backenddrills

BackendDrills resources

Study paths for Java, engineers, leads and architects

Choose one main path. Spend about 30–45 minutes per session; repeat or split sessions when a concept is new. This is guided practice, not a promise to complete 1008 scenarios in two weeks.

14-session engineering core · 14 sessionsSoftware engineer · 14 sessionsJava backend engineer · 15 sessionsEngineering lead · 8 sessionsSoftware architect · 8 sessions

How to use every session

  1. Read the free guide and check its version assumptions.
  2. Write a prediction, then attempt the selected drill before viewing the debrief.
  3. Produce the stated test, diagram or review note in your own words.
  4. Revisit a weak explanation after a few sessions and apply it to another workload.

All plan outlines and readings are public. Three complete drills are free; full-edition links require verified access. Open the interactive plan to track completion in this browser →.

14-session engineering core · 14 sessions

Follow the sessions in order, then choose an optional path. A session can take more than one day; the goal is better reasoning, not finishing all 1008 drills in two weeks.

Prerequisite: Basic programming, HTTP and SQL. Java examples assume familiarity with Java syntax; use the free readings first when a concept is new.

  1. Session 1: Start with evidence and ownership

    Separate the symptom, the resource boundary and the property that must remain true.

    Produce: An evidence ledger: facts, one competing explanation and a test that would change your mind.

    Free reading: Diagnosing HikariCP connection pool exhaustion

  2. Session 2: Get values and Java 8 pipelines right

    Review numeric representation, stream lifetime and the difference between data and a computation over data.

    Produce: Two boundary tests: one for a decimal value and one for a reused pipeline.

    Free reading: Java 8 streams: lifetime, duplicate keys and safe collection

  3. Session 3: Trace Spring transaction boundaries

    Draw the entry point, proxy and commit boundary before choosing propagation or rollback behavior.

    Produce: A call-path sketch and a test that checks committed rows after failure.

    Free reading: Why Spring @Transactional fails on self-invocation

  4. Session 4: Protect SQL correctness and query shape

    Distinguish a concurrency invariant from a fetch-shape problem; choose the right evidence for each.

    Produce: One two-transaction test and one query-count or row-volume check.

    Free reading: SQL transactions: prove the invariant with two sessions

  5. Session 5: Define API outcomes, retries and deadlines

    Separate transport failure from a known business outcome and give every retry an identity and time budget.

    Produce: An API contract covering success, rejection, uncertain completion and retry.

    Free reading: API retries: identity, deadlines and uncertain outcomes

  6. Session 6: Build tests that can reject a bad change

    Test real transaction and failure windows rather than relying only on mocks or a successful response.

    Produce: A regression test plan with controlled concurrency and a response lost after commit.

    Free reading: Backend testing: target the failure window, not just the happy path

  7. Session 7: Checkpoint: explain before reopening the answer

    Revisit the database and API boundaries from memory. Consult the debrief only after writing your explanation.

    Produce: Two corrected explanations and one specific gap to revisit after several sessions.

    Free reading: Backend testing: target the failure window, not just the happy path

  8. Session 8: Budget concurrency and Java 21 resources

    Identify the executor, cancellation owner and scarce resource before changing the threading model.

    Produce: A resource budget and a cancellation test with an explicit Java version note.

    Free reading: Debugging Java 21 virtual-thread pinning

  9. Session 9: Make messaging and replay accountable

    Locate the gap between a durable business effect and acknowledgment; distinguish publishing from consuming.

    Produce: A failure-window diagram and a replay test that inspects authoritative effects.

    Free reading: Handling duplicate Kafka messages without duplicate business effects

  10. Session 10: Use caching and signals to recover safely

    Relate load, cache expiry and queueing to customer outcomes; avoid diagnosing from an average alone.

    Produce: A bounded load experiment with latency distribution, correctness and stop criteria.

    Free reading: Diagnosing HikariCP connection pool exhaustion

  11. Session 11: Enforce authorization across every path

    Distinguish login from permission to use a particular object, including cache-hit and direct API paths.

    Produce: A two-user negative-test matrix for reads, updates and cached responses.

    Free reading: API authorization: check owner, action and every access path

  12. Session 12: Review readiness, shutdown and rollout

    Treat process health, admission, draining and schema compatibility as different deployment contracts.

    Produce: A rollout checklist with in-flight work, drain deadline and rollback conditions.

    Free reading: Cloud rollouts: readiness, draining and compatible rollback

  13. Session 13: Choose code and service boundaries deliberately

    Use a pattern to separate a concrete responsibility, then check whether service boundaries provide useful ownership.

    Produce: A design note explaining the invariant, rejected alternative and the cost of the abstraction.

    Free reading: Design patterns in practice: responsibility, state and trade-offs

  14. Session 14: Capstone: capacity, consistency and recovery

    Connect workload assumptions, downstream demand and restore evidence; revisit one weak decision from the core path.

    Produce: A short architecture decision record with capacity assumptions, consistency needs, acceptance test and recovery gate.

    Free reading: System design: workload, consistency and recovery before diagrams

Software engineer · 14 sessions

A broad route through data, APIs, testing, web clients, concurrency, security, cloud and design. Java concurrency examples can be translated to your stack.

Prerequisite: Basic programming, HTTP and SQL; core session 1 if incident practice is new.

  1. Session 1: Start with evidence and ownership

    Separate the symptom, the resource boundary and the property that must remain true.

    Produce: An evidence ledger: facts, one competing explanation and a test that would change your mind.

    Free reading: Diagnosing HikariCP connection pool exhaustion

  2. Session 2: Protect SQL correctness and query shape

    Distinguish a concurrency invariant from a fetch-shape problem; choose the right evidence for each.

    Produce: One two-transaction test and one query-count or row-volume check.

    Free reading: SQL transactions: prove the invariant with two sessions

  3. Session 3: Define API outcomes, retries and deadlines

    Separate transport failure from a known business outcome and give every retry an identity and time budget.

    Produce: An API contract covering success, rejection, uncertain completion and retry.

    Free reading: API retries: identity, deadlines and uncertain outcomes

  4. Session 4: Web/client integration

    Keep request identity and permission consistent between browser and API.

    Produce: A client state diagram covering stale responses and uncertain write outcomes.

    Free reading: Browser request races: stale reads and uncertain submits

  5. Session 5: Build tests that can reject a bad change

    Test real transaction and failure windows rather than relying only on mocks or a successful response.

    Produce: A regression test plan with controlled concurrency and a response lost after commit.

    Free reading: Backend testing: target the failure window, not just the happy path

  6. Session 6: Budget concurrency and Java 21 resources

    Identify the executor, cancellation owner and scarce resource before changing the threading model.

    Produce: A resource budget and a cancellation test with an explicit Java version note.

    Free reading: Debugging Java 21 virtual-thread pinning

  7. Session 7: Make messaging and replay accountable

    Locate the gap between a durable business effect and acknowledgment; distinguish publishing from consuming.

    Produce: A failure-window diagram and a replay test that inspects authoritative effects.

    Free reading: Handling duplicate Kafka messages without duplicate business effects

  8. Session 8: Use caching and signals to recover safely

    Relate load, cache expiry and queueing to customer outcomes; avoid diagnosing from an average alone.

    Produce: A bounded load experiment with latency distribution, correctness and stop criteria.

    Free reading: Diagnosing HikariCP connection pool exhaustion

  9. Session 9: Enforce authorization across every path

    Distinguish login from permission to use a particular object, including cache-hit and direct API paths.

    Produce: A two-user negative-test matrix for reads, updates and cached responses.

    Free reading: API authorization: check owner, action and every access path

  10. Session 10: Review readiness, shutdown and rollout

    Treat process health, admission, draining and schema compatibility as different deployment contracts.

    Produce: A rollout checklist with in-flight work, drain deadline and rollback conditions.

    Free reading: Cloud rollouts: readiness, draining and compatible rollback

  11. Session 11: Choose code and service boundaries deliberately

    Use a pattern to separate a concrete responsibility, then check whether service boundaries provide useful ownership.

    Produce: A design note explaining the invariant, rejected alternative and the cost of the abstraction.

    Free reading: Design patterns in practice: responsibility, state and trade-offs

  12. Session 12: Capstone: capacity, consistency and recovery

    Connect workload assumptions, downstream demand and restore evidence; revisit one weak decision from the core path.

    Produce: A short architecture decision record with capacity assumptions, consistency needs, acceptance test and recovery gate.

    Free reading: System design: workload, consistency and recovery before diagrams

  13. Session 13: Data pipeline integrity

    Define version ordering and compare derived state with its source.

    Produce: A source-version, replay and reconciliation contract with a deletion check.

    Free reading: Data pipelines: source versions, replay and reconciliation

  14. Session 14: AI integration safety

    Apply existing permission and test boundaries to model and tool workflows.

    Produce: A tool-permission matrix and a held-out evaluation that checks effects and provenance.

    Free reading: Defending RAG applications against prompt injection

Java backend engineer · 15 sessions

A practical Java emphasis with explicit Java 8 and Java 21 sessions, while retaining security, cloud, testing and architecture.

Prerequisite: Basic Java collections, lambdas, HTTP, SQL and Spring beans.

  1. Session 1: Start with evidence and ownership

    Separate the symptom, the resource boundary and the property that must remain true.

    Produce: An evidence ledger: facts, one competing explanation and a test that would change your mind.

    Free reading: Diagnosing HikariCP connection pool exhaustion

  2. Session 2: Get values and Java 8 pipelines right

    Review numeric representation, stream lifetime and the difference between data and a computation over data.

    Produce: Two boundary tests: one for a decimal value and one for a reused pipeline.

    Free reading: Java 8 streams: lifetime, duplicate keys and safe collection

  3. Session 3: Trace Spring transaction boundaries

    Draw the entry point, proxy and commit boundary before choosing propagation or rollback behavior.

    Produce: A call-path sketch and a test that checks committed rows after failure.

    Free reading: Why Spring @Transactional fails on self-invocation

  4. Session 4: Protect SQL correctness and query shape

    Distinguish a concurrency invariant from a fetch-shape problem; choose the right evidence for each.

    Produce: One two-transaction test and one query-count or row-volume check.

    Free reading: SQL transactions: prove the invariant with two sessions

  5. Session 5: Define API outcomes, retries and deadlines

    Separate transport failure from a known business outcome and give every retry an identity and time budget.

    Produce: An API contract covering success, rejection, uncertain completion and retry.

    Free reading: API retries: identity, deadlines and uncertain outcomes

  6. Session 6: Build tests that can reject a bad change

    Test real transaction and failure windows rather than relying only on mocks or a successful response.

    Produce: A regression test plan with controlled concurrency and a response lost after commit.

    Free reading: Backend testing: target the failure window, not just the happy path

  7. Session 7: Budget concurrency and Java 21 resources

    Identify the executor, cancellation owner and scarce resource before changing the threading model.

    Produce: A resource budget and a cancellation test with an explicit Java version note.

    Free reading: Debugging Java 21 virtual-thread pinning

  8. Session 8: Make messaging and replay accountable

    Locate the gap between a durable business effect and acknowledgment; distinguish publishing from consuming.

    Produce: A failure-window diagram and a replay test that inspects authoritative effects.

    Free reading: Handling duplicate Kafka messages without duplicate business effects

  9. Session 9: Use caching and signals to recover safely

    Relate load, cache expiry and queueing to customer outcomes; avoid diagnosing from an average alone.

    Produce: A bounded load experiment with latency distribution, correctness and stop criteria.

    Free reading: Diagnosing HikariCP connection pool exhaustion

  10. Session 10: Enforce authorization across every path

    Distinguish login from permission to use a particular object, including cache-hit and direct API paths.

    Produce: A two-user negative-test matrix for reads, updates and cached responses.

    Free reading: API authorization: check owner, action and every access path

  11. Session 11: Review readiness, shutdown and rollout

    Treat process health, admission, draining and schema compatibility as different deployment contracts.

    Produce: A rollout checklist with in-flight work, drain deadline and rollback conditions.

    Free reading: Cloud rollouts: readiness, draining and compatible rollback

  12. Session 12: Choose code and service boundaries deliberately

    Use a pattern to separate a concrete responsibility, then check whether service boundaries provide useful ownership.

    Produce: A design note explaining the invariant, rejected alternative and the cost of the abstraction.

    Free reading: Design patterns in practice: responsibility, state and trade-offs

  13. Session 13: Java 8: collector contracts and asynchronous continuations

    Explain merge semantics and continuation execution before introducing parallel work.

    Produce: Compare sequential and asynchronous behavior, then write a version-specific resource test.

    Free reading: Java 8 streams: lifetime, duplicate keys and safe collection

  14. Session 14: Java 21: virtual threads and monitor boundaries

    Distinguish Java 21 behavior from newer JDK changes; identify the actual scarce resource.

    Produce: A Java 21-specific experiment comparing waiting, monitor ownership and carrier availability.

    Free reading: Debugging Java 21 virtual-thread pinning

  15. Session 15: Capstone: capacity, consistency and recovery

    Connect workload assumptions, downstream demand and restore evidence; revisit one weak decision from the core path.

    Produce: A short architecture decision record with capacity assumptions, consistency needs, acceptance test and recovery gate.

    Free reading: System design: workload, consistency and recovery before diagrams

Engineering lead · 8 sessions

Practice review gates, test ownership, incident handoffs and operational decisions. Explain who acts and what evidence permits the next step.

Prerequisite: Core path or equivalent experience with API, database, deployment and permission boundaries.

  1. Session 1: Build tests that can reject a bad change

    Test real transaction and failure windows rather than relying only on mocks or a successful response.

    Produce: A regression test plan with controlled concurrency and a response lost after commit.

    Free reading: Backend testing: target the failure window, not just the happy path

  2. Session 2: Enforce authorization across every path

    Distinguish login from permission to use a particular object, including cache-hit and direct API paths.

    Produce: A two-user negative-test matrix for reads, updates and cached responses.

    Free reading: API authorization: check owner, action and every access path

  3. Session 3: Review readiness, shutdown and rollout

    Treat process health, admission, draining and schema compatibility as different deployment contracts.

    Produce: A rollout checklist with in-flight work, drain deadline and rollback conditions.

    Free reading: Cloud rollouts: readiness, draining and compatible rollback

  4. Session 4: Choose code and service boundaries deliberately

    Use a pattern to separate a concrete responsibility, then check whether service boundaries provide useful ownership.

    Produce: A design note explaining the invariant, rejected alternative and the cost of the abstraction.

    Free reading: Design patterns in practice: responsibility, state and trade-offs

  5. Session 5: Capstone: capacity, consistency and recovery

    Connect workload assumptions, downstream demand and restore evidence; revisit one weak decision from the core path.

    Produce: A short architecture decision record with capacity assumptions, consistency needs, acceptance test and recovery gate.

    Free reading: System design: workload, consistency and recovery before diagrams

  6. Session 6: Review a change with a comparable canary

    Identify whether the evidence supports expanding a deployment.

    Produce: An acceptance gate comparing like traffic, correctness and a rollback trigger.

    Free reading: Backend testing: target the failure window, not just the happy path

  7. Session 7: Give flaky tests an owner and exit condition

    Keep temporary exceptions from silently becoming the test strategy.

    Produce: A quarantine record with owner, diagnostic evidence and reinstatement criteria.

    Free reading: Backend testing: target the failure window, not just the happy path

  8. Session 8: Hand off an incident with uncertain outcomes

    Preserve business uncertainty instead of converting every failure into a retry.

    Produce: A handoff separating known effects, uncertain effects, actions and next owners.

    Free reading: API retries: identity, deadlines and uncertain outcomes

Software architect · 8 sessions

Work from constraints to capacity, ownership, consistency, migration and recovery. Keep cloud and cybersecurity decisions explicit.

Prerequisite: Core path or equivalent experience with transactions, retries, replay and service operations.

  1. Session 1: Define API outcomes, retries and deadlines

    Separate transport failure from a known business outcome and give every retry an identity and time budget.

    Produce: An API contract covering success, rejection, uncertain completion and retry.

    Free reading: API retries: identity, deadlines and uncertain outcomes

  2. Session 2: Enforce authorization across every path

    Distinguish login from permission to use a particular object, including cache-hit and direct API paths.

    Produce: A two-user negative-test matrix for reads, updates and cached responses.

    Free reading: API authorization: check owner, action and every access path

  3. Session 3: Review readiness, shutdown and rollout

    Treat process health, admission, draining and schema compatibility as different deployment contracts.

    Produce: A rollout checklist with in-flight work, drain deadline and rollback conditions.

    Free reading: Cloud rollouts: readiness, draining and compatible rollback

  4. Session 4: Choose code and service boundaries deliberately

    Use a pattern to separate a concrete responsibility, then check whether service boundaries provide useful ownership.

    Produce: A design note explaining the invariant, rejected alternative and the cost of the abstraction.

    Free reading: Design patterns in practice: responsibility, state and trade-offs

  5. Session 5: Capstone: capacity, consistency and recovery

    Connect workload assumptions, downstream demand and restore evidence; revisit one weak decision from the core path.

    Produce: A short architecture decision record with capacity assumptions, consistency needs, acceptance test and recovery gate.

    Free reading: System design: workload, consistency and recovery before diagrams

  6. Session 6: CQRS: own the lag window

    Decide where eventual consistency is acceptable and who resolves stalled views.

    Produce: A read-after-write contract and stale-projection detection gate.

    Free reading: System design: workload, consistency and recovery before diagrams

  7. Session 7: Active-active: establish write ownership

    Check which invariants survive concurrent regional writes.

    Produce: A conflict-resolution ADR with recovery authority and rejected alternatives.

    Free reading: System design: workload, consistency and recovery before diagrams

  8. Session 8: Strangler migration: one authoritative operation

    Prevent a transitional architecture from executing one intent twice.

    Produce: A migration map with routing ownership, reconciliation and rollback boundary.

    Free reading: Cloud rollouts: readiness, draining and compatible rollback

Optional specializations after your main path

Web/client integration

Prerequisite: API contracts and authorization

Produce: A client state diagram covering stale responses and uncertain write outcomes.

Read the free guide →

Data pipeline integrity

Prerequisite: SQL, event replay and recovery

Produce: A source-version, replay and reconciliation contract with a deletion check.

Read the free guide →

AI integration safety

Prerequisite: API contracts, testing and authorization

Produce: A tool-permission matrix and a held-out evaluation that checks effects and provenance.

Read the free guide →