The Frontier Has a Brake Pedal. The Floor Doesn't.
In June I asked whether Anthropic's warning was a brake pedal or a press release. The essay arrived β and it's a real mechanism, aimed one layer above where most of us actually ship agents.
In June I asked whether Anthropic's warning was a brake pedal or a press release. The essay arrived β and it's a real mechanism, aimed one layer above where most of us actually ship agents.
One compromised maintainer, 444+ packages, ~2B monthly installs. What the Shai-Hulud npm worm teaches platform teams about install-time trust β and how to harden against the next one.
The biggest thing stopping engineers from adopting AI isn't the tooling or the risk. It's the refusal to accept that an agent can out-produce them. Here's what that costs.
Companies see the knowledge bill at net-180. Nations see it at net-5-years. Part 3: what governments should actually be doing β and why nobody has a plan.
Prompt engineering micro-managed text. Context engineering hydrated it. Loop engineering builds the feedback loop the AI runs inside β and the token economy that makes or breaks it.
Anthropic wants the option to pause frontier AI development. A platform engineer reads the data behind the 'recursive self-improvement' warning β and the timing.
A follow-up to The AI Headcount Panic. The numbers crossed 150,000, and the first codebases gutted of senior engineers are starting to break. The bill arrives on a lag.
Companies across the globeβand Israeli high-tech especiallyβare mass-laying off in the name of AI. But is AI really the reason, or just the best available excuse?
A quick-reference glossary of NIST SP 800-53 control families referenced throughout the FedRAMP series β RA, CM, SA, AC, AU, SI β and what each one means for platform engineers.
Drawing the FedRAMP authorization boundary is the most consequential platform decision in the program β what's in, what's leveraged, what's external, and how 20x turns the boundary from a Visio diagram into a data structure.
Everyone prototypes an AI agent in a weekend. Almost nobody ships it cleanly. Here's the wall you're about to hit β and how the platform is evolving to remove it.
FIPS-validated crypto is a hard requirement inside a FedRAMP boundary β not a best practice. A practitioner's walkthrough of where FIPS lands across 800-53 control families, and how the Building for Compliance supply-chain work maps onto it.
A platform engineer's plain-English walkthrough of what FedRAMP actually is β impact levels, the document set (SSP, SAR, POA&M), the ATO process, and how Rev5 and 20x change the picture in 2026.
A platform engineer's take on starting the FedRAMP journey from outside the US β why a third-party partner matters, and what the '90 days' promise really means in 2026.
Two major open-source model releases in one week signal a tipping point. Here's why I'm running capable agent models on my own hardware β and how you can too.
Andrej Karpathy dropped a paradigm-shifting gist on building personal knowledge bases with LLMs β no vector DB, no embeddings, just raw/wiki/output folders. Here's what it means for the rest of us.
How a consultant's external perspective helps scaling organizations shift from reactive execution to intentional alignment β and why staying silent is the real failure.
MiniMax M2.5 achieves near-Opus 4.6 performance at 3% the cost. What this means for always-on agents, the SWE-bench, and the falling cost of intelligence.
A practical glossary for the DNS Evolution in Practice series: core DNS records, service discovery terms, traffic management concepts, and DNS security vocabulary.
Why I'm writing a four-part DNS series in 2026. Notes from 25 years of teaching the topic that most engineers β and most curricula β quietly underestimate.
How DNS attacks actually work β Kaminsky, Sea Turtle, MyEtherWallet, DigiNotar β and the layered defenses that hold up: DNSSEC, DoH, CAA, registrar lock.
A practitioner's tour of DNS β from the hosts file era and BIND at Berkeley to CoreDNS in Kubernetes β and the record types every engineer should actually understand.
A practitioner's k3d lab for Cilium: install it next to your laptop, walk a CiliumNetworkPolicy progression from default-deny to L7 HTTP filtering, and read the drops in Hubble.
How to turn SOC 2 from a yearly fire drill into a byproduct of how you build β AWS SCPs, GCP Org Policies, OPA, drift detection, and automated evidence collection.
How to map SOC 2 controls to your AWS, GCP, and Kubernetes stack β IAM, logging, encryption, change management, and what auditors actually want to see.