A new class of interface consumers 🍝
2026-09-22
Why interfaces built for agents need different rules than REST APIs: probabilistic consumers that read the spec at inference time, errors that have to be self-explanatory, and a trust boundary that dissolves into prompt injection.
mcp
Trivy Supply Chain Attack πŸ”—β˜ οΈ
2026-05-08
Walk through how the Trivy incident unfolded, from a pull_request_target/apidiff workflow that exposed CI secrets, through incomplete rotation, to TeamPCP hijacking tags and shipping malicious GitHub Actions and binaries, and why reading /proc on runners mattered for defenders. The post ends with concrete hardening ideas like pinning actions, short-lived creds, egress limits and SBOMs, with the takeaway that no single GitHub setting fixes this. You need overlapping controls because bots can chain small mistakes fast.
devsecops
Nix ❄️
2025-09-20
Discover how Nix can bring the β€œinfrastructure-as-code” mindset to your development machine, from reproducible environments to fully declarative macOS setups. This post explores the power of flakes, devShells, and nix-darwin, along with the challenges you might face along the way.
nix
devops
CUElang for Databricks asset bundles πŸ“¦
2025-05-09
This post introduces how CUE, a flexible and type-safe configuration language, is used to validate and enforce custom rules across Databricks asset bundles via an open-source tool called bundlecues.
golang
Tail Recursion πŸ”
2025-02-11
Tail recursion eliminates unnecessary stack frames by ensuring the recursive call is the last operation in a function, allowing compilers to optimize recursion into iteration, but not all languages (e.g., Python) support this optimization.
algorithms
BundleLint ✨
2025-01-15
I've developed BundleLint, a command line tool built using Go, to govern Databricks asset bundles and I've made it available for installation using Homebrew. While I acknowledge that other technologies like CUE lang and Open Policy Agent are contenders, building BundleLint was a fun and convenient process, allowing me to explore a different stack from my usual routine.
golang
Concurrent data retrieval
2024-10-25
Exploring the concept of asynchronicity in Python, the blog post delves into iterators, generators, coroutines, event loops, and concurrent data retrieval, highlighting the benefits of leveraging `asyncio` for efficient I/O-bound processes, and hints at tackling issues including overloading the server and race conditions.
async
Setting up CI/CD authentication for AWS using OpenID
2024-07-09
Using OpenID for authentication in a CI/CD pipeline and managing infrastructure as code with Terraform are discussed, along with how to integrate OpenID with GitLab CI to securely deploy resources in AWS using Terraform.
devops
PyPI over notebooks
2024-03-09
The blog post talks about the limitations of working with Databricks and the developer experience while using it, along with a workaround involving setting up a private PyPI repository for sharing and installing private packages in Databricks notebooks, as well as the use of personal access tokens and secrets management to ensure secure package installation and deployment.
data
A lightweight stack for a simple web app
2024-02-13
Struggling with SEO for a single-page React application, I delved into server-side rendering and explored htmx, a lightweight JavaScript library, to alleviate the issues while maintaining frontend interactivity with a concise, declarative approach that seemed promising, and also ventured into using Rust-based Axum for the backend and Askama for templates, providing insights into database setup and usage with SQLx.
web
1 / 2
πŸ‘‰