How this project works
Ironclad Commons is the Spring remake of Westloop: a neighborhood social network with accounts, profiles, follows, likes, comments, a following timeline, search, notices, and a real Ubuntu VPS deploy. Each numbered folder in fcc-spring-social is a working snapshot.
The stack, and why these tools
| Job | Choice | Why |
|---|---|---|
| Language / framework | Java, Spring Boot 3 | Spring Security is the adult auth stack. JPA unique constraints protect follows. Thymeleaf fragments + HTMX keep the UI server-rendered. |
| Database | PostgreSQL | Follows, likes, and comments need foreign keys and unique pairs. SQLite is only for the first laptop boot. |
| CSS | Tailwind CSS | Feeds, avatars, and a sticky nav are layout-heavy. Utilities stay in the templates you already edit. |
| JavaScript | HTMX + Alpine.js | HTMX posts to @PostMapping controllers. Do not add a React admin. |
| Authentication | Spring Security form login | formLogin() and BCryptPasswordEncoder. CSRF is on by default — send the token with HTMX headers. |
| Process / proxy | JAR + systemd, Nginx, Let’s Encrypt | Same VPS shape as Westloop: one app process, Postgres on localhost, Nginx for TLS and static/media files. |
| Hosting / DNS | Hetzner Cloud CX22 (or Contabo / DigitalOcean), Cloudflare Registrar + DNS | You own the box. PaaS is easier and teaches less. |
| Console locally, Postmark in production | Password reset must leave the laptop. |
If you already finished the Spring blog, keep going — this project adds a social graph and a VPS ship, not another CRUD journal.
Parts in order
Work through the parts in sequence. Each lesson explains the ideas, then points you to a runnable GitHub snapshot.