Notes on real-time systems, AI and shipping
Short, practical write-ups from production work: WebSockets at scale, agents and RAG, NestJS, Laravel, caching and deploys.
Watch queue depth trend, not the current number
Monitor queue depth over time from day one; the current number says little, but the slope tells you whether you have twenty minutes or two.
The systems I am proud of are built from boring parts
The best systems use boring parts like Postgres, a queue and a well-defined cache; the real engineering is in the failure handling.
Scaling 100k WebSocket connections: the reconnect storm
At 100k+ concurrent sockets, the hard part is not the count but the reconnect storm; jittered backoff, load shedding and resumable sessions fix it.
MCP went stateless, and that matters
The July MCP revision went stateless with OAuth 2.0 and OpenID Connect, so MCP servers can now run behind load balancers and serverless.
npm v12 blocks install scripts by default
npm v12 no longer runs preinstall, install or postinstall scripts unless you approve them, closing a common supply chain attack path.
Node.js moves to one major release a year
From Node 27, Node.js ships one major a year and every release becomes LTS, ending the odd/even split most teams already ignored.
How an endpoint got 45 percent faster with no clever code
Twenty minutes with a profiler beat a week of guessing: an N+1, a missing index and a useless cache made an endpoint 45 percent faster.
What actually breaks when AI agents go to production
Production agents fail on state, partial failure and knowing when to stop, which are distributed systems problems, not prompt problems.
Claude output is now watermarked
Claude output now carries watermarks and signed provenance by default; tell your users, and never treat a missing watermark as proof.
Splitting a monolith: what it actually bought us
Split a monolith for failure isolation and team ownership, not speed; if it is slow, profile first, since the cause is usually a missing index.
Handle SIGTERM or every deploy is a small outage
A Node service that ignores SIGTERM drops in-flight requests on every deploy; a short graceful shutdown handler fixes it.
What I stopped doing by hand with AI coding tools
AI tools took over my boilerplate, regex and first-draft tests; I ship faster, but I learn narrower, and that trade-off needs managing.
Mongo or Postgres is the wrong first question
Pick a database by your known access patterns; if you do not know them yet, pick Postgres, because it forgives wrong guesses best.
In RAG, retrieval is the product
Bad RAG answers usually come from bad retrieval, not a weak model; structural chunking, metadata filters and a small eval set fix more.
Build at night, decide in the morning
Late-night focus is great for writing code and bad for deciding what to build, so build at night and make decisions in the morning.
The hard part of passkeys is not WebAuthn
Implementing WebAuthn is the easy part of passkeys; the real work is account recovery and deciding whether a password fallback stays.
Caching mistakes I keep debugging
Before adding a cache, measure first, decide what invalidates it, set a TTL, and cache the expensive part rather than the whole result.
When GraphQL is worth it and when it is not
GraphQL pays off when many different clients need different slices of the same data; with one web client, REST usually wins on total effort.
Laravel ships the primitives Node developers rebuild by hand
Laravel ships primitives like debounced listeners and model-scoped locks that Node teams keep rebuilding by hand, and that is a culture difference.
Why I still write code as a tech lead
Leads should keep coding, but on the work nobody prioritizes, not the critical path, so their judgment stays sharp without blocking the team.
Green flags that someone is genuinely senior
A genuinely senior engineer volunteers a decision they got wrong and what it taught them, and asks about on-call before tech stack.
Use satisfies before you reach for as in TypeScript
Every `as` in TypeScript tells the compiler to stop checking; `satisfies` checks the shape and keeps the narrow type, so use it first.
At-least-once delivery means at least once
Every queue consumer will eventually run twice, so give each one an idempotency key and check it before doing the work.
Auto mode made code review the last human gate
With Claude Code's auto mode on by default, the approval prompt is gone as a safety layer, so code review is now the human gate that matters most.
Multi-tenancy with Laravel
Multi-tenancy is a software architecture in which a single instance of a software application serves multiple customers, called tenants. In the context of Laravel, multi-tenancy refers to the ability of a Laravel application to serve multiple tenants, each with their own separate database.