Search blips
- AI-augmented software developmentAdoptTechniquesNEW
AI-augmented software development (using AI assistants and agents to explore code, draft changes, write tests, and review work) is now our default way of building software. Engineers remain...
- AnsibleAdoptToolsNEW
Ansible is how we configure machines once they exist. It's agentless (it connects over SSH) and playbooks are readable YAML, so the same automation works for bare-metal servers in our datacenter and...
- AstroAdoptLanguages & FrameworksNEW
Astro is our framework for static sites: project documentation, websites, and this Technology Radar. It renders pages to static HTML at build time and ships no JavaScript unless a component needs it,...
- AzureHoldPlatformsNEW
We're placing Azure on hold. We've standardized on Google Cloud as our public cloud, and running a second hyperscaler doubles the identity, networking, security, and cost management we have to get...
- Bubble TeaAdoptLanguages & FrameworksNEW
Bubble Tea from Charm is our framework for building TUIs in Go. It's based on The Elm Architecture (a model, an update function, and a view), which keeps even complex interfaces predictable and...
- CloudEventsAdoptLanguages & FrameworksNEW
CloudEvents is a graduated CNCF specification for describing events in a common way: a small set of required attributes (`id`, `source`, `type`, and `specversion`) plus optional ones, with bindings...
- CUE for configurationAdoptLanguages & FrameworksNEW
We use CUE as our configuration language: to define schemas for configuration, validate YAML and JSON against them, and generate configuration where values are derived from one another. In CUE,...
- DaprTrialPlatformsNEW
Dapr (Distributed Application Runtime) is a graduated CNCF project that runs alongside an application and exposes common distributed-systems building blocks (service invocation, pub/sub, state...
- Event-driven architectureTrialTechniquesNEW
In an event-driven architecture, services publish facts about what has happened and other services react to them, instead of calling each other directly. It decouples producers from consumers, lets...
- GhosttyAdoptToolsNEW
Ghostty is our recommended terminal emulator. It's fast and GPU-accelerated, uses native UI on macOS and Linux, supports modern terminal protocols, and works well out of the box with little more than...
- GitHubHoldPlatformsNEW
We're placing GitHub on hold for new projects. Our source code, CI, and the provenance of our artifacts are core infrastructure, and we want them on infrastructure we control, alongside our private...
- GitLabAssessPlatformsNEW
We're assessing GitLab, in particular self-managed GitLab in our private datacenter, as the home for our source code and CI. It brings repositories, CI/CD, container and package registries, and...
- GNU GuixTrialPlatformsNEW
For immutable, repeatable machines we're trialing GNU Guix in preference to NixOS. Both build whole systems and packages from declarative, functional definitions. Guix uses Guile Scheme throughout,...
- GoAdoptLanguages & FrameworksNEW
Go is our default language for services, CLIs, and infrastructure tooling. It compiles to static binaries that cross-compile easily, its standard library covers most of what a service needs, and the...
- Google CloudAdoptPlatformsNEW
Google Cloud is our public cloud. We use it for workloads that need elastic capacity, global reach, or managed services we don't want to run ourselves, while steady-state workloads run in our private...
- HashiCorp ConsulAdoptPlatformsNEW
HashiCorp Consul provides service discovery, health checking, and a key/value store across our datacenter and cloud environments. Services register themselves and consumers find healthy instances...
- HashiCorp NomadAdoptPlatformsNEW
We schedule workloads with HashiCorp Nomad rather than Kubernetes. Nomad is a single binary that schedules containers, VMs, and plain executables, it integrates natively with Consul for service...
- HashiCorp VaultAdoptPlatformsNEW
HashiCorp Vault is our system of record for secrets. Applications get short-lived, dynamically generated credentials for databases and cloud providers, Vault's PKI engine issues our internal...
- Hermetic build environmentsTrialTechniquesNEW
A hermetic build declares every input up front (toolchain, dependencies, and source) and runs without network access, so the same inputs always produce the same outputs. Hermeticity makes builds...
- htmxAdoptLanguages & FrameworksNEW
htmx lets us build interactive web interfaces by returning HTML from the server and declaring behavior with HTML attributes such as `hx-get`, `hx-post`, `hx-target`, and `hx-swap`, rather than...
- ITIL 4TrialTechniquesNEW
ITIL 4 is a framework of service management practices organized around a service value system. We're trialing a lightweight subset (incident management, problem management, change enablement, and...
- MADRAdoptTechniquesNEW
MADR (Markdown Any Decision Records, originally Markdown Architectural Decision Records) is a lightweight template for recording decisions as Markdown files in the repository. Each record captures...
- NATSTrialPlatformsNEW
NATS is a lightweight, high-performance messaging system: a single small server binary offering publish/subscribe, request/reply, and queue groups, with multi-tenancy through accounts and leaf nodes...
- NATS JetStreamTrialPlatformsNEW
JetStream is the persistence layer built into the NATS server. It adds streams with configurable retention, durable consumers with acknowledgement and replay, and key/value and object stores, without...
- NeovimAdoptToolsNEW
Neovim is our recommended editor. It runs in the terminal, so it works the same in a remote workspace over SSH as it does locally; it has built-in LSP support for language-aware editing; and it's...
- OpenAPI/CLI + skillsAdoptTechniquesNEW
When we want AI agents to work with an internal system, we describe the system with an OpenAPI specification, ship a CLI built on it, and teach agents to use that CLI with a skill: a short Markdown...
- OryAdoptPlatformsNEW
Ory provides our identity and authorization stack as open-source, self-hostable services: Kratos for identity and user management, Hydra for OAuth 2.0 and OpenID Connect, Keto for fine-grained...
- Private datacenterAdoptPlatformsNEW
We run steady-state workloads in our own private datacenter. For predictable, always-on load, owned hardware costs far less than the equivalent cloud capacity, keeps data under our physical control...
- PythonHoldLanguages & FrameworksNEW
We're placing Python on hold for new services and tooling. Shipping Python reliably means managing an interpreter version, virtual environments, and a dependency tree that's hard to pin, vendor, and...
- RatatuiTrialLanguages & FrameworksNEW
Ratatui is the leading Rust library for building TUIs and the community-maintained successor to tui-rs. It renders immediate-mode widgets such as tables, charts, lists, and gauges with fine control...
- Red Hat UBI base imagesAdoptPlatformsNEW
Red Hat Universal Base Images (UBI) are our standard base for OCI container images. They're built from RHEL content, receive Red Hat's security updates, and can be freely redistributed, so the images...
- Remote development workspaces over localAdoptTechniquesNEW
We develop in remote workspaces (managed machines in our datacenter or cloud that developers reach over SSH) rather than on local laptops. Toolchains are defined once and identical for everyone,...
- Remote SSH applicationsAdoptTechniquesNEW
For internal applications we build terminal applications served over SSH rather than web applications. Users connect with `ssh` and authenticate with the keys or SSH certificates they already have,...
- RHELAdoptPlatformsNEW
We standardize on Red Hat Enterprise Linux for servers rather than Ubuntu. RHEL's long support lifecycle, SELinux enforcing by default, FIPS-validated cryptography, and broad vendor certification...
- RustTrialLanguages & FrameworksNEW
We're trialing Rust where its strengths matter most: performance-critical components, systems code, and anywhere memory safety bugs would be expensive. Its ownership model eliminates whole classes of...
- Sandboxed AI-augmented developer workspacesAdoptTechniquesNEW
AI coding agents run commands, install packages, and read whatever is within reach, and they can be steered by prompt injection hidden in issues, documentation, or dependencies. We run them in...
- SBOM generationAdoptTechniquesNEW
Every artifact we build ships with a software bill of materials (SBOM) in SPDX or CycloneDX format, generated in the build pipeline from the artifact itself rather than written by hand. SBOMs let us...
- SeaweedFSTrialPlatformsNEW
We're trialing SeaweedFS as our self-hosted, S3-compatible object store in place of MinIO. SeaweedFS is Apache-licensed, handles very large numbers of small files efficiently, and scales out with...
- SLSA build provenanceAdoptTechniquesNEW
We generate SLSA build provenance for every artifact: a signed in-toto attestation, produced by the build platform rather than the build script, that records what was built, from which source...
- SLSA v1.2AdoptTechniquesNEW
SLSA (Supply-chain Levels for Software Artifacts) is the OpenSSF framework for describing how trustworthy a software artifact's supply chain is, organized into tracks and levels. We use v1.2 of the...
- Specialized AI harnessesHoldToolsNEW
We're holding off on adopting a different specialized AI harness (a purpose-built agent tool or AI-first IDE) for each task. Every one brings its own configuration, permission model, and data...
- TerraformAdoptToolsNEW
Terraform is how we provision infrastructure in Google Cloud and our datacenter. Declarative configuration, a reviewable plan before every change, and providers for nearly every API mean...
- TUIAdoptTechniquesNEW
When an internal tool needs an interactive interface, we default to a text user interface (TUI) instead of a web UI. TUIs are keyboard-driven, start instantly, run over SSH, and ship as a single...
- Vendoring dependenciesAdoptTechniquesNEW
We vendor dependencies into the repository (`go mod vendor`, `cargo vendor`, and their equivalents) rather than fetching them at build time. Dependency updates arrive as reviewable diffs, builds work...
- VS CodeHoldToolsNEW
We're placing VS Code on hold as a default editor. Its remote development support installs a server into each remote workspace, its extension marketplace has become a supply chain risk with malicious...
- WireGuardAdoptToolsNEW
WireGuard is our VPN for connecting our private datacenter, Google Cloud, and engineers to the remote workspaces they work in. It's built into the Linux kernel, has a small codebase that's practical...