Fifty-four posts across twelve topic areas

Security & Operations 10 posts

The SOC tooling layer: credential exposure, security-automation architecture, alert triage, social engineering, and where vendor pricing distorts design.

AI Security & Agent Confinement 6 posts

What it means to run untrusted workloads and LLM agents safely: sandbox boundaries, isolation dimensions, network egress, model auditability, the limits of human oversight, and the gap between deployment speed and containment.

Machine Learning & Agents 6 posts

Foundation models, LLM post-training, retrieval, and the sovereign agent built on top of them.

Data Infrastructure 4 posts

Caching, metadata validation, semantic layers, and event spines, the plumbing underneath everything else.

Systems 8 posts

Small VMs, instruction sets, GPU shaders, and close-to-metal work you can read every line of in an afternoon.

Distributed Systems 1 post

Consensus protocols, scheduler design, replication, and the distributed primitives underneath modern infrastructure.

Methodology & Practice 11 posts

How the work itself gets done, and how to think about it: legibility and its limits, building trustworthy systems from untrustworthy parts, intent over specs, briefs that outlive tasks, and habits that compound.

Economics & Society 10 posts

Ads, rent, funding, and fees: who pays for software and for expertise, what a rent-free alternative takes, why data-driven markets commodify, how demand-pulled marketplaces drive innovation, why organizations cut instead of create, and who carries the consequence when an agent acts.

Privacy Engineering 1 post

Telemetry-free architecture, data minimisation, local observability, and the difference between a policy that says "we don't collect" and an architecture that cannot collect.

Self-hosting & Operations 1 post

The operational reality of running your own infrastructure: what breaks, what it costs in time, when it makes sense, and the minimum posture before "self-hosted" means anything.

Networking & Protocols 1 post

Network-layer controls, egress policy, isolation primitives, and the protocol decisions that shape what software can and cannot do once it is running.

Meta 5 posts

Notes about the blog itself and the tools underneath it, the layout, the server, the choices behind how this site is built.