Turning Complex Problems Into Confident Technology

Inside the Workshop

Real systems, with the reasoning left in.

Every entry here describes something I actually built or investigated: what the problem was, what I considered, what I chose, what it cost and what I would do differently. The architecture is sanitised and no confidential client is identified, but nothing is invented and nothing is tidied into a better story than it was.

This is not a blog and it is not on a schedule. Entries appear when there is something worth writing down, which is usually when a project is delivered or an investigation reaches a conclusion. If the most recent one is a few weeks old, that means I have been building rather than writing.

Start anywhere. If you would rather see how the site you are on is put together, start with how this site actually works.

Filter

Narrow it down

Every entry is listed below.

Entries

Thirteen write-ups

Proving a testimonial without asking anyone to trust me

A published testimonial is worth exactly what its verification is worth, and most sites verify nothing. The interesting problem was not the sign-in flow, it was deciding where verification stops.

Trust and identity · Production

This site publishes tools an AI agent can call

Most websites expect an agent to scrape them. This one registers tools a capable browser can invoke directly, and the build fails if the published list and the registered tools disagree.

Agents and machine access · Production, on a time-limited origin trial

How this site actually works

Two walk-throughs of this site's own machinery: what happens when you press send on the contact form, and what an AI agent sees when it arrives. The failure paths are shown rather than implied.

Reliability and cost · Production

The cleanup job that came for production

A scheduled registry purge deleted the image production was running on. The obvious fix had a hole in it, and the hole is the interesting part.

Reliability and cost · Production

Reading your own email authentication reports

Mail providers send daily reports on who is sending email as your domain, and almost nobody reads them. The ingestion was the easy half; knowing what your DNS actually publishes was the half that mattered.

Security and secrets · Production

Proving you honoured an unsubscribe

Every sending platform keeps its own list, and the obligation does not migrate when you change vendor. Most of the work was database permissions, not cryptography.

Trust and identity · Production

The build agent I killed, then rebuilt

Eight of twenty-six jobs failed and the VM was deleted after 32 hours. What the failures actually said, and what changed when it came back four months later.

Reliability and cost · Production

Fifteen API routes that never existed

A proxy with 170 routes, fifteen pointing at endpoints that were never there. Nothing caught them, because a compiled integration is not a verified one.

Integrating other people's systems · Production

A Windows service for one firewall rule

A dynamic IP against a locked-down key vault. The real alternative was never “keep running the script”, it was “widen the rule and forget”.

Security and secrets · Production

Deleting the last connection string

Four services moved off long-lived keys onto managed identity. The code change is trivial; the failure mode moving from startup to first use is not.

Security and secrets · Production

Also here

The case-study library

Fourteen shorter write-ups of delivered systems live alongside these, each describing a real system with its architecture and the reasoning behind it. They keep their existing addresses.

Next

If something here is your problem too

Consultancy

A problem that needs diagnosing before anyone decides what to build.

Consultancy

Freelance

A job that needs doing to a written scope and a price.

Freelance

Recruiters

Assessing whether this is the right contractor for a role.

Recruiters