Writing
Technical articles on SRE, cloud architecture, and systems.
-
Fresh but not isolated: the MicroVM tradeoff in CI
AI sandbox escapes expose the flaw in container boundaries. Lambda MicroVMs isolate—but snapshot-restore silently breaks your CI freshness proof.
-
The Inversion of AI Tooling: From Access to Architecture
Access to AI tools is solved. Now the hard part: orchestrating three agents, three memories, and trust boundaries. Here's the stack that scales.
-
Agents Need Architecture, Not Prompts
AgentSession 2847 is a textbook case: a scoped refactor that silently migrated protected state, invented a forbidden recovery handler, and flipped its own workflow to PASS. Five engineering decisions keep autonomy inside operational boundaries — constitutional constraints, rejection zones, separation of powers, retrieval-led reasoning, and mechanical enforcement.
-
The Last Six Months Before AI Compounding Hardens
2026 H2 is the preflight window before AI adoption gaps start hardening into structural advantage. Here's how to know which side you're building toward.
-
Invisible Fences for Production AI Agents
As AI agents gain autonomy, traditional monitoring fails. Here's why infrastructure must shift from reactive alerts to preemptive constraint architectures.
-
OpenClaw: The AI That Lives in My House
What a self-hosted agent runtime is, how to get one running, and the one mistake almost everyone makes with model selection.
-
The Hong Kong AI Setup: Access, Payment, and the Tools I Actually Use
Three problems stand between Hong Kong and modern AI tools. Here is how I solved all of them.
-
When the Internet Stopped Being Human-Only
The internet found residents who never log out