Find your next idea
Search everything.
Notes, complete book chapters, projects, and videos. One place to look.
Explore the library
Browse the complete catalog below. Enable JavaScript to search within chapters and posts.
Books and chapters
Modern CI
- Preface
- 1. Think in runs, not shell scripts
- 2. Draw control and trust boundaries
- 3. Make every application an independent repository
- 4. Keep contracts and dependency resolution honest
- 5. Run the laboratory before designing the fleet
- 6. Model identity, ownership, and permission together
- 7. Compile a pipeline into an immutable graph
- 8. Commit requests before acknowledging events
- 9. Claim work with short PostgreSQL transactions
- 10. Fence attempts and preserve uncertainty
- 11. Design an outbound runner protocol
- 12. Execute containers within explicit limits
- 13. Move live logs without hiding gaps
- 14. Preserve artifacts and keep cache trust separate
- 15. Build once and preserve the image digest
- 16. Integrate source events, schedules, and matrices
- 17. Give credentials to an authorized attempt, not a script name
- 18. Deploy an approved immutable release
- 19. Recover from cancellation, uncertainty, and rollback
- 20. Build an operator interface that explains state
- 21. Keep the CLI precise and extensions constrained
- 22. Observe reliability, capacity, and recovery
- 23. Test failures and upgrade through compatible states
- 24. Publish a reproducible release and maintain the project
- Appendix A. Laboratory runbook
- Appendix B. From chapters to eighty implementation work items
- Appendix C. Acceptance gates and failure experiments
- Appendix D. Glossary
- Appendix E. Primary sources
Nginx Log Security
- Nginx Log Security
- 1. Understand the feedback loop
- 2. Draw the trust boundaries
- 3. Design around failure
- 4. Run the laboratory
- 5. Produce logs you can safely analyze
- 6. Move events without losing their meaning
- 7. Commit events before acknowledging them
- 8. Connect ordinary Nginx to the guard
- 9. Know whose address you are blocking
- 10. Build a detector you can explain
- 11. Sign policy, not transport assumptions
- 12. Order updates across retries and restores
- 13. Make expiry work without the central server
- 14. Give operators precise controls
- 15. Observe the guard as an operating system
- 16. Move durable processing to PostgreSQL
- 17. Preserve the fast path in a Go agent
- 18. Test behavior at the boundary where it matters
- 19. Diagnose failures in the right order
- 20. Release a reproducible system
- Appendix A. Laboratory runbook
- Appendix B. From lessons to sixty implementation tasks
- Appendix C. Glossary and sources
AgentPlane
- Preface: A Platform Is a Set of Boundaries
- 01. Choose a Product Boundary Before a Technology Stack
- 02. Separate the Control Plane from the Execution Plane
- 03. Turn the Threat Model into Testable Invariants
- 04. Create a Reproducible Engineering Workspace
- 05. Design Tenant-Safe PostgreSQL Data
- 06. Keep Human, Service and Cluster Identities Distinct
- 07. Design APIs for Work That Finishes Later
- 08. Enroll Clusters Without Exporting Their Authority
- 09. Make Delivery Durable Without Promising Exactly-Once Effects
- 10. Use Kubernetes Reconciliation Without Expanding Authority
- 11. Integrate Agent Sandbox Through a Capability Adapter
- 12. Build Runtime Profiles for the Actual Threat Model
- 13. Model Sessions, Executions and Uncertainty Separately
- 14. Execute Commands and Handle Files Without Hidden Privilege
- 15. Make Network Policy an Enforced Property
- 16. Broker References, Not Customer Secret Values
- 17. Discover Tools Without Trusting Their Descriptions
- 18. Bind Authorization and Approval to the Exact Action
- 19. Preserve Workspaces Without Inventing Checkpoint Guarantees
- 20. Meter Usage and Reserve Capacity Without Double Counting
- 21. Observe the System Without Collecting the Customer
- 22. Build Interfaces That Preserve Scope and Uncertainty
- 23. Deploy and Upgrade Without Crossing the Trust Boundary
- 24. Design Recovery Before the First Production Incident
- 25. Build Evidence for Every Important Claim
- 26. Use Coding Agents as Bounded Engineering Collaborators
- 27. Deliver One Complete Vertical Slice
- 28. Maintain an Open Book Like a Software Project
- Appendix A. A Working Vocabulary
- Appendix B. Decision Records and Interface Contracts
- Appendix C. Review Answers and Failure Scenarios
- Appendix D. Companion Files and Build Commands
- Primary Sources and Verification Notes
Secret Contract Operator
- Preface: How to Use This Book
- 1. The Problem We Are Solving
- 2. Its Place in the Kubernetes Ecosystem
- 3. Architecture and Data Flow
- 4. Security Model and Authorization
- 5. Canonical API and Contract Semantics
- 6. Repository and Development Environment
- 7. The Pure Go Validator
- 8. The Reconcile Loop and Reliable Status
- 9. Watches, Indexes, and Performance
- 10. Integration with External Secrets Operator
- 11. Validating Consumers and Environment Configuration
- 12. Optional Injection and Safe Workload Changes
- 13. Rotation and Controlled Rollout
- 14. CI, GitOps, and Actual Deployment Control
- 15. Testing Strategy and Proving Invariants
- 16. Metrics, Events, and Operational Signals
- 17. Packaging, RBAC, and Installation
- 18. CI/CD, Releases, and the Supply Chain
- 19. Operational Procedures and Incidents
- 20. API Evolution and Open-source Maintenance
- 21. Practical Labs
- 22. Development with Codex and Execution Control
- Appendix A. Thirty Detailed Codex Prompts
- Appendix B. Concise API and Reason Reference
- Appendix C. Architecture Decision Register
- Appendix D. Glossary and Bibliography
Engineering a Universal Real-Time Tracking Platform
- Preface
- Chapter 1 - Define the Product Before the Architecture
- Chapter 2 - A Modular Monolith with Multiple Runtime Roles
- Chapter 3 - Model Anything That Moves
- Chapter 4 - Repository Design and Engineering Workflow
- Chapter 5 - PostgreSQL and PostGIS as the Platform Core
- Chapter 6 - Tenant Isolation and Row-Level Security
- Chapter 7 - Human Authentication and Session Security
- Chapter 8 - Authorization with RBAC, ABAC, and Resource Policies
- Chapter 9 - The Tracking Registry
- Chapter 10 - Audit, Classification, and Data Governance
- Chapter 11 - Design the Location Ingestion Contract
- Chapter 12 - Offline Delivery, Idempotency, Sequencing, and Data Quality
- Chapter 13 - Partitioned Location Storage and Query Design
- Chapter 14 - Latest State, Presence, and Movement
- Chapter 15 - Durable Asynchronous Work in PostgreSQL
- Chapter 16 - WebSocket Realtime Without Redis
- Chapter 17 - Geofences and Alert Processing
- Chapter 18 - Trips, Stops, Routes, and Activity Analytics
- Chapter 19 - Build the Angular Operations Dashboard
- Chapter 20 - Map Rendering and Route Playback with MapLibre
- Chapter 21 - Mobile Architecture with Angular, Ionic, and Capacitor
- Chapter 22 - Android Native Location Engine
- Chapter 23 - iOS Native Location Engine
- Chapter 24 - Public Tracking and Precision Controls
- Chapter 25 - Dispatch, Tasks, and Proof of Delivery
- Chapter 26 - Developer API, Webhooks, Exports, and Reports
- Chapter 27 - A Native GPS Protocol Gateway in Go
- Chapter 28 - Threat Model and Security Architecture
- Chapter 29 - Privacy, Consent, Retention, and Legal Holds
- Chapter 30 - Portable Deployment with Docker Compose and Nginx
- Chapter 31 - PostgreSQL Operations, Backups, and Disaster Recovery
- Chapter 32 - Observability and Incident Response
- Chapter 33 - Simulation, Load, Fault, and Field Testing
- Chapter 34 - Capacity Planning and Evolution
- Chapter 35 - Delivery Roadmap and Production Readiness
- Appendix A - Canonical Schema Blueprint
- Appendix B - REST API Blueprint
- Appendix C - WebSocket Protocol Blueprint
- Appendix D - Deployment Blueprint
- Appendix E - Operational Runbooks and Checklists
- Appendix F - Glossary and Further Reading
Field notes
- Your access log does not need that token
- Watch the age of the queue
- The webhook reply you send too early
- Reserve capacity before starting work
- Ready needs to match the generation
- Logs should tell you what went missing
- GitHub Copilot slash commands in VS Code
- Gemini CLI slash commands: context, tools, and sessions
- Cursor slash commands: ask, plan, and inspect
- Codex slash commands: a terminal field guide
- Claude Code slash commands: the command map
- ChatGPT slash commands: know your composer
- Cancel is a request, not an outcome
- Before blocking an IP, trace the proxies
- An approximate marker needs an approximate payload
- An approval belongs to one action
- AI changes need a verification loop
- Accepted should mean committed
- A validation result can reveal a secret
- A valid signature is only the first gate
- A useful AI handoff fits on one page
- A timeout is not a stopped deployment
- A slow map should not hold the stream hostage
- A secret update is not proof of rotation
- A lost reply should not erase a location
- A foreign key can cross a tenant boundary
- A fast cache is not a release artifact
- A cron tick needs an identity
- A ban should expire during an outage