Blog
Mert Özen's blog posts on software development, backend, frontend, and DevOps.
Performance, Optimization and Closing the Series: Where to Go From Here?
We close the series: the basic principles of performance, the most common bottlenecks (like the N+1 query), not optimizing without measuring, a recap of what we learned, and where to go next.
Deploying with CI/CD: Automating Test, Build and Deployment with GitHub Actions
We cover CI/CD: what continuous integration and continuous deployment mean, why an automated pipeline is needed, setting up a workflow with GitHub Actions, and automating test-build-deploy on every change.
Containerizing with Docker: Putting the Application into a Package That Runs the Same Everywhere
We cover containerizing the application with Docker: what a container is, how it solves the "it worked on my machine" problem, packaging a .NET app with a Dockerfile and multi-stage build.
Health Checks and Monitoring: Observing That the API Is Up and Healthy
We cover health checks and monitoring: automatically checking whether the application is healthy in production, observing dependencies like the database, the liveness/readiness distinction, and the basics of monitoring.
Caching: In-Memory and Distributed Cache with Redis
We cover caching: improving performance by temporarily storing frequently requested but rarely changing data, the difference between in-memory and Redis-based distributed cache, and cache consistency.
Integration Testing: Testing the API End to End with WebApplicationFactory
We cover integration testing: its difference from unit testing, what testing pieces together means, flowing a real request end to end with WebApplicationFactory, and using a separate test database.
Unit Testing: Testing Pieces of Code in Isolation with xUnit and Moq
We cover unit testing: what testing a unit in isolation means, why we write tests, the test structure with xUnit, faking dependencies with Moq, and the basic principles of writing good tests.
Documentation with Swagger/OpenAPI and Scalar: Make Your API Self-Describing
We cover API documentation: what OpenAPI is, why automatic documentation matters, OpenAPI support in .NET 9, and setting up interactive docs with Swagger UI and a modern alternative, Scalar.
CORS, Rate Limiting and Security Headers: Hardening the API Against External Threats
We cover three topics that harden the API against misuse: controlling which sites can access it with CORS, limiting requests with rate limiting, and adding basic protection with security headers.
Role- and Policy-Based Authorization: Deciding Who Is Allowed to Do What
We deepen authorization: what role-based permission is, where it falls short, how the policy and claim-based approach offers a more flexible solution, and how we set these up in .NET.
Authentication with JWT: How a Token Is Created and Verified
We cover authentication with JWT: what a token is, what its three parts mean, why it's signed, why the server is stateless, and setting up token creation and verification in .NET step by step.
Authentication and Authorization: The Difference Between Identity Verification and Permission
We separate two concepts most developers confuse: authentication (who are you?) and authorization (what are you allowed to do?). The difference, the correct order, and how these are positioned in .NET.