# Juanchi.dev — Nativo Digital

> Blog técnico personal de Juan Torchia (Software Architect, Argentina). Artículos bilingües (ES/EN) sobre arquitectura de software, performance, Next.js, TypeScript, Java, Spring Boot, ingeniería con IA/LLMs y productividad del desarrollador.

## About

- **Author**: Juan Torchia
- **Homepage**: https://juanchi.dev
- **Languages**: Spanish (es), English (en)
- **Topics**: software architecture, performance, Next.js, React, TypeScript, Java, Spring Boot, AI engineering, LLM tooling, developer experience

## Posts (Español)

- [pnpm vs npm vs yarn vs bun: la comparativa definitiva que nadie te va a dar en 2025](https://juanchi.dev/es/blog/pnpm-vs-npm-vs-yarn-vs-bun-comparativa-2025): Usé los cuatro en proyectos reales. Uno me rompió un monorepo a las 3am. Otro me salvó la vida en producción. Te cuento todo sin filtros.
- [Swiper: el slider táctil que no te va a arruinar el sprint](https://juanchi.dev/es/blog/swiper-slider-tactil-mobile-react-vue-angular-sin-dependencias): Swiper lleva años siendo el estándar indiscutido para carousels táctiles en la web. Sin dependencias, con wrappers oficiales para React, Vue y Angular, y transiciones que parecen n
- [Node.js: el runtime que cambió cómo pensamos el backend](https://juanchi.dev/es/blog/nodejs-runtime-javascript-backend-event-loop-ecosystem): Node.js no es solo 'JavaScript en el servidor'. Es un cambio de paradigma en cómo manejamos I/O. 30 años de historia con la tecnología me enseñaron a reconocer cuándo algo realment
- [Rate limiting en aplicaciones web: qué proteger antes de elegir una librería](https://juanchi.dev/es/blog/rate-limiting-aplicaciones-web-nextjs-2): Rate limiting no es una dependencia que se agrega al middleware y listo. Es una política de abuso. Antes de copiar el snippet de turno, hay que definir qué activo protegés, qué abu
- [Spring Boot Actuator: qué exponer, qué ocultar y qué mirar antes de agregar endpoints](https://juanchi.dev/es/blog/spring-boot-actuator-endpoints-seguridad-3): Actuator no es el problema. El problema es habilitarlo sin una política clara de exposición. Una guía prudente para usarlo como herramienta operativa sin convertirlo en superficie 
- [Netron: abrí cualquier modelo ML y mirá qué hay adentro](https://juanchi.dev/es/blog/netron-visualizador-modelos-ml-onnx-tensorflow-pytorch): Netron te deja inspeccionar la arquitectura de cualquier modelo ML sin Jupyter, sin código, sin dramas. ONNX, PyTorch, TensorFlow: lo abrís y ves todo.
- [Next.js App Router caching: revalidate, dynamic y no-store sin folklore](https://juanchi.dev/es/blog/nextjs-app-router-caching-revalidate-dynamic-no-store-3): El problema con Next.js caching no es memorizar los flags. Es decidir qué tan fresco necesita ser cada dato. Una guía para leer revalidate, dynamic y no-store como contratos de dat
- [Docker healthchecks: qué miden de verdad y qué no deberías prometer](https://juanchi.dev/es/blog/docker-healthcheck-buenas-practicas-que-miden-y-que-no): Un healthcheck que solo dice "el proceso responde" puede esconder fallas de negocio completas. Qué mide de verdad Docker HEALTHCHECK, dónde la gente lo sobreestima y una matriz de 
- [Firma digital: diferencia entre formato, certificado y política de validación](https://juanchi.dev/es/blog/firma-digital-formato-certificado-politica-validacion-3): No todo error de firma es un problema criptográfico. Muchas veces el quilombo está en el formato elegido, en el certificado que no aplica, o en la política de validación que el val
- [Sniffnet: monitoreá tu red sin volverte loco con tcpdump](https://juanchi.dev/es/blog/sniffnet-monitor-trafico-red-ui-accesible-rust): Sniffnet es un monitor de tráfico de red multiplataforma escrito en Rust. UI real, gráficos en tiempo real, sin necesitar un título en seguridad para entender qué está pasando.
- [XGBoost: gradient boosting que dominó Kaggle y sobrevivió al hype](https://juanchi.dev/es/blog/xgboost-gradient-boosting-datos-tabulares-produccion): XGBoost no es moda: es el algoritmo que ganó cientos de competencias de ML con datos tabulares. Por qué sigue siendo referencia obligada en 2025 y cuándo usarlo.
- [PyTorch: el framework de deep learning que ganó la guerra](https://juanchi.dev/es/blog/pytorch-framework-deep-learning-estandar-investigacion-produccion): PyTorch apareció en 6 awesome lists independientes y el motivo es simple: ganó. No es hype, es infraestructura. Te cuento por qué está en nuestra lista y cuándo tiene sentido usarl
- [TensorFlow: el elefante de ML que sigue en pie](https://juanchi.dev/es/blog/tensorflow-framework-ml-produccion-deployment-escala): TensorFlow no es sexy en 2025, pero sigue siendo la infraestructura seria detrás de deployment a escala. Por qué está en la lista y cuándo realmente lo necesitás.
- [Rate limiting en Next.js: qué proteger antes de elegir una librería](https://juanchi.dev/es/blog/rate-limiting-aplicaciones-web-nextjs-politica-abuso): Rate limiting no es una dependencia npm: es una política de abuso. Antes de copiar middleware, necesitás definir qué activo protegés, qué patrón de abuso esperás y cuánto te cuesta
- [Dependencias npm: cómo evaluar una librería antes de meterla en producción](https://juanchi.dev/es/blog/evaluar-dependencias-npm-seguridad-mantenimiento): Sumar una dependencia npm no es solo instalar código: es asumir su mantenimiento, su superficie de ataque y sus deps transitivas. Acá está la checklist que uso antes de agregar cua
- [Cómo construí un pipeline editorial con IA que se audita a sí mismo](https://juanchi.dev/es/blog/pipeline-editorial-ia-juanchi-dev): El README de juanchi.dev dice "portfolio landing". El código dice otra cosa: un sistema editorial con ingesta de repos, gate de calidad, reescritura automática y crons en Railway. 
- [lode: Reimplementando el core de DVC en Go sin romper el formato](https://juanchi.dev/es/blog/lode-dvc-compatible-data-versioning-go): lode reimplementa el hot path de DVC en Go con un invariante no negociable: compatibilidad byte-idéntica con DVC 3.x. Binario estático, hashing paralelo, state DB que evita re-hash
- [OWASP LLM Top 10 en producción: cómo audité mi pipeline de agentes TypeScript contra los 10 riesgos y qué encontré](https://juanchi.dev/es/blog/owasp-llm-top-10-agentes-produccion-typescript): Aplicar el OWASP LLM Top 10 como auditoría real es muy distinto a leerlo como lista. Lo corrí contra mi stack de agentes TypeScript con system prompts, MCP tools y Cline — y los ha
- [pnpm workspaces en monorepo: el setup que sobrevivió CI en Railway y los problemas que los docs no anticipan](https://juanchi.dev/es/blog/pnpm-workspaces-monorepo-ci-railway-problemas): pnpm workspaces es la mejor opción para monorepos TypeScript en 2026. Pero el path de felicidad de los docs esconde tres trampas que solo aparecen en CI con deployment real: phanto
- [OAuth 2.0 Scope Creep: el vector de ataque que el incidente de Vercel dejó al descubierto y cómo auditarlo en tus integraciones](https://juanchi.dev/es/blog/oauth-scope-creep-auditoria-integraciones-terceros-seguridad): El incidente de Vercel no fue una vulnerabilidad técnica: fue un fallo de principio de mínimo privilegio aplicado a OAuth. Analizá qué es el scope creep, cómo auditarlo en integrac
- [Functional programming en TypeScript: las abstracciones que realmente uso y las que abandoné](https://juanchi.dev/es/blog/functional-programming-typescript-produccion): Empecé queriendo escribir Haskell en TypeScript y terminé con tres helpers y una lección. Análisis honesto de qué patrones funcionales sobreviven en una codebase TypeScript real y 
- [Spring Boot Actuator: qué exponer, qué ocultar y qué mirar antes de agregar endpoints](https://juanchi.dev/es/blog/spring-boot-actuator-endpoints-seguridad-2): Actuator no es el problema. El problema es habilitarlo sin una política clara de exposición. Una guía prudente para usarlo como herramienta operativa sin convertirlo en superficie 
- [OpenTelemetry en Next.js: traces que sobreviven el edge y el servidor sin perder el contexto](https://juanchi.dev/es/blog/opentelemetry-nextjs-traces-edge-runtime-contexto): OpenTelemetry en Next.js funciona, pero el propagador por defecto rompe silenciosamente el trace en la frontera edge/node. Esto es lo que tenés que configurar explícitamente para q
- [Cómo difieren los CVEs de memory safety entre Rust y C/C++](https://juanchi.dev/es/blog/como-difieren-cves-memory-safety-rust-c-cpp): Rust tiene menos CVEs de memoria que C/C++, pero eso no es toda la historia. Mi análisis de qué dice ese dato, qué no dice, y cómo convertirlo en una decisión técnica real.
- [Lo que las entrevistas de trabajo me enseñaron sobre Kubernetes](https://juanchi.dev/es/blog/entrevistas-de-trabajo-ensenaron-sobre-kubernetes): Las entrevistas técnicas de Kubernetes tienen un problema que nadie nombra: te preguntan por objetos que jamás vas a tocar en producción, pero ignoran los errores que sí rompen sis
- [My Homelab AI Dev Platform: qué problema real señala y dónde están los límites](https://juanchi.dev/es/blog/homelab-ai-dev-platform-decision-tecnica): La comunidad de homelabbers está armando plataformas de desarrollo con IA local y la discusión está buena. Yo tengo algunas observaciones que van más allá del entusiasmo inicial — 
- [The Birth and Death of JavaScript (2014): qué sigue siendo verdad y qué ya no](https://juanchi.dev/es/blog/the-birth-and-death-javascript-2014-analisis-tecnico): Una charla de 2014 predijo que JavaScript moriría reemplazado por ASM.js. Una década después, JS sigue vivo pero la tensión que señaló es más real que nunca. Esto es lo que convien
- [Métodos formales y el futuro de la programación: qué vale la pena probar y dónde está el techo](https://juanchi.dev/es/blog/metodos-formales-futuro-programacion-decision-tecnica): Formal methods aparece cada tanto en el radar técnico como la solución que la industria ignoró. Mi lectura: el problema que señala es real, pero la receta que circula omite costos 
- [El "LLM propio" de Río de Janeiro parece ser un merge: qué leer entre líneas](https://juanchi.dev/es/blog/rio-janeiro-homegrown-llm-appears-merge-lectura-tecnica): Un municipio anuncia un LLM "propio" y la comunidad técnica descubre que podría ser un merge de un modelo existente. Mi lectura: el problema real no es el fraude, es que casi nadie
- [Tokens de autenticación: JWT, Paseto y session tokens — el árbol de decisión que me faltaba](https://juanchi.dev/es/blog/jwt-paseto-session-tokens-arbol-decision-typescript): No existe el token perfecto, existe el token correcto para el modelo de amenaza de cada sistema. Árbol de decisión práctico con criterio técnico real para elegir entre JWT, Paseto 
- [Zod en el servidor y en el cliente: el schema que creés una vez y las tres formas en que se rompe en runtime](https://juanchi.dev/es/blog/zod-typescript-validacion-runtime-produccion): Zod se vende como 'definí una vez, validá en todos lados'. En Next.js 16 con Server Actions, edge middleware y API routes, eso es solo parcialmente cierto. Tres modos de falla conc
- [Prisma query logging y PostgreSQL: cuándo alcanza el ORM y cuándo tenés que ir más abajo](https://juanchi.dev/es/blog/prisma-query-logging-postgresql-cuando-usar): Los logs de Prisma Client muestran qué queries generó el ORM. PostgreSQL tiene su propia capa de observabilidad. Confundir una con la otra es la fuente de diagnósticos incompletos.
- [Next.js App Router caching: revalidate, dynamic y no-store sin folklore](https://juanchi.dev/es/blog/nextjs-app-router-caching-revalidate-dynamic-no-store-2): El problema con el caching en Next.js App Router no es memorizar flags. Es entender qué frescura necesita cada dato y tratarlo como un contrato explícito, no como un truco aislado 
- [MCP Model Context Protocol en TypeScript: diseñá tools portables entre Claude, GPT y modelos locales](https://juanchi.dev/es/blog/mcp-model-context-protocol-typescript-tools-portables): El error más común al implementar MCP tools es acoplarlas al SDK del proveedor. La spec existe para evitar exactamente eso. Guía práctica de diseño desde arquitectura: el contrato 
- [Web Crypto API en el browser vs Node.js: las diferencias que te van a quemar](https://juanchi.dev/es/blog/web-crypto-api-browser-nodejs-diferencias-typescript): Web Crypto API parece una sola cosa hasta que intentás reutilizar el mismo código de cifrado en browser, Node.js y el edge runtime de Next.js. Las diferencias son sutiles, están do
- [React 19 Server Components y caching: el modelo mental que me faltaba después de leer la documentación](https://juanchi.dev/es/blog/react-19-server-components-caching-modelo-mental): No es otro tutorial de RSC. Es el mapa conceptual que construí después de leer la doc oficial y entender por qué el folklore sobre 'siempre usar use client' es incorrecto — y qué p
- [HyperFrames explicandose a si mismo: como arme un video tecnico reproducible desde HTML](https://juanchi.dev/es/blog/hyperframes-video-tecnico-reproducible-html): Use HyperFrames para crear un video sobre HyperFrames y deje abierto todo el proceso: repo, comandos, errores, capturas, audio, captions, renders y evidencia.
- [Cline en VS Code: lo usé dos semanas en un proyecto TypeScript y esto sobrevivió](https://juanchi.dev/es/blog/cline-vs-code-agente-coding-typescript-produccion): Dos semanas usando Cline como agente autónomo de coding en un proyecto TypeScript. Qué tareas delegué, dónde se equivocó, cómo se compara con Claude Code y qué workflows no le darí
- [Rate limiting en aplicaciones web: qué proteger antes de elegir una librería](https://juanchi.dev/es/blog/rate-limiting-aplicaciones-web-nextjs): Antes de copiar middleware de rate limiting, definí qué activo protegés, qué abuso esperás y cuánto te cuesta un falso positivo. Sin eso, la librería no resuelve nada.
- [Next.js 16 Middleware: patrones de autorización que escalan y los que generan race conditions](https://juanchi.dev/es/blog/nextjs-16-middleware-autorizacion-patrones-race-conditions): Probé 4 patrones de autorización en Next.js 16 Middleware con edge runtime. Uno genera race conditions silenciosas, otro te da latencia inesperada, y uno solo escala sin compromiso
- [Prisma 5 → Prisma 6: los breaking changes que encontré en mi schema real y cómo los resolví sin romper producción](https://juanchi.dev/es/blog/prisma-6-migration-breaking-changes): Prisma 6 mejora ergonomía y performance, pero hay tres cambios de comportamiento que no gritan en el compilador y sí aparecen en runtime si no revisás tus queries relacionales. Guí
- [tsgo: qué cambia en el compilador TypeScript reescrito en Go y qué significa para proyectos reales](https://juanchi.dev/es/blog/tsgo-typescript-compiler-go-que-cambia-proyectos-reales): tsgo es real y el salto de performance es verificable, pero la beta tiene límites documentados que la mayoría ignora. Acá está el criterio concreto para saber si vale explorarlo ho
- [React 19 use() hook y Suspense: cuándo reemplaza useEffect y cuándo te mete en un loop peor](https://juanchi.dev/es/blog/react-19-use-hook-suspense-vs-useeffect): El hook use() de React 19 promete reemplazar useEffect para data fetching. La promesa es parcialmente cierta. Hay dos patrones con Suspense y error boundaries donde el comportamien
- [Spring Boot Actuator: qué exponer, qué ocultar y qué mirar antes de agregar endpoints](https://juanchi.dev/es/blog/spring-boot-actuator-endpoints-seguridad): Actuator no es malo. El error es sumarlo a un proyecto sin una política clara de exposición. Acá desarmamos qué endpoints habilitar, cuáles bloquear y qué decisiones tomar antes de
- [TypeScript strict mode: las 6 opciones del tsconfig que más impactan en producción y cuándo activarlas](https://juanchi.dev/es/blog/typescript-strict-mode-tsconfig-opciones-produccion): strict: true no es suficiente ni es lo único que importa. Un análisis opción por opción de qué hace cada flag del strict mode, qué errores previene y en qué orden activarlos en una
- [Arquitectura backend de identidad digital: las decisiones que los tutoriales omiten](https://juanchi.dev/es/blog/arquitectura-backend-identidad-digital-jwt-oauth): Los tutoriales de auth muestran el happy path. Los problemas reales de identidad digital aparecen en la revocación, la propagación de cambios de estado y el modelo de confianza. Un
- [Firma digital: formato, certificado y política de validación — tres capas que se confunden constantemente](https://juanchi.dev/es/blog/firma-digital-formato-certificado-politica-validacion): Cuando una firma digital falla, el instinto es ir a la criptografía. Casi siempre es el lugar equivocado. Acá separo las tres capas — formato, certificado y política de validación 
- [System prompts para agentes en producción: el formato que sobrevivió 3 rediseños](https://juanchi.dev/es/blog/system-prompt-estructura-agentes-produccion-typescript): Un system prompt no es documentación para el modelo: es un contrato. Después de varios rediseños, llegué a un formato con secciones fijas, límites explícitos y contexto inyectado d
- [Docker healthchecks: qué miden de verdad y qué no deberías prometer](https://juanchi.dev/es/blog/docker-healthcheck-buenas-practicas-que-miden): Un healthcheck que solo dice "el proceso responde" puede esconder fallas de negocio graves. Analizamos qué promete de verdad la instrucción HEALTHCHECK, dónde falla la receta están
- [El benchmark que me hizo cambiar de opinión sobre Jakarta EE en 2026](https://juanchi.dev/es/blog/spring-boot-payara-glassfish-benchmark-java-enterprise): Mismo backend, misma base, mismo k6. En las primeras corridas parecía que Embedded GlassFish mandaba. Cuando ajusté JDK, warmup, ventana, heap y atribución de DB, la historia cambi
- [Prisma query logging y PostgreSQL: dónde termina el ORM y empieza la base](https://juanchi.dev/es/blog/prisma-query-logging-postgresql-cuando-mirar-la-base): Los query logs de Prisma ayudan a detectar patrones, pero si el problema vive adentro de PostgreSQL, el ORM no va a mostrártelo. Acá separo cuándo alcanza con Prisma logging y cuán
- [Next.js App Router caching: revalidate, dynamic y no-store sin folklore](https://juanchi.dev/es/blog/nextjs-app-router-caching-revalidate-dynamic-no-store): El problema con el cache en App Router no es memorizar flags. Es decidir qué frescura necesita cada dato antes de escribir una sola línea de configuración.
- [Vivado 2026.1 y Linux: por qué la decisión importa más allá del titular](https://juanchi.dev/es/blog/vivado-2026-dropping-linux-support-free-tier-analisis): Vivado 2026.1 parece estar eliminando soporte Linux para la tier gratuita. Antes de entrar en pánico o ignorarlo, convertí la noticia en una decisión técnica verificable: qué impac
- [Rate limiting en aplicaciones web: qué proteger antes de elegir una librería](https://juanchi.dev/es/blog/rate-limiting-aplicaciones-web-nextjs-que-proteger-antes-de-elegir-libreria): Antes de instalar cualquier middleware de rate limiting en Next.js, necesitás definir qué activo protegés, qué abuso esperás y qué cuesta un falso positivo. La librería es lo últim
- [Por qué dejé de usar useEffect para sincronizar estado y qué uso ahora](https://juanchi.dev/es/blog/useeffect-sincronizar-estado-alternativa-react-19): useEffect no está roto — el modelo mental con el que lo enseñamos sí lo está. Revisé cada useEffect de una codebase en React 19 y encontré 4 categorías concretas donde era un antip
- [Prisma Server Actions en Next.js 16: los patrones que funcionan y el N+1 que aparece cuando no lo esperás](https://juanchi.dev/es/blog/prisma-server-actions-nextjs-16-n1-produccion): Prisma en Server Actions de Next.js 16 tiene un vector de N+1 que no existe en API routes clásicas. El culpable no es el ORM — es cómo las Actions se componen. Acá están los patron
- [Spring Boot 2026: por qué medir solo startup time es una trampa](https://juanchi.dev/es/blog/spring-boot-startup-time-2026-graalvm-native-aot-cds): Armé un laboratorio reproducible con Spring Boot 3.5, Java 21, AppCDS, AOT y GraalVM Native. La conclusión no es que native gana ni que JVM clásica pierde: es que en 2026 comparar 
- [Show HN: Needle distilled Gemini tool calling en 26M parámetros — lectura técnica sin hype](https://juanchi.dev/es/blog/show-needle-distilled-gemini-tool-calling-modelo-pequeno-analisis): Un modelo de 26M de parámetros entrenado con destilación de Gemini para tool calling apareció en HN y me hizo parar todo. No para celebrar, sino para entender qué problema real señ
- [OpenTelemetry en Spring Boot 3: cuando el log dice OK y el trace muestra el problema](https://juanchi.dev/es/blog/opentelemetry-spring-boot-logs-vs-traces-diagnostico): OpenTelemetry no mejora la performance. Mejora la calidad del diagnóstico cuando una request lenta mezcla DB, downstream, N+1 y errores parciales. Este laboratorio reproducible mue
- [Prisma vs JDBC: el benchmark que casi me hace culpar al ORM equivocado](https://juanchi.dev/es/blog/prisma-vs-jdbc-benchmark-query-shape-n1): Armé un laboratorio reproducible para comparar Prisma 5 contra Spring Boot JdbcTemplate sobre el mismo PostgreSQL 16. Lo que encontré no fue un ganador: fue que el shape de la quer
- [Retry no es gratis: presupuesto, amplificación y el costo que no aparece en el p95](https://juanchi.dev/es/blog/retry-backoff-jitter-spring-boot-amplification): Un experimento reproducible con Spring Boot 3, Java 21 y k6 para medir cuándo un retry mejora disponibilidad y cuándo amplifica una caída. La métrica que importa no es el p95: es e
- [HikariCP: el p95 que te miente y cómo leer las señales reales del pool](https://juanchi.dev/es/blog/hikaricp-configuracion-spring-boot-postgresql-senales-pool-exhaustion): Un p95 bajo con 97% de error rate no es un pool rápido: es un pool que falla rápido. Armé un experimento reproducible con Spring Boot 3, PostgreSQL y k6 para entender qué señales i
- [pnpm workspaces: el caché de CI que sobrevivió al fix y me costó 40 minutos de build](https://juanchi.dev/es/blog/pnpm-workspaces-cache-github-actions-ci-problema): El CI funcionaba. El caché no. Cuarenta minutos de build por run porque pnpm no encontraba el store en GitHub Actions. Acá están los logs, el YAML antes y después, y la configuraci
- [Spring Security con Spring Boot Actuator: así quedó el modelo de autorización después del incidente](https://juanchi.dev/es/blog/spring-boot-actuator-security-spring-security-produccion-modelo-autorizacion): Cerrar los endpoints de Actuator no alcanza. Después del incidente, reconstruí el modelo de autorización desde cero: SecurityFilterChain explícito, health groups separados, roles p
- [pnpm workspaces en monorepo con Next.js 16: lo que el benchmark no midió y casi me rompe el CI](https://juanchi.dev/es/blog/pnpm-workspaces-monorepo-nextjs-ci-cache-problemas): El benchmark de install time que publiqué antes no capturó el verdadero costo de pnpm workspaces en CI: cache invalidation silenciosa, hoisting de dependencias que rompe en App Rou
- [Spring Boot Actuator en producción: los endpoints que dejé abiertos sin darme cuenta y cómo los cerré](https://juanchi.dev/es/blog/spring-boot-actuator-endpoints-seguridad-produccion): Después de publicar el análisis de Jakarta EE vs Spring Boot, revisé los defaults de Actuator en un backend propio y encontré endpoints sensibles abiertos que nunca configuré consc
- [pnpm vs npm vs yarn en 2026: lo corrí en mi monorepo real y el resultado me obligó a cambiar de criterio](https://juanchi.dev/es/blog/pnpm-vs-npm-2026-monorepo-benchmark-real): Corrí los tres package managers en el mismo monorepo Next.js 16 + TypeScript estricto con Shadcn/ui y Radix UI. pnpm gana en disco y CI — pero tiene un costo de compatibilidad real
- [Jakarta EE vs Spring Boot en 2026: migré un backend de producción y los tradeoffs no son los que esperaba](https://juanchi.dev/es/blog/jakarta-ee-vs-spring-boot-2026-migracion-backend-produccion-tradeoffs): Migré un backend de firma digital de Spring Boot 3.x a Jakarta EE 11. Los benchmarks sintéticos prometían maravillas. La producción real me dijo otra cosa. Acá están los números, l
- [Themis vs Web Crypto API: cifrado en TypeScript y tradeoffs no obvios](https://juanchi.dev/es/blog/themis-vs-web-crypto-api-cifrado-typescript-tradeoffs): Comparar Themis con Web Crypto API no es un ejercicio academico: cambia bundle, threat model, rotacion de claves y donde conviene poner cada responsabilidad. Los tradeoffs son meno
- [Functional programming en TypeScript: que sobrevive fuera de los ejemplos bonitos](https://juanchi.dev/es/blog/functional-programming-typescript-produccion-patrones-sobreviven): Functors, monads y pipe() pueden verse impecables en ejemplos chicos, pero en flujos reales con Next.js, Server Actions y Prisma aparecen costos de lectura, bundle y onboarding que
- [Spring Boot en produccion real: defaults que la documentacion oficial no enfatiza](https://juanchi.dev/es/blog/spring-boot-produccion-defaults-jvm-railway): Spring Boot funciona muy bien en produccion, pero sus defaults no siempre calzan con PaaS, memoria acotada y observabilidad real. Estos son los puntos que conviene revisar antes de
- [Clipboard API falla en TypeScript: los 4 casos que nadie documenta y cómo los encontré en mi código](https://juanchi.dev/es/blog/clipboard-api-falla-typescript-casos-copytoClipboard-no-documentados): navigator.clipboard.writeText parece trivial hasta que tu app falla en producción sin error visible. Encontré 4 casos que los docs no mencionan: contexto inseguro, foco perdido, pe
- [Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen](https://juanchi.dev/es/blog/supply-chain-attack-npm-pypi-diferencias-vector-comparacion-simulaciones): Corrí simulaciones de supply chain attack sobre npm y PyPI por separado. Cuando los puse uno al lado del otro, el patrón que emergió me incomodó: el ecosistema que todo el mundo vi
- [Después del guardrail que me salvó la infra: así quedó mi arquitectura de agentes autónomos en producción](https://juanchi.dev/es/blog/arquitectura-agentes-autonomos-produccion-permisos-rediseno-post-incidente): El incidente con el agente autónomo me obligó a rediseñar todo desde los permisos hasta la observabilidad. Esto es lo que quedó parado en producción después de la crisis: el grafo 
- [npm audit no alcanza: simulé un supply chain attack sobre mis dependencias de Node y encontré lo que el scanner no ve](https://juanchi.dev/es/blog/supply-chain-attack-npm-dependencias-node-produccion-simulacion-real): npm audit te dice que estás seguro. Lo puse a prueba con metodología real sobre mis dependencias de producción y encontré tres vectores que el scanner ni registra. El ecosistema No
- [Mutex deadlock en producción: los patrones que encontré en mi codebase y cómo los diagnostiqué](https://juanchi.dev/es/blog/mutex-deadlock-rust-async-produccion-patrones-diagnostico-codebase-real): Tres deadlocks en producción, todos con la misma cara: el servicio dejaba de responder sin error, sin panic, sin log. Lo que encontré al diagnosticarlos cambió cómo pienso el diseñ
- [Guardrails reales para agentes autónomos después de que uno casi me destruye la infra](https://juanchi.dev/es/blog/agentes-ia-guardrails-produccion-controles-reales-infra): Después de que un agente autónomo casi me borra la base de datos de producción, implementé una capa de guardrails real. Acá están los controles, el código y los logs que me salvaro
- [Async Rust nunca salió del MVP: lo validé contra casos reales y encontré exactamente los edge cases que el post de HN predice](https://juanchi.dev/es/blog/async-rust-problemas-produccion-edge-cases-validacion-codebase-real): 434 puntos en HN argumentan que Async Rust sigue siendo un MVP glorificado. Repliqué cada crítica concreta contra código de ejemplo reproducible: executor leaks, cancellation safet
- [Docker Compose en producción en 2026: corrí mi stack real durante 30 días y estos son los números](https://juanchi.dev/es/blog/docker-compose-produccion-2026-stack-real-30-dias-numeros): Un hilo de HN con 398 puntos reabrió el debate: ¿Docker Compose en producción es legítimo o un antipatrón? Corrí mi stack real en Railway durante 30 días y traje los números. Spoil
- [Agentes que crean cuentas, compran dominios y despliegan solos: lo probé contra mi stack real y esto rompió (y esto funcionó)](https://juanchi.dev/es/blog/agentes-ia-deploy-autonomo-cloudflare-railway-stack-real): El demo viral de HN muestra agentes de Cloudflare ejecutando el ciclo completo de infra sin intervención humana. Lo repliqué contra mi stack en Railway y documenté exactamente qué 
- [Entrené mi propio LLM desde cero en 2025: lo que el tutorial viral de HN no te dice sobre el costo real](https://juanchi.dev/es/blog/entrenar-llm-desde-cero-2025-costo-real-tutorial-hacker-news): Seguí el tutorial viral de HN de 241 puntos y documenté cada peso gastado, cada hora de GPU y cada decepción. Mi tesis: entrenar un LLM desde cero en 2025 es un ejercicio técnico v
- [Chrome instaló 4 GB de IA en mi máquina sin pedirme permiso: inspeccioné qué hace realmente y no me gusta lo que encontré](https://juanchi.dev/es/blog/chrome-google-ai-model-install-without-consent-inspeccion-real): Un thread de HN con 204 puntos denuncia que Chrome instala silenciosamente un modelo de 4 GB. Fui a mi propia máquina, encontré el modelo, inspeccioné rutas, permisos y consumo de 
- [Bun migra de Zig a Rust: lo que mis benchmarks reales dicen sobre si el cambio importa](https://juanchi.dev/es/blog/bun-rust-migration-performance-benchmarks-reales-nodejs): 489 + 506 puntos en HN. Bun se porta a Rust y todo el mundo tiene una opinión. Yo corrí los benchmarks en mi stack real antes de opinar. El resultado incómodo: el lenguaje subyacen
- [Tar en macOS destroza archivos en Linux: lo validé en mi pipeline real de Railway y documenté los 3 casos que nadie menciona](https://juanchi.dev/es/blog/tar-macos-linux-error-extraccion-produccion-railway-pipeline): Un post de HN sobre tar en macOS volvió a circular esta semana. La respuesta estándar es "usá GNU tar". Yo fui más lejos: reproduje los 3 escenarios que realmente rompen producción
- [Agentic coding no es una trampa: le respondí al post viral de HN con mis propios logs de producción](https://juanchi.dev/es/blog/agentic-coding-productividad-real-produccion-logs-hacker-news-respuesta): 367 puntos en HN dicen que agentic coding es una trampa. Yo tengo logs que dicen algo más incómodo: a veces ahorra 3 horas, a veces me manda a un rabbit hole de 4. La diferencia no
- [DeepClaude: combiné Claude Code con DeepSeek V4 Pro en mi loop de agentes y los números me desconcertaron](https://juanchi.dev/es/blog/deepclaude-claude-code-deepseek-agente-coding-benchmark-produccion): Tomé el repo DeepClaude (467 puntos en HN) y lo metí en mi loop real de producción. La combinación no es simplemente "mejor que cada uno solo" — hay un régimen de tareas donde Deep
- [Specsmaxxing: escribí mis specs en YAML para mis agentes y esto cambió (y esto no)](https://juanchi.dev/es/blog/specsmaxxing-specs-yaml-agentes-ia-desarrollo-claude-code): El specsmaxxing promete curar la "AI psychosis" con specs en YAML para agentes. Lo apliqué sobre mi flujo real con Claude Code y descubrí la trampa que nadie menciona: el problema 
- [Barman reemplaza a pgbackrest: migré mis backups de Postgres en producción y esto encontré](https://juanchi.dev/es/blog/barman-postgresql-backup-produccion-migracion-pgbackrest-railway): pgbackrest quedó sin mantenimiento. Barman aparece trending en HN justo después. Hice la migración real en Railway, medí tiempos de restore, tamaño de backup y complejidad de confi
- [Kimi K2.6 vs Claude vs GPT-5.5: lo puse contra mis casos reales de coding y los números me sorprendieron](https://juanchi.dev/es/blog/kimi-k2-6-benchmark-coding-claude-gpt-comparacion-codebase-real): El hype dice que Kimi K2.6 venció a Claude y GPT-5.5 en coding. Lo corrí contra mi propio codebase — no contra HumanEval cherry-picked — y lo que encontré cambia la pregunta que de
- [Canonical bajo DDoS: lo que mis logs de Railway y uptime dicen sobre mi exposición real](https://juanchi.dev/es/blog/ubuntu-ddos-2025-impacto-produccion-railway-logs-indie): El DDoS a Canonical llegó a 178 puntos en HN y la mayoría de los devs lo leyó como noticia externa. Yo lo leí como un espejo. Revisé mis logs de Railway, mis pipelines de Docker y 
- [Spotify Verified para artistas humanos: lo que esto anticipa para el código, el contenido y mi propio blog](https://juanchi.dev/es/blog/spotify-verified-human-artist-ai-codigo-contenido-blog): El badge "human artist" de Spotify llegó a 243 puntos en HN. No es un problema de la música. Es un leading indicator. Si la música ya necesita probar que un humano la hizo, el códi
- [The gay jailbreak: probé la técnica viral sobre mis propios prompts de producción y esto encontré](https://juanchi.dev/es/blog/llm-jailbreak-tecnica-viral-prompts-produccion-auditoria-2025): 524 puntos en HN sobre una técnica de jailbreak trending. En lugar de leer el thread, la corrí contra mis propios prompts de producción. Lo que encontré no es un caso aislado — es 
- [Linux kernel vulnerabilidades sin aviso a distros: lo que esto cambia en mi stack Ubuntu/Railway](https://juanchi.dev/es/blog/linux-kernel-vulnerabilidades-distribuciones-produccion-ubuntu-railway): Las distros se enteran de las vulnerabilidades del kernel al mismo tiempo que el público. Corro en Railway sobre Ubuntu y esto me obligó a revisar cada capa de mi stack. Lo que enc
- [Malware en PyTorch Lightning: simulé el mismo vector de supply chain attack sobre mis dependencias de ML en producción](https://juanchi.dev/es/blog/supply-chain-attack-pytorch-lightning-dependencias-ml-produccion): El ecosistema Python de ML tiene un problema estructural que Node y Rust resolvieron hace años: la cadena de dependencias transitivas de una sola librería de ML puede superar las 2
- [Intenté reproducir el caso OpenClaw en Claude Code: mi resultado contradice el post viral](https://juanchi.dev/es/blog/claude-code-censura-commits-keywords-openclaw-reproduccion): El thread de HN decía que Claude Code bloqueaba o redirigía billing si OpenClaw aparecía en el historial Git. Armé un repo público, un harness reproducible y corrí la matriz. En Cl
- [Bugs que Rust no atrapa: los corrí contra casos reales y encontré exactamente los que me prometieron que no existirían](https://juanchi.dev/es/blog/bugs-rust-no-previene-errores-logicos-produccion): 648 puntos en HN sobre bugs que Rust no previene. Tomé la lista, la corrí contra ejemplos reproducibles de producción y encontré exactamente lo que prometían que no iba a existir. 
- [Copy Fail: reproduje el bug más viral de HN en código de ejemplo reproducible y encontré algo peor](https://juanchi.dev/es/blog/copy-fail-clipboard-bug-reproduccion-nextjs-seguridad): Copy Fail llegó al #1 de Hacker News con 977 puntos. Lo reproduje en mi stack de Next.js y encontré algo que el post viral no menciona: cuando el clipboard falla en silencio durant
- [Ghostty deja GitHub: lo que mis logs de uso dicen sobre la dependencia real de los devs en plataformas de Microsoft](https://juanchi.dev/es/blog/ghostty-deja-github-dependencia-devs-plataformas-microsoft-logs): Ghostty no está dejando GitHub, está señalando que nadie debería haberle dado tanto poder en primer lugar. Analicé mis propios logs de uso y dependencia en CI, releases, issues y P
- [TypeScript 7 beta benchmark: lo que los números del repo me confirmaron y lo que todavía no me cierra](https://juanchi.dev/es/blog/typescript-7-beta-benchmark-tsgo-vs-tsc6): Armé un lab público con benchmarks reproducibles para medir TypeScript 7 native preview contra TypeScript 6 en repos reales. Los resultados son interesantes, pero la historia más ú
- [OpenAI en Amazon Bedrock: simulé la migración desde mi stack actual y los números no cierran como promete el anuncio](https://juanchi.dev/es/blog/openai-amazon-bedrock-migracion-costos-simulacion-stack): El anuncio de OpenAI en Amazon Bedrock suena prometedor. Simulé mover mis llamadas de API reales a Bedrock y los números de cold start, overhead de IAM y pricing real destruyen la 
- [LocalSend: lo instalé en todo mi stack y reemplazó AirDrop, pero hay un tradeoff que nadie menciona](https://juanchi.dev/es/blog/localsend-alternativa-airdrop-open-source-tradeoff-redes-corporativas): LocalSend lidera HN hoy con 850 puntos. Lo instalé en Mac, Linux y mobile, medí latencia contra AirDrop nativo y encontré el tradeoff concreto que los posts entusiastas no cuentan:
- [¿Quién es dueño del código que escribió Claude Code? Corrí git blame sobre un proyecto real y el resultado es incómodo](https://juanchi.dev/es/blog/propiedad-intelectual-codigo-generado-ia-git-blame-claude-code): Corrí git blame sobre un proyecto donde usé Claude Code intensivamente. El 61% de las líneas no son mías. Eso no es un problema legal todavía — es un problema de accountability cua
- [4TB de voz robados de Mercor: simulé el mismo ataque sobre mi stack de datos IA](https://juanchi.dev/es/blog/mercor-robo-datos-voz-contratistas-ia-simulacion-stack): Mercor perdió 4TB de muestras de voz de 40k contratistas IA. Corrí la misma simulación que hice con GoDaddy: ¿qué datos de API, metadatos y artefactos de entrenamiento estoy exponi
- [pgbackrest dejó de mantenerse: qué hago ahora con mis backups de Postgres en producción](https://juanchi.dev/es/blog/pgbackrest-alternativa-postgres-backup-produccion): HN 425 puntos sobre el fin del mantenimiento de pgbackrest me agarró con la guardia baja. Lo que aprendí evaluando Barman, WAL-G y pg_dump puro — y por qué los tiempos de restore t
- [Microsoft y OpenAI rompen su acuerdo exclusivo: lo que mis logs de uso dicen sobre a quién le conviene realmente](https://juanchi.dev/es/blog/microsoft-openai-deal-exclusividad-logs-uso-costos-api): Microsoft y OpenAI terminaron su acuerdo de exclusividad. Todo el mundo opina. Yo abrí mis logs de API de los últimos 90 días y encontré algo que no vi en ningún análisis: el cambi
- [GoDaddy le dio mi dominio a un desconocido: simulé el ataque con mi propia infra y entendí qué tan expuesto estaba](https://juanchi.dev/es/blog/godaddy-domain-hijacking-security-simulacion-ataque-infra-propia): HN score 610 sobre el caso GoDaddy. No lo cubro como noticia: tomé mis propios dominios en Railway y Vercel, simulé cada paso que habría dado un atacante, y entendí que el problema
- [Asahi Linux 7.0 en Apple Silicon: lo instalé en mi máquina real y esto dice sobre el futuro del kernel en ARM](https://juanchi.dev/es/blog/asahi-linux-70-apple-silicon-instalacion-kernel-arm): Instalé Asahi Linux 7.0 en Apple Silicon y medí qué funciona en mi flujo de desarrollo real. El driver de GPU importa menos de lo que pensás. Lo que cambió de verdad es otra cosa.
- [Un agente borró mi base de datos en producción: lo que mis logs dicen que el post viral de HN omite](https://juanchi.dev/es/blog/agente-ia-borro-base-datos-produccion-logs-guardrails): El post de HN con 689 puntos sobre un agente que destruyó una DB en producción está generando búsquedas masivas. Yo no reproduzco el caso ajeno: abro mis propios logs de CrabTrap y
- [TypeScript 7.0 Beta: lo probé contra mi código real y esto cambió (y esto no)](https://juanchi.dev/es/blog/typescript-70-beta-novedades-prueba-codebase-real): TypeScript 7.0 Beta está trending, pero los changelogs mienten por omisión. Corrí la beta contra el codebase real de juanchi.dev y medí qué rompe, qué mejora y si el upgrade vale h
- [Plain text ganó. Migré mis notas de Notion a Markdown y perdí más de lo que esperaba](https://juanchi.dev/es/blog/migrar-notion-markdown-plain-text-lo-que-perdi): Migré mi stack completo de notas de Notion a archivos Markdown planos. El proceso duró tres días. Lo que perdí no era lo que pensaba que iba a perder — y eso me dice algo incómodo 
- [GPT-5.5 en la API: lo puse contra mis casos reales y los números no justifican el upgrade todavía](https://juanchi.dev/es/blog/gpt-55-api-benchmark-comparacion-casos-reales-produccion): Corrí GPT-5.5 contra mis prompts de producción reales y los comparé con GPT-4o en latencia, costo y calidad de output. El salto de marketing no coincide con el salto en mis métrica
- [Cancelé Claude: medí el deterioro de calidad con mis propios benchmarks antes de irme](https://juanchi.dev/es/blog/claude-calidad-deterioro-2025-benchmarks-propios-cancelacion): 874 puntos en HN sobre 'I cancelled Claude'. Antes de sumarme al coro, corrí mis propios casos de regresión con logs reales de Claude Code. El deterioro existe — pero no donde la g
- [Bitwarden CLI comprometido: lo que un supply chain attack sobre una herramienta que uso me obliga a revisar](https://juanchi.dev/es/blog/bitwarden-cli-supply-chain-attack-checkmarx-superficie-confianza): Checkmarx detectó un supply chain attack sobre el ecosistema de Bitwarden CLI. Yo uso esa herramienta en producción. Esto no es un problema de Bitwarden — es un problema de cómo cu
- [Agent Vault: probé el proxy de credenciales open-source para agentes y esto resuelve (y esto no)](https://juanchi.dev/es/blog/agent-vault-proxy-credenciales-open-source-agentes-ia): Agent Vault promete resolver el problema de credenciales en agentes IA con un proxy open-source. Lo instalé contra mi setup real, medí la fricción y encontré algo incómodo: resuelv
- [Claude Code quality reports: corrí los mismos casos que rompieron a todos y esto encontré en mis logs](https://juanchi.dev/es/blog/claude-code-quality-issues-2025-logs-propios-validacion): 742 puntos en HN sobre los quality reports de Claude Code. Anthropic publicó un update tranquilizador. Yo abrí mis logs de los últimos 90 días y corrí los mismos prompts que le fal
- [LLMs que generan security reports: corrí el mismo prompt sobre código de ejemplo reproducible](https://juanchi.dev/es/blog/llm-security-reports-code-analysis-kernel-produccion-falsos-negativos): HN reportó que el kernel de Linux está recibiendo removals basados en security reports generados por LLMs. Tomé el mismo patrón y lo corrí sobre código de ejemplo reproducible en p
- [Agentes async: lo que 'all your agents are going async' no te dice sobre el debugging](https://juanchi.dev/es/blog/agentes-async-debugging-observabilidad-silencio-produccion): El post de HN tiene 127 puntos y nadie habla del problema real: cuando un agente falla en modo async, no obtenés stack trace. Obtenés silencio. Y el silencio en producción es el pe
- [Agentes paralelos en Zed: los probé en mi flujo real y esto cambió (y esto no)](https://juanchi.dev/es/blog/agentes-paralelos-zed-editor-flujo-real-comparacion-claude-code): 229 puntos en HN, trending en todos lados. Corrí parallel agents de Zed contra mi setup de Claude Code y medí dónde gana cada uno. Spoiler: la paralelización resuelve el problema e
- [CrabTrap: puse un proxy LLM-as-a-judge delante de mi agente en producción y esto pasó](https://juanchi.dev/es/blog/crabtrap-llm-judge-proxy-agente-produccion-seguridad): Instalé CrabTrap en mi infra real: un proxy que intercepta llamadas HTTP de agentes y juzga cada respuesta con otro LLM antes de ejecutarla. Medí latencia, falsos positivos y costo
- [Google TPU v8: lo corrí contra lo que tengo en producción y los números no cierran como prometen](https://juanchi.dev/es/blog/google-tpu-v8-agentic-era-benchmark-developers-independientes): Google anunció dos chips diseñados para la "era agéntica". Corrí mi carga de trabajo real de agentes contra sus números publicados. La brecha entre el marketing de hardware y lo qu
- [Windows 9x Subsystem for Linux: lo instalé, lo rompí y entendí por qué importa más de lo que parece](https://juanchi.dev/es/blog/windows-9x-subsystem-for-linux-instalacion-compatibilidad-deuda-tecnica): ¿Por qué alguien construye un subsistema que corre Linux dentro de Windows 95? No es nostalgia. Es una pregunta filosófica sobre compatibilidad, deuda técnica e identidad del siste
- [r/programming baneó contenido LLM: yo baneé mis propios posts y encontré el criterio imposible](https://juanchi.dev/es/blog/reddit-programming-ban-llm-contenido-criterio-moderacion-posts): r/programming le cerró la puerta al contenido LLM. Revisé mis últimos 20 posts buscando cuáles hubieran sobrevivido la moderación. El criterio que emergió no es "generado por IA vs
- [Claude Code en el Pro plan: si lo sacan, eso dice todo sobre para quién existe Anthropic](https://juanchi.dev/es/blog/claude-code-pro-plan-anthropic-cambio-pricing-developers): Tengo los números de mis últimas semanas usando Claude Code desde el Pro plan. Si Anthropic lo mueve a Max o Team solamente, no es una decisión de pricing: es una declaración de in
- [Lo que construir con MCP me enseñó sobre su gap más raro](https://juanchi.dev/es/blog/mcp-protocol-gaps-agentes-contexto-estacionario-mutante): Llevo semanas usando MCP en producción y el problema que encontré no está en ningún post de Dev.to. MCP asume que el contexto no cambia entre llamadas. Mis agentes viven en context
- [OpenAI vende espacios publicitarios por relevancia de prompt: lo simulé con mis propios logs](https://juanchi.dev/es/blog/publicidad-llms-prompt-relevance-openai-ads-chatgpt): OpenAI tiene un socio vendiendo placements de publicidad basados en la relevancia del prompt. Agarré mis propios logs de queries a ChatGPT y proyecté cuáles serían 'monetizables'. 
- [El 44% de Deezer es IA. Corrí git blame sobre mis commits y encontré algo incómodo](https://juanchi.dev/es/blog/contenido-generado-ia-plataformas-git-blame-autoria-codigo): Deezer dice que el 44% de las canciones que se suben por día son generadas por IA. Hice el mismo ejercicio con mis commits del último mes. El número que encontré me generó exactame
- [Anthropic revirtió su posición sobre Claude CLI: la semana pasada era un gris, hoy es verde. Mi flujo de trabajo no cambió.](https://juanchi.dev/es/blog/claude-cli-usage-policy-reversal-anthropic-cambio-posicion-developers): Anthropic acaba de decir que el uso de Claude vía CLI al estilo OpenClaw está permitido. La semana pasada lo hacía con cierta incomodidad. Hoy lo hago igual. Lo que cambió fue el p
- [Notion filtra los emails de todos los editores de páginas públicas](https://juanchi.dev/es/blog/notion-privacidad-datos-filtrados-emails-editores-paginas-publicas): Uso Notion como segunda memoria desde 2021. Cuando me enteré de que filtra los emails de todos los editores de páginas públicas, revisé mis páginas compartidas. La cantidad no me m
- [Prove you are a robot: CAPTCHAs invertidos para agentes IA](https://juanchi.dev/es/blog/captcha-agentes-ia-identidad-inverso-autenticacion-bots): El CAPTCHA nació para demostrar que sos humano. Ahora mis agentes necesitan demostrar que son bots para funcionar. Medí los retries, el overhead, y la fricción real. Los números so
- [Claude system prompt diff: lo que cambió entre Opus 4.6 y 4.7 (y yo lo estaba viendo sin saberlo)](https://juanchi.dev/es/blog/claude-system-prompt-diff-opus-46-47-cambios-comportamiento-agentes): Difeo línea por línea los system prompts públicos de Claude entre versiones y mapeo los cambios de comportamiento que ya estaba observando en producción antes de saber que el promp
- [Vercel April 2026 breach: no me rompieron la infra, me rompieron la excusa](https://juanchi.dev/es/blog/vercel-breach-supply-chain-modelo-amenazas-tercerizado): El incidente de Vercel de abril 2026 no fue el problema. El problema fue que yo había tercerizado mi modelo de amenazas junto con el deployment. Una reflexión incómoda sobre neglig
- [El problema de confianza que Emacs resolvió y los agentes IA ignoran](https://juanchi.dev/es/blog/confianza-herramientas-configuracion-entorno-propio-mcp-emacs-agentes): Emacs lleva décadas pensando en cómo confiarle acceso real a tu sistema a plugins no auditados. En 2025, el ecosistema de agentes IA tiene exactamente el mismo problema y ni siquie
- [Defluffer promete -45% en tokens. Yo medí el costo semántico del ahorro y es incómodo](https://juanchi.dev/es/blog/defluffer-compresion-prompts-tokens-overhead-semantico-benchmark): El 45% de reducción de tokens es real. Lo que no mide nadie es cuánto contexto implícito perdés en el camino. Armé un benchmark propio y los números son más complejos de lo que el 
- [Por qué los trenes de Japón son tan confiables (y qué tiene que ver con tu infra de software)](https://juanchi.dev/es/blog/sistemas-confiables-diseno-institucional-infraestructura-japon-software): El tren japonés no es bueno por tecnología superior. Es bueno porque construyeron instituciones donde fallar cuesta más que mantener. Llevo semanas pensando en qué significa eso pa
- [Agentes IA que pasan tus tests. Ese es el problema.](https://juanchi.dev/es/blog/agentes-ia-tests-falsos-positivos-assertions-vacios): Corrí mis agentes contra un suite de tests que yo mismo escribí y casi el 30% de los pases eran técnicamente correctos pero conceptualmente vacíos. El agente aprendió a satisfacer 
- [Brunost existe: un lenguaje de programación en Nynorsk y lo que eso dice sobre quién decide qué es legible](https://juanchi.dev/es/blog/brunost-lenguaje-programacion-nynorsk-legibilidad-codigo-idioma): Existe un lenguaje de programación escrito en Nynorsk —la variante minoritaria del noruego— y eso me hizo caer en algo que nunca me había preguntado en serio: ¿por qué doy por sent
- [Escribí un intérprete de Python en Python. Lo que aprendí no tiene nada que ver con Python](https://juanchi.dev/es/blog/interprete-python-python-aprendizaje-compiladores-llm): Un post de HN con 150 puntos me llevó a construir un intérprete de Python desde cero. No aprendí Python. Aprendí exactamente dónde me miente la IA cuando genera código.
- [¿Los costos de los agentes IA crecen exponencial? Corrí mis logs y la respuesta me sorprendió](https://juanchi.dev/es/blog/costos-agentes-ia-2025-logs-reales-analisis): Un post en Hacker News con 208 puntos pregunta si los costos de agentes IA crecen exponencialmente. Yo tengo meses de logs reales. La respuesta no es lo que nadie espera: no es exp
- [Medí cuánto me cuesta en tokens cada decisión de diseño de mi agente (y los números me incomodan)](https://juanchi.dev/es/blog/tokenizer-costs-agentes-decisiones-arquitectonicas): Prompt largo vs corto, tool calls vs texto plano, contexto acumulado vs resumido. Medí el costo en tokens de cada decisión arquitectónica en mis agentes reales. Los números no son 
- [Claude Design y lo que revela sobre cómo Anthropic piensa (o no piensa) en developers](https://juanchi.dev/es/blog/claude-design-anthropic-developer-experience-tension): Un post viral con 1050 puntos en HN sobre el diseño de Claude me hizo reflexionar sobre algo que llevo meses sintiendo: hay una brecha enorme entre el Claude que Anthropic muestra 
- [m2cgen: exportá tu modelo de ML sin llevar Python a producción](https://juanchi.dev/es/blog/m2cgen-exportar-modelos-ml-sin-dependencias-python): Entrenás en Python, deployás en Java, Go o lo que tengas. m2cgen convierte tus modelos de scikit-learn en código nativo sin ninguna dependencia de runtime.
- [Claude Opus 4.7 y el principio del fin de la abundancia en IA](https://juanchi.dev/es/blog/escasez-ia-modelos-frontier-costo-opus-47): Dos años de modelos cada vez más baratos y más capaces nos acostumbraron mal. Opus 4.7 trendeó hoy junto a un artículo sobre 'el inicio de la escasez en IA'. Los puse juntos y algo
- [Cloudflare como capa de inferencia para agentes: lo que promete y lo que me preocupa](https://juanchi.dev/es/blog/cloudflare-ai-platform-agentes-inferencia-edge): Cloudflare está apostando a ser el tejido conectivo de los sistemas multi-agente: inferencia en el edge, cercana al usuario, diseñada para agentes. El pitch es tentador. Pero centr
- [SPICE + Claude Code + osciloscopio: cuando el agente toca el mundo físico](https://juanchi.dev/es/blog/spice-claude-code-osciloscopio-simulacion-verificacion-automatizada): Simulación de circuitos, captura de señal real y verificación automática con un LLM encadenado. Lo que pasa cuando la realidad no coincide con la simulación — y el agente tiene que
- [CodeBurn y el problema que no sabía que tenía: cuántos tokens gasto por tarea real](https://juanchi.dev/es/blog/codeburn-claude-code-token-usage-analisis-costo-real-por-tarea): CodeBurn salió en HN y me obligó a calcular mis números reales de Claude Code por primera vez. El resultado fue incómodo: en algunas tareas gasto más tokens debugueando al agente q
- [Awesome desactualizadas: cómo construí un sistema de curación auto-regulado](https://juanchi.dev/es/blog/awesome-curated-01-el-problema): GitHub tiene miles de listas awesome-* pero la mitad están abandonadas. Construí un sistema que detecta las vivas, las scrappea, deduplica cross-fuente y clasifica con IA. Primero 
- [Qwen3.6-35B-A3B corre en mi laptop y dibuja mejor que Claude Opus 4.7](https://juanchi.dev/es/blog/qwen3-6-local-vs-claude-opus-4-7-dibujo-ascii-benchmark-real): Un modelo open-weight de 35B parámetros corriendo en mi máquina le ganó a Claude Opus 4.7 en una tarea concreta: dibujar un pelícano en ASCII. No es un benchmark abstracto. Es una 
- [Google Gemma 4 corre nativo en iPhone: lo probé y la brecha entre 'funciona' y 'es útil' sigue siendo enorme](https://juanchi.dev/es/blog/llm-on-device-iphone-gemma4-inferencia-local-mobile): Gemma 4 corre offline en iPhone. Lo repliqué en mi 13 con 128GB casi llenos. Funciona. Pero el gap entre 'corre' y 'sirve para algo concreto' es exactamente la historia de toda la 
- [US v. Heppner: tu chat con la IA no tiene privilegio legal y casi nadie lo sabe](https://juanchi.dev/es/blog/privilegio-legal-chats-ia-us-v-heppner-privacidad-conversaciones): Un fallo federal en EE.UU. acaba de establecer que los chats con IA no tienen privilegio abogado-cliente. Yo le pregunté a Claude si una cláusula contractual me podía complicar. Ah
- [¿Las herramientas IA usan tus créditos sin decirte para qué?](https://juanchi.dev/es/blog/herramientas-ia-que-usan-tus-creditos-opacidad-token-usage): Gas Town me hizo revisar mis logs de uso de Claude por primera vez en meses. Lo que encontré no fue robo — fue opacidad total. Y eso es casi peor, porque no tenés a quién reclamarl
- [Seguridad como proof of work: por qué el compliance no salva a nadie](https://juanchi.dev/es/blog/seguridad-proof-of-work-compliance-señalizacion-secret-hardcodeado): Pasé semanas configurando SPF, DKIM, DMARC, Dependabot y Snyk. Y de todos modos alguien me aprobó una PR con una API key en texto plano. El problema no es que la seguridad sea difí
- [El ecosistema local de LLMs no necesita Ollama (y me incomodó descubrirlo)](https://juanchi.dev/es/blog/local-llm-sin-ollama-llamacpp-wrapper-minimo-pipelines): Fui team Ollama desde el día uno. La semana pasada intenté reemplazarlo con llama.cpp directo y un wrapper mínimo. El resultado me obligó a repensar algo que creía que ya tenía res
- [Themis: criptografía seria sin morir en el intento](https://juanchi.dev/es/blog/themis-criptografia-alto-nivel-sin-openssl): Themis es la librería de crypto que los devs necesitaban: AES, ECC y forward secrecy con una API que no te hace querer abandonar la profesión. Apareció en 7 listas independientes. 
- [Local MCP Server en 15 minutos (y qué hacer con él después)](https://juanchi.dev/es/blog/mcp-server-local-herramientas-ia-tutorial-caso-uso): Levanté un MCP server local en 12 minutos. En el minuto 13 me quedé mirando la pantalla sin saber qué hacer. Este post es sobre ese momento — y sobre por qué MCP es el protocolo qu
- [Optimicé una imagen Docker de 1.58GB a 186MB. Y rompí el hot reload sin que nadie me lo dijera por dos días.](https://juanchi.dev/es/blog/optimizar-imagen-docker-tamano-multistage-build-errores): Reduje una imagen Docker de 1.58GB a 186MB con multi-stage builds. La imagen quedó perfecta. El hot reload en dev dejó de funcionar. Nadie me lo dijo hasta dos días después. Esto e
- [Cosas que estás sobreingeniando en tu agente de IA (y el LLM ya hace solo)](https://juanchi.dev/es/blog/overengineering-agentes-ia-llm-reimplementar-lo-que-ya-existe): Abrí mi código de producción y conté cuántas líneas escribí para reimplementar cosas que el LLM ya maneja. El número duele. Este post es esa autopsia.
- [Claude Code Routines: semanas ignorándolo y finalmente entendí por qué importa](https://juanchi.dev/es/blog/claude-code-rutinas-workflow-automatizacion-tareas-repetitivas): Usé Claude Code semanas sin configurar una sola rutina. Asumí que era overhead para gente con demasiado tiempo libre. Con 611 puntos en HN no podía seguir mirando para otro lado. A
- [Air Powered Segment Display: cuando alguien elige aire comprimido en lugar de píxeles](https://juanchi.dev/es/blog/display-neumatico-hardware-artistico-aire-comprimido-segmentos): Vi un display de segmentos alimentado por aire comprimido y no pude pensar en otra cosa en todo el día. Hay algo que la gente que elige lo físico y lo lento está viendo que los que
- [N-Day-Bench: ¿pueden los LLMs encontrar vulnerabilidades reales en código real?](https://juanchi.dev/es/blog/n-day-bench-llms-vulnerabilidades-seguridad-benchmark): Aprobé tres PRs con keys hardcodeadas. Los mismos modelos que las escribieron podrían haberlas encontrado. N-Day-Bench mide exactamente ese gap — y los números me incomodan más de 
- [Bondi Sonoro: bitácora de un experimento con datos reales, música generativa y la mecánica de MTA.me](https://juanchi.dev/es/blog/colectivos-buenos-aires-tiempo-real-sonificacion-gtfs-rt): Del GTFS estático de trenes al tiempo real de colectivos. Un recorrido por las decisiones, los errores, los rediseños, y por qué un pluck que no sonaba fue la clave para entender t
- [Lo que aprendieron construyendo un runtime de Rust para TypeScript — y lo que yo no puedo ver con objetividad](https://juanchi.dev/es/blog/rust-runtime-typescript-rendimiento-decisiones-diseno): Vengo de quemarme con Rust y de escribir sobre patrones de TypeScript. Estoy en el peor lugar posible para ser objetivo. Aun así, leí el post técnico línea por línea y encontré tre
- [Multi-Agentic Software Development es un problema de sistemas distribuidos](https://juanchi.dev/es/blog/multi-agente-sistemas-distribuidos-desarrollo-condiciones-carrera): Leí el paper sobre desarrollo multi-agente y me cayó la ficha tarde: los bugs raros que veía en PRs vibe-coded no eran bugs de IA. Eran condiciones de carrera entre agentes. Lo mis
- [Datos abiertos y creatividad: cómo hice que los trenes del AMBA toquen música](https://juanchi.dev/es/blog/datos-abiertos-transporte-creatividad-datos-publicos-trenes-buenos-aires): Un experimento de sonificación con los horarios GTFS de los ferrocarriles argentinos. Y la historia de pensar como arquitecto cuando los datos ideales no existen.
- [Un lenguaje 'perfeccionable': por qué la idea me parece hermosa y por qué va a fracasar igual](https://juanchi.dev/es/blog/diseno-lenguajes-programacion-evolucion-sintaxis-fracaso-adopcion): Leí la propuesta de un lenguaje de programación diseñado para evolucionar su propia sintaxis y no pude dejar de pensar en los tres lenguajes que amé, domené y tuve que abandonar. N
- [Apple como 'perdedor de IA' que termina ganando: lo viví cuando Anthropic no me respondió un mes](https://juanchi.dev/es/blog/apple-ia-privacidad-on-device-modelos-locales): El 'moat accidental' de Apple: la privacidad no era una feature, era el plan B que nadie tomaba en serio. Tengo un M3 Pro y los números de inferencia local ya no son una broma.
- [Docker for Novices: el recurso que 16 listas no pueden estar equivocadas](https://juanchi.dev/es/blog/docker-for-novices-recurso-curado-16-awesome-lists): Una charla de conferencia de 2019 que apareció en 16 awesome lists independientes. ¿Vale la pena en 2024? Analizamos por qué este recurso de Docker sigue siendo una entrada sólida.
- [Gmail, SPF, DKIM, DMARC y 3 semanas de infierno: el 99% de reputación no alcanza](https://juanchi.dev/es/blog/gmail-reputacion-email-deliverability-spf-dkim-dmarc): Mandé el primer batch de este blog a 300 suscriptores y la mitad fue a spam. Configuré todo lo que había que configurar. Y aun así Gmail hace lo que quiere. Esta es la bitácora.
- [Docker pull falla en España por Cloudflare y un partido de fútbol — nadie habla del patrón real](https://juanchi.dev/es/blog/cloudflare-dns-bloqueo-infraestructura-docker-espana): Un partido de fútbol bloqueó Cloudflare en España y rompió Docker Hub para miles de devs. Tengo un cliente en Madrid con quien deployamos cada dos semanas. Esto no es un post sobre
- [Una bailarina con ALS controló una performance con ondas cerebrales — y no pude pensar en otra cosa](https://juanchi.dev/es/blog/bci-als-brainwaves-interfaz-cerebro-computadora-arte): Una artista con ALS usó una BCI para controlar una performance de danza en tiempo real. No es rehabilitación. No es medicina. Es arte. Y el stack técnico es más accesible de lo que
- [Surelock y deadlocks en Rust: lo intenté, me quemé, y ahora entiendo por qué esto tiene 214 puntos](https://juanchi.dev/es/blog/surelock-rust-deadlock-mutex-deadlock-free): Tenía código Rust en producción con mutexes. Me dio un deadlock a las 2am. Cuando vi Surelock en Hacker News con 214 puntos, abrí el repo y entendí por qué el compilador de Rust te
- [Cómo rompieron los benchmarks top de agentes de IA — y lo que eso dice del stack que estoy usando](https://juanchi.dev/es/blog/ai-agent-benchmarks-rotos-patrones-stack): Leí el paper que explotó en HN sobre cómo explotan los mejores benchmarks de agentes de IA. El problema no son los modelos — es que estamos midiendo las cosas equivocadas y constru
- [Revisé 3 PRs vibe-coded con keys hardcodeadas — y el problema no es la IA, soy yo que los aprobé](https://juanchi.dev/es/blog/vibe-coding-security-code-review-keys-hardcodeadas): Tres PRs generados con IA. Tres API keys de AWS en el código. Tres veces que los aprobé porque los tests pasaban. El problema de seguridad en el vibe-coding no está en el modelo — 
- [Contribuir al kernel de Linux con IA: leí el hilo de HN y tengo una opinión que no le va a gustar a nadie](https://juanchi.dev/es/blog/contribuir-kernel-linux-con-ia-opinion-hacker-news): 324 puntos en HN. Los comentarios divididos entre 'jamás' y 'ya está pasando'. Yo metí el historial completo de git de Linux en una base de datos y lo que encontré me obliga a toma
- [Twill.ai y el sueño de 'delegá a un agente, recibí un PR': yo ya lo viví y fue más raro de lo que parece](https://juanchi.dev/es/blog/twill-ai-agents-prs-automation-responsabilidad-epistemica): YC S25, agentes que leen issues y mandan PRs solos. Suena al futuro. Pero llevo meses trabajando con agentes que codean y el problema real no es si el PR compila — es quién entiend
- [Francia abandona Windows por Linux: lo que los devs argentinos no estamos viendo](https://juanchi.dev/es/blog/france-linux-migration-argentina-infraestructura-publica): Francia anunció la migración Linux más grande de Europa. Yo trabajé seis meses con una dependencia provincial que intentó lo mismo y terminó peor que antes. No por el OS — por el F
- [¿Git va a morir por culpa de los agentes de IA? Hay $17M que dicen que sí](https://juanchi.dev/es/blog/sucesor-git-control-versiones-agentes-ia-17m): Cada tanto aparece alguien que quiere matar a Git y siempre pienso lo mismo: el problema no es la herramienta, somos nosotros. Pero este pitch me cayó diferente. Porque los agentes
- [TigerFS: un filesystem adentro de PostgreSQL (y por qué esta obsesión colectiva me parece un síntoma)](https://juanchi.dev/es/blog/tigerfs-filesystem-sobre-postgres-experimento): Alguien metió un filesystem completo adentro de PostgreSQL. El año pasado yo metí el historial de git de Linux en una base de datos. Hay un patrón acá que vale la pena entender — n
- [Reverse engineering SynthID: ¿qué pasa con el watermark de Gemini cuando el modelo corre en tu browser?](https://juanchi.dev/es/blog/synthid-watermark-deteccion-ia-gemini-local-edge-reverse-engineering): Alguien está haciendo ingeniería inversa al sistema de detección de watermarks de Google. Yo metí Gemma en el browser el mes pasado. El cruce es inevitable: ¿SynthID sobrevive cuan
- [Research-Driven Agents: cuando un agente lee antes de codear](https://juanchi.dev/es/blog/agentes-ia-investigacion-antes-de-codear): Meses viendo agentes tirar código sin contexto y romper todo. Armé un experimento real: forzar al agente a producir un artefacto de investigación antes de tocar un archivo. Lo que 
- [La criptografía que usás para firmar digitalmente tiene fecha de vencimiento: qué publicó NIST y cómo migrar tu HSM](https://juanchi.dev/es/blog/nist-post-quantum-firma-digital-hsm-migracion): NIST finalizó los estándares post-quantum en agosto de 2024. RSA y ECDSA tienen deadline de 2035. Si firmás documentos, JWTs o certificados con un HSM, esto te afecta ahora — te ex
- [9 patrones de TypeScript que eliminan bugs antes de ejecutar el código](https://juanchi.dev/es/blog/5-patrones-typescript-eliminan-bugs-compile-time): Discriminated unions, branded types, satisfies, infer, Result<T,E>, type predicates y mapped types: los patrones del sistema de tipos que hacen que categorías enteras de bugs sean 
- [Realoqué $100/mes de Claude Code a Zed + OpenRouter: lo que nadie te cuenta sobre cambiar de tool](https://juanchi.dev/es/blog/claude-code-alternativas-costo-zed-openrouter): No es solo un tema de plata. Cuando cambiás de herramienta de IA, cambiás tu workflow. Y cuando cambiás tu workflow, cambiás qué proyectos te animás a arrancar. Cuento qué perdí, q
- [Metí el historial completo de git de Linux en una base de datos — y lo que encontré me pareció arqueología](https://juanchi.dev/es/blog/linux-kernel-git-history-base-de-datos-analisis-pgit): Qué pasa cuando dejás de tratar tu historial de commits como logs y empezás a tratarlo como datos. Lo hice con repos viejos míos. Lo que encontré fue incómodo, revelador, y me hizo
- [El mes que Anthropic no respondió: billing, confianza y el costo oculto de depender de APIs de IA](https://juanchi.dev/es/blog/anthropic-billing-support-vendor-lock-in-apis-ia): Un thread de HN con 365 puntos me dio permiso de decir lo que venía evitando: construir sobre APIs de IA tiene un riesgo de soporte y continuidad que nadie discute honestamente. Yo
- [Project Glasswing: lo que la IA no te dice cuando genera tu código](https://juanchi.dev/es/blog/project-glasswing-software-supply-chain-security-ai): Glasswing me tocó un nervio que tengo hace tiempo. Deployamos con IA, generamos código con IA, y la superficie de ataque creció de formas que todavía no terminamos de mapear. Esto 
- [LittleSnitch para Linux: por qué tardó tanto y qué dice eso del ecosistema](https://juanchi.dev/es/blog/littlesnitch-linux-firewall-outbound-monitoring): Llevo años desarrollando en Linux y la ausencia de un outbound firewall decente con GUI siempre fue el elefante en el cuarto. No es un review — es una excusa para hablar de por qué
- [MegaTrain: entrenar LLMs de 100B+ parámetros en una sola GPU (y por qué tuve que cerrar la laptop)](https://juanchi.dev/es/blog/megatrain-full-precision-training-single-gpu-llms-100b): Leí el título y pensé que era clickbait. Me senté, leí el paper, y tuve que levantarme a caminar. MegaTrain propone entrenar modelos de 100B+ parámetros en una sola GPU con full pr
- [Scion: el testbed de orquestación de agentes que Google acaba de open-sourcear](https://juanchi.dev/es/blog/scion-google-orquestacion-agentes-ia-testbed): Google open-sourceó Scion, un testbed para orquestar agentes de IA. Lo miré junto a Freestyle (sandboxes) y ahora entiendo qué hace cada uno — y tengo una opinión sobre hacia dónde
- [Tu score de accesibilidad te está mintiendo](https://juanchi.dev/es/blog/accesibilidad-web-real-score-lighthouse-vs-experiencia-usuario): Saqué 98/100 en Lighthouse y axe en juanchi.dev. Después le pedí a alguien con lector de pantalla que la usara. Lo que pasó me dio vergüenza. El score perfecto y la experiencia rea
- [Nunca más tipees openssl x509 -text -noout: creé una extensión de VS Code para ver certificados SSL/TLS](https://juanchi.dev/es/blog/x509-certificate-viewer-vscode-extension): Harté de buscar el comando exacto de openssl cada vez que necesitaba inspeccionar un .pem o un .pfx. Creé X509 Certificate Utility para VS Code y cambió mi flujo de trabajo para si
- [Harté de esperar que alguien maintuviera la extensión de HAProxy para VS Code — así que la hice yo](https://juanchi.dev/es/blog/haproxy-vscode-extension-gmm-haproxy): La única extensión de HAProxy para VS Code no la tocaban desde 2019. Todos los días la usaba en el trabajo y en mi homelab, y todos los días me tragaba errores de sintaxis sin ning
- [Vibe-coding vs stress-coding: cómo trabajo yo realmente con IA en proyectos que importan](https://juanchi.dev/es/blog/vibe-coding-vs-stress-coding-ia-proyectos-reales): El vibe-coding es fantástico hasta que el proyecto tiene usuarios reales. Acá la diferencia concreta entre cómo uso IA para experimentar y cómo la uso cuando hay producción de por 
- [Cómo Linux ejecuta un binario: lo entendí a los 33 años de programar y me da vergüenza](https://juanchi.dev/es/blog/linux-elf-dynamic-linking-como-funciona): 33 años con computadoras y recién ahora entiendo qué pasa entre que escribís `./mi-programa` y corre el código. ELF, dynamic linking, ld-linux — el agujero negro que siempre esquiv
- [Google Maps para codebases: pegué la URL de mi propio repo y me asusté un poco](https://juanchi.dev/es/blog/codebase-visualization-github-ai-analisis): Existe una herramienta que te permite pegar una URL de GitHub y preguntarle cualquier cosa sobre el código. La usé con mi propio proyecto. Lo que me mostró sobre mí mismo no fue có
- [Quantum computing para el dev web que no estudió física: ¿cuándo preocuparse en serio?](https://juanchi.dev/es/blog/quantum-computing-timeline-desarrolladores-web): Un post de HN con 289 puntos sobre criptografía cuántica me dejó con una pregunta que no sé responder honestamente: ¿cuándo debería un full-stack developer empezar a preocuparse po
- [Metí Gemma corriendo en el browser, sin API keys, y me cambió cómo pienso el edge](https://juanchi.dev/es/blog/gemma-llm-browser-sin-api-keys-local): Hay una creencia instalada sobre AI en producción que está bastante equivocada: que necesitás una API, un server y una tarjeta de crédito para meter inteligencia en tu app. Lo corr
- [Sandboxes para agentes de código: qué es Freestyle y por qué me importa](https://juanchi.dev/es/blog/sandboxes-coding-agents-freestyle): Cuando empecé a usar agentes de código en proyectos reales, el mayor miedo no era que escribieran mal — era que ejecutaran cosas en mi máquina sin que yo entendiera qué. Freestyle 
- [Metí un LLM chico adentro de una app Next.js y esto fue lo que aprendí](https://juanchi.dev/es/blog/llm-pequeno-browser-edge-inferencia-nextjs): Reproducí el experimento del LLM tiny que explotó en Show HN: Gemma corriendo en el browser, sin API keys, desde mi stack habitual. Acá está todo lo que salió mal — y lo poco que s
- [Claude Code se rompió con las actualizaciones de febrero — y yo también lo sentí](https://juanchi.dev/es/blog/claude-code-updates-febrero-2025): Un thread de HN con 702 puntos me hizo dar cuenta de algo incómodo: Claude Code empezó a fallar justo cuando más lo necesitaba, y eso me obligó a preguntarme cuánto de mi criterio 
- [De DOS a Cloud: mi viaje de 33 años con la tecnología — desde una Amiga en 1994 hasta deployar en Railway con Next.js](https://juanchi.dev/es/blog/de-dos-a-cloud-mi-viaje-33-anos-1775496952619): Empecé tocando una Amiga 500 a los 3 años sin entender nada. Hoy hago deploy en segundos desde una terminal. En el medio: cyber cafés, servidores Linux a las 3am, y un pivot de car
- [De 3 segundos a 300ms: cómo optimicé el performance de una app Next.js en producción](https://juanchi.dev/es/blog/optimizacion-performance-nextjs-3s-a-300ms): Diagnóstico brutal, cambios concretos y métricas reales. Así pasé una app Next.js de ser un desastre lento a cargar en 300ms — sin magia, sin excusas, con trabajo.
- [El stack tecnológico perfecto en 2025: lo que elegiría si arrancara un proyecto hoy](https://juanchi.dev/es/blog/stack-tecnologico-perfecto-2025): Después de años rompiendo cosas en producción, acá está mi stack ideal para 2025. Sin hype, sin vendor lock-in innecesario, y con las cicatrices suficientes para justificar cada de
- [TypeScript: los patrones que realmente uso todos los días](https://juanchi.dev/es/blog/typescript-patrones-avanzados-que-uso): Discriminated unions, branded types, generics avanzados y cómo pienso en tipos cuando programo. No es un tutorial académico — es lo que realmente uso en producción después de años 
- [Cómo construí juanchi.dev con el stack más bleeding edge de 2025: Next.js 16, React 19, Tailwind v4 y Railway](https://juanchi.dev/es/blog/como-construi-juanchi-dev): Un postmortem honesto de construir mi portfolio con lo más nuevo de 2025. Spoiler: casi todo rompió. Lo reconstruí igual. Te cuento por qué vale la pena.
- [Next.js App Router: la guía que me hubiera gustado tener cuando migré de Pages Router](https://juanchi.dev/es/blog/nextjs-app-router-guia-completa): Migré tres proyectos en producción de Pages Router a App Router y rompí todo dos veces antes de entender cómo funciona de verdad. Server Components, streaming, cache, layouts anida
- [De DOS a Cloud: mi viaje de 33 años con la tecnología — desde una Amiga en 1994 hasta deployar en Railway con Next.js](https://juanchi.dev/es/blog/de-dos-a-cloud-mi-viaje-33-anos): Arrancué con una Amiga 500 a los 3 años y hoy deployeo apps en Railway con Next.js. Esta es la historia sin filtros de cómo la tecnología me formó, me rompió y me volvió a armar — 
- [Docker para desarrolladores Node.js: de cero a producción sin morir en el intento](https://juanchi.dev/es/blog/docker-nodejs-de-cero-a-produccion): Me llevó tres Dockerfiles rotos, dos servidores caídos en producción y una noche sin dormir entender cómo funciona Docker con Node.js de verdad. Acá te cuento todo lo que aprendí p

## Posts (English)

- [pnpm vs npm vs yarn vs bun: The Real Comparison Nobody Gives You in 2025](https://juanchi.dev/en/blog/pnpm-vs-npm-vs-yarn-vs-bun-definitive-comparison-2025): I used all four in real projects. One wrecked a monorepo at 3am. Another saved my ass in production. Here's the unfiltered truth about every major package manager in 2025.
- [Swiper: the touch slider that won't wreck your sprint](https://juanchi.dev/en/blog/swiper-touch-slider-carousel-react-vue-angular): Swiper has been the undisputed standard for touch carousels on the web for years. Zero dependencies, official wrappers for React, Vue and Angular, and transitions that feel genuine
- [Node.js: the runtime that changed how we think about backend](https://juanchi.dev/en/blog/nodejs-runtime-that-changed-backend-forever): Node.js isn't just "JavaScript on the server." It's a paradigm shift in how we handle I/O. Thirty years in tech taught me to recognize when something genuinely moves the ground ben
- [Rate limiting in web apps: what to protect before picking a library](https://juanchi.dev/en/blog/rate-limiting-web-apps-what-to-protect-before-picking-library): Rate limiting is not a dependency you drop into middleware and call it done. It's an abuse policy. Before you copy that snippet, you need to define what asset you're protecting, wh
- [Spring Boot Actuator: What to Expose, What to Hide, and What to Check Before Adding Endpoints](https://juanchi.dev/en/blog/spring-boot-actuator-endpoints-security-expose-hide): Actuator isn't the problem. The problem is enabling it without a clear exposure policy. A pragmatic guide to using it as an operational tool without turning it into unnecessary pub
- [Netron: Open Any ML Model and See What's Actually Inside](https://juanchi.dev/en/blog/netron-inspect-ml-models-no-jupyter-no-drama): Netron lets you inspect the architecture of any ML model — no Jupyter, no code, no drama. ONNX, PyTorch, TensorFlow: open it and see everything.
- [Next.js App Router Caching: revalidate, dynamic, and no-store Without the Folklore](https://juanchi.dev/en/blog/nextjs-app-router-caching-revalidate-dynamic-no-store-3): The problem with Next.js caching isn't memorizing the flags. It's deciding how fresh each piece of data actually needs to be. A guide to reading revalidate, dynamic, and no-store a
- [Docker healthchecks: what they actually measure and what you shouldn't promise](https://juanchi.dev/en/blog/docker-healthcheck-what-it-measures-decision-matrix): A healthcheck that only says "the process responds" can hide entire business failures. What Docker HEALTHCHECK actually measures, where people overestimate it, and a decision matri
- [Digital Signatures: Format, Certificate, and Validation Policy Are Not the Same Thing](https://juanchi.dev/en/blog/digital-signature-format-certificate-validation-policy-2): Not every signature error is a cryptographic problem. Most of the time the mess is in the format you picked, the certificate that doesn't fit the required profile, or the validatio
- [Sniffnet: monitor your network without losing your mind to tcpdump](https://juanchi.dev/en/blog/sniffnet-monitor-network-traffic-without-tcpdump): Sniffnet is a cross-platform network traffic monitor written in Rust. Real UI, real-time charts, no security PhD required to understand what's actually going on.
- [XGBoost: the gradient boosting that dominated Kaggle and survived the hype](https://juanchi.dev/en/blog/xgboost-gradient-boosting-tabular-data-production): XGBoost isn't a trend — it's the algorithm that won hundreds of ML competitions on tabular data. Why it's still the mandatory reference in 2025 and when you should reach for it.
- [PyTorch: the deep learning framework that won the war](https://juanchi.dev/en/blog/pytorch-deep-learning-framework-won-the-war): PyTorch showed up in 6 independent awesome lists and the reason is simple: it won. This isn't hype — it's infrastructure. Here's why it made our list and when it actually makes sen
- [TensorFlow: the ML elephant that's still standing](https://juanchi.dev/en/blog/tensorflow-ml-at-scale-serious-production-deployment): TensorFlow isn't sexy in 2025, but it's still the serious infrastructure behind deployment at scale. Why it made the list and when you actually need it.
- [Rate limiting in Next.js: what to protect before picking a library](https://juanchi.dev/en/blog/rate-limiting-nextjs-policy-before-library): Rate limiting isn't an npm dependency — it's an abuse policy. Before copying middleware, you need to define what asset you're protecting, what abuse pattern you expect, and what a 
- [npm Dependencies: How to Evaluate a Library Before Shipping It to Production](https://juanchi.dev/en/blog/npm-dependencies-evaluate-library-before-production): Adding an npm dependency isn't just installing code — it's taking on its maintenance, its attack surface, and its transitive deps. Here's the checklist I run before adding any pack
- [How I built a self-auditing editorial pipeline with AI](https://juanchi.dev/en/blog/editorial-pipeline-ai-juanchi-dev): The README on juanchi.dev says "portfolio landing". The code says something else: an editorial system with repo ingestion, quality gate, automatic rewriting, and crons on Railway. 
- [lode: Reimplementing DVC's core in Go without breaking the format](https://juanchi.dev/en/blog/lode-dvc-compatible-data-versioning-go): lode reimplements DVC's hot path in Go with a non-negotiable invariant: byte-identical compatibility with DVC 3.x. Static binary, parallel hashing, state DB that avoids re-hashing.
- [OWASP LLM Top 10 in Production: How I Audited My TypeScript Agent Pipeline Against All 10 Risks — and What I Found](https://juanchi.dev/en/blog/owasp-llm-top-10-audit-typescript-agent-pipeline): Running the OWASP LLM Top 10 as a real audit is a completely different experience than reading it as a checklist. I ran it against my TypeScript agent stack with system prompts, MC
- [pnpm workspaces in a monorepo: the setup that survived CI on Railway and the problems the docs don't warn you about](https://juanchi.dev/en/blog/pnpm-workspaces-monorepo-ci-railway-real-problems): pnpm workspaces is the best option for TypeScript monorepos in 2026. But the happy path in the docs hides three traps that only show up in CI with real deployments: phantom depende
- [OAuth 2.0 Scope Creep: the Attack Vector the Vercel Incident Exposed and How to Audit It in Your Integrations](https://juanchi.dev/en/blog/oauth-scope-creep-vercel-incident-audit-integrations): The Vercel incident wasn't a technical vulnerability — it was a least-privilege failure applied to OAuth. Break down what scope creep is, how to audit it in existing integrations, 
- [Functional programming in TypeScript: the abstractions I actually use and the ones I dropped](https://juanchi.dev/en/blog/functional-programming-typescript-patterns-i-use-and-dropped): I started wanting to write Haskell in TypeScript and ended up with three helpers and a lesson. An honest breakdown of which functional patterns survive in a real TypeScript codebas
- [Spring Boot Actuator: What to Expose, What to Hide, and What to Check Before Adding Endpoints](https://juanchi.dev/en/blog/spring-boot-actuator-what-to-expose-hide-endpoints): Actuator isn't the problem. Enabling it without a clear exposure policy is. A practical guide to using it as an operational tool without turning it into unnecessary public attack s
- [OpenTelemetry in Next.js: traces that survive the edge/server boundary without losing context](https://juanchi.dev/en/blog/opentelemetry-nextjs-traces-edge-server-context): OpenTelemetry in Next.js works, but the default propagator silently breaks the trace at the edge/node boundary. Here's what you need to configure explicitly so context doesn't vani
- [How Memory Safety CVEs Differ Between Rust and C/C++](https://juanchi.dev/en/blog/memory-safety-cves-rust-vs-c-cpp-analysis): Rust has fewer memory CVEs than C/C++ — but that's not the whole story. My analysis of what that number actually says, what it doesn't, and how to turn it into a real technical dec
- [What Job Interviews Taught Me About Kubernetes](https://juanchi.dev/en/blog/what-job-interviews-taught-me-about-kubernetes): Kubernetes technical interviews have a problem nobody names: they ask about objects you'll never touch in production, while ignoring the mistakes that actually break real systems. 
- [My Homelab AI Dev Platform: What Problem It Actually Signals and Where the Limits Are](https://juanchi.dev/en/blog/homelab-ai-dev-platform-real-limits-checklist): The homelabber community is building local AI dev platforms and the discussion is genuinely interesting. I have some observations that go beyond the initial excitement — and a chec
- [The Birth and Death of JavaScript (2014): What Still Holds and What Doesn't](https://juanchi.dev/en/blog/birth-death-javascript-2014-what-still-holds-what-doesnt): A 2014 talk predicted JavaScript would die, replaced by ASM.js. A decade later, JS is still alive — but the tension it identified is more real than ever. Here's what's worth extrac
- [Formal Methods and the Future of Programming: What's Worth Trying and Where the Ceiling Is](https://juanchi.dev/en/blog/formal-methods-future-programming-worth-trying-ceiling): Formal methods keeps surfacing on the technical radar as the solution the industry ignored. My read: the problem it points to is real, but the recipe floating around omits costs th
- [Rio de Janeiro's "Own LLM" Looks Like a Merge: What to Read Between the Lines](https://juanchi.dev/en/blog/rio-de-janeiro-llm-merge-model-checklist-verification): A municipality announces its "own" LLM and the technical community discovers it might be a merge of an existing model. My read: the real problem isn't the fraud — it's that almost 
- [Authentication tokens: JWT, Paseto, and session tokens — the decision tree I always needed](https://juanchi.dev/en/blog/jwt-paseto-session-tokens-decision-tree-typescript): There's no such thing as the perfect token — only the right token for your system's threat model. A practical decision tree with real technical judgment for choosing between JWT, P
- [Zod on the server and the client: the schema you define once and the three ways it breaks in runtime](https://juanchi.dev/en/blog/zod-nextjs-server-client-schema-runtime-failures): Zod sells itself as "define once, validate everywhere." In Next.js 16 with Server Actions, edge middleware, and API routes, that's only partially true. Three concrete failure modes
- [Prisma query logging and PostgreSQL: when the ORM is enough and when you have to go deeper](https://juanchi.dev/en/blog/prisma-query-logging-vs-postgresql-when-to-use-each): Prisma Client logs show you what queries the ORM generated. PostgreSQL has its own observability layer. Confusing the two is the source of incomplete diagnostics. Here I separate t
- [Next.js App Router Caching: revalidate, dynamic, and no-store Without the Folklore](https://juanchi.dev/en/blog/nextjs-app-router-caching-revalidate-dynamic-no-store-2): The problem with Next.js App Router caching isn't memorizing flags. It's understanding what freshness each piece of data actually needs and treating that as an explicit contract — 
- [MCP Model Context Protocol in TypeScript: build portable tools across Claude, GPT, and local models](https://juanchi.dev/en/blog/mcp-typescript-portable-tools-claude-gpt-local-models): The most common mistake when implementing MCP tools is coupling them to the provider's SDK. The spec exists to prevent exactly that. A practical architecture guide: the input/outpu
- [Web Crypto API in the browser vs Node.js: the differences that will burn you](https://juanchi.dev/en/blog/web-crypto-api-browser-nodejs-edge-differences): Web Crypto API looks like one thing — until you try to reuse the same encryption code across browser, Node.js, and Next.js edge runtime. The differences are subtle, they're documen
- [React 19 Server Components and caching: the mental model I was missing after reading the docs](https://juanchi.dev/en/blog/react-19-server-components-caching-mental-model): This isn't another RSC tutorial. It's the conceptual map I built after reading the official docs and understanding why the folklore around 'always use use client' is wrong — and wh
- [HyperFrames Explains Itself: Building a Reproducible Technical Video From HTML](https://juanchi.dev/en/blog/hyperframes-reproducible-technical-video-html): I used HyperFrames to build a video about HyperFrames, then published the whole process: source, commands, mistakes, screenshots, audio, captions, renders, and evidence.
- [Cline in VS Code: I used it two weeks on a TypeScript project and this survived](https://juanchi.dev/en/blog/cline-vscode-autonomous-coding-agent-typescript-two-weeks): Two weeks using Cline as an autonomous coding agent on a TypeScript project. What tasks I delegated, where it screwed up, how it compares to Claude Code, and which workflows I'd ne
- [Rate limiting in web apps: what to protect before picking a library](https://juanchi.dev/en/blog/rate-limiting-web-apps-what-to-protect-before-choosing-library): Before you copy-paste rate limiting middleware, define what asset you're protecting, what abuse you're expecting, and what a false positive costs you. Without that, the library sol
- [Next.js 16 Middleware: authorization patterns that scale and the ones that cause race conditions](https://juanchi.dev/en/blog/nextjs-16-middleware-authorization-patterns-race-conditions): I tested 4 authorization patterns in Next.js 16 Middleware with edge runtime. One causes silent race conditions, another gives you unexpected latency, and only one scales without c
- [Prisma 5 → Prisma 6: The Breaking Changes I Hit in My Real Schema and How I Fixed Them Without Breaking Production](https://juanchi.dev/en/blog/prisma-5-to-6-breaking-changes-migration-guide): Prisma 6 improves ergonomics and performance, but there are three behavior changes that won't scream at you in the compiler — and will absolutely show up at runtime if you don't au
- [tsgo: what changes in the TypeScript compiler rewritten in Go and what it means for real projects](https://juanchi.dev/en/blog/tsgo-typescript-compiler-go-real-projects): tsgo is real and the performance jump is verifiable — but the beta has documented limits that most posts quietly ignore. Here's the concrete criteria for deciding whether to explor
- [React 19 use() hook and Suspense: when it replaces useEffect and when it throws you into a worse loop](https://juanchi.dev/en/blog/react-19-use-hook-suspense-vs-useeffect): React 19's use() hook promises to replace useEffect for data fetching. That promise is partially true. There are two patterns with Suspense and error boundaries where the behavior 
- [Spring Boot Actuator: What to Expose, What to Hide, and What to Check Before Adding Endpoints](https://juanchi.dev/en/blog/spring-boot-actuator-endpoints-what-to-expose-hide): Actuator isn't the problem. The mistake is adding it to a project with no clear exposure policy. Here I break down which endpoints to enable, which to block, and what decisions to 
- [TypeScript strict mode: the 6 tsconfig options that actually matter in production and when to enable them](https://juanchi.dev/en/blog/typescript-strict-mode-tsconfig-options-production): strict: true is not enough — and it's not the whole story. A flag-by-flag breakdown of what each strict mode option actually does, what bugs it prevents, and the order to enable th
- [Digital identity backend architecture: the decisions tutorials skip](https://juanchi.dev/en/blog/digital-identity-backend-architecture-decisions-tutorials-skip): Auth tutorials show you the happy path. The real problems in digital identity show up in revocation, state-change propagation, and the trust model. A decision guide from the inside
- [Digital signatures: format, certificate, and validation policy — three layers people constantly mix up](https://juanchi.dev/en/blog/digital-signature-format-certificate-validation-policy-layers): When a digital signature fails, the instinct is to look at cryptography. Most of the time the problem is format or validation policy. Here I separate the three layers so the next e
- [System prompts for production agents: the format that survived 3 redesigns](https://juanchi.dev/en/blog/system-prompts-production-agents-format-three-redesigns): A system prompt isn't documentation for the model — it's a contract. After several redesigns, I landed on a format with fixed sections, explicit limits, and dynamically injected co
- [Docker healthchecks: what they actually measure and what you shouldn't promise](https://juanchi.dev/en/blog/docker-healthcheck-what-it-measures-best-practices): A healthcheck that only says "the process is responding" can hide serious business-level failures. Let's break down what the HEALTHCHECK instruction actually promises, where the st
- [The benchmark that made me change my mind about Jakarta EE in 2026](https://juanchi.dev/en/blog/spring-boot-payara-glassfish-benchmark-java-enterprise): Same backend, same database, same k6. In the first runs it looked like Embedded GlassFish was on top. When I fixed JDK, warmup, window, heap, and DB attribution, the story changed:
- [Prisma Query Logging and PostgreSQL: Where the ORM Ends and the Database Begins](https://juanchi.dev/en/blog/prisma-query-logging-postgresql-orm-vs-database): Prisma query logs help you catch patterns, but if the problem lives inside PostgreSQL, the ORM won't show it to you. Here I break down when Prisma logging is enough and when you ne
- [Next.js App Router caching: revalidate, dynamic, and no-store without the folklore](https://juanchi.dev/en/blog/nextjs-app-router-caching-revalidate-dynamic-no-store): The problem with App Router cache isn't memorizing flags. It's deciding what freshness each piece of data actually needs before you write a single line of configuration.
- [Vivado 2026.1 and Linux: why this decision matters beyond the headline](https://juanchi.dev/en/blog/vivado-2026-1-linux-free-tier-technical-decision-analysis): Vivado 2026.1 looks like it's dropping Linux support for the free tier. Before you panic or dismiss it, I turned the news into a verifiable technical decision: what's actually impa
- [Rate limiting in web apps: what to protect before picking a library](https://juanchi.dev/en/blog/rate-limiting-nextjs-what-to-protect-before-choosing-library): Before you install any rate limiting middleware in Next.js, you need to define what asset you're protecting, what abuse you're expecting, and what a false positive actually costs y
- [Why I Stopped Using useEffect to Sync State — and What I Use Instead](https://juanchi.dev/en/blog/why-i-stopped-using-useeffect-sync-state-react-19): useEffect isn't broken — the mental model we teach with it is. I audited every useEffect in a React 19 codebase and found 4 concrete categories where it was an antipattern. Here ar
- [Prisma Server Actions in Next.js 16: the patterns that work and the N+1 that sneaks up on you](https://juanchi.dev/en/blog/prisma-server-actions-nextjs-16-n1-composition-patterns): Prisma in Next.js 16 Server Actions has an N+1 vector that doesn't exist in classic API routes. The culprit isn't the ORM — it's how Actions compose. Here are the patterns that pre
- [Spring Boot 2026: Why Measuring Only Startup Time Is a Trap](https://juanchi.dev/en/blog/spring-boot-startup-time-2026-graalvm-native-aot-cds): I built a reproducible lab with Spring Boot 3.5, Java 21, AppCDS, AOT, and GraalVM Native. The conclusion isn't that native wins or that classic JVM loses: it's that in 2026, compa
- [Show HN: Needle distilled Gemini tool calling into 26M parameters — technical read, zero hype](https://juanchi.dev/en/blog/needle-gemini-tool-calling-26m-parameters-technical-read): A 26M parameter model trained via Gemini distillation for tool calling showed up on HN and made me stop everything. Not to celebrate — to understand what real problem it points at,
- [OpenTelemetry on Spring Boot 3: when logs say OK and traces show the problem](https://juanchi.dev/en/blog/opentelemetry-spring-boot-logs-vs-traces-diagnosis): OpenTelemetry doesn't improve performance. It improves diagnostic quality when a slow request mixes DB, downstream, N+1, and partial errors. This reproducible lab shows which signa
- [Prisma vs JDBC: the benchmark that almost made me blame the wrong ORM](https://juanchi.dev/en/blog/prisma-vs-jdbc-benchmark-query-shape-n1): I built a reproducible lab to compare Prisma 5 against Spring Boot JdbcTemplate on the same PostgreSQL 16. What I found wasn't a winner: it was that query shape and N+1 explain alm
- [Retry isn't free: budget, amplification, and the cost that never shows up in p95](https://juanchi.dev/en/blog/retry-backoff-jitter-spring-boot-amplification): A reproducible experiment with Spring Boot 3, Java 21, and k6 to measure when retry actually buys availability and when it amplifies a failure. The metric that matters isn't p95: i
- [HikariCP: the p95 that lies to you and how to read the real pool signals](https://juanchi.dev/en/blog/hikaricp-configuration-spring-boot-postgresql-pool-exhaustion-signals): A low p95 with a 97% error rate isn't a fast pool — it's a pool that fails fast. I built a reproducible experiment with Spring Boot 3, PostgreSQL, and k6 to understand which signal
- [pnpm workspaces: the CI cache that survived the fix and cost me 40 minutes per build](https://juanchi.dev/en/blog/pnpm-workspaces-ci-cache-github-actions-40-minutes-fix): The CI was green. The cache wasn't working. Forty minutes per build run because pnpm couldn't find the store in GitHub Actions. Here are the logs, the before/after YAML, and the ex
- [Spring Security with Spring Boot Actuator: the authorization model that survived the incident](https://juanchi.dev/en/blog/spring-security-spring-boot-actuator-authorization-model-production): Locking down Actuator endpoints isn't enough. After the incident, I rebuilt the authorization model from scratch: explicit SecurityFilterChain, separate health groups, roles for /m
- [pnpm workspaces in a Next.js 16 monorepo: what the benchmark didn't measure and almost broke my CI](https://juanchi.dev/en/blog/pnpm-workspaces-nextjs-16-monorepo-ci-hoisting-cache): The install-time benchmark I published earlier didn't capture the real cost of pnpm workspaces in CI: silent cache invalidation, dependency hoisting that breaks in App Router, and 
- [Spring Boot Actuator in Production: The Endpoints I Left Open by Accident and How I Closed Them](https://juanchi.dev/en/blog/spring-boot-actuator-production-endpoints-hardening-checklist): After publishing my Jakarta EE vs Spring Boot analysis, I audited Actuator's defaults on a backend I own and found sensitive endpoints wide open — ones I never consciously configur
- [pnpm vs npm vs yarn in 2026: I ran all three on my real monorepo and it forced me to change my mind](https://juanchi.dev/en/blog/pnpm-vs-npm-vs-yarn-2026-monorepo-real-benchmark): I ran all three package managers on the same Next.js 16 + strict TypeScript monorepo with Shadcn/ui and Radix UI. pnpm wins on disk and CI — but there's a real compatibility cost t
- [Jakarta EE vs Spring Boot in 2026: I Migrated a Production Backend and the Tradeoffs Aren't What You'd Expect](https://juanchi.dev/en/blog/jakarta-ee-vs-spring-boot-2026-production-migration-tradeoffs): I migrated a digital signature backend from Spring Boot 3.x to Jakarta EE 11. The synthetic benchmarks looked great. Production told me a different story. Here are the real numbers
- [Themis vs Web Crypto API: TypeScript Encryption Tradeoffs That Are Not Obvious](https://juanchi.dev/en/blog/themis-vs-web-crypto-api-typescript-encryption-tradeoffs): Comparing Themis with Web Crypto API is not academic: it changes bundle size, threat model, key rotation, and where each responsibility should live. The tradeoffs are less obvious 
- [Functional Programming in TypeScript: What Survives Outside Pretty Examples](https://juanchi.dev/en/blog/functional-programming-typescript-production-patterns-that-survive): Functors, monads, and pipe() can look pristine in small examples, but real Next.js flows with Server Actions and Prisma expose readability, bundle, and onboarding costs worth measu
- [Spring Boot in Real Production: Defaults the Official Docs Do Not Emphasize](https://juanchi.dev/en/blog/spring-boot-production-defaults-jvm-railway): Spring Boot works very well in production, but its defaults do not always fit PaaS constraints, tight memory, and real observability. These are the points worth reviewing before tr
- [Clipboard API Fails in TypeScript: The 4 Cases Nobody Documents and How I Found Them in reproducible example code](https://juanchi.dev/en/blog/clipboard-api-typescript-fails-undocumented-cases-copytext): navigator.clipboard.writeText looks trivial until your app silently breaks in production with zero visible error. I found 4 cases the docs never mention: insecure context, lost foc
- [Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks](https://juanchi.dev/en/blog/supply-chain-npm-vs-pypi-simulation-comparison-dangerous-vector): I ran supply chain attack simulations on npm and PyPI separately. When I put them side by side, the pattern that emerged made me uncomfortable: the ecosystem everyone watches isn't
- [After the Guardrail That Saved My Infrastructure: My Autonomous Agent Architecture in Production](https://juanchi.dev/en/blog/autonomous-agent-architecture-production-permissions-observability): The autonomous agent incident forced me to redesign everything — from permissions to observability. This is what ended up running in production after the crisis: the real graph, th
- [npm audit isn't enough: I simulated a supply chain attack on my Node dependencies and found what the scanner can't see](https://juanchi.dev/en/blog/npm-audit-supply-chain-attack-node-dependencies-what-scanner-misses): npm audit tells you you're safe. I stress-tested that claim with real methodology against my production dependencies and found three attack vectors the scanner doesn't even registe
- [Mutex deadlocks in production: the patterns I found in my codebase and how I diagnosed them](https://juanchi.dev/en/blog/mutex-deadlock-async-rust-production-diagnosis-patterns): Three deadlocks in production, all with the same face: the service stopped responding — no error, no panic, no log. What I found while diagnosing them changed how I think about loc
- [Real guardrails for autonomous agents after one almost destroyed my infrastructure](https://juanchi.dev/en/blog/real-guardrails-autonomous-ai-agents-production-incident): After an autonomous agent nearly wiped my production database, I built a real guardrails layer. Here are the controls, the code, and the logs that saved my skin.
- [Async Rust Never Left MVP: I Validated It Against real-world cases and Found Exactly the Edge Cases That HN Post Predicted](https://juanchi.dev/en/blog/async-rust-never-left-mvp-edge-cases-real-codebase-validated): 434 points on HN argue that Async Rust is still a glorified MVP. I replicated every concrete criticism against reproducible example code: executor leaks, cancellation safety, Pin h
- [Docker Compose in Production in 2026: I Ran My Real Stack for 30 Days and Here Are the Numbers](https://juanchi.dev/en/blog/docker-compose-production-2026-real-metrics-30-days): A HN thread with 398 points blew up the debate again: is Docker Compose in production legitimate or an antipattern? I ran my real stack on Railway for 30 days and brought actual nu
- [Agents That Create Accounts, Buy Domains, and Deploy on Their Own: I Tested It Against My Real Stack — Here's What Broke (and What Worked)](https://juanchi.dev/en/blog/ai-agents-autonomous-deploy-cloudflare-railway-real-stack-test): The viral HN demo shows Cloudflare agents running the full infra cycle with zero human intervention. I replicated it against my Railway stack and documented exactly what the agent 
- [I Trained My Own LLM from Scratch in 2025: What That Viral HN Tutorial Doesn't Tell You About the Real Cost](https://juanchi.dev/en/blog/trained-llm-from-scratch-2025-real-cost-viral-hn-tutorial): I followed the viral 241-point HN tutorial and documented every dollar spent, every GPU hour, and every disappointment. My thesis: training an LLM from scratch in 2025 is a valid t
- [Chrome Installed 4 GB of AI on My Machine Without Asking: I Inspected What It's Actually Doing and I Don't Like What I Found](https://juanchi.dev/en/blog/chrome-installed-4gb-ai-model-without-consent-inspected): A HN thread with 204 points calls out Chrome silently installing a 4 GB model. I went to my own machine, found the model, inspected paths, permissions, and resource consumption. I 
- [Bun Migrates from Zig to Rust: What My Real Benchmarks Say About Whether It Matters](https://juanchi.dev/en/blog/bun-zig-to-rust-migration-real-benchmarks-performance): 489 + 506 points on HN. Bun ports to Rust and everyone has a take. I ran the benchmarks on my real stack before opening my mouth. The uncomfortable result: the underlying language 
- [macOS tar destroys files on Linux: I validated it in my real Railway pipeline and documented the 3 cases nobody mentions](https://juanchi.dev/en/blog/macos-tar-linux-extraction-error-railway-pipeline-3-real-cases): A HN post about tar on macOS made the rounds again this week. The standard answer is "use GNU tar." I went further: I reproduced the 3 scenarios that actually break production in m
- [Agentic Coding Is Not a Trap: I Answered the Viral HN Post With My Own Production Logs](https://juanchi.dev/en/blog/agentic-coding-not-a-trap-production-logs-vs-viral-hn-post): 367 points on HN say agentic coding is a trap. I have logs that say something more uncomfortable: sometimes it saves 3 hours, sometimes it sends me down a 4-hour rabbit hole. The d
- [DeepClaude: I Combined Claude Code with DeepSeek V4 Pro in My Agent Loop and the Numbers Threw Me Off](https://juanchi.dev/en/blog/deepclaude-claude-code-deepseek-v4-pro-agent-loop-real-numbers): I took the DeepClaude repo (467 points on HN) and dropped it into my real production loop. The combination isn't simply "better than either alone" — there's a specific task regime 
- [Specsmaxxing: I Wrote YAML Specs for My AI Agents — Here's What Changed (and What Didn't)](https://juanchi.dev/en/blog/specsmaxxing-yaml-specs-ai-agents-what-changed): Specsmaxxing promises to cure "AI psychosis" with YAML specs for agents. I applied it to my real workflow with Claude Code and found the trap nobody mentions: the quality problem d
- [Barman Replacing pgbackrest: I Migrated My Postgres Backups in Production and Here's What I Found](https://juanchi.dev/en/blog/barman-replacing-pgbackrest-postgres-backup-production-migration): pgbackrest went unmaintained. Barman shows up trending on HN almost immediately after. I did the actual migration on Railway, measured restore times, backup size, and configuration
- [Kimi K2.6 vs Claude vs GPT-5.5: I ran it against my real coding cases and the numbers surprised me](https://juanchi.dev/en/blog/kimi-k2-6-vs-claude-vs-gpt-5-5-real-coding-benchmark): The hype says Kimi K2.6 beat Claude and GPT-5.5 at coding. I ran it against my own codebase — not cherry-picked HumanEval — and what I found changes the question you should actuall
- [Canonical under DDoS: what my Railway logs and uptime say about my real exposure](https://juanchi.dev/en/blog/canonical-ddos-railway-logs-real-exposure-ubuntu-2025): The Canonical DDoS hit 178 points on HN and most devs read it as someone else's news. I read it as a mirror. I dug through my Railway logs, my Docker pipelines, and my Ubuntu depen
- [Spotify Verified for Human Artists: What It Signals for Code, Content, and My Own Blog](https://juanchi.dev/en/blog/spotify-verified-human-artist-signal-for-code-content-blogs): Spotify's "human artist" badge hit 243 points on HN. This isn't a music industry problem. It's a leading indicator. If music already needs to prove a human made it, code and posts 
- [The gay jailbreak: I ran the viral technique against my own production prompts and here's what I found](https://juanchi.dev/en/blog/llm-jailbreak-audited-production-prompts-2025): 524 points on HN about a trending jailbreak technique. Instead of reading the thread, I ran it against my own production prompts. What I found isn't an isolated case — it's a syste
- [Linux kernel vulnerabilities without distro notice: what this changes in my Ubuntu/Railway stack](https://juanchi.dev/en/blog/linux-kernel-vulnerabilities-ubuntu-railway-stack-disclosure): Distros find out about kernel vulnerabilities at the same time as the public. I run on Railway over Ubuntu and this forced me to audit every layer of my stack. What I found isn't r
- [Malware in PyTorch Lightning: I Simulated the Same Supply Chain Attack Vector on My ML Dependencies in Production](https://juanchi.dev/en/blog/pytorch-lightning-supply-chain-attack-ml-dependencies-audit): The Python ML ecosystem has a structural problem that Node and Rust solved years ago: the transitive dependency chain of a single ML library can exceed 200 entries, most without ve
- [I tried to reproduce the OpenClaw case in Claude Code: my result contradicts the viral post](https://juanchi.dev/en/blog/claude-code-blocks-commits-openclaw-alignment-agent-mode): The HN thread claimed Claude Code blocked or redirected billing when OpenClaw appeared in Git history. I built a public repo, a reproducible harness, and ran the matrix. On Claude 
- [Bugs Rust Won't Catch: I Ran the List Against real-world cases and Found Exactly What I Was Told Wouldn't Exist](https://juanchi.dev/en/blog/bugs-rust-wont-catch-real-codebase-logic-errors): 648 points on HN about bugs Rust doesn't prevent. I took the list, ran it against reproducible production-style examples, and found exactly what they promised wouldn't be there. Ru
- [Copy Fail: I Reproduced the Most Viral HN Bug in reproducible example code and Found Something Worse](https://juanchi.dev/en/blog/copy-fail-clipboard-api-silent-bug-credentials-nextjs): Copy Fail hit #1 on Hacker News with 977 points. I reproduced it in my Next.js stack and found something the viral post never mentions: when the clipboard fails silently during a p
- [Ghostty Leaves GitHub: What My Usage Logs Say About Devs' Real Dependency on Microsoft Platforms](https://juanchi.dev/en/blog/ghostty-leaves-github-developer-dependency-microsoft-platforms): Ghostty isn't leaving GitHub — it's pointing out that nobody should've given it that much power in the first place. I audited my own usage logs: CI, releases, issues, Pages. The nu
- [TypeScript 7 beta benchmark: what the repo numbers confirmed for me — and what I still don't buy](https://juanchi.dev/en/blog/typescript-7-beta-benchmark-tsgo-vs-tsc6): I built a public lab with reproducible benchmarks to measure TypeScript 7 native preview against TypeScript 6 on real repos. The results are interesting, but the more useful story 
- [OpenAI on Amazon Bedrock: I simulated the migration from my current stack and the numbers don't add up like the announcement promises](https://juanchi.dev/en/blog/openai-amazon-bedrock-migration-simulation-costs-latency-numbers): The OpenAI on Amazon Bedrock announcement sounds promising. I simulated moving my real API calls to Bedrock and the cold start numbers, IAM overhead, and actual pricing destroy the
- [LocalSend: I installed it across my entire stack and it replaced AirDrop, but there's a tradeoff nobody mentions](https://juanchi.dev/en/blog/localsend-airdrop-open-source-alternative-real-tradeoff): LocalSend is leading HN today with 850 points. I installed it on Mac, Linux and mobile, measured latency against native AirDrop, and found the concrete tradeoff that all the enthus
- [Who owns the code Claude Code wrote? I ran git blame on a real project and the result is uncomfortable](https://juanchi.dev/en/blog/who-owns-claude-code-output-git-blame-real-project): I ran git blame on a project where I used Claude Code heavily. 61% of the lines aren't mine. That's not a legal problem yet — it's an accountability problem for when something blow
- [Mercor's 4TB Voice Heist: I Ran the Same Attack on My Own AI Data Stack](https://juanchi.dev/en/blog/mercor-4tb-voice-breach-simulated-attack-ai-data-stack): Mercor lost 4TB of voice samples from 40k AI contractors. I ran the same simulation I did after the GoDaddy incident: what API tokens, metadata, and training artifacts am I unknowi
- [pgbackrest is unmaintained: what I'm doing with my Postgres backups in production now](https://juanchi.dev/en/blog/pgbackrest-unmaintained-postgres-backup-alternatives-production): A 425-point HN thread about pgbackrest losing its maintainer caught me completely off guard. What I learned evaluating Barman, WAL-G, and plain pg_dump — and why restore times tell
- [Microsoft and OpenAI Break Their Exclusive Deal: What My API Usage Logs Actually Say About Who Benefits](https://juanchi.dev/en/blog/microsoft-openai-exclusive-deal-api-logs-who-benefits): Microsoft and OpenAI ended their exclusivity agreement. Everyone's got a hot take. I opened my API logs from the last 90 days and found something I didn't see in any of the analyse
- [GoDaddy gave my domain to a stranger: I simulated the attack on my own infra and learned how exposed I really was](https://juanchi.dev/en/blog/godaddy-domain-hijacking-simulated-attack-own-infra): HN score 610 on the GoDaddy case. I didn't cover it as news: I took my own domains on Railway and Vercel, simulated every step an attacker would have taken, and realized the proble
- [Asahi Linux 7.0 on Apple Silicon: I Installed It on My Real Machine and Here's What It Says About the Future of the Kernel on ARM](https://juanchi.dev/en/blog/asahi-linux-70-apple-silicon-installed-measured-real-workflow): I installed Asahi Linux 7.0 on Apple Silicon and measured what actually works in my real development workflow. The GPU driver matters less than you think. What really changed is so
- [An Agent Deleted My Production Database: What My Logs Say That the Viral HN Post Leaves Out](https://juanchi.dev/en/blog/ai-agent-deleted-production-database-logs-guardrails-real-analysis): The HN post with 689 points about an agent that destroyed a production DB is generating massive searches. I'm not rehashing someone else's war story — I'm opening my own CrabTrap a
- [TypeScript 7.0 Beta: I Ran It Against real-world cases — Here's What Changed (and What Didn't)](https://juanchi.dev/en/blog/typescript-7-beta-real-codebase-results-what-changed): TypeScript 7.0 Beta is trending, but changelogs lie by omission. I ran the beta against the juanchi.dev codebase and measured what breaks, what improves, and whether the upgrade is
- [Plain text won. I migrated my notes from Notion to Markdown and lost more than I expected](https://juanchi.dev/en/blog/plain-text-won-migrating-notion-to-markdown-what-i-lost): I migrated my entire note stack from Notion to plain Markdown files. The process took three days. What I lost wasn't what I thought I was going to lose — and that tells me somethin
- [GPT-5.5 in the API: I ran it against my real production cases and the numbers don't justify the upgrade yet](https://juanchi.dev/en/blog/gpt-5-5-api-benchmark-real-production-cases-vs-gpt-4o): I ran GPT-5.5 against my actual production prompts and compared it to GPT-4o on latency, cost, and output quality. The marketing leap doesn't match the leap in my metrics. Here are
- [I Almost Cancelled Claude: I Ran My Own Benchmarks Before Pulling the Trigger](https://juanchi.dev/en/blog/cancelled-claude-quality-degradation-benchmarks-real-logs): 874 points on HN for 'I cancelled Claude'. Before joining the chorus, I ran my own regression cases against real Claude Code logs. The degradation is real — just not where everyone
- [Bitwarden CLI compromised: what a supply chain attack on a tool I actually use forces me to audit](https://juanchi.dev/en/blog/bitwarden-cli-supply-chain-attack-trust-surface-audit): Checkmarx detected a supply chain attack targeting the Bitwarden CLI ecosystem. I use that tool in production. This isn't a Bitwarden problem — it's a problem with how any dev buil
- [Agent Vault: I tested the open-source credential proxy for agents — here's what it solves (and what it doesn't)](https://juanchi.dev/en/blog/agent-vault-open-source-credential-proxy-agents-review): Agent Vault promises to solve the credential problem in AI agents with an open-source proxy. I ran it against my real setup, measured the friction, and found something uncomfortabl
- [Claude Code quality reports: I ran the same prompts that broke everyone and here's what my logs showed](https://juanchi.dev/en/blog/claude-code-quality-reports-logs-analysis-hn-thread): 742 points on HN about Claude Code quality reports. Anthropic published a reassuring update. I opened my logs from the last 90 days and ran the same prompts the community keeps com
- [LLMs generating security reports: I ran the same prompt on reproducible example code](https://juanchi.dev/en/blog/llms-generating-security-reports-ran-prompt-on-my-own-code): HN reported that the Linux kernel is receiving removals based on LLM-generated security reports. I took the same pattern and ran it against my own production code. What I found mad
- [Async agents: what 'all your agents are going async' doesn't tell you about debugging](https://juanchi.dev/en/blog/async-ai-agents-debugging-silence-production-observability): The HN post has 127 points and nobody's talking about the real problem: when an async agent fails, you don't get a stack trace. You get silence. And silence in production is the wo
- [Zed Parallel Agents: I Tested Them in My Real Workflow — Here's What Changed (and What Didn't)](https://juanchi.dev/en/blog/zed-parallel-agents-real-workflow-comparison-claude-code): 229 points on HN, trending everywhere. I ran Zed's parallel agents against my Claude Code setup and measured where each one wins. Spoiler: parallelization solves the wrong problem 
- [CrabTrap: I Put an LLM-as-a-Judge Proxy in Front of My Production Agent and Here's What Happened](https://juanchi.dev/en/blog/crabtrap-llm-judge-proxy-production-agent-results): I installed CrabTrap on my real infrastructure — a proxy that intercepts HTTP calls from agents and judges every response with another LLM before executing it. I measured latency, 
- [Google TPU v8: I ran it against my production workload and the numbers don't add up](https://juanchi.dev/en/blog/google-tpu-v8-agentic-era-benchmark-production-workload): Google announced two chips designed for the "agentic era." I ran my real agent workload against their published numbers. The gap between hardware marketing and what an indie dev ca
- [Windows 9x Subsystem for Linux: I installed it, broke it, and understood why it matters more than it seems](https://juanchi.dev/en/blog/windows-9x-subsystem-for-linux-installed-broke-understood): Why would anyone build a subsystem that runs Linux inside Windows 95? It's not nostalgia. It's a philosophical question about compatibility, technical debt, and operating system id
- [r/programming banned LLM content: I banned my own posts and found the impossible criterion](https://juanchi.dev/en/blog/r-programming-llm-ban-tested-own-posts-original-thought-criterion): r/programming shut the door on LLM content. I reviewed my last 20 posts to see which ones would have survived moderation. The criterion that emerged isn't "AI-generated vs human" —
- [Claude Code on the Pro Plan: If They Pull It, That Says Everything About Who Anthropic Actually Cares About](https://juanchi.dev/en/blog/claude-code-pro-plan-anthropic-who-it-serves): I have the numbers from my last few weeks running Claude Code on the Pro plan. If Anthropic moves it to Max or Team only, that's not a pricing decision — it's a statement of intent
- [What Building with MCP Taught Me About Its Weirdest Gap](https://juanchi.dev/en/blog/building-with-mcp-stationary-context-gap-production-bugs): I've been running MCP in production for weeks and the problem I found isn't in any Dev.to post. MCP assumes context doesn't change between calls. My agents live in contexts that mu
- [OpenAI is selling ad placements by prompt relevance — I simulated it with my own logs](https://juanchi.dev/en/blog/openai-prompt-relevance-ads-analyzed-my-own-logs): OpenAI has a partner selling ad placements based on prompt relevance. I grabbed my own ChatGPT query logs and projected which ones would be 'monetizable'. The result disturbed me b
- [44% of Deezer Is AI. I Ran git blame on My Commits and Found Something Uncomfortable](https://juanchi.dev/en/blog/deezer-44-percent-ai-git-blame-commits-authorship): Deezer says 44% of songs uploaded daily are AI-generated. I ran the same exercise on my commits from the last month. The number I found made me feel exactly the same discomfort.
- [Anthropic reversed its position on Claude CLI: last week it was gray, today it's green. My workflow didn't change.](https://juanchi.dev/en/blog/anthropic-claude-cli-usage-policy-reversal-workflow-unchanged): Anthropic just said Claude CLI usage in the OpenClaw style is allowed. Last week I was doing it with a knot in my stomach. Today I'm doing the exact same thing. What changed was th
- [Notion Leaks the Emails of Every Editor on Public Pages](https://juanchi.dev/en/blog/notion-leaks-emails-editors-public-pages-privacy): I've used Notion as my second brain since 2021. When I found out it exposes the emails of every editor on public pages, I audited my shared pages. The number didn't bother me as mu
- [Prove you are a robot: reversed CAPTCHAs for AI agents](https://juanchi.dev/en/blog/reversed-captchas-ai-agent-identity-web-overhead): CAPTCHAs were born to prove you're human. Now my agents need to prove they're bots just to function. I measured the retries, the overhead, the real friction. The numbers are ugly.
- [Claude system prompt diff: what changed between Opus 4.6 and 4.7 (and I was watching it happen without knowing why)](https://juanchi.dev/en/blog/claude-system-prompt-diff-opus-46-47-behavior-changes): I diff the public Claude system prompts line by line between versions and map the behavior changes I was already observing in production before I knew the prompt had changed. The c
- [Vercel April 2026 breach: it didn't break my infra, it broke my excuse](https://juanchi.dev/en/blog/vercel-april-2026-breach-supply-chain-threat-model): The Vercel April 2026 incident wasn't the problem. The problem was that I had outsourced my threat model along with my deployment. An uncomfortable reflection on epistemic negligen
- [The Trust Problem Emacs Solved That AI Agents Are Ignoring](https://juanchi.dev/en/blog/emacs-trust-model-ai-agents-mcp-security): Emacs has spent decades thinking about how to safely grant real system access to unaudited plugins. In 2025, the AI agent ecosystem has the exact same problem — and isn't even havi
- [Defluffer promises -45% tokens. I measured the semantic cost of that savings and it's uncomfortable](https://juanchi.dev/en/blog/defluffer-semantic-cost-token-compression-benchmark): The 45% token reduction is real. What nobody measures is how much implicit context you lose along the way. I built my own benchmark and the numbers are more complicated than the he
- [Why Japanese Trains Are So Reliable (And What It Has To Do With Your Software Infrastructure)](https://juanchi.dev/en/blog/japanese-trains-reliable-software-infrastructure-institutional-design): Japanese trains aren't good because of superior technology. They're good because they built institutions where failing costs more than maintaining. I've spent weeks thinking about 
- [AI Agents That Pass Your Tests. That's the Problem.](https://juanchi.dev/en/blog/ai-agents-false-positive-tests-real-problem): I ran my agents against a test suite I wrote myself and nearly 30% of the passes were technically correct but conceptually hollow. The agent learned to satisfy the assertion, not t
- [Brunost Exists: A Programming Language in Nynorsk and What That Says About Who Decides What's Readable](https://juanchi.dev/en/blog/brunost-nynorsk-programming-language-english-code-default): There's a programming language written in Nynorsk — Norway's minority written standard — and it cracked open a question I'd never seriously asked myself: why do I take for granted 
- [I Wrote a Python Interpreter in Python. What I Learned Has Nothing to Do With Python](https://juanchi.dev/en/blog/python-interpreter-in-python-what-i-learned-about-ai-llms): A 150-point HN post sent me down a rabbit hole building a Python interpreter from scratch. I didn't learn Python. I learned exactly where AI lies to me when it generates code.
- [Do AI Agent Costs Grow Exponentially? I Ran My Logs and the Answer Surprised Me](https://juanchi.dev/en/blog/do-ai-agent-costs-grow-exponentially-real-logs-analysis): A Hacker News thread with 208 points asks whether AI agent costs grow exponentially. I have months of real production logs. The answer isn't what anyone expects: it's not exponenti
- [I Measured How Much Each Agent Design Decision Costs in Tokens (The Numbers Make Me Uncomfortable)](https://juanchi.dev/en/blog/measuring-token-costs-agent-design-decisions-real-numbers): Long vs short prompts, tool calls vs plain text, accumulated vs summarized context. I measured the real token cost of every architectural decision in my production agents. The numb
- [Claude Design and What It Reveals About How Anthropic Thinks (or Doesn't Think) About Developers](https://juanchi.dev/en/blog/claude-design-anthropic-developer-experience-political-reading): A viral HN post with 1050 points on Claude's design made me confront something I've been feeling for months: there's a massive gap between the Claude Anthropic shows in presentatio
- [m2cgen: export your ML model without shipping Python to production](https://juanchi.dev/en/blog/m2cgen-export-ml-model-to-java-go-csharp-without-python): Train in Python, deploy in Java, Go, or whatever you've got. m2cgen converts your scikit-learn models into native code with zero runtime dependencies.
- [Claude Opus 4.7 and the Beginning of the End of AI Abundance](https://juanchi.dev/en/blog/claude-opus-47-end-of-ai-abundance-frontier-model-costs): Two years of models getting cheaper and smarter every quarter trained us to expect that forever. Opus 4.7 trended today alongside a piece about 'the start of AI scarcity.' I put th
- [Cloudflare as an Inference Layer for Agents: What It Promises and What Worries Me](https://juanchi.dev/en/blog/cloudflare-ai-platform-inference-layer-agents-promises-risks): Cloudflare is betting on becoming the connective tissue of multi-agent systems: edge inference, close to the user, built for agents. The pitch is tempting. But centralizing inferen
- [SPICE + Claude Code + Oscilloscope: When the Agent Touches the Physical World](https://juanchi.dev/en/blog/spice-claude-code-oscilloscope-agent-physical-world-verification): Circuit simulation, real signal capture, and automatic verification with a chained LLM. What happens when reality doesn't match the simulation — and the agent has to decide what to
- [CodeBurn and the Problem I Didn't Know I Had: Tokens Per Real Task](https://juanchi.dev/en/blog/codeburn-claude-code-token-usage-per-task-analysis): CodeBurn dropped on HN and forced me to calculate my real Claude Code numbers for the first time. The result was uncomfortable: on some tasks I'm burning more tokens debugging the 
- [Stale Awesome Lists: How I Built a Self-Regulating Curation System](https://juanchi.dev/en/blog/stale-awesome-lists-self-regulating-curation-system): GitHub has thousands of awesome-* lists but half of them are dead. I built a system that detects the live ones, scrapes them, deduplicates cross-source, and classifies with AI. Fir
- [Qwen3.6-35B-A3B Runs on My Laptop and Draws Better Than Claude Opus 4.7](https://juanchi.dev/en/blog/qwen3-35b-local-vs-claude-opus-4-7-ascii-art-benchmark): A 35B open-weight model running on my machine beat Claude Opus 4.7 at a concrete task: drawing a pelican in ASCII art. Not an abstract benchmark. A real question about what we're p
- [Google Gemma 4 Runs Natively on iPhone: I Tested It and the Gap Between 'Works' and 'Useful' Is Still Massive](https://juanchi.dev/en/blog/google-gemma-4-runs-natively-on-iphone-on-device-llm-gap): Gemma 4 runs offline on iPhone. I replicated it on my 13 with a nearly full 128GB. It works. But the gap between 'runs' and 'actually does something useful' is exactly the story of
- [US v. Heppner: Your AI Chat Has No Legal Privilege and Almost Nobody Knows It](https://juanchi.dev/en/blog/us-v-heppner-ai-chat-no-legal-privilege-attorney-client): A federal ruling just established that AI chats carry no attorney-client privilege. I'd asked Claude whether a contract clause could bite me. Now I'm reading that ruling and proces
- [Do AI Tools Spend Your Credits Without Telling You Why?](https://juanchi.dev/en/blog/ai-tools-spending-your-credits-without-transparency-audit): Gas Town made me dig into my Claude usage logs for the first time in months. What I found wasn't theft — it was total opacity. And that's almost worse, because there's no one to bl
- [Security as Proof of Work: Why Compliance Saves Nobody](https://juanchi.dev/en/blog/security-proof-of-work-compliance-vs-real-effectiveness): I spent weeks setting up SPF, DKIM, DMARC, Dependabot, and Snyk. And someone still approved a PR with a plaintext API key. The problem isn't that security is hard — it's that it be
- [The Local LLM Ecosystem Doesn't Need Ollama (And That Made Me Uncomfortable)](https://juanchi.dev/en/blog/local-llm-without-ollama-llama-cpp-direct-production-pipelines): I've been team Ollama since day one. Last week I tried replacing it with raw llama.cpp and a minimal wrapper. What I found forced me to rethink something I thought I'd already figu
- [Themis: Serious Cryptography Without Losing Your Mind](https://juanchi.dev/en/blog/themis-serious-cryptography-without-losing-your-mind): Themis is the crypto library devs actually needed: AES, ECC, and forward secrecy wrapped in an API that won't make you quit the profession. It showed up in 7 independent awesome li
- [Local MCP Server in 15 Minutes (And What to Do With It After)](https://juanchi.dev/en/blog/local-mcp-server-15-minutes-use-cases-tutorial): I had a local MCP server running in 12 minutes. Minute 13 I just stared at the screen with no idea what to do next. This post is about that moment — and why MCP is the protocol eve
- [I Optimized a Docker Image from 1.58GB to 186MB — And Silently Broke Hot Reload for Two Days](https://juanchi.dev/en/blog/docker-image-optimization-1-58gb-to-186mb-broke-hot-reload): I shrunk a Docker image from 1.58GB to 186MB with multi-stage builds. The image was perfect. Hot reload stopped working. Nobody told me for two days. Here's what I broke and how to
- [Things You're Over-Engineering in Your AI Agent (That the LLM Already Handles)](https://juanchi.dev/en/blog/over-engineering-ai-agents-what-the-llm-already-does): I opened my production repo and counted the lines I wrote to re-implement things the LLM already handles. The number hurts. This post is that autopsy — 340 lines of misplaced confi
- [Claude Code Routines: Weeks Ignoring It and I Finally Get Why It Matters](https://juanchi.dev/en/blog/claude-code-routines-workflow-what-i-ignored-for-weeks): I used Claude Code for weeks without setting up a single routine. Assumed it was overhead for people with too much free time. Then a post hit 611 points on HN and I couldn't look a
- [Air Powered Segment Display: Choosing Compressed Air Over Pixels](https://juanchi.dev/en/blog/air-powered-segment-display-compressed-air-artistic-hardware): I saw a seven-segment display powered by compressed air and couldn't think about anything else for the rest of the day. There's something people who choose the physical and the slo
- [N-Day-Bench: Can LLMs Find Real Vulnerabilities in Real Code?](https://juanchi.dev/en/blog/n-day-bench-can-llms-find-real-vulnerabilities-in-real-code): I approved three PRs with hardcoded keys. The same models that helped write them could have caught them. N-Day-Bench measures exactly that gap — and the numbers bother me more than
- [Bondi Sonoro: A Build Log of Real Data, Generative Music, and the MTA.me Mechanic](https://juanchi.dev/en/blog/bondi-sonoro-build-log-real-data-generative-music-mta-mechanic): From static train GTFS to real-time bus positions. A full walkthrough of the decisions, the bugs, the rewrites — and why a silent pluck was the key to understanding the whole syste
- [What They Learned Building a Rust Runtime for TypeScript — and What I Can't See Objectively](https://juanchi.dev/en/blog/rust-runtime-typescript-performance-design-decisions-review): I've burned myself with Rust and spent posts deep in TypeScript patterns. I'm the worst possible person to be objective here. I read every line anyway — and found three design deci
- [Multi-Agent Software Development Is a Distributed Systems Problem](https://juanchi.dev/en/blog/multi-agent-software-development-distributed-systems-problem): I read the multi-agent development paper and the penny dropped hard: the weird bugs I kept seeing in vibe-coded PRs weren't AI hallucinations. They were race conditions between age
- [Open Data and Creativity: How I Made Buenos Aires Trains Play Music](https://juanchi.dev/en/blog/open-data-creativity-buenos-aires-trains-play-music): A sonification experiment using GTFS schedules from Argentina's commuter rail network — and the story of thinking like an architect when the ideal data simply doesn't exist.
- [A 'perfectible' language: why the idea is beautiful and why it'll fail anyway](https://juanchi.dev/en/blog/perfectible-programming-language-beautiful-idea-doomed-to-fail): I read a proposal for a language designed to evolve its own syntax and couldn't stop thinking about the three languages I loved, mastered, and had to abandon. Not because they were
- [Apple as the AI 'Loser' That Ends Up Winning: I Lived It When Anthropic Ghosted Me for a Month](https://juanchi.dev/en/blog/apple-ai-privacy-on-device-local-models-m3-pro-ollama): Apple's 'accidental moat': privacy wasn't a feature — it was the Plan B nobody took seriously. I have an M3 Pro and the local inference numbers are no longer a joke. Real benchmark
- [Docker for Novices: The Resource That 16 Lists Can't Be Wrong About](https://juanchi.dev/en/blog/docker-for-novices-resource-16-awesome-lists-recommend): A 2019 conference talk that showed up in 16 independent awesome lists. Still worth it in 2024? We dig into why Docker for Novices keeps earning its spot as a solid entry point for 
- [Gmail, SPF, DKIM, DMARC, and 3 Weeks of Hell: 99% Reputation Isn't Enough](https://juanchi.dev/en/blog/gmail-spf-dkim-dmarc-deliverability-99-percent-reputation-not-enough): I sent the first batch from this blog to 300 subscribers and half landed in spam. I configured everything that needed configuring. And Gmail still does whatever it wants. This is t
- [Docker Pull Fails in Spain Because of Cloudflare and a Soccer Match — Nobody Talks About the Real Pattern](https://juanchi.dev/en/blog/docker-pull-fails-spain-cloudflare-soccer-match-infrastructure-pattern): A soccer match triggered ISP blocks on Cloudflare ranges in Spain and broke Docker Hub for thousands of devs. I have a client in Madrid we deploy with every two weeks. This isn't a
- [A Dancer with ALS Controlled a Performance with Her Brainwaves — and I Couldn't Stop Thinking About It](https://juanchi.dev/en/blog/dancer-with-als-bci-brainwave-performance-open-source-stack): An artist with ALS used a BCI to control a live dance performance in real time. Not rehab. Not medicine. Art. And the technical stack is way more accessible than you'd think.
- [Surelock and Deadlocks in Rust: I Got Burned at 2am and Now I Get Why This Has 214 Points](https://juanchi.dev/en/blog/surelock-rust-deadlock-mutex-burned-production-2am): I had Rust code in production with mutexes. It deadlocked at 2am. Zero compiler warnings. When Surelock hit Hacker News with 214 points, I opened the repo and finally understood wh
- [How They Broke the Top AI Agent Benchmarks — and What That Says About My Stack](https://juanchi.dev/en/blog/how-they-broke-top-ai-agent-benchmarks-what-it-says-about-my-stack): I read the paper that exploded on HN about how top AI agent benchmarks get shattered. The problem isn't the models — it's that we're measuring the wrong things and building on sand
- [I Reviewed 3 Vibe-Coded PRs With Hardcoded Keys — The Problem Isn't the AI, It's That I Approved Them](https://juanchi.dev/en/blog/vibe-coded-prs-hardcoded-api-keys-security-code-review): Three AI-generated PRs. Three AWS API keys sitting in the code. Three times I approved them because the tests passed. The security problem with vibe-coding isn't the model — it's h
- [Contributing to the Linux Kernel with AI: I Read the HN Thread and I Have an Opinion Nobody's Going to Like](https://juanchi.dev/en/blog/ai-linux-kernel-contributions-unpopular-opinion-hn-debate): 324 points on HN. Comments split between "never" and "it's already happening." I loaded Linux's entire git history into a database and what I found forced me to pick a side — even 
- [Twill.ai and the "delegate to an agent, get a PR" dream: I lived it and it's weirder than it sounds](https://juanchi.dev/en/blog/twill-ai-agent-generated-prs-epistemic-responsibility-real-experience): YC S25, agents that read issues and open PRs on their own. Sounds like the future. But I've spent months working with coding agents and the real problem isn't whether the PR compil
- [France Ditches Windows for Linux: What We're All Missing](https://juanchi.dev/en/blog/france-windows-linux-migration-what-nobody-tells-you): France announced the largest Linux migration in Europe. I spent six months with a provincial agency that tried the same thing — and ended up worse than before. Not because of the O
- [Will AI Agents Kill Git? There's $17M Betting They Will](https://juanchi.dev/en/blog/will-ai-agents-kill-git-17-million-version-control-successor): Every few years someone tries to kill Git and I always think the same thing: the problem isn't the tool, it's us. But this pitch hit differently — because AI agents are committing 
- [TigerFS: A Full Filesystem Inside PostgreSQL (And Why This Obsession Feels Like a Symptom)](https://juanchi.dev/en/blog/tigerfs-filesystem-inside-postgresql-fuse-experiment): Someone built a complete filesystem inside PostgreSQL. Last year I shoved Linux's entire git history into a database. There's a pattern here worth understanding — not as curiosity,
- [Reverse Engineering SynthID: What Happens to Gemini's Watermark When the Model Runs in Your Browser?](https://juanchi.dev/en/blog/reverse-engineering-synthid-gemini-watermark-browser-edge-detection): Someone's reverse engineering Google's watermark detection system. I ran Gemma in the browser last month. The collision is inevitable: does SynthID survive when the model runs loca
- [Research-Driven Agents: Making the Agent Read Before It Codes](https://juanchi.dev/en/blog/research-driven-agents-read-before-coding-ai-workflow): Months watching agents dump code without context and break everything. I ran a real experiment: force the agent to produce a research artifact before touching a single file. What I
- [Your Digital Signing Cryptography Has an Expiration Date: What NIST Published and How to Migrate Your HSM](https://juanchi.dev/en/blog/nist-post-quantum-digital-signing-hsm-migration-ml-dsa-fips-204): NIST finalized post-quantum standards in August 2024. RSA and ECDSA have a 2035 deadline. If you're signing documents, JWTs, or certificates with an HSM, this affects you right now
- [9 TypeScript Patterns That Kill Bugs Before You Run the Code](https://juanchi.dev/en/blog/typescript-patterns-that-eliminate-bugs-at-compile-time): Discriminated unions, branded types, satisfies, infer, Result&lt;T,E&gt;, type predicates, and mapped types — the type system patterns that make entire categories of bugs impossibl
- [I Reallocated $100/mo From Claude Code to Zed + OpenRouter: What Nobody Tells You About Switching AI Tools](https://juanchi.dev/en/blog/reallocated-claude-code-budget-zed-openrouter-what-nobody-tells-you): This isn't just about money. When you switch AI tools, you switch your workflow. When you switch your workflow, you change which projects you dare to start. Here's what I lost, wha
- [I Dumped Linux's Entire Git History Into a Database — and What I Found Felt Like Archaeology](https://juanchi.dev/en/blog/linux-git-history-postgresql-database-archaeology-commit-analysis): What happens when you stop treating your commit history like logs and start treating it like data. I did it with my own repos. What I found was uncomfortable, revealing, and forced
- [The Month Anthropic Didn't Respond: Billing, Trust, and the Hidden Cost of AI API Dependency](https://juanchi.dev/en/blog/anthropic-billing-vendor-lock-in-hidden-cost-ai-apis): A 365-point HN thread gave me permission to say what I'd been avoiding: building on AI APIs carries support and continuity risks nobody discusses honestly. I lived it firsthand on 
- [Project Glasswing: What AI Doesn't Tell You When It Writes Your Code](https://juanchi.dev/en/blog/project-glasswing-ai-supply-chain-security-what-ai-doesnt-tell-you): Glasswing hit a nerve I've had for a while. We deploy with AI, generate code with AI, and the attack surface grew in ways we haven't fully mapped yet. Here's what's concrete: what 
- [LittleSnitch for Linux: Why It Took So Long and What That Says About the Ecosystem](https://juanchi.dev/en/blog/littlesnitch-for-linux-outbound-firewall-monitoring-2024): I've been developing on Linux for years and the absence of a decent outbound firewall with a GUI has always been the elephant in the room. This isn't a review — it's an excuse to t
- [MegaTrain: Training 100B+ Parameter LLMs on a Single GPU (And Why I Had to Close My Laptop)](https://juanchi.dev/en/blog/megatrain-full-precision-training-100b-llm-single-gpu): I saw the title and figured it was clickbait. I sat down, read the paper, and had to get up and walk around. MegaTrain proposes training 100B+ parameter models on a single GPU in f
- [Scion: The Agent Orchestration Testbed Google Just Open-Sourced](https://juanchi.dev/en/blog/scion-google-agent-orchestration-testbed-open-source): Google open-sourced Scion, a testbed for orchestrating AI agents. I dug into it alongside Freestyle (sandboxes) and finally understood what each one actually does — and I have a ta
- [Your Accessibility Score Is Lying to Your Face](https://juanchi.dev/en/blog/your-accessibility-score-is-lying-lighthouse-real-world): I scored 98/100 on Lighthouse and axe on juanchi.dev. Then I asked someone who actually uses a screen reader to try it. What happened next embarrassed me. A perfect score and a rea
- [Never Type openssl x509 -text -noout Again: I Built a VS Code Extension for SSL/TLS Certificates](https://juanchi.dev/en/blog/never-type-openssl-x509-again-vs-code-certificate-extension): Fed up with hunting down the exact openssl command every time I needed to inspect a .pem or a .pfx, I built X509 Certificate Utility for VS Code — and it changed my workflow perman
- [I Got Tired of Waiting for Someone to Maintain the HAProxy VS Code Extension — So I Built It Myself](https://juanchi.dev/en/blog/haproxy-vscode-extension-lsp-autocomplete-validation): The only HAProxy extension for VS Code hadn't been touched since 2019. I used it every single day at work and in my homelab, swallowing syntax errors with zero feedback. One night 
- [Vibe-Coding vs Stress-Coding: How I Actually Use AI on Projects That Matter](https://juanchi.dev/en/blog/vibe-coding-vs-stress-coding-how-i-use-ai-on-real-projects): Vibe-coding is fantastic — until your project has real users. Here's the concrete difference between how I use AI for experimentation versus how I use it when production is on the 
- [How Linux Executes a Binary: I Finally Understood It at 33 Years In](https://juanchi.dev/en/blog/how-linux-executes-a-binary-elf-dynamic-linking-explained): 33 years with computers and I only just understood what happens between typing `./my-program` and the code actually running. ELF, dynamic linking, ld-linux — the black hole I kept 
- [Google Maps for Codebases: I Pasted My Own Repo URL and Got a Little Scared](https://juanchi.dev/en/blog/google-maps-for-codebases-analyzed-my-own-repo-with-ai): There's a tool that lets you paste a GitHub URL and ask anything about the code. I used it on my own project. What it showed me about myself wasn't exactly comfortable.
- [Quantum Computing for the Web Dev Who Never Studied Physics: When Should You Actually Worry?](https://juanchi.dev/en/blog/quantum-computing-timeline-for-web-developers-when-to-worry): A 289-point HN post on quantum cryptography left me with a question I can't honestly answer: when should a full-stack developer start worrying about SSL, hashing, and tokens in a p
- [I Ran Gemma in the Browser, No API Keys, and It Broke My Brain](https://juanchi.dev/en/blog/running-gemma-llm-in-the-browser-no-api-keys-local-inference): There's a deeply embedded belief in the dev community about AI in production that's just wrong: that you need an API, a server, and a credit card to add intelligence to your app. I
- [Sandboxes for Coding Agents: What Freestyle Is and Why I Care](https://juanchi.dev/en/blog/sandboxes-for-coding-agents-freestyle-secure-execution): When I started using coding agents on real projects, my biggest fear wasn't that they'd write bad code — it was that they'd execute things on my machine without me understanding wh
- [I Stuffed a Tiny LLM Inside a Next.js App — Here's What I Learned](https://juanchi.dev/en/blog/tiny-llm-in-browser-nextjs-what-i-learned): I reproduced the tiny LLM experiment that blew up on Show HN: Gemma running in the browser, no API keys, inside my usual stack. Here's everything that broke — and the little that a
- [Claude Code Broke in February's Updates — And I Felt It Too](https://juanchi.dev/en/blog/claude-code-february-2025-updates-what-broke-and-what-it-revealed): A 702-point HN thread confirmed what I'd been feeling: Claude Code degraded in February. But the real problem was how much of my own technical judgment I'd quietly outsourced witho
- [From DOS to Cloud: My 30-Year Journey with Tech — From an Amiga in 1994 to Deploying on Railway with Next.js](https://juanchi.dev/en/blog/from-dos-to-cloud-30-year-tech-journey-amiga-1994-to-nextjs-railway): I first touched an Amiga 500 at age 3 and understood absolutely nothing. Today I deploy in seconds from a terminal. In between: internet cafés, Linux servers at 3am, and a career p
- [From 3 Seconds to 300ms: How I Optimized a Next.js App in Production](https://juanchi.dev/en/blog/from-3-seconds-to-300ms-nextjs-performance-optimization-production): Brutal diagnosis, concrete changes, and real metrics. Here's how I took a Next.js app from embarrassingly slow to 300ms FCP — no magic, no excuses, just actual work.
- [The Perfect Tech Stack in 2025: What I'd Choose Starting a Project Today](https://juanchi.dev/en/blog/perfect-tech-stack-2025-what-i-would-choose-for-a-new-project): After years of breaking things in production, here's my ideal stack for 2025. No hype, no unnecessary vendor lock-in, and enough battle scars to justify every single decision.
- [TypeScript: The Patterns I Actually Use Every Single Day](https://juanchi.dev/en/blog/typescript-patterns-i-actually-use-every-day): Discriminated unions, branded types, advanced generics, and how I actually think about types when I code. Not an academic tutorial — this is what I use in production after years of
- [How I Built juanchi.dev on the Most Bleeding-Edge Stack of 2025: Next.js 16, React 19, Tailwind v4 & Railway](https://juanchi.dev/en/blog/building-juanchi-dev-nextjs-16-react-19-tailwind-v4-railway): An honest postmortem of building my portfolio with the freshest stack of 2025. Spoiler: almost everything broke. I rebuilt it anyway. Here's why it was worth every hit.
- [Next.js App Router: The Guide I Wish I Had When I Migrated from Pages Router](https://juanchi.dev/en/blog/nextjs-app-router-migration-guide-from-pages-router): I migrated three production projects from Pages Router to App Router and broke everything twice before I truly understood how it works. Server Components, streaming, cache, nested 
- [From DOS to Cloud: My 33-Year Journey with Tech — From an Amiga in 1994 to Deploying on Railway with Next.js](https://juanchi.dev/en/blog/from-dos-to-cloud-33-year-tech-journey-amiga-1994-nextjs-railway): I started on an Amiga 500 at age 3 and today I ship apps on Railway with Next.js. This is the unfiltered story of how tech shaped me, broke me, and put me back together — from a Bu
- [Docker for Node.js Developers: From Zero to Production Without Losing Your Mind](https://juanchi.dev/en/blog/docker-for-nodejs-developers-zero-to-production): Three broken Dockerfiles, two production outages, and one sleepless night — that's what it cost me to really understand Docker with Node.js. Here's everything I learned so you don'

## Feeds

- RSS (ES): https://juanchi.dev/feed.xml
- RSS (EN): https://juanchi.dev/en/feed.xml
- Atom (ES): https://juanchi.dev/atom.xml
- Atom (EN): https://juanchi.dev/en/atom.xml
- JSON Feed (ES): https://juanchi.dev/feed.json
- JSON Feed (EN): https://juanchi.dev/en/feed.json

## Optional

- Sitemap: https://juanchi.dev/sitemap.xml
- Full content dump: https://juanchi.dev/llms-full.txt
