Part 3: From Silent Servers to a Real-Time View
The disk filled at 4pm. I found out at 9pm. Going from a silent server to a real-time view of everything, without a per-seat SaaS bill.
Field notes · published via Aqilra
Security-grade engineering, from whiteboard to production. Notes written while building and running the lab's own systems — published on Aqilra, the lab's publishing platform.
The disk filled at 4pm. I found out at 9pm. Going from a silent server to a real-time view of everything, without a per-seat SaaS bill.
The fail-closed pipeline every change clears before production, the day it went red five times, and signed artifacts verified at runtime.
I have not been breached by a supply-chain attack. This is the drill I rehearse for anyway, in three acts: crisis, survival, advancement.
Short-lived tokens, rotating refresh, 2FA, email-match OAuth, and the one-call revocation I built the day I couldn't cleanly remove one person.
Three minutes after DNS resolved, the first bot arrived. What a live WAF monitor showed me, and the drift I found when I finally looked.
The whole posture behind live production systems, on one page. Four rings, six principles, and the disclosure discipline behind all of it.
All posts are written and hosted on Aqilra — the publishing platform built at this lab — and syndicated here via its RSS feed.