Three Valleys, One Gradient Step
A one-dimensional gradient descent lab records every update from three starting points and shows why the lowest observed result needs a separate global-minimum argument.
Hands-on labs in cybersecurity, devops, AI, and observability — every post comes with runnable code.
A one-dimensional gradient descent lab records every update from three starting points and shows why the lowest observed result needs a separate global-minimum argument.
One GPU VM serves an open-weight Qwen coding model with vLLM, Qwen Code with the Superpowers skills runs unattended in a locked-down container, and a verifier with hidden tests decides whether the agent really finished.
A LangChain agent in TypeScript that answers questions about a shop database through three typed tools, runs on four open-weight models on Amazon Bedrock, and signs in with aws login instead of an access key.
Follow a number through authenticated Pub/Sub delivery, separate runtime permissions from push identity, and distinguish acceptance from completion.
A chat app whose agent answers maths problems by writing Python and running it in a separate sandbox service, with a tool description generated from the sandbox itself.
Run the same shell executor with two Kubernetes configurations, then measure which workers can read private data and reach a local download fixture.
Turn staffing, delayed research savings, and a factory expansion into a small optimization model—and read what its answer actually proves.
Connect completed speech transcripts to local Postgres retrieval, a Responses agent, and queued Realtime audio—with persistent chat history.
Google's TimesFM 3.0 forecasts a series with no training and no API key, and it takes covariates now. On hourly PM2.5 in Milan, tomorrow's weather is worth 16% of the error — and yesterday's carbon monoxide, the strongest correlate in the dataset at +0.92, is worth slightly less than nothing. That gap is the whole point.
Alibaba's page-agent embeds a GUI agent directly in your web app — no headless browser, no extension, DOM-only. Getting it working takes an afternoon. Keeping the model credential out of the browser is the part that turns 'add an AI assistant' into 'operate an authenticated LLM relay', and it changes what your markup is for.
The managed Drive connector syncs every three hours, is console-only, and can no longer be pointed at a folder. So this lab writes the sync loop by hand — and then proves the two things a sync loop is actually judged on: an edit shows up, and a moved folder doesn't go stale.
Vertex AI Search hands you the entire retrieval stack — parsing, chunking, embedding, indexing, reranking, grounded answers with citations — behind one API. This lab stands it up with Terraform, then proves the answers really come from the corpus using ten facts no model could ever have been trained on.
Every network has a story about inbound traffic and a shrug about outbound. Here's the control that closes it — a private subnet with no route out, one Envoy gateway that allow-lists by FQDN, and the four statistics that finally answer how many requests went where, carrying how many bytes.
A private Telegram bot, a LangChain agent with four typed tools, and a mock indoor garden — all in one container that never accepts an inbound connection. Long polling is the trick that makes a home-lab AI device reachable from your phone without port-forwarding, a public URL, or a TLS certificate.
A miniature enterprise GCP landing zone — folders, a Shared-VPC host, two service projects, one front door, one back door — where a scripted verifier logs in as each project's identity and proves every isolation guarantee with a real allowed/denied API call.
An MCP server hands your agent the descriptions of its tools, and the model treats them as trusted context. Split one exfiltration instruction across three innocent-looking tools and no per-description scan will ever see it — but the model reassembles it and reads your SSH key out. Watch it happen against a local agent, then watch a guardrail shut it down. Fully offline.
Vibe-code an AI app in an afternoon and the model ends up wired to two of the most dangerous sinks a program has: the network and the shell. Watch a poisoned document leak a secret, watch a 'process my data' request become a reverse shell — then watch the same app, hardened, shut both down. Fully offline, on your laptop.
A migration that silently corrupts data and then commits cannot be rolled back — only recovered from. This lab provisions a real Cloud SQL for PostgreSQL instance with Terraform, breaks it on purpose, and lets a runner detect the damage, restore from backup, and prove the restore with checksums — with no human in the loop.
Add a Prometheus replica and every query sees every series twice; shard the targets and every query sees a slice of the truth. This lab builds both failure modes on purpose in a kind cluster, puts Thanos Query in front of them, and proves the fix with an automated verifier — same answers as an unscaled control install, shards exposed as partial, duplicates collapsed, and pods killed mid-run without a gap in the data.
Installing kube-prometheus-stack is where most tutorials stop and where the real work starts. This lab builds the customization layer teams actually need — recording rules with human-readable node names, twin dashboards that prove why they matter, and Grafana-managed alerts landing in your own TypeScript server — then breaks the cluster on purpose to watch all six alerts fire.
The same freshly downloaded app, watched from inside the kernel instead of in front of it. An eBPF sensor attributes every DNS answer and TCP connect to the exact process that made it — catching a covert beacon delegated to a dropped helper binary, the one thing a network proxy can name a destination but never a process for.
A freshly downloaded tool works fine — and quietly talks to domains its vendor doesn't own. Here's a transparent mitmproxy + dnsmasq gateway that forces an uncooperative app through it, reads three layers of egress evidence, and shows exactly where visibility ends.
Every Flux quickstart stops at the happy path. This laptop-sized lab breaks a Helm-based GitOps loop five ways on purpose — plaintext secrets, migration hooks, a broken upgrade, the dreaded stuck release, and manual drift — and shows the exact recovery mechanics for each.
The same vulnerable app from the exploit lab, caught for free — before any of it runs. Gitleaks and Semgrep on the source, Trivy on the build, and a Kyverno gate that refuses to admit the bad image. One command runs the whole gauntlet on your laptop and diffs vulnerable against hardened.
One URL, a throwaway Kubernetes cluster, and only open-source tools. Scan a live app with nuclei, then turn each finding into a stolen SSN, a root shell, a leaked API key, and a crashed pod — every step reproducible on your laptop.
OpenAI and Google will run 'deep research' for you in their cloud. This lab builds the miniature version — a LangGraph Deep Agents CLI in TypeScript, driven entirely by a 4B model in Ollama — and documents every trick it takes to make a small local model actually finish the loop.
A webmail client that removes every <script> from an email can still hand an attacker your CSRF token — one character at a time — using nothing but CSS. Here's the attack, running locally, and the three-layer fix that stops it.
A malicious Python package doesn't wait for you to import it — its setup.py runs at pip install time and can ship your credentials out first. Here's a laptop-sized sandbox that lets the install succeed while blocking and naming the leak.
A source-only scanner reads your .py files, but Python runs bytecode — and a shipped .pyc can diverge from its source so the code that executes is not the code you reviewed.