Things I build, break, fix, and write about

28 August 2026
Static Pod config breaks without API access

Kubernetes static pods are unforgiving when kubelet cannot satisfy a reference locally. I have seen a tidy manifest fail because it quietly leaned on the API server, and the fix was not clever, just stripping it back to node-side input.

28 August 2026
Gateway API TCPRoute for raw L4 routing

Gateway API TCPRoute finally gives raw L4 routing a proper shape, without the usual controller-specific nonsense. I like it because it stays plain,...

27 August 2026
Clipboard hijacking in cryptocurrency transfers

clipboard hijacking works because the address still looks right, until it does not. I prefer to treat the clipboard as hostile, especially with...

27 August 2026
Device encryption limits corporate data theft

Device encryption is useful, but it will not save you from corporate endpoint data theft once a session is live. I have seen the mess that comes from...

Latest blog posts you might like

22 August 2026
Skia integration for Rust image decoding

Chromium image codecs are where browser safety gets real, because malformed images arrive before anything else useful has happened. I like the Skia route for that reason; it keeps the ugly parsing...

22 August 2026
Styled output in macOS Terminal can leak data over DNS

macOS Terminal ANSI escape codes are one of those details I keep tripping over, because the wrong sequence can do more than colour text. I like this kind of bug precisely because it is small, ugly,...

21 August 2026
Tool boundaries in incident response for AI agents

When an autonomous AI intrusion lands, I care less about the model’s output and more about whether my tools still work. If a hosted service refuses the forensic workload, your response path is already...

21 August 2026
Flatpak pipewire escape through module loading

Flatpak PipeWire sandbox escape sounds tidy until you look at the PulseAudio path properly, where a length check passes for authentication and module loading stays open. Give a Flatpak...

20 August 2026
Founder-led startups and the cost of replacing generalists

AI can make founder-led startups look busier than they are, which is exactly why I distrust it when the team is already thin. The easy wins are real, but once you remove the generalist, you often...

20 August 2026
RCU and refcount faults in Linux kernel net/sched

RCU and refcount faults in the Linux kernel net/sched path are the sort of bug I like least, because the refcount check arrives after the damage is already done. On a busy CentOS 9 box, the race is...

19 August 2026
Simple Caddy access rules for cgit

I keep cgit behind Caddy access rules because the decision belongs at the front door, not buried in the app. It is a blunt setup, but it keeps browser noise out, leaves Git clients alone, and avoids...

19 August 2026
Skipping fenced code blocks in Neovim Markdown outline

Neovim Markdown outline navigation gets ugly fast if you let fenced examples count as headings. I fixed that with a small state flag, a blunt scan, and no ceremony; the sort of change that quietly...

18 August 2026
LLM-assisted pull requests and CLA friction

LLM-assisted pull requests tend to look harmless until the CLA, provenance, or disclosure rules kick in. I have seen good fixes stall there, not because the code was bad, but because the project had...

18 August 2026
CVE-2020-8561 and DNS proxy TOCTOU risk

CVE-2020-8561 is the sort of Kubernetes CVE records problem I trust least, because the bug is in the behaviour, not a neat patched release. If your tooling only reads version fields, it can miss the...