· 16 min
Setting up Claude Code for a multi-repo workspace
A layered CLAUDE.md, tight permissions, hooks, skills and scoped MCP servers: the setup that keeps Claude Code safe and cheap across dozens of repositories.
16 min
Writing · 10 articles
Long-form notes on designing, securing and running production systems, mostly on Google Cloud. Every article is written from a real decision, with the trade-offs and the numbers behind it. Filter by topic, or start with the newest.
· 16 min
A layered CLAUDE.md, tight permissions, hooks, skills and scoped MCP servers: the setup that keeps Claude Code safe and cheap across dozens of repositories.
16 min
· 14 min
What a Cloud Run cold start is made of, how to measure each phase, and which fixes, and which min-instances bill, actually shorten it for your service.
14 min
· 15 min
One validated config module per service, secrets bound at deploy time, and no fallbacks in code: a config setup that fails loudly instead of leaking quietly.
15 min
· 15 min
Firestore is superb at keyed reads and poor at friends-of-friends. When a graph database earns its place, and how to keep two stores honest.
15 min
· 13 min
How I structure Google Cloud IAM so people get access through groups, workloads get one keyless service account each, and every grant is small and auditable.
13 min
· 17 min
Pub/Sub will deliver some messages twice, and that is by design. Here is how to build consumers whose side effects happen once anyway, with working code.
17 min
· 19 min
Every upstream call spends money and quota. A layered defence of validation, rate limits, caching, single-flight and leases keeps both under control.
19 min
· 13 min
Early-stage systems rarely go broke on traffic. They bleed money while idle. How to design a GCP stack whose cost stays near zero when no one is using it.
13 min
· 16 min
Where the money goes when users upload photos, and a GCS upload-and-variants pipeline that lets a CDN serve small, immutable files for years.
16 min
· 14 min
Swap service account keys in GitHub secrets for short-lived OIDC tokens, lock the trust to your own repo, and deploy to Cloud Run with no JSON key.
14 min