Field notes

Small ideas.
Better systems.

Practical AI guides and a closer look at the decisions behind reliable software. One useful idea at a time.

From the bookshelf

Read a little.
Try something.

29 notes5 books

29 notes to explore

LogBranik
Security2 min read

Your access log does not need that token

Useful security observations start with a deliberate field list, before credentials and visitor data spread through the pipeline.

Read the note
LogBranik
Observability3 min read

Watch the age of the queue

A healthy process and a short queue can still hide stale security decisions. Measure the delay an operator needs to act on.

Read the note
Modern CI
Event processing2 min read

The webhook reply you send too early

Returning success before an event is durable leaves a small failure window with a very expensive consequence.

Read the note
AgentPlane
Reliability3 min read

Reserve capacity before starting work

A concurrency quota needs a durable reservation before dispatch, plus a recovery policy for allocations whose outcome is unknown.

Read the note
Codepop Engineering
Delivery3 min read

Ready needs to match the generation

A deployment gate must distinguish a current validation result from a positive condition left by an earlier specification.

Read the note
Modern CI
Observability2 min read

Logs should tell you what went missing

A reconnecting log stream needs ordering, ownership, and an honest answer when the missing bytes are no longer available.

Read the note
CoGitHub CopilotCommand reference
IDE workflows3 min read

GitHub Copilot slash commands in VS Code

The commands in GitHub’s VS Code cheat sheet, practical prompts for fixing code and writing tests, and how to check commands supplied by extensions.

Read the guide
GeGemini CLICommand reference
Coding agents5 min read

Gemini CLI slash commands: context, tools, and sessions

The documented Gemini CLI command families and their subcommands, with a practical way to inspect project context before changing code.

Read the guide
CuCursorCommand reference
IDE workflows4 min read

Cursor slash commands: ask, plan, and inspect

A complete snapshot of the documented Cursor CLI command families, including aliases, with a small workflow for investigating a UI bug.

Read the guide
CxCodexCommand reference
Coding agents4 min read

Codex slash commands: a terminal field guide

The documented Codex CLI menu, grouped by task, plus a practical plan, inspect, and review loop for a real code change.

Read the guide
ClClaude CodeCommand reference
Coding agents5 min read

Claude Code slash commands: the command map

Navigate Claude Code’s documented commands, aliases, bundled skills, and retired entries without confusing the terminal with Claude web chat.

Read the guide
GChatGPTCommand reference
Chat assistants3 min read

ChatGPT slash commands: know your composer

A complete snapshot of the documented desktop command menu, with a clear distinction between ChatGPT web, desktop actions, and custom shortcuts.

Read the guide
Modern CI
Delivery2 min read

Cancel is a request, not an outcome

A useful deployment history records when cancellation was requested and what the running operation actually did.

Read the note
LogBranik
Security2 min read

Before blocking an IP, trace the proxies

An address becomes a useful enforcement identity only after the ingress path and forwarding-header trust are clear.

Read the note
Universal Tracking
Security3 min read

An approximate marker needs an approximate payload

Location privacy belongs in the server's public projection, covering snapshots, live deltas, expiry, and revocation rather than only the marker shown on a map.

Read the note
AgentPlane
Integrations2 min read

An approval belongs to one action

Bind a human decision to the exact tool call, then preserve that identity through retries and uncertain results.

Read the note
✳Across toolsWorked workflow
Practical workflows3 min read

AI changes need a verification loop

Turn a broad AI request into a small, observable change: define the behavior, inspect the diff, test the boundary, and record the evidence.

Read the guide
LogBranik
Event processing3 min read

Accepted should mean committed

An ingestion response is a promise about durable observations, including the awkward case where the commit succeeds and the reply disappears.

Read the note
Codepop Engineering
Security3 min read

A validation result can reveal a secret

Removing secret values from logs does not stop an untrusted rule author from learning through repeated pass/fail answers.

Read the note
LogBranik
Security3 min read

A valid signature is only the first gate

Authenticating a policy's bytes does not make every authenticated policy appropriate for the receiving agent.

Read the note
✳Across toolsWorked workflow
Prompting & context3 min read

A useful AI handoff fits on one page

A practical context brief for moving a task between conversations or tools without losing decisions, evidence, and the next useful step.

Read the guide
Modern CI
Reliability3 min read

A timeout is not a stopped deployment

A missing heartbeat changes what you know about a runner. It does not tell you what happened on the deployment target.

Read the note
Universal Tracking
Reliability3 min read

A slow map should not hold the stream hostage

Bound each WebSocket client's queue, coalesce replaceable marker updates, and give critical events a recoverable path when a browser cannot keep up.

Read the note
Codepop Engineering
Reliability2 min read

A secret update is not proof of rotation

Object versions, credential validity and workload adoption describe different events. A restart policy needs to say which one it observes.

Read the note
Universal Tracking
Event processing3 min read

A lost reply should not erase a location

A mobile location queue needs stable point identities and explicit acknowledgements, especially when retries regroup the same observations into different batches.

Read the note
AgentPlane
Security3 min read

A foreign key can cross a tenant boundary

A valid project ID proves existence. A scoped reference also proves that the project belongs to the right organization.

Read the note
Modern CI
Delivery2 min read

A fast cache is not a release artifact

Build speed and release identity solve different problems. Keeping them separate makes the pipeline easier to trust.

Read the note
Modern CI
Integrations2 min read

A cron tick needs an identity

Schedulers become easier to recover when an intended occurrence is durable data rather than a timer callback.

Read the note
LogBranik
Reliability2 min read

A ban should expire during an outage

The edge needs enough local time and policy state to end a temporary restriction without waiting for the central server.

Read the note