Latest notes

Short, opinionated takes on infrastructure, networking, and tooling. Updated when there's something worth saying.

Notes on running QUIC at the edge in 2026

2026-05-29 · 7 min read

Real-world latency wins from HTTP/3 in mid-tier CDN deployments. What works, what doesn't, and why the middlebox compatibility story is still messy in some regions.

eBPF for application observability: the boring parts

2026-05-22 · 5 min read

Everyone talks about eBPF as a silver bullet. Here's what actually changed in our small infra stack after six months — and what we ripped back out.

Migrating a small Postgres workload to managed RDS

2026-05-15 · 9 min read

The good, the annoying, and the surprising during a single-day cutover from self-hosted Postgres to a managed AWS RDS instance. Lessons that don't fit in marketing slides.

WireGuard primitives vs. commercial VPN providers

2026-05-08 · 6 min read

A practical comparison from the perspective of someone who has run both for a small team. Why neither is universally "better".

Living with Let's Encrypt rate limits at scale

2026-04-30 · 4 min read

How a small infra team accidentally hit LE's per-week limit, what we learned about CT logs, and the alerting we wired up afterwards.