Pure-Rust Git, no git binary
Doing local Git from Rust with gix rather than shelling out to the git binary or linking libgit2, and why that avoids a lot of cross-compilation pain.


Doing local Git from Rust with gix rather than shelling out to the git binary or linking libgit2, and why that avoids a lot of cross-compilation pain.

Routing AWS GuardDuty and Security Hub findings so an alert still means something: forward high severity only, and drop the duplicates.

An accidental major version bump was the last straw after months of unreliability. Why a Go framework moved off GitHub, and what moved with it.

Why security-critical infrastructure got raw resources rather than community wrapper modules, and what that actually cost in lines and in review.

Applying a security baseline to a fresh AWS account: audit logging, config recording, threat detection and an operator role that is not root.

Replacing long-lived AWS access keys in CI with OIDC federation, so the pipeline mints a short-lived token instead of holding a secret.

AWS tagging in two layers: account-wide invariants on the provider default tags, resource specifics in the module, and which one wins on a clash.

Why a clap global flag stops working inside a passthrough subtree: the tokens get captured as trailing args before the flag is ever parsed.

Storage answers where a secret lives, not what happens to it in memory. Wrapping secrets so they redact in Debug and zero on drop.

The bootstrap stack has to create the bucket its own state lives in. Applying once with a local backend, then migrating the state into it.
