2026-07-30
Add a blocking Bun audit gate without losing the report
Use a pinned Bun audit job to block high-severity findings, retain JSON evidence, and govern the audit's coverage limits.
Writing
Practical details from backend systems, delivery, and operating software.
2026-07-30
Use a pinned Bun audit job to block high-severity findings, retain JSON evidence, and govern the audit's coverage limits.
2026-07-29
Bind a potentially malicious held run to its immutable commit, review every executable change, and approve only when the run is explained.
2026-07-29
Design Redis Streams consumer groups for bounded retries, crash recovery, idempotent effects, partitioning, and production operations.
2026-07-29
Size Spring Boot shutdown against distinct Pod-deletion and probe-failure grace periods, then validate and drill each path separately.
2026-07-29
Attach one named pressure and swap rule to a restartable service, observe it in dry-run mode, then gate live userspace OOM enforcement.
2026-07-29
Define route, byte, fanout, transformation, and tenant work limits that reject oversized vLLM requests before backend allocation.
2026-07-28
Classify post_start and pre_stop work by ordering and omission, then test managed stop, SIGKILL, and self-exit behavior.
2026-07-28
Choose skill versus tool, keep routing metadata small, disclose detail progressively, and test both validation and runtime loading.
2026-07-28
Alert on the serving certificate chain, then prove a Spring Boot SSL bundle rotation reached the external TLS endpoint.
2026-07-27
Keep correctness-critical services required while making proven telemetry, cache, and debugging dependencies optional in Docker Compose.
2026-07-26
Replace one static third-party registry credential with provider-supported OIDC while preserving feed scope and external-code isolation.
2026-07-26
A practical architecture and technical blueprint for configurable, auditable approval workflows across sensitive financial documents.
2026-07-26
Handle generated credentials inside one job, pass only a handle across jobs, and contain an exposed workflow run.
2026-07-26
Build a whole-process JVM memory budget, then distinguish Java heap exhaustion from a cgroup OOM kill using JVM, Docker, and cgroup evidence.
2026-07-26
Separate prefill from decode, validate execution and topology, and accept vLLM tuning only with production service evidence.
2026-07-24
A tested decorator and cache proof, plus conditional Apollo, urql, and Relay guidance for Next.js products.
2026-07-24
Pass a host-bound credential through systemd into one Compose service, then verify access, rotation, cleanup, and mount namespace failure.
2026-07-24
A static portfolio moved its GitHub-backed home route to dynamic rendering with a six-hour process-local stale-good cache.
2026-07-24
Build and test PostgreSQL 18 physical recovery from a base backup and archived WAL, and verify native incremental base backup chains.