# Tools & Workflow

> The tools a job expects you to already know - migrations, build systems, message queues, CI/CD, containers, cloud, auth, and observability - each explained for the day you have to use it.

55 guides.

- [What Tooling Even Is](https://themissingmanual.dev/guides/what-tooling-even-is) _(beginner)_ - The Tools & Workflow category has 54+ guides and no single job needs all of them. This is the map: why the tool list is long on purpose, the ~12 themes underneath the names, and how to learn whichever one your job hands you.
- [Flyway, From Zero](https://themissingmanual.dev/guides/flyway-database-migrations) _(intermediate)_ - Version-control your database schema with Flyway: numbered, immutable migration files applied in order, so every environment ends up with the exact same schema.
- [Liquibase, From Zero](https://themissingmanual.dev/guides/liquibase-database-migrations) _(intermediate)_ - Database migrations with Liquibase: changesets in SQL, YAML, or XML, a tracked changelog, and database-agnostic changes when you need to target more than one engine.
- [Alembic, From Zero](https://themissingmanual.dev/guides/alembic-migrations) _(intermediate)_ - Schema migrations for Python and SQLAlchemy with Alembic: autogenerate from your models, review the diff, and apply with upgrade/downgrade.
- [Prisma Migrate, From Zero](https://themissingmanual.dev/guides/prisma-migrate) _(intermediate)_ - Schema-first migrations in the Node world: edit your Prisma schema, generate a migration, and keep dev and production in sync without drift.
- [golang-migrate and Atlas](https://themissingmanual.dev/guides/golang-migrate-and-atlas) _(intermediate)_ - Database migrations for Go and beyond: golang-migrate's plain up/down SQL files versus Atlas's declarative, diff-the-desired-state approach.
- [dbmate and Sqitch](https://themissingmanual.dev/guides/dbmate-and-sqitch) _(intermediate)_ - Lightweight, framework-agnostic database migrations: dbmate's simple timestamped SQL files and Sqitch's dependency-graph approach with verify and revert.
- [Maven, From Zero](https://themissingmanual.dev/guides/maven-from-zero) _(intermediate)_ - Java's build tool and dependency manager: the POM, the build lifecycle, coordinates and repositories, and why 'it works on Maven Central' is the default.
- [Gradle, From Zero](https://themissingmanual.dev/guides/gradle-from-zero) _(intermediate)_ - The flexible build tool behind Java, Kotlin, and Android: tasks and the build graph, the Groovy/Kotlin DSL, dependency configurations, and the build cache.
- [npm, pnpm, and Yarn](https://themissingmanual.dev/guides/npm-pnpm-yarn) _(intermediate)_ - Node package managers explained: package.json, the lockfile that pins your real dependency tree, semver ranges, and why pnpm's content-addressed store is so fast.
- [Python Packaging: pip, venv, Poetry, uv](https://themissingmanual.dev/guides/python-packaging-pip-poetry-uv) _(intermediate)_ - Taming Python environments: virtual environments, pip and requirements, the modern pyproject.toml with Poetry, and uv's blazing resolver - without dependency hell.
- [Make and Makefiles](https://themissingmanual.dev/guides/make-and-makefiles) _(beginner)_ - The 50-year-old build tool that still runs everything: targets, prerequisites, and recipes - a dependency graph that rebuilds only what changed.
- [Bazel, From Zero](https://themissingmanual.dev/guides/bazel-from-zero) _(advanced)_ - Google's build system for huge, multi-language repos: hermetic, reproducible builds with aggressive caching and parallelism - and the steep tradeoff that buys.
- [Kafka, From Zero](https://themissingmanual.dev/guides/kafka-from-zero) _(intermediate)_ - The distributed log everyone runs in production: topics, partitions, offsets, and consumer groups - append-only streams you can replay, not a traditional queue.
- [Redis, From Zero](https://themissingmanual.dev/guides/redis-from-zero) _(intermediate)_ - The in-memory data store that does ten jobs: cache, session store, queue, rate limiter, and lock - with data structures, TTLs, and the persistence tradeoff.
- [RabbitMQ, From Zero](https://themissingmanual.dev/guides/rabbitmq-from-zero) _(intermediate)_ - The classic message broker: exchanges, queues, and bindings route messages to workers, with acknowledgements and dead-letter queues for reliable delivery.
- [NATS and Amazon SQS](https://themissingmanual.dev/guides/nats-and-sqs) _(intermediate)_ - Two lighter messaging options: NATS for fast, simple pub/sub and request-reply, and SQS for a fully managed, zero-ops cloud queue.
- [GitLab CI/CD, From Zero](https://themissingmanual.dev/guides/gitlab-ci-cd) _(intermediate)_ - Pipelines defined in .gitlab-ci.yml: stages, jobs, and runners that build, test, and deploy on every push - with artifacts, caching, and environments.
- [Jenkins, From Zero](https://themissingmanual.dev/guides/jenkins-from-zero) _(intermediate)_ - The CI server that still runs much of enterprise: the Jenkinsfile pipeline-as-code, stages and steps, agents, and the plugin ecosystem for better and worse.
- [Argo CD and GitOps](https://themissingmanual.dev/guides/argo-cd-and-gitops) _(intermediate)_ - Deployment by pull, not push: GitOps makes a Git repo the source of truth for your cluster, and Argo CD continuously reconciles reality to match it.
- [CircleCI, From Zero](https://themissingmanual.dev/guides/circleci-from-zero) _(intermediate)_ - Cloud-native CI/CD with config.yml: jobs, workflows, executors, and orbs - fast parallel pipelines without running your own server.
- [Helm, From Zero](https://themissingmanual.dev/guides/helm-from-zero) _(intermediate)_ - The package manager for Kubernetes: charts template your manifests, values parameterize them per environment, and releases are versioned and rollback-able.
- [kubectl, Day to Day](https://themissingmanual.dev/guides/kubectl-day-to-day) _(intermediate)_ - The Kubernetes commands you actually use: get/describe/logs/exec to see what's happening, apply to change it, and the debugging loop when a pod won't start.
- [Podman, From Zero](https://themissingmanual.dev/guides/podman-from-zero) _(intermediate)_ - The daemonless, rootless container engine: a drop-in for most Docker commands, plus pods and the security win of running without a root daemon.
- [Ansible, From Zero](https://themissingmanual.dev/guides/ansible-from-zero) _(intermediate)_ - Configuration management without agents: SSH into your servers and run idempotent playbooks that bring them to a desired state, every time.
- [Pulumi, From Zero](https://themissingmanual.dev/guides/pulumi-from-zero) _(intermediate)_ - Infrastructure as actual code: define cloud resources in TypeScript, Python, or Go, with real loops and functions, while Pulumi tracks state like Terraform.
- [AWS CloudFormation](https://themissingmanual.dev/guides/aws-cloudformation) _(intermediate)_ - AWS's native infrastructure as code: declare resources in a template, and CloudFormation creates, updates, and rolls back the whole stack as one unit.
- [AWS Core Services](https://themissingmanual.dev/guides/aws-core-services) _(intermediate)_ - The handful of AWS services behind most apps: S3, EC2, RDS, IAM, and Lambda - what each does, how they fit together, and the IAM model that gates it all.
- [Azure Fundamentals](https://themissingmanual.dev/guides/azure-fundamentals) _(intermediate)_ - Microsoft's cloud for people who know AWS or none: resource groups and subscriptions, the core compute/storage/database services, and Entra ID for identity.
- [GCP Fundamentals](https://themissingmanual.dev/guides/gcp-fundamentals) _(intermediate)_ - Google Cloud essentials: projects as the unit of organization, the core compute and storage services, and IAM - with a quick map from AWS terms.
- [OpenTelemetry, From Zero](https://themissingmanual.dev/guides/opentelemetry-from-zero) _(intermediate)_ - The vendor-neutral standard for telemetry: traces, metrics, and logs from one instrumentation, exported anywhere via the OTel collector.
- [Sentry, From Zero](https://themissingmanual.dev/guides/sentry-error-tracking) _(beginner)_ - Error tracking that turns a vague bug report into a stack trace: grouped issues, the breadcrumbs and context around a crash, releases, and source maps.
- [The ELK Stack](https://themissingmanual.dev/guides/elk-elasticsearch-stack) _(intermediate)_ - Centralized logging with Elasticsearch, Logstash, and Kibana: ship logs from everywhere, index them, and search and visualize across your whole fleet.
- [Datadog, From Zero](https://themissingmanual.dev/guides/datadog-from-zero) _(intermediate)_ - The all-in-one observability platform: the agent, metrics and dashboards, APM traces, log management, and monitors - plus the bill that surprises teams.
- [Grafana Loki](https://themissingmanual.dev/guides/grafana-loki-logs) _(intermediate)_ - Logs that act like Prometheus: Loki indexes only labels (not full text), making centralized logging cheap, and ties them to your metrics in Grafana.
- [Pytest, From Zero](https://themissingmanual.dev/guides/pytest-from-zero) _(intermediate)_ - Python testing that gets out of your way: plain assert, fixtures for setup and teardown, parametrize for table-driven tests, and a rich plugin ecosystem.
- [JUnit and Mockito](https://themissingmanual.dev/guides/junit-and-mockito) _(intermediate)_ - The Java testing duo: JUnit 5 for structuring and running tests with assertions and lifecycle, and Mockito for mocking the collaborators you want to isolate.
- [Jest and Vitest](https://themissingmanual.dev/guides/jest-and-vitest) _(intermediate)_ - JavaScript and TypeScript testing: Jest's batteries-included matchers, mocks, and snapshots - and Vitest, the faster, Vite-native drop-in with the same API.
- [Playwright, From Zero](https://themissingmanual.dev/guides/playwright-from-zero) _(intermediate)_ - Reliable browser end-to-end tests: auto-waiting locators that kill flakiness, cross-browser runs, tracing, and codegen to record a test by clicking.
- [Cypress and Selenium](https://themissingmanual.dev/guides/cypress-and-selenium) _(intermediate)_ - Two more ways to test in a browser: Cypress's developer-friendly in-browser runner, and Selenium/WebDriver, the long-standing cross-language standard.
- [Testcontainers, From Zero](https://themissingmanual.dev/guides/testcontainers-from-zero) _(intermediate)_ - Integration tests against the real thing: spin up a throwaway Postgres, Kafka, or Redis in Docker for each test run, then tear it down automatically.
- [Load Testing: k6 and JMeter](https://themissingmanual.dev/guides/load-testing-k6-jmeter) _(intermediate)_ - Find the breaking point before your users do: k6's scriptable load tests and JMeter's mature GUI approach, plus how to read the results.
- [ESLint and Prettier](https://themissingmanual.dev/guides/eslint-and-prettier) _(beginner)_ - Stop arguing about code style: Prettier formats automatically, ESLint catches real bugs and bad patterns, and together they end the bikeshedding.
- [Ruff and Black](https://themissingmanual.dev/guides/ruff-and-black) _(beginner)_ - Python code quality at speed: Black formats with no options to argue about, and Ruff lints and now formats astonishingly fast, replacing a stack of older tools.
- [SonarQube, From Zero](https://themissingmanual.dev/guides/sonarqube-from-zero) _(intermediate)_ - The enterprise code-quality gate: static analysis for bugs, vulnerabilities, and code smells, with coverage and a quality gate that can block a merge.
- [pre-commit Hooks](https://themissingmanual.dev/guides/pre-commit-hooks) _(beginner)_ - Catch problems before they're committed: the pre-commit framework runs formatters, linters, and secret scanners automatically on every git commit.
- [OAuth2 and OpenID Connect](https://themissingmanual.dev/guides/oauth2-and-oidc) _(intermediate)_ - The standard behind 'Log in with Google': OAuth2 grants delegated access, OIDC adds identity on top, and the authorization-code-with-PKCE flow ties it together.
- [JWT, In Depth](https://themissingmanual.dev/guides/jwt-in-depth) _(intermediate)_ - What a JSON Web Token really is: three base64 parts, a signature you must verify, and the stateless-auth tradeoffs (plus the mistakes that cause breaches).
- [Keycloak and Auth0](https://themissingmanual.dev/guides/keycloak-and-auth0) _(intermediate)_ - Don't build auth yourself: a managed identity provider (Auth0) or a self-hosted one (Keycloak) gives you login, social sign-on, MFA, and OIDC out of the box.
- [OpenAPI and Swagger](https://themissingmanual.dev/guides/openapi-and-swagger) _(intermediate)_ - Describe your REST API once in OpenAPI, and get interactive docs, client SDKs, request validation, and contract tests for free - the API as a spec.
- [Elasticsearch and OpenSearch](https://themissingmanual.dev/guides/elasticsearch-and-opensearch) _(intermediate)_ - Full-text search at scale: the inverted index, analyzers and relevance scoring, and how a search engine differs from a database WHERE clause.
- [GraphQL Clients (Apollo)](https://themissingmanual.dev/guides/graphql-clients-apollo) _(intermediate)_ - Consuming GraphQL from the front end: how Apollo Client's normalized cache, queries, and mutations change data fetching versus REST calls.
- [HashiCorp Vault](https://themissingmanual.dev/guides/hashicorp-vault) _(intermediate)_ - Stop hardcoding secrets: Vault stores them encrypted, gates access by policy, issues short-lived dynamic credentials, and keeps an audit trail.
- [Artifact Registries: Docker Hub, Nexus, Artifactory](https://themissingmanual.dev/guides/artifact-registries) _(intermediate)_ - Where your builds live: container and package registries that store, version, and serve your artifacts - with the proxying and access control teams rely on.
- [Protobuf and Avro](https://themissingmanual.dev/guides/protobuf-and-avro) _(intermediate)_ - Binary serialization with a schema: Protocol Buffers and Avro make data small and fast across services, and force you to think about schema evolution.
