Engineering deep dives, not tutorials.
System design, distributed systems, and production patterns for engineers who build at scale.
Latest Articles
Fresh deep dives into system design, security, and engineering.

AI Video Generation in 2025 — Models, Costs, and How to Build a Cost-Effective Pipeline
A guide to AI video models — Sora, Veo 2, Kling, Runway, Pika — per-second pricing, quality tradeoffs, and pipelines that cut costs by 80%.

AI Models in 2025 — Cost, Capabilities, and Which One to Use
A comparison of AI models from Anthropic, OpenAI, Google, Meta, Mistral, and DeepSeek — pricing, capabilities, and the best fit per use case.

AI Image Generation in 2025 — Models, Costs, and How to Optimize Spend
A guide to AI image generation models — DALL-E 3, Imagen 3, Stable Diffusion, FLUX, Midjourney — pricing, quality, and how to cut costs 10-20x.

AI Coding Assistants in 2025 — Every Tool Compared, and Which One to Actually Use
A deep comparison of AI coding assistants — Copilot, Cursor, Claude Code, Aider, Windsurf, and more — features, pricing, and which wins per workflow.

AI Agents Demystified — It's Just Automation With a Better Brain
A no-hype take on AI agents: the same automation patterns we've built for decades, except the if/else decision engine is replaced by an LLM.

Security Ticketing and Incident Response
Build an effective security incident response process — incident classification, runbooks, ticketing workflows, and post-incident reviews.
What I Write About
More Articles
Browse All arrow_forward
Supply Chain Security — Protecting Your Software Pipeline
A guide to software supply chain security — the SLSA framework, dependency pinning, provenance verification, and lessons from the xz attack.

Security Mindset for Engineers — Think Like an Attacker
How to adopt a security-first mindset as a software engineer — threat modeling, attack surfaces, defense in depth, and least privilege.

Secrets Management — Vault, SSM, and Secrets Manager
A practical guide to secrets management in the cloud — comparing HashiCorp Vault, AWS SSM, and Secrets Manager, with rotation strategies.

Penetration Testing Basics for Developers
A developer-friendly intro to penetration testing — reconnaissance, common attack vectors, tools like Burp Suite and OWASP ZAP, and test cases.

OWASP Top 10 for Cloud Applications
The OWASP Top 10 through the lens of cloud-native apps — how each vulnerability manifests in AWS/GCP/Azure, with serverless-specific defenses.

Dependency Vulnerability Detection at Scale
How to detect and manage vulnerable dependencies across hundreds of repos — SCA tools, SBOM generation, and automated remediation pipelines.

Container Security — Docker and Kubernetes Hardening
A hands-on guide to securing Docker and Kubernetes — image scanning, rootless containers, network policies, and runtime threat detection.

Compliance Automation — SOC2 and ISO 27001
Automate SOC2 and ISO 27001 compliance with infrastructure as code, continuous monitoring, and policy-as-code tools like AWS Config and OPA.

Code Signing — Why and How
Why code signing matters and how to implement it — signing Git commits, Docker images with cosign, and building a chain of trust to production.
Ready to build something together?
I take on 1-2 projects at a time. Let's talk about your next challenge.
Hire Me