<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom"><title>Aleksandar Popovic — Field notes</title><id>https://alekpopovic.github.io/feed.xml</id><link href="https://alekpopovic.github.io/feed.xml" rel="self"/><link href="https://alekpopovic.github.io/"/><updated>2026-10-10T00:00:00+00:00</updated><entry><title>Your access log does not need that token</title><id>https://alekpopovic.github.io/posts/your-access-log-does-not-need-that-token/</id><link href="https://alekpopovic.github.io/posts/your-access-log-does-not-need-that-token/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Useful security observations start with a deliberate field list, before credentials and visitor data spread through the pipeline.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Watch the age of the queue</title><id>https://alekpopovic.github.io/posts/watch-the-age-of-the-queue/</id><link href="https://alekpopovic.github.io/posts/watch-the-age-of-the-queue/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A healthy process and a short queue can still hide stale security decisions. Measure the delay an operator needs to act on.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>The webhook reply you send too early</title><id>https://alekpopovic.github.io/posts/the-webhook-reply-you-send-too-early/</id><link href="https://alekpopovic.github.io/posts/the-webhook-reply-you-send-too-early/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Returning success before an event is durable leaves a small failure window with a very expensive consequence.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Reserve capacity before starting work</title><id>https://alekpopovic.github.io/posts/reserve-capacity-before-starting-work/</id><link href="https://alekpopovic.github.io/posts/reserve-capacity-before-starting-work/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A concurrency quota needs a durable reservation before dispatch, plus a recovery policy for allocations whose outcome is unknown.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Ready needs to match the generation</title><id>https://alekpopovic.github.io/posts/ready-needs-to-match-the-generation/</id><link href="https://alekpopovic.github.io/posts/ready-needs-to-match-the-generation/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A deployment gate must distinguish a current validation result from a positive condition left by an earlier specification.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Logs should tell you what went missing</title><id>https://alekpopovic.github.io/posts/logs-should-tell-you-what-went-missing/</id><link href="https://alekpopovic.github.io/posts/logs-should-tell-you-what-went-missing/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A reconnecting log stream needs ordering, ownership, and an honest answer when the missing bytes are no longer available.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>GitHub Copilot slash commands in VS Code</title><id>https://alekpopovic.github.io/posts/github-copilot-slash-commands/</id><link href="https://alekpopovic.github.io/posts/github-copilot-slash-commands/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>The commands in GitHub’s VS Code cheat sheet, practical prompts for fixing code and writing tests, and how to check commands supplied by extensions.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Gemini CLI slash commands: context, tools, and sessions</title><id>https://alekpopovic.github.io/posts/gemini-cli-slash-commands/</id><link href="https://alekpopovic.github.io/posts/gemini-cli-slash-commands/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>The documented Gemini CLI command families and their subcommands, with a practical way to inspect project context before changing code.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Cursor slash commands: ask, plan, and inspect</title><id>https://alekpopovic.github.io/posts/cursor-slash-commands/</id><link href="https://alekpopovic.github.io/posts/cursor-slash-commands/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A complete snapshot of the documented Cursor CLI command families, including aliases, with a small workflow for investigating a UI bug.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Codex slash commands: a terminal field guide</title><id>https://alekpopovic.github.io/posts/codex-slash-commands/</id><link href="https://alekpopovic.github.io/posts/codex-slash-commands/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>The documented Codex CLI menu, grouped by task, plus a practical plan, inspect, and review loop for a real code change.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Claude Code slash commands: the command map</title><id>https://alekpopovic.github.io/posts/claude-code-slash-commands/</id><link href="https://alekpopovic.github.io/posts/claude-code-slash-commands/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Navigate Claude Code’s documented commands, aliases, bundled skills, and retired entries without confusing the terminal with Claude web chat.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>ChatGPT slash commands: know your composer</title><id>https://alekpopovic.github.io/posts/chatgpt-slash-commands/</id><link href="https://alekpopovic.github.io/posts/chatgpt-slash-commands/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A complete snapshot of the documented desktop command menu, with a clear distinction between ChatGPT web, desktop actions, and custom shortcuts.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Cancel is a request, not an outcome</title><id>https://alekpopovic.github.io/posts/cancel-is-a-request-not-an-outcome/</id><link href="https://alekpopovic.github.io/posts/cancel-is-a-request-not-an-outcome/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A useful deployment history records when cancellation was requested and what the running operation actually did.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Before blocking an IP, trace the proxies</title><id>https://alekpopovic.github.io/posts/before-blocking-an-ip-trace-the-proxies/</id><link href="https://alekpopovic.github.io/posts/before-blocking-an-ip-trace-the-proxies/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>An address becomes a useful enforcement identity only after the ingress path and forwarding-header trust are clear.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>An approximate marker needs an approximate payload</title><id>https://alekpopovic.github.io/posts/an-approximate-marker-needs-an-approximate-payload/</id><link href="https://alekpopovic.github.io/posts/an-approximate-marker-needs-an-approximate-payload/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Location privacy belongs in the server&#39;s public projection, covering snapshots, live deltas, expiry, and revocation rather than only the marker shown on a map.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>An approval belongs to one action</title><id>https://alekpopovic.github.io/posts/an-approval-belongs-to-one-action/</id><link href="https://alekpopovic.github.io/posts/an-approval-belongs-to-one-action/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Bind a human decision to the exact tool call, then preserve that identity through retries and uncertain results.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>AI changes need a verification loop</title><id>https://alekpopovic.github.io/posts/ai-changes-need-a-verification-loop/</id><link href="https://alekpopovic.github.io/posts/ai-changes-need-a-verification-loop/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Turn a broad AI request into a small, observable change: define the behavior, inspect the diff, test the boundary, and record the evidence.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>Accepted should mean committed</title><id>https://alekpopovic.github.io/posts/accepted-should-mean-committed/</id><link href="https://alekpopovic.github.io/posts/accepted-should-mean-committed/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>An ingestion response is a promise about durable observations, including the awkward case where the commit succeeds and the reply disappears.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A validation result can reveal a secret</title><id>https://alekpopovic.github.io/posts/a-validation-result-can-reveal-a-secret/</id><link href="https://alekpopovic.github.io/posts/a-validation-result-can-reveal-a-secret/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Removing secret values from logs does not stop an untrusted rule author from learning through repeated pass/fail answers.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A valid signature is only the first gate</title><id>https://alekpopovic.github.io/posts/a-valid-signature-is-only-the-first-gate/</id><link href="https://alekpopovic.github.io/posts/a-valid-signature-is-only-the-first-gate/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Authenticating a policy&#39;s bytes does not make every authenticated policy appropriate for the receiving agent.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A useful AI handoff fits on one page</title><id>https://alekpopovic.github.io/posts/a-useful-ai-handoff/</id><link href="https://alekpopovic.github.io/posts/a-useful-ai-handoff/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A practical context brief for moving a task between conversations or tools without losing decisions, evidence, and the next useful step.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A timeout is not a stopped deployment</title><id>https://alekpopovic.github.io/posts/a-timeout-is-not-a-stopped-deployment/</id><link href="https://alekpopovic.github.io/posts/a-timeout-is-not-a-stopped-deployment/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A missing heartbeat changes what you know about a runner. It does not tell you what happened on the deployment target.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A slow map should not hold the stream hostage</title><id>https://alekpopovic.github.io/posts/a-slow-map-should-not-hold-the-stream-hostage/</id><link href="https://alekpopovic.github.io/posts/a-slow-map-should-not-hold-the-stream-hostage/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Bound each WebSocket client&#39;s queue, coalesce replaceable marker updates, and give critical events a recoverable path when a browser cannot keep up.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A secret update is not proof of rotation</title><id>https://alekpopovic.github.io/posts/a-secret-update-is-not-proof-of-rotation/</id><link href="https://alekpopovic.github.io/posts/a-secret-update-is-not-proof-of-rotation/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Object versions, credential validity and workload adoption describe different events. A restart policy needs to say which one it observes.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A lost reply should not erase a location</title><id>https://alekpopovic.github.io/posts/a-lost-reply-should-not-erase-a-location/</id><link href="https://alekpopovic.github.io/posts/a-lost-reply-should-not-erase-a-location/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A mobile location queue needs stable point identities and explicit acknowledgements, especially when retries regroup the same observations into different batches.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A foreign key can cross a tenant boundary</title><id>https://alekpopovic.github.io/posts/a-foreign-key-can-cross-a-tenant-boundary/</id><link href="https://alekpopovic.github.io/posts/a-foreign-key-can-cross-a-tenant-boundary/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>A valid project ID proves existence. A scoped reference also proves that the project belongs to the right organization.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A fast cache is not a release artifact</title><id>https://alekpopovic.github.io/posts/a-fast-cache-is-not-a-release-artifact/</id><link href="https://alekpopovic.github.io/posts/a-fast-cache-is-not-a-release-artifact/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Build speed and release identity solve different problems. Keeping them separate makes the pipeline easier to trust.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A cron tick needs an identity</title><id>https://alekpopovic.github.io/posts/a-cron-tick-needs-an-identity/</id><link href="https://alekpopovic.github.io/posts/a-cron-tick-needs-an-identity/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>Schedulers become easier to recover when an intended occurrence is durable data rather than a timer callback.</summary><author><name>Aleksandar Popovic</name></author></entry><entry><title>A ban should expire during an outage</title><id>https://alekpopovic.github.io/posts/a-ban-should-expire-during-an-outage/</id><link href="https://alekpopovic.github.io/posts/a-ban-should-expire-during-an-outage/"/><updated>2026-10-10T00:00:00+00:00</updated><summary>The edge needs enough local time and policy state to end a temporary restriction without waiting for the central server.</summary><author><name>Aleksandar Popovic</name></author></entry></feed>