2021
- newYearEve
- 2021
- Automation
- Smart Home
- Career
- Best Practices
- Git
- Logging
- Web Fundamentals
- DNS
- HTTPS
- Performance
- AI Tools
- ChatGPT
- Claude
- Gemini
- Laravel
- Eloquent
- MySQL
- HTTPS
- TLS
- Web Security
- Certificates
- Developer Life
- Debugging
- Docker
- DevOps
- Transactions
- Queues
- LLMs
- AI
- AI Coding
- Developer Tools
- React Native
- Expo
- Kate PMS
- Mobile Apps
- Laravel
- Authentication
- Sanctum
- Cookies
- API Design
- Payments
- Idempotency
- DeepSeek
- Open Source AI
- LLMs
- AI News
- Git
- Version Control
- AI Coding
- Prompting
- PHP
- Checklist
- MCP
- AI Agents
- OpenAI
- Architecture
- Microservices
- Modular Monolith
- Estimation
- Developer Life
- Project Planning
- Humour
- OAuth
- OpenID Connect
- Authentication
- Embeddings
- Vector Search
- RAG
- pgvector
- OpenAI
- GPT-4.1
- Codex CLI
- Events
- Testing
- Clean Code
- Maintainability
- Code Review
- Webhooks
- API
- Security
- Claude Code
- Workflow
- AI
- LLM
- Prompt Injection
- Mobile
- React
- Networking
- TCP
- UDP
- HTTP/3
- CLAUDE.md
- AWS
- Cloud Security
- Backups
- PHPUnit
- Software Engineering
- Leadership
- Communication
- RAG
- Embeddings
- AI Engineering
- IT Infrastructure
- Networking
- Access Control
- CI/CD
- GitHub Actions
- Gemini CLI
- Claude Code
- JavaScript
- Async/Await
- Node.js
- Promises
- Security
- Cryptography
- Passwords
- MySQL
- Database
- Vibe Coding
- Software Quality
- DNS
- Code Reading
- Onboarding
- Productivity
- Background Jobs
- Developer Humour
- Estimates
- Dev Life
- JWT
- o3-mini
- DeepSeek R1
- Rate Limiting
- Kate PMS
- E-Signing
- Audit Trail
- REST
- GraphQL
- API Design
- Laravel 12
- Upgrade Guide
- Open Source
- Self-Hosting
- Task Scheduling
- Cron
- Secrets
- CORS
- PHP
- PHP-FPM
- OPcache
- GitHub Copilot
- Software Architecture
- Engineering
- TypeScript
- JavaScript
- Type Safety
- AI Security
- React Native
- Product Design
- AI Agents
- Kiro
- Queues
- Redis
- RabbitMQ
- AWS SQS
- Nginx
- Apache
- GPT-5
- gpt-oss
- Clean Code
- Architecture
- Naming
- Documentation
- Career
- ADR
- Teamwork
- Supply Chain
- Kate HRM
- HR Software
- Permissions
- System Design
- Pagination
- SSH
- Linux
- Big O
- Databases
- Laravel Boost
- MCP
- Developer Skills
- Validation
- Databases
- Indexes
- Code Quality
- Deployment
- Developer Humour
- Feature Flags
- Code Review
- Pull Requests
- Docker
- Cursor
- Authorization
- RBAC
- Gemini
- Long Context
- PHP 8.4
- Caching
- Dependency Injection
- Web Performance
- Browser
- CSS
- Database
- Migrations
- ChatGPT
- AI for Developers
- Monitoring
- On-Call
- REST
- Backend
- SQL
- NoSQL
- Database Design
- Coding Agents
- Claude 4
- API Resources
- REST API
- Load Balancing
- Scaling
- AWS
- AI Tools
- Claude
- Sora 2
- CTE
- 2FA
- TOTP
- Programming Languages
- Prompts
- Developer Workflow
- API Gateway
- APIs
- Passport
- API Auth
- Learning
- Burnout
- Developer Growth
- Web Development
- SEO
- Kate Mall
- ChatGPT Atlas
- Agent Skills
- Middleware
- Laravel 12
- Collections
- Context Window
- Monitoring
- Commit Messages
- Self Review
- Growth
- Regex
- Programming Basics
- Text Processing
- Database Design
- Normalization
- Linux
- Server Security
- Linux Foundation
- Open Standards
- Legacy Code
- Documentation
- AI Workflow
- File Uploads
- Test Data
- Hashing
- Performance
- Caching
- Enums
- Scope Creep
- Estimation
- Codex
- Gemini CLI
- Timezones
- Carbon
- Bugs
- PHP 8.5
- Gemini 3
- GPT-5.1
- Data Integrity
- Event Loop
- Async
- Opus 4.5
- AI Models
- React
- Forms
- Frontend
- Backups
- AI Images
- DALL-E
- Midjourney
- Race Conditions
- Concurrency
- Legacy Code
- Refactoring
- Senior Engineer
- Scope
- LLM
- CDN
- Web
- Sub-Agents
- Soft Deletes
- Audit Log
- Concurrency
- AI Learning
- NestJS
- AI Evals
- Policies
- SPF DKIM DMARC
- Unicode
- UTF-8
- Knowledge Graph
- Value Objects
- Technical Debt
- Feature Flags
- Laravel Pennant
- Deployment
- Copilot
- Composer
- Dependencies
- Artisan
- Automation
- AWS S3
- Object Storage
- Cloud
- Small Language Models
- Ollama
- Production
- Sessions
- HTTP
- Mentoring
- SQL
- Virtual Machines
- Web Development
- HTTP/2
- QUIC
- Web Performance
- AI Integration
- LLM API
- SOLID
- OOP
- Hosting
- Serverless
- Merge Conflicts
- Temperature
- AI Development
- Reverse Proxy
- Nginx
- Infrastructure
- Verification
- Passkeys
- WebAuthn
- Teams
- Communication
- Stakeholders
- Monorepo
- CI/CD
- Versioning
- JSON Schema
- Livewire
- Inertia
- Meetings
- Distributed Systems
- Privacy
- Full-Stack
- T-Shaped Skills
- Money
- Notifications
- Web Security
- HTTP Headers
- CSP
- Function Calling
- Load Testing
- k6
- Data Extraction
- Debugging
- WebSockets
- SSE
- Real-Time
- Laravel Reverb
- Infrastructure as Code
- Terraform
- Side Projects
- Laravel Pint
- OpenAPI
- Swagger
- UX
- Multimodal
- Jest
- Pair Programming
- APIs
- Rate Limiting
- Resilience
- Dev Humour
- Design Tokens
- JWT
- API Keys
- Sessions
- PHPStan
- Rector
- Incidents
- Reporting
- Dashboards
- Zero Trust
- IAM
- Search
- Laravel Scout
- Junior Developers
- Mentoring
- Images
- WebP
- AVIF
- Bug Reports
- Let's Encrypt
- Design Docs
- Software Design
- Observers
- Replication
- Accountability
- Data Structures
- Reliability
- LLM Memory
- Error Handling
- Payments
- Payment Gateway
- Webhooks
- PCI DSS
- Observability
- OpenTelemetry
- Personal Brand
- Writing
- Conventions
- Dates
- Scheduling
- Disaster Recovery
- Compression
- Brotli
- Deadlines
- Developer Habits
- State Machines
- Tech Roles
- UUID
- ULID
- Horizon
- Planning
- Engineering Culture
- Ownership
- Soft Skills
- Socialite
- Cost Control
- Collations
- Unicode
- Octane
- PostgreSQL
What Managing a Company's IT Infrastructure Taught Me as a Developer
About Post
Developers love to say "it's not a code problem, it's an infrastructure problem", and then hand it to someone else.
At Kate, alongside building our software, I also look after the company's IT infrastructure: networking, hardware, and making all the pieces of hardware and software work together. So when it's an infrastructure problem, it still lands on my desk.
That's been one of the most useful things I've done as a developer. It changed how I write software, how I think about failure, and how I explain technical problems to people who just want things to work. Here are the lessons that stuck.
Lesson 1: the network is a real thing, not a cloud icon
As a web developer, the network is mostly invisible. You call an API, it answers. When you're responsible for the network itself, you learn what's behind that abstraction: switches, cabling, Wi-Fi coverage, DHCP, DNS, firewalls and internet links that occasionally decide to have a bad day.
The biggest change for me was how I debug. Instead of "the app is slow", I now ask: slow for whom, from where, on which connection? Is DNS resolving? Is it one floor, one device, one network segment, or everyone? A clear picture of the path from the user's device to the server turns a vague complaint into a short list of suspects.
It also made me a more defensive developer. Code that assumes the network is always fast and always there is code that will eventually let a user down. Timeouts, retries and clear error messages stopped being nice-to-haves.
Lesson 2: integration is where the surprises live
Inside an application, you control the code on both sides of every function call. Integrating hardware and software is different. A device has its own firmware, its own protocol and its own idea of how things should work, and you can't open a pull request against it.
What helps:
- Read the manual first, and test with the real device early. The spec and the behaviour are not always the same thing.
- Put a thin layer in between. Same rule as with any third-party API: wrap it, so that when the vendor or model changes, one piece of your system changes, not all of it.
- Plan for the device being offline. Buffer, retry and log, so a temporary disconnect doesn't turn into lost data.
Lesson 3: if it isn't written down, it doesn't exist
This is the lesson I'd put on a poster. Infrastructure is full of facts that live in one person's head: which port goes where, which device has a fixed IP, which licence renews when, which setting you changed to make the printer behave.
Memory is a terrible database. Now I document as I go, not afterwards:
- A network map and a simple IP plan, kept current.
- An inventory of hardware and software, with owners, warranties and renewal dates.
- Short runbooks for common tasks: setting up a new staff laptop, adding a user, restoring a file.
- A change log. "What changed recently?" is the first question in almost every incident.
The test is simple: could someone else handle the common problems on a day I'm not there? If not, the documentation isn't done. That's also, by the way, exactly the same test I apply to a codebase's README.
Lesson 4: backups are a promise you must test
Every organisation "has backups". The real question is whether you can restore from them, how long it takes, and how much you'd lose.
The rule I follow is the classic 3-2-1: three copies of important data, on two different kinds of storage, with one copy off-site. Then I add the step people skip: actually restore something, regularly. A file, a mailbox, a database. Untested backups have a way of failing on the one day they matter.
This carries straight into software. Whenever I design a system now, I think about recovery from the start: what is the source of truth, what can be rebuilt, and what can't?
Lesson 5: access control is mostly about people, not technology
The technical side of access control is well understood: individual accounts, strong passwords, multi-factor authentication, least privilege. The hard part is the human lifecycle around it.
- Joiners: people should get the access their role needs, not a copy of whatever the last person had.
- Movers: when someone changes roles, remove the old access, not just add the new.
- Leavers: a clear offboarding checklist, done on the last day, every time.
- Shared accounts: avoid them, and where you can't, use a password manager instead of a spreadsheet.
It's the same thinking that goes into role-based access in the software we build, like Kate PMS. The difference is that in infrastructure, nobody writes a test that fails when an old account is still active. You have to make the review a habit.
Lesson 6: change one thing at a time
When something breaks, the temptation is to try five fixes at once. Restart the router, update the driver, change the setting, swap the cable. If it starts working, you don't know which one fixed it, and you've possibly broken something else along the way.
Debugging infrastructure taught me the discipline that also makes code debugging faster: form a guess, change one thing, observe, write down the result. Slow is smooth, and smooth is fast.
What I'd tell any developer: spend some time on the infrastructure side if you get the chance. You'll write more resilient code, debug faster, and understand why "it works on my machine" was never the end of the story.
The short version
- Know the path from the user's device to your server.
- Wrap every integration, and plan for it being offline.
- Document as you go; test it by asking "could someone else do this?"
- 3-2-1 backups, and restore something regularly.
- Access control is a lifecycle: joiners, movers, leavers.
- Change one thing at a time, and write down what you did.
Have you ever had to wear the IT hat alongside the developer one? What did it teach you that code never did?

Be first to comment it...