AI Security Review Finds the Bug Your CI Gates Missed

Table of Contents

  • The Problem
  • Naaa… the alternatives
  • The Pipeline
  • The ai-analysis Job, Commented
  • Downloading Results, Bundling the Source
  • The Empty Report
  • Downloading Artifacts, Watching the Run
  • The AI Scripts
  • The Report That Caught the Bug
  • The Full Results, as an Example
  • The Numbers
  • Security Considerations
  • Monitoring and Observability
  • Conclusion
  • Reflections

Here we are.

My debug/test API, pytbak, runs a proper CI: unit tests, linting, a Docker build, Trivy scanning, Checkov, a Kubernetes syntax check. Every gate maps to a category of failure I have seen before. And yet, I kept being bothered by one specific class of bug, the one that no scanner materializes out of thin air, because it lives in my logic and not in a CVE database.

From Contract to iContract: Turning a Platform PDF Into a Skill, and the Gate That Makes It Stick

Table of Contents

  • Introduction
  • The Problem: A PDF Is Not an Interface
  • The Architecture: From Contract to Skill
  • Part One: What the App Must Be
    • Example 1: A Health-Check Clause Becomes Four Endpoints
    • Example 2: “No Root” Becomes a securityContext Block
    • Example 3: “No Persistent Data in a Container” Becomes Three Manifests
    • Example 4: A Four-Layer Image Hierarchy Becomes a Dockerfile and a Tag Strategy
  • Part Two: What the App Must Say
    • Example 5: “Logs MUST Be JSON on stdout” Becomes a Logger and a Field Contract
    • Example 6: A Three-Tier Metrics Rule Becomes an Annotation and a NetworkPolicy
    • Example 7: “MUST Send Traces to a Collector” Becomes an SDK Init and an Egress Policy
    • Example 8: “Alert on Trends, Not Numbers” Becomes a Recording Rule and an HPA
  • Part Three: Where the App Lives
    • Example 9: A Naming Convention Becomes a Derivation Rule
    • Example 10: “Never Commit a Plain Secret” Becomes Vault or AWS Secrets Manager
    • Example 11: “The Management Port MUST NOT Be Public” Becomes Three Absences
  • Part Four: How the App Ships
    • Example 12: “No Human Tampering With the Artifact” Becomes a CI Workflow With Teeth
    • Example 13: Terraform Guardrails Become a Module Call You Cannot Widen
    • Example 14: “MUST Be in the Service Catalog First” Becomes Labels and a Generated Entry
  • The Real Speedup: Building Something the Contract Never Anticipated
  • How to Make Skills Actually Respected: The Gate
  • From a Working App to a Platform Citizen
  • Does the AI Actually Comply?
  • Security Considerations
  • Download the Skills
  • Conclusion
  • Reflections

Well. Every platform team eventually writes the same document: a PDF (or a Confluence page pretending to be one) that says what an application must do before it’s allowed to run on the shared cluster. Containerized. Non-root. Health endpoints on a specific port. No plain secrets in Git. It’s correct, it’s thorough, and almost nobody who needs to follow it has actually read it end to end.

What AI Actually Costs: 27 Sessions of Real Data

Table of Contents

  • Introduction
  • The Question Nobody Answers
  • The Dataset: 27 Sessions, 61 Days
  • Where the Money Actually Goes
    • Cache Read Is the Bill
    • The Whale Session
    • Head and Tail
  • The Model Mix Problem
  • Output Compression: The Lever Everyone Reaches For First
  • The Velocity Half of the Question
    • km/l Is Not the Metric. km/€ Is.
    • The Efficiency Gap Between People
  • A Framework for Getting the Data
    • Step 1: Parse Your Own Logs
    • Step 2: The Ticket Protocol
    • Step 3: The Metrics That Matter
  • From Measurement to a Development Framework
    • Rule 1: One Ticket, One Session
    • Rule 2: Route the Model to the Task
    • Rule 3: Compress the Output
    • Rule 4: Build Skills, Not Prompts
  • The Maturity Path
  • The Honest Caveats
  • Conclusion
  • Reflections

Here we are. Every conversation about AI in engineering right now runs on vibes. It’s faster. It’s cheaper. It’s transformative. Ask for a number and the room goes quiet.

The Safe Zone: Where AI Actually Belongs in Business Processes

Table of Contents

  • Introduction
  • The Problem With Urgency
  • The Safe Zone Framework
  • The Case: Algolia Usage Exporter
    • Before / After
    • How It’s Built
    • The Skill Framework: Three Skills, Not One Prompt
    • From API Schema to Natural-Language Contract
    • What It Exposes
    • Numbers That Weren’t Visible Before
  • Why the Pattern Replicates
  • The Honest Challenges
    • AI Amplifies Whatever Maturity Already Exists
    • Tech Debt Doesn’t Disappear
    • Creating Is Easy. Deploying on Shared Platform Isn’t
    • Ownership Is Still Informal
    • The Escalation Risk: Safe Today, Critical Tomorrow
  • A Maturity Model, Not a Tech Roadmap
  • Security Considerations
  • Conclusion
  • Reflections

Here we are. I recently put together an internal presentation on introducing AI into business processes, and the hardest part wasn’t the technology. It was convincing people to look in the opposite direction of where they instinctively point AI.

I Made Claude Code Talk Like a Caveman for 61 Days, Then Did the Math

Table of Contents

  • Introduction
  • The Problem: Verbose Agents Cost Real Money
  • Enter Caveman Mode
  • The Question I Actually Wanted Answered
  • Method: Mining 27 Session Logs
  • The Results, Per Model
  • Where the Money Actually Goes
  • How Big Were These Sessions, Really?
  • The Fable 5 Shift
  • From a Homelab Toy to an Enterprise Line Item
  • Reflections
  • Conclusion

Strange… an AI assistant that talks less should cost less. Obvious, right? I wanted a number, not a vibe.

Who Is Your AI Agent Acting For? RFC 8693 On-Behalf-Of Delegation

Table of Contents

  • Introduction
  • The Problem: agents are anonymous proxies
  • Enter RFC 8693: Token Exchange, On-Behalf-Of
  • The Architecture
  • The Identity Flow, Step by Step
  • Token Anatomy
  • Inside the JWT: Claims, Exchange Mechanics, Group-Based Permissions
  • Where Authorization Actually Happens
  • Observability: Watching Delegation Happen
  • Security Properties
  • Conclusion
  • Reflections

Here we are. Everyone is wiring AI agents to real systems — Kubernetes clusters, CI pipelines, internal APIs — and almost nobody is asking the boring question first: when the agent calls a tool, who is it?

Running a Local LLM on AMD Radeon 780M — gfx1103, ROCm, and the GPU That Wasn't Supposed to Work

Table of Contents

  • The Machine
  • The Problem: gfx1103 Doesn’t Exist
  • GTT Memory — 24 GB for Free
  • The ROCm Stack
  • Getting GPU Inference Working
  • Optimizing: The Hidden GPU Clock Problem
  • Benchmarks — Every Configuration Tested
  • The Surprising Finding: CPU Beats GPU on Generation
  • The Real Bottleneck: Single-Channel RAM
  • The Breakthrough: MoE on CPU
  • Monitoring with Collectd and Grafana
  • What the Dashboard Actually Shows
  • Lessons Learned

I wanted a local AI box. Not a cloud API with latency and per-token billing. Not a GPU workstation that sounds like a jet engine. A quiet mini-PC that runs a capable model at home, on my desk, forever, for free.

AI Agentic Development Changes Who Builds Software — and That's an Infrastructure Problem

Table of Contents

  • The Shift Is Already Happening
  • The Problem Nobody Prepared For
  • The Design Principle: Safe by Default
  • The Platform Contract — What Every App Must Be
    • Supported Languages and Base Images
    • Supported Components
    • T-shirt Sizing
    • Port Contract
    • Health Endpoints
    • Secrets: Sealed, Always
    • Images: Commit SHA, Never Latest
    • Network: Default Deny, Every Time
  • The Three-Tier Monitoring Contract
    • System Tier — Automatic
    • Framework Tier — App Metrics
    • Business Tier — What the App Actually Does
  • The Review Gate — 35+ Checks Before Deploy
  • The Helm Chart — Five Questions, Full Platform
  • The CI/CD Pipeline — AI App Meets GitOps
  • The Skill Pipeline — AI Onboarding an AI App
  • The RACI Collapse
  • Conclusion

Here we are. Somewhere in the last twelve months, something quietly changed.

Monitoring Contentful Usage — Building a Prometheus Exporter Because the UI Won't Tell You

Table of Contents

  • Introduction
  • The Problem
  • The Architecture
  • How It Works
  • CLI Mode — One-Shot Reports
  • Prometheus Mode — Continuous Monitoring
  • Deploying on Kubernetes with Helm
  • Grafana Dashboards
  • Security Considerations
  • Conclusion
  • Reflections

Here we are. If you’ve ever managed a Contentful space at scale — I mean real scale, with thousands of entries, a dozen environments, and a team that publishes hourly — you’ve hit the wall. The Contentful web app shows you… not much. A few dashboard widgets, some high-level numbers, but nothing you can export, alert on, or trend over time.

Algolia prometheus exporter

Algolia Usage Exporter — A Case Study in AI-Assisted Tooling

What is this?

A lightweight Prometheus exporter that collects usage and infrastructure metrics from the Algolia search API and exposes them at /metrics for Prometheus / Datadog scraping.

It runs as a standalone HTTP server (single binary via Docker/Podman), requires minimal configuration (just two API keys), and exports metrics like:

  • Usage statistics: search operations, records, processing time, QPS, write operations
  • Infrastructure metrics: CPU, RAM, SSD utilization, build times (Premium plan only)
  • Health signals: scrape success status, timestamps

The entire project lives in a single Python package with ~50KB of code, a Helm chart for Kubernetes deployment, and full test coverage across unit, integration, and e2e layers.