Blog
Porting a Go framework to Rust separates design from idiom. Which decisions survived the move, which were habits, and how to tell them apart.
A sibling to go-tool-base rather than a port, filling the gap between excellent Rust crates and a coherent way to assemble them.
Making OS-keychain support provably absent from a Go binary for regulated or air-gapped builds, using a registry and a blank import.
A primer on the six Rust concepts you need to follow the rest: ownership and borrowing, traits, enums and match, Result and the question mark.
Credential storage for a Go CLI: an env-var reference by default, an opt-in OS keychain, and plaintext only as a last resort and banned in CI.
A user-settable AI base URL decides where your API key gets sent. Validating it to reject userinfo, non-HTTPS schemes and redirects.
Catching secrets by shape rather than by name: patterns for provider key prefixes, URL userinfo and auth headers, plus a fuzzy fallback.
Every finding in a security audit reduced to untrusted input reaching a powerful operation unchecked. One checked chokepoint per boundary fixes it.
Why a write-once boolean still needs a mutex: the Go memory model needs a happens-before edge before another goroutine is guaranteed to see it.
Reassigning a package-level function variable in tests is a latent data race that t.Parallel exposes. The fix is structural, not another lock.