Introduction
Principles
Guidelines
  • Brainstorming
    • Convergent Techniques
    • Divergent Techniques
    • Facilitation Without Anchoring
    • Framing Techniques
  • Cookbook
    • Recipe Quality
      • Behavioral Requirements
      • Completeness
      • Cookbook Compliance
      • Cross-Recipe Consistency
      • Source Fidelity
      • Template Conformance
    • Skills And Agents
      • Agent Lint Checklist
      • Agent Structure Reference
      • Authoring Skills and Rules
      • Rule Lint Checklist
      • Rule Structure Reference
      • Skill Lint Checklist
      • Skill Structure Reference
    • Testing
      • Properties of Good Tests
      • Unit Test Patterns
    • Ui
      • Platform Design Languages
  • Implementing
    • Accessibility
      • Accessibility from day one
      • Dynamic Type
      • Font Scaling
    • Code Quality
      • Architecture
      • Completeness: finish the work, don't defer by default
      • Dependency Injection
      • File paths
      • Hilt dependency injection for Android
      • Linting before the first PR
      • Naming
      • No external dependencies in core libraries
      • Nullable Reference Types
      • Scope discipline
      • Shell scripts
      • Small, atomic commits
      • Type hints
      • TypeScript strictness configuration
      • Use roadmap_lib
      • Value objects over primitive obsession
      • Verification harnesses as agent guardrails
      • Writing code for the AI reader
      • YAML frontmatter
    • Concurrency
      • Adopt Swift 6 strict concurrency incrementally
      • Immutability
      • Kotlin Flow and StateFlow: lifecycle-aware state exposure
      • No blocking the main thread
    • Data
      • Access Pattern Analysis
      • Advanced database indexing
      • Clock Systems for Sync
      • Conflict Resolution
      • Connection pooling for server and serverless backends
      • Constraints and validation
      • Data retention and deletion
      • Data types and type affinity
      • Database
      • Database backup and recovery
      • Database naming conventions
      • Deterministic IDs
      • Foreign keys and referential integrity
      • Indexing
      • JSON columns and generated columns
      • Normalization and denormalization
      • Offline-First Architecture
      • Primary key strategies
      • Query Optimization
      • Relationship patterns
      • Room persistence on Android
      • Schema evolution and migrations
      • SQLite Sync Tooling
      • Sync Engine Design
      • Sync Protocol
      • Sync Schema Design
      • Table partitioning and time-series data
      • Transaction isolation and serialization-failure retry
      • Transactions and Concurrency
      • Zero-downtime migrations: expand and contract
    • Feature Management
      • A/B testing
      • Debug mode
      • Feature flags
    • Infrastructure
      • Containerization
      • Kubernetes configuration and secrets
      • Kubernetes workloads
      • Twelve-factor configuration
    • Internationalization
      • Localizability
      • RTL layout support
    • Networking
      • AI Cost Management
      • API Design
      • Be strict and maintain: Postel reconsidered (RFC 9413)
      • Caching
      • Error Responses
      • HTTP conditional requests and optimistic concurrency
      • Idempotency keys for write APIs
      • MCP server design
      • Offline and Connectivity
      • Pagination
      • Rate Limiting
      • Real-Time Communication
      • Retry and Resilience
      • Timeouts
      • Web services
    • Observability
      • AI Provider Observability
      • Analytics
      • Continuous profiling
      • Distributed tracing and context propagation
      • Instrumented logging
      • Metrics instrumentation: RED and USE
      • Service-level objectives and error budgets
    • Platform Integration
      • App Intents
      • Background tasks
      • Deep linking
      • Handoff and continuity
      • Notifications
      • Scriptable and automatable
      • Search integration
      • Share and inter-app data flow
      • Use AppKit and UIKit, not SwiftUI
      • Widgets and glanceable surfaces
    • Security
      • Agent guardrails
      • Authentication
      • Authorization
      • Consent management
      • Content Security Policy
      • CORS
      • Data subject rights (DSAR)
      • Dependency Security
      • Input Validation
      • LLM and agentic application security
      • MCP server security
      • MCP tool input validation
      • Passkeys and WebAuthn
      • PII detection and redaction
      • PII handling and classification
      • Privacy and security by default
      • Secure Storage
      • Security Headers Checklist
      • Sender-constrained access tokens
      • Sensitive Data
      • Token Handling
      • Transport Security
    • Skills And Agents
      • Agent Structure Reference
      • Authoring Skills and Rules
      • Context and memory management for agents
      • Performance: Speed and Token Efficiency
      • Rule Structure Reference
      • Skill Structure Reference
    • Testing
      • Comprehensive unit testing
      • Property-Based Testing
      • Swift Testing
      • Test Data
      • Test Doubles
      • Unit Test Patterns
    • Ui
      • Always show progress
      • Android edge-to-edge and window insets
      • Android navigation in Compose
      • Android predictive back
      • Animation & Motion
      • Apple design language and widgets
      • Color
      • Core Web Vitals and performance budgets
      • Cross-platform token adaptation
      • Dashboard service is display-only
      • Data Display
      • Design token distribution
      • Design-Time Data
      • Feedback Patterns
      • Fluent Design
      • Form Design
      • High DPI / Display Scaling
      • Iconography
      • Jetpack Compose performance and stability
      • Jetpack Compose side effects
      • Jetpack Compose: state hoisting and unidirectional data flow
      • Layout
      • Material 3 theming on Android
      • Modern CSS layout and Baseline-driven adoption
      • Platform Design Languages
      • Previews
      • Progressive Web App installability
      • Spacing
      • State Design
      • Theming
      • Theming with tokens
      • Touch & Click Targets
      • Typography
      • Visual Hierarchy
      • Windows 11 materials (Mica and Acrylic)
  • Planning
    • Code Quality
      • Agent instruction files (AGENTS.md / CLAUDE.md)
      • Algorithmic Complexity
      • App Interactions
      • Architecture
      • Choosing a .NET target framework
      • Choosing a Windows UI framework and deployment model
      • Cross-Cutting Detection
      • Dependency Clusters
      • Essential vs accidental complexity
      • Framework Conventions
      • Interface Cohesion
      • Kotlin Multiplatform
      • Lifecycle Patterns
      • Module Boundaries
      • Purpose Classification
      • Runtime Conditions
      • Scope discipline
      • Search for existing solutions before building
      • Spec-driven development (plan before code)
      • System Dependencies
      • System Interactions
    • Data
      • Access Pattern Analysis
      • Choose SwiftData vs Core Data
      • Choosing a primary datastore
      • Clock Systems for Sync
      • Conflict Resolution
      • CQRS and event sourcing
      • Database
      • Indexing
      • JSON columns and generated columns
      • Normalization and denormalization
      • Offline-First Architecture
      • Primary key strategies
      • Relationship patterns
      • SQLite Sync Tooling
      • Sync Engine Design
      • Sync Protocol
      • Sync Schema Design
      • Transactions and Concurrency
      • Vector search and retrieval
    • Feature Management
      • Feature flags
    • Infrastructure
      • Immutable infrastructure
      • Infrastructure as code
    • Networking
      • API Design
      • API versioning and deprecation
      • Caching
      • Choosing an API style (REST, gRPC, GraphQL)
      • Design-first API development with OpenAPI
      • Offline and Connectivity
      • Pagination
      • Real-Time Communication
    • Security
      • Authentication
      • Data privacy regulations
      • Privacy and security by default
      • Privacy by design
      • Threat modeling
    • Testing
      • Test Pyramid
    • Ui
      • Choose a rendering strategy per route, minimize client JS
      • Dashboard service is display-only
      • Data Display
      • Design tokens
      • Platform Design Languages
      • Separate server state from client state
  • Researching
    • Evidence
      • Research results document
      • Verification and trust scoring
    • Process
      • Agentic research design lessons
      • Research methodology and sources
      • Research type taxonomy
  • Reviewing
    • Conformance: The Criterion Walk
    • Writing the Review Report
    • Accessibility
      • Accessibility from day one
    • Code Quality
      • Bulk operation verification
      • Code hygiene: remove the old thing
      • Dependency Injection
      • File paths
      • Law of Demeter and Tell, Don't Ask
      • Naming
      • No external dependencies in core libraries
      • Scope discipline
      • Shell scripts
      • Type hints
      • Use roadmap_lib
      • YAML frontmatter
    • Data
      • Query Optimization
    • Infrastructure
      • Container image security
    • Internationalization
      • Localizability
      • RTL layout support
    • Networking
      • Hyrum's Law: all observable behavior becomes contract
      • MCP server review checklist
      • Rate Limiting
      • Timeouts
    • Observability
      • Analytics
      • Instrumented logging
    • Platform Integration
      • Deep linking
      • Use AppKit and UIKit, not SwiftUI
    • Security
      • Authentication
      • Authorization
      • Content Security Policy
      • CORS
      • Dependency Security
      • Input Validation
      • LLM red teaming
      • Privacy and security by default
      • Secure Storage
      • Security Headers Checklist
      • Sensitive Data
      • Token Handling
      • Transport Security
      • Vulnerability prioritization by exploitability
    • Skills And Agents
      • Agent Lint Checklist
      • Performance: Speed and Token Efficiency
      • Rule Lint Checklist
      • Skill Lint Checklist
    • Testing
      • Flaky Test Prevention
      • Post-generation verification
      • Security Testing
    • Ui
      • Color
      • Touch & Click Targets
  • Shipping
    • A/B testing
    • Bulk operation verification
    • Continuous delivery
    • Database backup and recovery
    • Dependency Security
    • Ephemeral preview environments
    • Feature flags
    • Incident response and blameless postmortems
    • MSIX Packaging
    • Progressive delivery
    • Schema evolution and migrations
    • Ship a privacy manifest and declare required-reason APIs
    • Small, atomic commits
    • Software supply-chain integrity
    • Transport Security
    • Trunk-based development
    • Windows ARM64 and Native AOT
  • Storytelling
    • Ecosystem Narration
    • Explaining a Project
    • Grounded Synthesis
    • Narrative Arc
    • Narrative Craft
    • Positioning
  • Testing
    • Agent evaluation and safety
    • Comprehensive unit testing
    • Contract testing for services
    • Database testing
    • Design-Time Data
    • Eval-driven development for agent behavior
    • Flaky Test Prevention
    • Flaky test quarantine lifecycle
    • Fuzz testing
    • Groundedness and hallucination checks
    • Linting from day one
    • Mutation Testing
    • Post-generation verification
    • Previews
    • Properties of Good Tests
    • Property-Based Testing
    • Security Testing
    • Snapshot testing discipline
    • Test Data
    • Test Doubles
    • Test Pyramid
    • The Testing Workflow
    • Tool-call evaluation
    • Unit Test Patterns
Ingredients
Recipes
Compliance
Reference
Appendix

Cookbook Projects

Infrastructure

4 documents

Containerization

Build small, secure container images with multi-stage builds, pinned slim bases, non-root users, cache-ordered layers, and no baked-in secrets.

Kubernetes configuration and secrets

Externalize Kubernetes config via ConfigMaps and treat Secrets as unencrypted base64 — encrypt at rest, tighten RBAC, and prefer external secret managers.

Kubernetes workloads

Run Kubernetes workloads with explicit resource requests/limits, health probes, hardened pod security, and safe rollout strategies.

Twelve-factor configuration

Read config that varies between deploys from the environment and promote one immutable build artifact unchanged across every environment.

© 2026 Agentic Development Studiov1.0.35 · 0d4521a6
TermsPrivacy

The Agentic Developer family

Hub

  • BitbagThe Agentic Developer persona
  • MessagesSend & receive messages
  • HubThe Agentic Developer Hub
  • NewsNews & updates
  • StatusSystem status
  • CommunityForums & discussion
  • HelpHelp topics
  • SupportGet support
  • StoreHub merch & gear
  • OrganizationsManage organizations

Learn

  • AcademyLearn agentic dev

Plan

  • ProjectsProject planning
  • NarrativesEcosystem stories
  • NotebookNotes & notebooks
  • ResearchStore & review research
  • DocsOrganize your documents

Build

  • TeamYour agentic dev team
  • Code ReviewsCode reviews
  • CookbookRecipes & patterns
  • ToolkitThe developer toolkit
  • ToolsDeveloper tools
  • TestingTest plans & bugs
  • ShiprMove code to production

Personas

  • PersonasDefine your personas
  • Persona BuilderConfigure personas
  • Persona RegistryBrowse agentic personas
  • Knowledge BasesKnowledge bases
  • Team BuilderBuild agentic teams
  • Team RegistryRegister agentic teams
  • My TeamsBuild your own agentic teams

Products

  • ProductsDefine products
  • StorageManage storage
  • EcosystemsBuild ecosystems
  • AuthenticationCustomer auth
  • CustomersManage customers
  • BillingCustomer billing
  • MessagingEmail & SMS integrations
  • NotificationsSend notifications
  • SitesQuick landing pages
  • CommunitiesBuild communities
  • DashboardsStatus dashboards
  • DevicesConnect devices
  • DomainsCustom domains
  • IntegrationsManage integrations
  • RegistriesBuild registries
  • GamificationProduct gamification
  • GamesBuild your games
  • StoresSell your products

Hire

  • ConsultantsFind consultants
  • RegistryRegistered hub developers
  • FishLamp DesignThe studio behind the Hub
  • fishlampdesign.comFishLamp Design — second domain

Terms of Service

Privacy Policy