Showing 1–9 of 9 posts

Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It.

Published: September 29, 2026 Reading time: 17 min

Most of the conversation about AI coding tools is still about models: which one is smarter, faster, cheaper. But the more interesting shift over the past couple of weeks has been about containment. OpenAI paused training of its most powerful models after agents breached security controls on websites during training and evaluation, and then shelved the launch of its next ChatGPT model because it “didn’t quite meet the bar in terms of staying within scope and authorisation.” One of those agents had gained unauthorised access to a Medicare statistics portal run by Services Australia, and the Australian government set up a taskforce in response. Nvidia announced an Open Agent Safety Platform built around a sandboxed agent runtime and an out-of-band watchdog. GitHub added local sandboxing and OpenTelemetry to its Copilot app, and made workflow execution protections in GitHub Actions generally available. ...

Continue Reading

After Generation: Where the Product Lives

Published: September 23, 2026 Reading time: 10 min

A laptop that serves your app is a demo. It has not yet chosen a home. Generation made the first half cheap. A short prompt produces something that compiles, looks like the idea, and runs on the machine that wrote it. The craft bar on that side of the work is ownership of code you did not type. This post is about the next scarce decision, once the demo already works: where it lives, and which jobs you are refusing to take. ...

Continue Reading

Angular Router Resources: Route Data on the Same Graph as the Screen

Published: September 22, 2026 Reading time: 12 min

A trip detail screen needs three things that do not depend on each other: the trip, the passenger, and the seat map. Each call takes about a second. The screen still makes the user wait three, because the route loads them in a line, then dumps the result into ActivatedRoute for the component to unpack. That loader sits next to a codebase that already moved. Screen state is a signal. Forms are heading toward Signal Forms. Async reads go through resource. The route is the part that still speaks resolver. ...

Continue Reading

Obsidian on a Git Research Vault

Published: September 22, 2026 Reading time: 7 min

You already have the research repo. Inbox, concepts, counterarguments, drafts — plain Markdown, versioned, ugly on purpose. Then someone mentions Obsidian, and it starts to look like the real personal-knowledge app you were supposed to be using. It is not. The repository is the system. Obsidian is one optional way to look at it. If you have never opened it: Obsidian is a local desktop app that treats a folder of Markdown files as a vault. The problem it aims at is finding and connecting notes you already wrote, without locking them inside a proprietary cloud document. If you try it later, look for “Open folder as vault,” wikilinks and backlinks, and the graph view — that is enough to recognize the product. It is not a cloud suite, not a notebook runtime, and not required infrastructure for this workflow. ...

Continue Reading

Essential Skills When Generation Is Cheap

Published: September 14, 2026 Reading time: 8 min

The senior frontend map did not get a new section called “AI.” The tools did. The roadmaps did. Job posts did. None of that changed what senior means: you make decisions the team will live with, and you own the result. What changed is how cheap it became to produce something that looks like that work. A first draft used to cost enough that it carried some thought. Now it does not. Fluent, compiling, plausible code is the default output of a short prompt. The scarce work moved up: deciding whether that draft should exist, whether it is working-but-wrong, and whether this was a place generation should have been invited at all. ...

Continue Reading

Linux VXLAN and Why CNI Exists

Published: September 10, 2026 Reading time: 8 min

Part 3 kept everything on one machine: namespaces as workloads, veth as cables, bridge or macvlan or ipvlan as the attachment. That is enough for a single Docker host. Two hosts do not share a broadcast domain just because both run Linux. Something has to carry Ethernet (or IP) across the real network between them. VXLAN is one common way to do that. CNI is something else entirely: a contract so Kubernetes (and other runtimes) can plug a pod into whatever network architecture you chose. ...

Continue Reading

I Interview Frontend Hires for Other Companies

Published: September 9, 2026 Reading time: 17 min

Partner companies ask me to help hire their frontend developers. Not “sit in on the final call.” The work starts in a room with their CTO, someone from HR, and whoever currently leads the development team. I listen to what they think they need. Then I tell them who they can actually use, read the incoming resumes, choose who is worth an interview, and run the loop. I follow the same path for my own team. The difference is who lives with the result. When I hire badly for myself, I absorb it — I mentor the person, or I carry the gap in the sprint. When I hire badly for a partner, they keep the person and I keep the reputation. ...

Continue Reading

Linux Network Namespaces and Virtual Links

Published: September 4, 2026 Reading time: 9 min

Part 1 built Layer 2 stacks on a host. Part 2 moved packets between IP networks. Both assumed one network stack: one set of interfaces, routes, and firewall rules. This post isolates whole stacks on the same machine. A network namespace is a private view of networking. A veth pair is a cable between views. A bridge, macvlan, or ipvlan is how those cables join a shared domain or a parent NIC. ...

Continue Reading

Linux as a Router: Forwarding, Policy Routing, and nftables

Published: September 1, 2026 Reading time: 9 min

In VLANs, Bonding, and Bridging, the host stayed inside one or more Layer 2 domains: bonds for uplinks, VLANs for separation, bridges for VMs. That stack answers “who shares this Ethernet segment?” This post answers a different question: how does a Linux box move packets between IP networks? That is routing — forwarding, policy routing when you have more than one path, and nftables rules that decide what is allowed to cross. ...

Continue Reading