Field notes
Small ideas.
Better systems.
Practical AI guides and a closer look at the decisions behind reliable software. One useful idea at a time.
From the bookshelf
Read a little.
Try something.
Your access log does not need that token
Useful security observations start with a deliberate field list, before credentials and visitor data spread through the pipeline.
Watch the age of the queue
A healthy process and a short queue can still hide stale security decisions. Measure the delay an operator needs to act on.
The webhook reply you send too early
Returning success before an event is durable leaves a small failure window with a very expensive consequence.
Reserve capacity before starting work
A concurrency quota needs a durable reservation before dispatch, plus a recovery policy for allocations whose outcome is unknown.
Ready needs to match the generation
A deployment gate must distinguish a current validation result from a positive condition left by an earlier specification.
Logs should tell you what went missing
A reconnecting log stream needs ordering, ownership, and an honest answer when the missing bytes are no longer available.
GitHub Copilot slash commands in VS Code
The commands in GitHub’s VS Code cheat sheet, practical prompts for fixing code and writing tests, and how to check commands supplied by extensions.
Gemini CLI slash commands: context, tools, and sessions
The documented Gemini CLI command families and their subcommands, with a practical way to inspect project context before changing code.
Cursor slash commands: ask, plan, and inspect
A complete snapshot of the documented Cursor CLI command families, including aliases, with a small workflow for investigating a UI bug.
Codex slash commands: a terminal field guide
The documented Codex CLI menu, grouped by task, plus a practical plan, inspect, and review loop for a real code change.
Claude Code slash commands: the command map
Navigate Claude Code’s documented commands, aliases, bundled skills, and retired entries without confusing the terminal with Claude web chat.
ChatGPT slash commands: know your composer
A complete snapshot of the documented desktop command menu, with a clear distinction between ChatGPT web, desktop actions, and custom shortcuts.
Cancel is a request, not an outcome
A useful deployment history records when cancellation was requested and what the running operation actually did.
Before blocking an IP, trace the proxies
An address becomes a useful enforcement identity only after the ingress path and forwarding-header trust are clear.
An approximate marker needs an approximate payload
Location privacy belongs in the server's public projection, covering snapshots, live deltas, expiry, and revocation rather than only the marker shown on a map.
An approval belongs to one action
Bind a human decision to the exact tool call, then preserve that identity through retries and uncertain results.
AI changes need a verification loop
Turn a broad AI request into a small, observable change: define the behavior, inspect the diff, test the boundary, and record the evidence.
Accepted should mean committed
An ingestion response is a promise about durable observations, including the awkward case where the commit succeeds and the reply disappears.
A validation result can reveal a secret
Removing secret values from logs does not stop an untrusted rule author from learning through repeated pass/fail answers.
A valid signature is only the first gate
Authenticating a policy's bytes does not make every authenticated policy appropriate for the receiving agent.
A useful AI handoff fits on one page
A practical context brief for moving a task between conversations or tools without losing decisions, evidence, and the next useful step.
A timeout is not a stopped deployment
A missing heartbeat changes what you know about a runner. It does not tell you what happened on the deployment target.
A slow map should not hold the stream hostage
Bound each WebSocket client's queue, coalesce replaceable marker updates, and give critical events a recoverable path when a browser cannot keep up.
A secret update is not proof of rotation
Object versions, credential validity and workload adoption describe different events. A restart policy needs to say which one it observes.
A lost reply should not erase a location
A mobile location queue needs stable point identities and explicit acknowledgements, especially when retries regroup the same observations into different batches.
A foreign key can cross a tenant boundary
A valid project ID proves existence. A scoped reference also proves that the project belongs to the right organization.
A fast cache is not a release artifact
Build speed and release identity solve different problems. Keeping them separate makes the pipeline easier to trust.
A cron tick needs an identity
Schedulers become easier to recover when an intended occurrence is durable data rather than a timer callback.
A ban should expire during an outage
The edge needs enough local time and policy state to end a temporary restriction without waiting for the central server.
No notes found.
Try a broader keyword or clear the filters to explore every note.