Software & AI Engineering Concepts Author: Saad Ahmed https://concepts.saad.run/ Algorithms and data structures - Big O - Big Theta - Big Omega - amortized analysis - Arrays - linked lists - stacks - queues - deques - ring buffers - Hash maps - hash sets - collision resolution - load factor - Heaps - priority queues - balanced search trees - tries - B-trees - B+ trees - LSM trees - skip lists - Binary search - two pointers - sliding window - prefix sums - difference arrays - Recursion - backtracking - divide and conquer - greedy algorithms - dynamic programming - BFS - DFS - topological sorting - cycle detection - strongly connected components - Shortest paths - minimum spanning trees - union-find - Segment trees - Fenwick trees - interval trees - Bloom filters - Count-Min Sketch - HyperLogLog - reservoir sampling - Consistent hashing - rendezvous hashing - sorting stability Languages and runtimes - Static typing - dynamic typing - structural typing - nominal typing - Generics - variance - subtyping - type inference - Algebraic data types - discriminated unions - exhaustive matching - nullable types - Value semantics - reference semantics - aliasing - immutability - Closures - lexical scope - ownership - borrowing - lifetimes - Compilation - interpretation - bytecode - JIT - AOT - deoptimization - Stack allocation - heap allocation - garbage collection - reference counting - Memory leaks - object pooling - resource cleanup - deterministic destruction - Exceptions - error values - typed errors - exception boundaries - ABI - FFI - reflection - metaprogramming - undefined behavior Operating systems and hardware - Processes - threads - scheduling - context switches - CPU affinity - System calls - interrupts - signals - interprocess communication - Virtual memory - page tables - page faults - mmap - swapping - File descriptors - sockets - pipes - shared memory - Blocking I/O - nonblocking I/O - asynchronous I/O - epoll - kqueue - CPU caches - cache lines - locality - cache coherence - false sharing - NUMA - SIMD - vectorization - Filesystems - journaling - buffering - fsync - atomic rename - Namespaces - cgroups - resource limits - OOM termination - Wall clocks - monotonic clocks - clock drift - clock precision Concurrency and parallelism - Concurrency - parallelism - CPU-bound work - I/O-bound work - Threads - processes - coroutines - futures - promises - event loops - Race conditions - data races - atomicity - visibility - ordering - Mutexes - semaphores - condition variables - read-write locks - barriers - Deadlock - livelock - starvation - priority inversion - Compare-and-swap - memory barriers - happens-before - Lock-free - wait-free - ABA problem - Thread pools - bounded queues - work stealing - executor saturation - Structured concurrency - cancellation propagation - task supervision - Actor model - channels - message passing - backpressure Networking and protocols - IP - TCP - UDP - QUIC - TCP handshake - retransmission - congestion control - flow control - keepalive - DNS - recursive resolution - TTL - negative caching - TLS - certificate chains - hostname verification - mutual TLS - HTTP/1.1 - HTTP/2 - HTTP/3 - head-of-line blocking - Connection pooling - connection reuse - proxies - NAT - load balancing - HTTP methods - status codes - headers - content negotiation - compression - Cookies - sessions - CORS - same-origin policy - WebSockets - SSE - polling - long polling - Connection timeout - read timeout - idle timeout - deadlines - jitter Code design and maintainability - Cohesion - coupling - encapsulation - information hiding - SOLID - DRY - KISS - YAGNI - separation of concerns - Dependency inversion - dependency injection - composition - inheritance - Pure functions - side effects - referential transparency - Design by contract - invariants - preconditions - postconditions - Strategy - factory - builder - adapter - decorator - facade - Observer - command - state pattern - Code smells - refactoring - technical debt - complexity budgets - Error taxonomy - domain errors - exception boundaries - Public interfaces - dependency cycles - static analysis - code review Architecture and domain modeling - Monolith - modular monolith - microservices - service-oriented architecture - Layered architecture - hexagonal architecture - clean architecture - Event-driven architecture - message-driven architecture - serverless - Bounded contexts - ubiquitous language - context mapping - Entities - value objects - aggregates - aggregate invariants - Repositories - domain services - ports and adapters - Domain events - integration events - anti-corruption layers - CQRS - event sourcing - projections - snapshots - replay - ADRs - RFCs - architecture fitness functions - Strangler migration - branch by abstraction - evolutionary architecture APIs and integrations - REST - RPC - gRPC - GraphQL - Resource modeling - schema validation - API contracts - Safe methods - idempotency - idempotency keys - deduplication - Offset pagination - cursor pagination - keyset pagination - Filtering - sorting - partial updates - bulk operations - Versioning - backward compatibility - deprecation - schema evolution - OpenAPI - Protocol Buffers - serialization compatibility - Authentication - authorization - API scopes - Webhook signatures - replay protection - delivery retries - Long-running operations - job handles - consumer-driven contracts Rate limiting and admission control - Fixed-window counter - boundary bursts - Sliding-window log - Sliding-window counter - weighted-window approximation - Token bucket - burst capacity - refill rate - Leaky bucket - GCRA - Per-IP limits - per-user limits - per-tenant limits - hierarchical quotas - Weighted requests - concurrency limits - admission control - Distributed counters - Redis Lua - atomic updates - quota leasing - Clock skew - TTL - hot keys - fail-open - fail-closed - HTTP 429 - Retry-After - load shedding - adaptive concurrency Caching - Cache-aside - read-through - write-through - write-behind - TTL - expiration - eviction - invalidation - LRU - LFU - FIFO - admission policy - Stale-while-revalidate - stale-if-error - negative caching - Cache stampede - dogpile effect - single-flight - request coalescing - TTL jitter - probabilistic early refresh - Cache penetration - cache avalanche - hot keys - Local cache - distributed cache - multilevel cache - coherence - Versioned keys - tenant-aware keys - cache poisoning - CDN - Vary - ETag - conditional requests - cache hit ratio Relational databases and SQL - Keys - constraints - referential integrity - functional dependencies - Normalization - denormalization - Joins - subqueries - CTEs - recursive queries - SQL window functions - Composite indexes - covering indexes - partial indexes - expression indexes - Selectivity - index column order - sargability - Query planner - statistics - cardinality estimation - EXPLAIN - Sequential scan - index scan - nested-loop join - hash join - merge join - N+1 queries - batching - prepared statements - connection pooling - Partitioning - materialized views - generated columns - Vacuum - table bloat - index bloat - online migrations - backfills Transactions and concurrency control - ACID - transaction boundaries - autocommit - Read committed - repeatable read - serializable - Dirty read - nonrepeatable read - phantom read - Lost update - write skew - serialization anomaly - MVCC - snapshot isolation - serializable snapshot isolation - Optimistic concurrency - pessimistic concurrency - version columns - Row locks - table locks - advisory locks - predicate locks - Deadlock detection - lock ordering - lock timeout - Compare-and-set - transaction retries - retry-safe operations - WAL - crash recovery - two-phase locking - two-phase commit Nonrelational databases and search - Key-value stores - document databases - wide-column stores - graph databases - Time-series databases - object storage - blob storage - Partition keys - sort keys - access-pattern-driven modeling - Secondary indexes - sparse indexes - global indexes - local indexes - Read amplification - write amplification - compaction - tombstones - Inverted index - analyzers - tokenization - stemming - BM25 - faceting - fuzzy matching - full-text search - Graph traversal - graph query languages - Retention - downsampling - rollups - Vector databases - approximate nearest neighbors Distributed systems - Partial failure - failure detection - network partitions - Replication - sharding - rebalancing - Leader-follower - multi-leader - leaderless replication - Synchronous replication - asynchronous replication - replication lag - Strong consistency - eventual consistency - causal consistency - Linearizability - sequential consistency - serializability - Read-your-writes - monotonic reads - consistent-prefix reads - CAP - PACELC - quorum reads - quorum writes - Raft - Paxos - consensus - leader election - Split-brain - leases - distributed locks - fencing tokens - Lamport clocks - vector clocks - clock skew - CRDTs - conflict resolution - last-write-wins - Anti-entropy - read repair - hinted handoff - gossip - Consistent hashing - virtual nodes - hot partitions - Byzantine faults Messaging and durable workflows - Queues - publish-subscribe - event streams - Producers - consumers - consumer groups - partitions - offsets - At-most-once - at-least-once - exactly-once semantics - Acknowledgments - visibility timeouts - redelivery - Exponential backoff - jitter - retry budgets - Dead-letter queues - poison messages - Idempotent consumers - deduplication - inbox pattern - Transactional outbox - CDC - Sagas - compensation - orchestration - choreography - Delayed jobs - scheduled jobs - durable execution - checkpointing - Replay - retention - schema registry - event versioning - Consumer lag - backpressure - queue growth - cancellation Data engineering - ETL - ELT - batch processing - stream processing - Event time - processing time - watermarks - late events - Tumbling windows - hopping windows - sliding windows - session windows - Stateful processing - stream joins - checkpoints - Data warehouse - data lake - lakehouse - OLTP - OLAP - Columnar storage - Parquet - Avro - ORC - compression - Star schema - snowflake schema - dimensional modeling - Slowly changing dimensions - Data contracts - schema evolution - lineage - catalogs - Freshness - completeness - reconciliation - backfills - incremental processing Reliability and resilience - Availability - reliability - durability - fault tolerance - SLI - SLO - SLA - error budget - Fault domains - blast radius - redundancy - Circuit breaker - bulkhead - graceful degradation - Retry amplification - cascading failure - thundering herd - Timeouts - deadline propagation - cancellation - Liveness - readiness - startup checks - Failover - failback - regional evacuation - Disaster recovery - RPO - RTO - restore drills - Chaos engineering - fault injection - overload protection - On-call - runbooks - incident response - postmortems - toil Observability and debugging - Logs - metrics - traces - profiles - Structured logs - correlation IDs - trace context - Spans - distributed tracing - context propagation - Counters - gauges - histograms - summaries - RED method - USE method - golden signals - p50 - p95 - p99 - tail latency - Cardinality - sampling - exemplars - Head sampling - tail sampling - Burn-rate alerts - actionable alerts - alert fatigue - CPU profiles - heap profiles - lock profiles - flame graphs - Thread dumps - core dumps - query tracing - hypothesis testing Performance and capacity - Latency - throughput - utilization - saturation - Tail latency - fan-out amplification - stragglers - Little’s Law - queueing theory - queue stability - Amdahl’s Law - scalability limits - Load testing - stress testing - soak testing - spike testing - Open-loop load - closed-loop load - coordinated omission - Warmup - cold starts - benchmark bias - Batching - pipelining - parallelism - Connection pools - thread pools - memory pressure - GC pauses - Vertical scaling - horizontal scaling - autoscaling lag - headroom - Cost per request - cost per tenant - capacity forecasts Security and privacy - Threat modeling - attack surface - trust boundary - Least privilege - defense in depth - zero trust - Authentication - authorization - accounting - RBAC - ABAC - ReBAC - OAuth 2.0 - OpenID Connect - PKCE - Sessions - JWT - refresh tokens - revocation - CSRF - XSS - SQL injection - command injection - SSRF - path traversal - insecure deserialization - IDOR - BOLA - Password hashing - salts - key derivation - TLS - encryption at rest - envelope encryption - key rotation - Secrets management - certificate rotation - workload identity - Tenant isolation - row-level security - audit trails - Data minimization - pseudonymization - anonymization - re-identification - SBOM - dependency vulnerabilities - artifact signing - sandboxing Infrastructure and cloud - Virtual machines - containers - image layers - registries - Infrastructure as code - immutable infrastructure - drift detection - Pods - deployments - services - ingress - scheduling - Requests and limits - autoscaling - StatefulSets - persistent volumes - Service mesh - sidecars - service discovery - VPC - subnets - routing - security groups - IAM - workload identity - short-lived credentials - Managed databases - object storage - managed queues - Multi-zone - multi-region - spot capacity - reserved capacity - Configuration management - secret injection - environment parity - FinOps - egress costs - resource tagging Testing and delivery - Unit tests - integration tests - component tests - end-to-end tests - Contract tests - property-based tests - fuzzing - Mutation testing - differential testing - Deterministic tests - flaky tests - test isolation - Mocks - stubs - fakes - test doubles - Test pyramid - risk-based testing - CI/CD - artifact promotion - reproducible builds - hermetic builds - Feature flags - canary release - blue-green deployment - rolling deployment - Rollback - roll-forward - schema compatibility - Trunk-based development - GitHub flow - release gates - Supply-chain security - release observability Frontend and client engineering - DOM - CSSOM - layout - paint - compositing - Event loop - tasks - microtasks - Client state - server state - URL state - Optimistic updates - rollback - cache invalidation - CSR - SSR - SSG - hydration - streaming rendering - Progressive enhancement - code splitting - tree shaking - lazy loading - Virtualization - memoization - render profiling - Accessibility - semantic HTML - keyboard navigation - Core Web Vitals - performance budgets - IndexedDB - local storage - session storage - service workers - Offline synchronization - responsive design - design systems - CSP - internationalization - localization - timezones SaaS and business workflows - Multi-tenancy - tenant provisioning - tenant isolation - Shared database - separate schemas - separate databases - Entitlements - subscriptions - usage metering - Payment idempotency - billing reconciliation - Money precision - currency - rounding - Order state machines - payment state machines - approval workflows - Audit trails - immutable financial records - Notifications - delivery preferences - deduplication - Temporal modeling - effective dates - timezone boundaries - Data export - deletion - retention - Tenant configuration - SSO - provisioning - noisy-neighbor protection Distributed key-value stores and Redis - Distributed key-value store - Redis - Valkey - etcd - Redis strings - hashes - lists - sets - sorted sets - streams - bitmaps - HyperLogLog - Redis Cluster - hash slots - hash tags - MOVED - ASK - resharding - Redis replication - replication lag - asynchronous replication - Redis Sentinel - failover - RDB snapshots - AOF - appendfsync - AOF rewrite - persistence recovery - Redis TTL - lazy expiration - active expiration - maxmemory - eviction policy - MULTI/EXEC - WATCH - Lua scripts - Redis Functions - atomicity - Redis pipelining - transactions - connection pools - blocking commands - Redis Pub/Sub - Redis Streams - consumer groups - pending entries - XACK - XAUTOCLAIM - Hot keys - big keys - cache stampede - cluster imbalance - network partitions - Redis locks - lease expiry - fencing tokens - Redlock - lock safety assumptions - Linearizable KV reads - compare-and-swap - watches - leases - consensus-backed coordination Model behavior and API integration - Tokens - tokenization - input token budget - output token budget - context window - Model capabilities - modalities - capability detection - provider compatibility - Model selection - routing - fallback - escalation - version pinning - model migrations - Instruction hierarchy - instruction following - nondeterminism - reproducibility limits - Sampling - temperature - top-p - stop sequences - reasoning effort - inference budgets - Structured outputs - tool calls - final responses - refusals - truncation - Streaming events - partial responses - completion status - cancellation - Timeouts - retries - quotas - rate limits - ambiguous outcomes - Model confidence - factual correctness - knowledge cutoff - retrieved evidence Prompt engineering - System instructions - developer instructions - user requests - instruction precedence - Task framing - constraints - success criteria - ambiguity handling - Zero-shot prompting - few-shot prompting - example selection - negative examples - Delimiters - structured input - instruction-data separation - Task decomposition - staged prompting - prompt chaining - Output contracts - JSON schemas - formatting constraints - Grounding instructions - citation requirements - abstention - clarification - Prompt templates - variables - prompt versioning - prompt regression tests - Conflicting instructions - overconstraint - prompt brittleness - underspecification - Prompt optimization - evaluation flywheel - measured outcomes Context engineering - Context construction - context selection - relevance - authority - freshness - provenance - Context ordering - placement - token allocation - context budgets - Truncation - compression - compaction - conversation summarization - Selective history retrieval - just-in-time retrieval - progressive disclosure - Lost-in-the-middle - context pollution - stale context - contradictory evidence - User preferences - task instructions - task state - retrieved evidence - Tool-result filtering - result summarization - source attribution - Prompt caching - reusable prefixes - context reuse - Constraint preservation - context handoff - session continuation Knowledge-base ingestion - Source connectors - synchronization - change detection - incremental ingestion - Document parsing - OCR - layout extraction - tables - captions - images - Normalization - deduplication - ingestion validation - Document IDs - versions - stable chunk IDs - source URLs - Metadata extraction - source permissions - access-control metadata - Fixed-size chunking - recursive chunking - semantic chunking - structure-aware chunking - Chunk overlap - parent-child chunks - document hierarchy - Failed-ingestion recovery - dead-letter ingestion - backfills - Freshness - expiration - deletion propagation - data lineage Retrieval and RAG - RAG - dense retrieval - sparse retrieval - keyword search - embeddings - Embedding compatibility - cosine similarity - vector distance - normalization - ANN - HNSW - IVF - product quantization - index tuning - BM25 - hybrid search - reciprocal rank fusion - Metadata filtering - permission filtering - tenant-aware retrieval - Query rewriting - query expansion - query decomposition - multi-query retrieval - Bi-encoders - cross-encoders - reranking - Parent-document retrieval - hierarchical retrieval - graph-assisted retrieval - Deduplication - diversity - maximal marginal relevance - context packing - Recall@k - precision@k - MRR - nDCG - No-result behavior - insufficient evidence - retrieval freshness - Groundedness - faithfulness - citation attribution - citation verification - Embedding migrations - reindexing - retrieval poisoning Tools, function calling, and MCP - Tool discovery - tool selection - tool descriptions - tool granularity - Function calling - JSON schemas - typed arguments - argument validation - Typed outputs - structured errors - retryable errors - permanent errors - Read tools - write tools - synchronous tools - asynchronous tools - Parallel tool calls - dependency ordering - tool-call budgets - Timeouts - cancellation - pagination - result-size limits - Idempotency - deduplication - tool contract testing - Authorization - scoped credentials - dry runs - previews - audit trails - Tool-result sanitization - untrusted tool outputs - MCP tools - MCP resources - MCP prompts - capability negotiation - MCP transports - session lifecycle - protocol versioning - MCP authorization Agent loop engineering - Observe-decide-act loop - action-result feedback - next-action selection - Explicit task state - objectives - completion criteria - Stop conditions - maximum steps - token budgets - time budgets - cost budgets - Progress detection - repeated-action detection - stuck-loop detection - No-progress termination - partial completion - handoff - Replanning - recoverable failure - terminal failure - Retry policy - recovery policy - tool failure recovery - Checkpointing - resumability - durable state - Interruptibility - user steering - cancellation propagation - Context compaction - objective preservation - verified completion Agent harness and orchestration - Agent harness - workflow graph - state machine - Deterministic routing - model-selected routing - Planner-executor - supervisor-worker - router patterns - Handoffs - delegation - sequential execution - parallel execution - Dependency graphs - shared state - isolated state - Durable workflows - event-driven execution - long-running jobs - Checkpoints - replay - session lifecycle - Error boundaries - concurrency limits - resource isolation - Workspace management - artifact management - runtime policy enforcement Memory engineering - Working memory - session memory - persistent memory - Episodic memory - semantic memory - procedural memory - Explicit memories - inferred memories - user preferences - task-local instructions - Memory extraction - write policies - relevance - retrieval - Provenance - confidence - timestamps - Deduplication - conflict resolution - staleness - expiry - Forgetting - user correction - deletion propagation - Tenant isolation - user isolation - memory poisoning - Summaries - original evidence - cross-session consistency Planning, reasoning, and verification - Task decomposition - dependency-aware planning - replanning - Hypothesis generation - evidence gathering - external verification - Critique-revision loops - generator-verifier pattern - Correlated errors - independent verification - consistency checks - Constraint checking - source verification - executable checks - Tests - validators - database queries - artifact inspection - Abstention - confidence calibration - clarification - Plausibility - demonstrated correctness - completion evidence Actions and side-effect safety - Read-only actions - consequential actions - action previews - Human-in-the-loop - approvals - approval binding - Permission scope - delegation - least privilege - Idempotency keys - duplicate prevention - request identity - Ambiguous outcomes - reconciliation - read-after-write verification - Transaction boundaries - compensation - rollback - roll-forward - TOCTOU - optimistic concurrency - stale approvals - Auditability - action provenance - execution receipts Evaluation engineering - Representative datasets - production examples - golden datasets - Rubrics - golden answers - human annotation - inter-rater agreement - Component evaluation - end-to-end evaluation - task completion rate - Instruction adherence - retrieval relevance - groundedness - citation correctness - Tool-selection accuracy - argument correctness - unauthorized-action rate - Loop efficiency - unnecessary actions - recovery success - Deterministic graders - model graders - judge calibration - judge bias - Adversarial cases - slice analysis - regression suites - Repeated runs - stochastic variation - confidence intervals - Online experiments - shadow runs - canary evaluation - Quality-latency-cost tradeoffs - evaluation coverage LLM observability and debugging - Execution traces - model spans - tool spans - handoff traces - Prompt versions - context versions - retrieved-document IDs - Token usage - cost attribution - budget tracking - Time to first token - end-to-end latency - tool latency - Tool failures - loop counts - repeated actions - timeout rates - Error taxonomies - trace replay - production-to-eval datasets - Sensitive-data redaction - access-controlled telemetry - Prompt failures - context failures - retrieval failures - model failures - application failures LLM application security - Direct prompt injection - indirect prompt injection - tool-output injection - Instruction-data separation - trust boundaries - untrusted documents - Retrieval poisoning - memory poisoning - Secret leakage - data exfiltration - cross-tenant leakage - Excessive agency - privilege escalation - confused-deputy attacks - Malicious URLs - SSRF - generated command injection - Sandbox isolation - network egress controls - output validation - Approval bypass - tool supply chain - connector permissions - Jailbreaks - adversarial evaluation - policy enforcement LLM performance and cost - Input token cost - output token cost - reasoning budgets - Prompt caching - context reuse - reusable prefixes - Response caching - semantic caching - cache invalidation - tenant isolation - Model routing - small-model first pass - escalation - Batching - parallelization - streaming - Latency budgets - retrieval latency - tool latency - Provider quotas - backpressure - admission control - retry amplification - Cost per completed task - quality-adjusted cost - budget enforcement - Graceful degradation - cancellation - unnecessary tool calls - Prefill - decoding - KV cache - continuous batching - quantization LLM application UX - Streaming responses - progress updates - perceived latency - User interruption - user steering - cancellation - Clarification UX - preview-before-action - approval UX - Citations - source inspection - uncertainty communication - Editable plans - partial results - recoverable errors - Draft state - approved state - executed state - Session continuity - undo - correction - Accessibility - human handoff - trust calibration Multimodal application integration - Image inputs - document inputs - audio inputs - video frames - OCR quality - layout understanding - image grounding - Speech recognition - text-to-speech - speech-to-speech - Voice activity detection - diarization - turn detection - Streaming transcription - barge-in - interruption handling - Word error rate - transcription latency - audio buffering - Realtime sessions - transport selection - session recovery - Multimodal prompt injection - consent - media retention Technical strategy and architecture judgment - Problem framing - requirements discovery - functional requirements - quality attributes - Nonfunctional requirements - measurable constraints - tradeoff analysis - Decision-making under uncertainty - reversible decisions - irreversible decisions - Build-buy-partner - total cost of ownership - unit economics - Technical roadmaps - platform strategy - portfolio risk - Standardization - team autonomy - technology adoption - technology retirement - Migration sequencing - dependency management - technical debt prioritization - Operability - maintainability - architecture governance Organizational engineering - Cross-team interfaces - ownership boundaries - service ownership - Platform teams - product teams - enabling teams - Conway’s Law - cognitive load - developer experience - Influence without authority - mentoring - sponsorship - delegation - RFC review - design review - constructive disagreement - Stakeholder alignment - negotiation - risk communication - Engineering standards - exceptions - incident leadership - Delivery bottlenecks - outcome metrics - learning culture Principal-level applied AI judgment - AI suitability - deterministic workflows - probabilistic decisions - Workflow-versus-agent choice - automation boundaries - human accountability - Action severity - acceptable error rates - failure containment - Evaluation coverage - real-world coverage - launch criteria - Vendor dependency - portability - model upgrade strategy - Data rights - retention - provenance - audit evidence - Cost-quality-latency optimization - build-versus-buy - Shared AI platform - application-specific harness - operational ownership - Enforceable governance - policy-as-code - adoption strategy