Blog
Popular this month

2 October 2026
Binding a Port to Loopback Instead of Writing a Firewall Rule
A monitoring dashboard needed to be reachable for a one-time setup and invisible afterward. The fix was one word in a docker-compose file, not a firewall rule to remember to keep in sync.

24 September 2026
Setting Up a Private Admin Panel Without Ever Opening It Myself
A monitoring tool that never touches the public internet still needs a first-run setup wizard completed once. The setup happened through a tunnel and a script, not a browser tab someone sat in front of.

4 September 2026
A Public MCP Server With Nothing Private to Leak
The read-only tools an AI agent gets to call are backed by the exact same published-only queries the public blog already uses — which is what makes skipping authentication a non-decision instead of a risk.

28 July 2026
The Dollar Sign That Broke My Bcrypt Hash
A bcrypt hash stored in .env stopped matching after a routine restart. The cause was not the hash — it was Next.js expanding $ as a shell-style variable reference.

10 July 2026
Why My Blog API Requires Login Even to Read
Unlike /api/projects, GET /api/posts is auth-gated. The reasoning is about what a draft is allowed to leak, not about performance or caching.