DevSecOpsSecurity Automation Developers Do Not Route Around
A hardcoded credential sat in the security report for three weeks, beside 190 low-severity notices about test fixtures. The tooling was fine. The signal was not.
Read MorePage 4 of 4 — notes on engineering, AI and the cloud.
DevSecOpsA hardcoded credential sat in the security report for three weeks, beside 190 low-severity notices about test fixtures. The tooling was fine. The signal was not.
Read More
Artificial IntelligenceMost teams argue about which model is best. After shipping generative AI for real clients, I've found the model matters far less than the workload around it.
Read More
Edge ComputingA client wanted edge computing for a slow page. Network latency was 180ms of a 2.3 second load. The rest was a missing index and 1.8MB of JavaScript.
Read More
IoTThe fifty-sensor pilot worked perfectly. At five thousand devices every assumption in it turned out to be wrong — not slightly wrong, wrong in kind.
Read More
BlockchainI have been asked to build on a blockchain four times. Three would have worked better as a Postgres table with an audit log. The fourth was a genuinely good fit.
Read More
DockerA release slipped two days because a server had Node 16 and a laptop had Node 18. Nobody was careless — environments drift, and that is what containers fixed.
Read More
KubernetesExit code 137, no useful error, two hours reading application code. The container was being killed for exceeding a memory limit somebody copied from a template.
Read More
MicroservicesSix microservices, four people, forty requests per second. Every feature touched three of them. They had split up because monoliths supposedly do not scale.
Read More
API DevelopmentWe shipped a list endpoint without pagination because the list had thirty items. Eighteen months later it had 62,000, and four clients depended on the shape.
Read More
Data EngineeringA pipeline ran green for eleven months while dropping 4% of records. Nobody found it through monitoring. An analyst found it because a number felt low.
Read More
AI Coding ToolsI used whichever tool was already open for six months and got inconsistent results. The variation was not in the models — it was in the shape of the task.
Read More
RAGMy first RAG system answered confidently and completely wrongly in front of a client. The model was fine. The right paragraph was never in the context.
Read More
Prompt EngineeringThe best prompt improvement I made last year was deleting three paragraphs. Accuracy went from the low eighties to the mid nineties.
Read More
Large Language ModelsA developer spent a day debugging a summariser that kept ignoring the end of long documents. There was no error. The context window was simply full.
Read More
Machine LearningA team spent four months on a churn model that was never used. Not because the model was bad — because nobody asked when the predictions would be needed.
Read More