HULAHO

LiMiT · Deterministic workspace

Software reference notes

10 concise reference notes for software. These are public reference material, not private user records or a transfer of language-model weights.

Authentication and authorization

Authentication establishes an identity or possession of a credential. Authorization decides which operations and resources that identity may access. An authenticated user must still be checked against the owner of each private resource.

Authored reference note; not externally verified product advice · ref-031

Idempotent operations

An idempotent operation has the same intended effect when applied repeatedly as when applied once. This property is useful when retries can happen. It does not mean every response byte or timestamp must be identical.

Authored reference note; not externally verified product advice · ref-032

Transactions

A transaction groups related storage changes so they can commit together or roll back together. Define the boundary around the state that must remain consistent. External side effects need separate coordination because a database rollback cannot unsend a message.

Authored reference note; not externally verified product advice · ref-033

Validation boundaries

Validate type, size, range, allowed keys and semantic constraints at trusted execution boundaries. A well-formed JSON object can still contain an invalid operation or another users resource identifier. Syntax validation is only one layer.

Authored reference note; not externally verified product advice · ref-034

Typed composition

A reusable function should declare its inputs and outputs. Connect steps using explicit references and reject missing, forward or incompatible references. Composition becomes easier to inspect when each step has a narrow contract.

Authored reference note; not externally verified product advice · ref-035

Version pinning

Pin a dependency version when changing that dependency could change the meaning of a stored function. Keep the previous version available for reproducibility. Updating a version pointer is different from rewriting the older definition.

Authored reference note; not externally verified product advice · ref-036

Regression tests

A regression test records behavior that must continue working after a change. Include the original failing case when fixing a bug. Tests that only mirror implementation details may pass while the user-visible requirement remains broken.

Authored reference note; not externally verified product advice · ref-037

Integration versus unit tests

Unit tests isolate components. Integration tests verify interactions among components. Browser or end-to-end tests exercise representative user flows. A passing result at one level does not replace checks at other failure boundaries.

Authored reference note; not externally verified product advice · ref-038

Observability signals

Latency, traffic, errors and saturation provide complementary views of service behavior. Measure the user-visible path as well as internal components. One healthy process metric does not establish that users can complete their tasks.

Primary-source summary · ref-039

Primary reference: sre.google

Bounded resource use

Limit request sizes, storage, concurrency, recursion and computational search. Reject or truncate work explicitly when a bound is reached. Report a search limit as incomplete work rather than treating it as proof that no solution exists.

Authored reference note; not externally verified product advice · ref-040

In chat, use knowledge: topic. Browse all reference topics.