About · Senior Software Engineer & Cloud Architect

About

I design, harden and cut the cost of production systems on Google Cloud, and write about the trade-offs.

I’m Nic Vannetti, a senior software engineer and cloud architect based in Italy. For 20+ years I’ve built backend systems and the platforms they run on, most recently on Google Cloud.

My work sits where architecture meets operations: designing services that are simple to run, locking down access with least-privilege IAM, and keeping the monthly bill proportional to the value a system delivers. Right now that includes a large-scale social platform I’m building, where I make — and live with — every one of those decisions.

I write here in English, in long form, because the interesting part of engineering is rarely the happy path. Each article starts from a decision I had to make, measure or fix, written up so the next person can decide faster.

Lately a lot of my attention goes to AI-assisted engineering: how to use tools like Claude Code across real codebases without lowering the bar on review, security or ownership.

01Career

  1. 2020 – present

    Senior Software & Solutions Architect | Lead Full-Stack Specialist · Aalto srl

    Strategic partner on enterprise architecture projects, internal portal development and technical consulting for complex organisations.

  2. 2006 – 2020

    Software Architect & Senior Full-Stack Developer · IT consulting & freelance

    Grew from application development into architecture consulting, data modelling and end-to-end ownership of systems for SMEs and larger companies.

02Stack I work with

Cloud

  • Google Cloud
  • Cloud Run
  • Pub/Sub
  • IAM & Workload Identity Federation
  • Secret Manager

Backend

  • Node.js
  • TypeScript
  • Fastify
  • OpenAPI & JSON Schema

Data

  • Firestore
  • Neo4j
  • Cloud Storage & CDN

Frontend

  • Next.js
  • React
  • Tailwind CSS

AI tooling

  • Claude Code
  • MCP servers
  • Hooks & skills

03Principles

  1. 01

    Cost is a feature.

    Spend is a design input, reviewed alongside latency and error rates.

  2. 02

    Boring infrastructure, interesting product.

    Plain, managed building blocks, so the novelty goes where users can see it.

  3. 03

    Measure before you optimise.

    No change ships without a number before and a number after.

  4. 04

    Least privilege by default.

    Access goes to groups, scoped to a job, and gets reviewed on a schedule.

  5. 05

    Write the decision down.

    A choice without a written reason gets made again, usually worse.

04Elsewhere