Under Construction

The Blog

Insights, tutorials, and stories from the world of software development.

Join my community?Contact to join
Unity
Mar 25, 2026

Unity Addressables

This article introduces Unity Addressables from basic to advanced, explaining how it differs from Resources and AssetBundles for lazy loading, async loading, memory management, and content updates. It covers key concepts like Address, AssetReference, Label, Group, and Profile, then walks through setup, loading, instantiation, reference counting, label-based loading, Play Mode Scripts, remote/CDN updates, and best practices to avoid duplicate bundles and improve performance.

Minh Khoa
15 min
209
26
Backend
Mar 1, 2026

Distinguishing API Gateway, Load Balancer, and Reverse Proxy

This article explains the differences between Reverse Proxy, Load Balancer, and API Gateway, which are easy to confuse because all sit between clients and backend servers. It shows how a Reverse Proxy hides backend servers and can handle SSL/TLS termination, caching, security headers, compression, and URL rewriting; how a Load Balancer distributes traffic across multiple backend instances using L4 or L7 approaches, common balancing algorithms, health checks, and sticky sessions; and how an API Gateway becomes a single entry point for microservices, handling authentication, authorization, rate limiting, request/response transformation, API aggregation, circuit breaking, service discovery, logging, monitoring, and versioning. The post also compares the three roles directly, gives real-world deployment patterns, and offers practical advice for choosing and combining them in backend architectures.

Minh Khoa
30 min
244
20
Backend
Mar 1, 2026

Distinguishing Authentication (Authentication) and Authorization (Authorization)

This article explains the difference between Authentication (AuthN) and Authorization (AuthZ) in backend security. It defines AuthN as identifying who a user is and AuthZ as checking what they are allowed to do, then walks through common authentication methods like Basic Auth, session-based auth, token-based auth with JWT, and SSO using SAML, OAuth2, and OpenID Connect. It also covers authorization models such as RBAC, ABAC, and ACL, compares AuthN and AuthZ in a summary table, and shows how they are typically split across an API Gateway and microservices in a modern system, including practical notes on JWT revocation with short-lived access tokens, refresh tokens, and Redis blacklists.

Minh Khoa
15 min
162
43
Tool
Feb 25, 2026

Trufflehog

This article introduces TruffleHog, an open-source tool for finding and handling exposed secrets such as API keys, database passwords, private keys, and tokens. It explains how TruffleHog discovers secrets across Git history, filesystems, Docker containers, S3, CI logs, chat, and wikis; classifies more than 800 secret types; validates findings by testing them; and analyzes common secrets with API lookups. The post also covers scanning Git repositories and AWS S3, and shows how to read results such as Verified: false versus Verified: true, including when to revoke, delete from Git history, and rotate credentials.

Minh Khoa
15 min
141
32
AWS
Feb 25, 2026

Self-Study AWS SAA-C03?

This post introduces a self-built website for studying AWS SAA-C03. The author explains how it organizes lessons into 23 chapters covering fundamentals, IAM, EC2, S3, VPC, RDS, Route 53, serverless, containers, security and encryption, plus decision trees, architecture patterns, service comparisons, and a practice exam. It also supports both English and Vietnamese, uses a simple responsive interface with sidebar navigation, and is meant to help learners study AWS in one place.

Minh Khoa
888 min
203
54
Unity
Feb 23, 2026

Boxing in Unity

This article explains boxing and unboxing in C#, showing how a value type such as int, float, bool, or struct is wrapped into an object on the heap, and why that matters in Unity. It describes how boxing creates memory allocations that lead to GC pressure, spikes, and FPS drops, especially in update loops, and notes that boxing can happen implicitly through Debug.Log, interface calls on structs, generic misuse, LINQ, foreach over struct enumerators, event arguments, and List<object>. The post then gives practical ways to avoid boxing, such as not storing value types in object, using generics instead of interfaces when possible, casting to string for Debug.Log, using struct-friendly systems like ECS and Burst, and watching for GC Alloc in the Unity Profiler or Deep Profile. It ends with a simple summary: boxing turns a struct into an object, creates garbage, triggers GC, and should be avoided in performance-critical Unity code.

Minh Khoa
15 min
192
50
Previous
Page 8 of 9
Next