Sign in

Chad

@chadfennell.com
98 followers 262 following 196 posts

The Ted Lasso of Software Consultants

PostsRepliesMedia
Chad @chadfennell.com · 14h
If you're looking to level-up on container security: www.oreilly.com/library/view... An accessible and thorough intro on the fundamentals.
oreilly.com
000
Reposted by Chad
Sarah Andersen @sarahseeandersen.bsky.social · 30/09/2026
The image is of a four panel comic.
The first panel shows Sarah, the protagonist, holding a red ball labeled "A SILLY MEME".
The second panel shows Sarah taking the ball and going through a door labeled "GROUP CHAT".
The third panel shows a group of women sitting together and consoling one woman in the center. The woman in the center is saying "...And that's how it happened. It's been the worst day of my life."
The fourth panel shows Sarah standing in the doorway behind them awkwardly holding the red ball.
112188503891
Chad @chadfennell.com · 27/09/2026
Whatever benefit types confer to agents they are negated by the verbosity of TS. Holy hell.
000
Reposted by Chad
Brittany Ellich @brittanyellich.com · 23/09/2026
Me spinning up a quick lil Astra session to resolve some merge conflicts on an old PR
"What is my purpose" meme, Rick saying "You resolve merge conflicts" and the sad little robot saying "oh my god"
41629
Chad @chadfennell.com · 16/09/2026
Fascinating - TIL!
000
Reposted by Chad
Andree Toonk @atoonk.bsky.social · 27/08/2026
We've come a long way over the last few months. Today we're offically launching Tailscale PAM (beta). I'm super happy with this beautiful integration, amazing team work! 🧡
0193
Chad @chadfennell.com · 26/08/2026
Something I recently suggested to a client who was looking for ways to ease team AI fatigue: Trad Day Reserve at least day a week to write everything by hand - add tackle technical debt for extra therapy Slow is smooth, smooth is fast.
000
Chad @chadfennell.com · 26/08/2026
Tailscale's forthcoming Aperture+ looks very promising. Everybody and their mother seems to be launching their own agent sandbox/runner platform. A+ = BYO infra (includes your laptop) and make it as simple as logging into an app for access. Cheap, secure, sovereign. youtu.be/j3CNNXUc4KE?...
youtu.be
TailscaleUp Keynote Live Stream
YouTube video by Tailscale
161
Chad @chadfennell.com · 26/08/2026
Incus continues to slay discuss.linuxcontainers.org/t/incus-7-3-...
discuss.linuxcontainers.org
Incus 7.3 has been released
The Incus team is pleased to announce the release of Incus 7.3! Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix ...
000
Chad @chadfennell.com · 24/08/2026
Been enjoying dbt - I chose it for a client project that required ongoing analytics work. It gave us a nice balance of features w/out having to rewrite our brains to a totally new paradigm: a light DSL over SQL with composable primitives, build time data validation, and a lot more. www.getdbt.com
getdbt.com
Deliver trusted data with dbt | dbt Labs
dbt Labs empowers data teams to build reliable, governed data pipelines—accelerating analytics and AI initiatives with speed and confidence.
000
Chad @chadfennell.com · 24/08/2026
Feeling the need for some maker inspiration, I picked up this the other day www.penguinrandomhouse.com/books/313546... It's excellent, plus one, would recommend.
penguinrandomhouse.com
Jony Ive by Leander Kahney: 9781591847069 | PenguinRandomHouse.com: Books
“An adulating biography of Apple’s left-brained wunderkind, whose work continues to revolutionize modern technology.” —Kirkus Reviews In 1997, Steve Jobs...
000
Chad @chadfennell.com · 22/08/2026
Playing with Kimi-K3 (via DeepInfra) on Hermes Agent today - extremely good experience so far (doing some business planning). deepinfra.com/moonshotai/K...
deepinfra.com
Kimi K3 API - Demo - DeepInfra
Kimi K3 is Moonshot AI's 2.8T-parameter open-weight multimodal reasoning model. Built for complex coding, knowledge work, and long-horizon agentic workflows, it excels at navigating large repositories...
010
Reposted by Chad
Mike Zornek, looking for work. @mikezornek.com · 13/08/2026
I'm looking for more Elixir consulting work, so I built a low-risk offer to reach new faces. Two weeks. One problem. $6,000 (discounted). One nagging thing: flaky tests, a stalled upgrade, a Sentry backlog. Know a team it'd suit? A share or intro would mean a lot. 🙏 #ElixirLang
mikezornek.com
Elixir Consulting
Elixir and Phoenix consulting. Fixed-price two-week sprints at $6,000, or ongoing hourly work, for teams that need upgrades, stability, and senior review.
041
Reposted by Chad
Zach Daniel @zachdaniel.dev · 12/08/2026
We have a serious CVE for #AshFramework. If you are using #AshFramework please update to the latest version as soon as you can. cna.erlef.org/cves/CVE-202...
cna.erlef.org
CVE-2026-67579
0129
Reposted by Chad
johanna @jola.dev · 06/08/2026
Wrote a little quickstart and background for how to my Elixir atproto OAuth library to build apps. Definitely planning to write more content like this! Atproto enables building really interesting apps and experiences, and #ElixirLang is a great language for it jola.dev/posts/latch-...
jola.dev
Latch - an Elixir atproto OAuth library
Introducing Latch, an idiomatic elixir atproto OAuth library and client, built for flexibility and correctness.
2336
Chad @chadfennell.com · 29/07/2026
A fantastic white paper on code sandbox security with a really important vector that I hand't considered: patch cadence arxiv.org/pdf/2606.08433
arxiv.org
010
Reposted by Chad
Mike Dalessio @flavorjon.es · 29/07/2026
Upgrade Rails immediately, kids, this is a big one. github.com/rails/rails/...
github.com
Possible arbitrary file read and remote code execution in Active Storage variant processing
### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process envi...
14930
Chad @chadfennell.com · 29/07/2026
Over the past couple of years, I noticed a lot of devs (myself included) were pretty fuzzy about what people mean by "sandboxes" for agents and dev spaces. Recently, I had the idea to turn some of that research into a website for fun if not profit: sandboxicon.com
sandboxicon.com
sandboxicon.com, shared kernel, or its own?
A field guide to container and VM isolation, and what your AI coding agent actually runs with by default. Every claim is labeled by how well it's sourced.
210
Chad @chadfennell.com · 19/07/2026
😂
000
Chad @chadfennell.com · 15/07/2026
Wat
000
Chad @chadfennell.com · 15/07/2026
Nothing new under the sun and all that www.preprints.org/manuscript/2... Cognitive Offloading Is a Cognitive Universal We show how ecological niche construction...& the ability of LLMs to demonstrate fluent language use in the absence of extra-linguistic input all exemplify this offloading process
preprints.org
000
Chad @chadfennell.com · 12/07/2026
For better or worse, the kind of things I think about while hiking. Conversations, projects, and ideas rattle around in my head and I try to take a step back and think hard about funamentals. I enjoy nature and stuff too. chadfennell.com/lab/5-heavin...
chadfennell.com
The Unbearable Lightness of Software
Developers often reject systems on the basis of 'heaviness.' But is heaviness the right criterion for selection?
000
Chad @chadfennell.com · 12/07/2026
Bumped into BEAR INFO up in the Muir Wilderness area this week😂 "If you see a bear, chase it like you are trying to catch it and eat it, Get mad. Be mean. They will run away in terror - Charlotte Lake Ranger" RIDE IT LIKE A WILD STALION. DRIVE IT INSANE BY INSCESSANTLY TALKING ABOUT THE WORLD CUP
BEAR INTO
Bears have gotten food from hikers in this area and will continue to try to get your food. DO NOT LET THEM.
Keep all food, trash, and scented items in a locked bear canister, a closed Food storage locker, a backpack ont your back, or in your hands. Never leave foo unattended, not even for a minute.
If you see a bear, chase i like you are trying to catch it and eat it, Get mad.
Be mean. They will run away in terror.
Chase the bear
er as long as you
physically can. Die not get between
a
mother and cub, but you ean chase them as a unit. Loud noises dont really seare
bears on their own.
Thank you for helping take care of these amazing ammal friends!
- Charlt
Lake Ranger
010
Chad @chadfennell.com · 03/07/2026
Whether it's AI use, politics, or business - the opinions of people in the arena will always carry more weight for me than those on the sidelines.
000
Reposted by Chad
mean things I say to myself @meantomyself.bsky.social · 29/06/2026
Old enough to recognize this as a data center
Lockable floppy disk holder from the late 20th century
976259583481
Chad @chadfennell.com · 01/07/2026
ARIatHOME never fails to put me in a good mood. NYC is a such a gift. www.youtube.com/watch?v=GGUl...
youtube.com
Is SHREDDING in PUBLIC Like This Even LEGAL??
YouTube video by ARIatHOME
000
Reposted by Chad
Shahryar Tavakkoli @shahryar-tbiz.bsky.social · 29/06/2026
🚀 Dear Elixir developers! 💜 Please help test Mishka Chelekom Headless Components! Your feedback will help us find bugs and get ready for release. 🐛✨ Our biggest release yet is almost here, with even more features on the way! 🎉🔥 Thanks for your support! 🙌 #ElixirLang
193
Chad @chadfennell.com · 26/06/2026
GitHub has fewer nines than The Straight of Hormuz
010
Reposted by Chad
Josh Price @joshprice.com · 24/06/2026
💥 Elixir PSA: update Plug *immediately* to the latest possible (1.20.1) The latest CVE makes it trivially easy to DOS a plug based server. cna.erlef.org/cves/CVE-202... This one is a doozy stay safe out there and keep your deps updated! #elixir-lang
cna.erlef.org
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
42930
Chad @chadfennell.com · 23/06/2026
Some brain droppings on Complexity and Polyglot Programming chadfennell.com/lab/4-polygl...
chadfennell.com
On Polyglot Programming
Build a toolbox and fill it full of tools.
000
Chad @chadfennell.com · 22/06/2026
firecracker level isolation w/out firecracker hassles - very promising microsandbox.dev Plus, secrets stay on the host (like Deno's new offering). More of this plz.
microsandbox.dev
microsandbox - Every agent deserves its own machine
microsandbox runs lightweight microVMs locally on your machine. Programmable networking, custom filesystems, secrets that never leak.
100
Reposted by Chad
Sam Rose @samwho.dev · 18/06/2026
I've made a Kubernetes that runs in the browser, and today we're open sourcing it. The hope here is to make super interactive and visual web content about Kubernetes much easier to write, and we have a whole bunch planned this year. Repo: github.com/ngrok/webern... Demo: webernetes-demo.ngrok.app
1317436
Chad @chadfennell.com · 10/06/2026
It's easy to get tunnel vision as an adult, particularly in a busy chaotic environment. We start hammering things into the shapes of previous problems we solved out of convenience and sometimes...despiration.
static.klipy.com
Admiral Ackbar: It's A Trap Meme
Alt: Admiral Ackbar: It's A Trap Meme
100
Chad @chadfennell.com · 06/06/2026
Woooooot!!!
020
Chad @chadfennell.com · 04/06/2026
An educational frozen dessert called "Popcyclical" that comes in the shape of Pope Leo with a wrapper that has the MAGNIFICA HUMANITAS Encyclical written in Dr. Bronner's font. Papa paparum est, poppa of poppas, Pope of Popes. #free_product_ideas
000
Chad @chadfennell.com · 04/06/2026
A Zoom plugin called "FATALITY" that allows you to murder one avatar a day. #free_product_ideas_thursday
000
Chad @chadfennell.com · 30/05/2026
TIL Firewalla's Wake on LAN implementation just works with my home dev box. I can wake it up remotely with a click on the Firewalla app.
static.klipy.com
Will Ferrell Enjoys Hot Coffee
ALT: Will Ferrell Enjoys Hot Coffee
000
Reposted by Chad
Tyler A. Young ⚗️🧑🏻‍💻 @tylerayoung.com · 28/05/2026
At work, we got our app compiling without warnings on #ElixirLang 1.20-rc.6. The new type system discovered ~500 issues that 1.19 did not. - Most were just dead code (handling patterns that could never actually match in practice) - A handful were outright bugs. (See below)
1282
Chad @chadfennell.com · 27/05/2026
GPT/codex has gotten pretty dang good.
000
Reposted by Chad
Lauren Deschain @thatnerdchick.bsky.social · 25/05/2026
Thanks, Vonnegut. 💜
277189335173
Reposted by Chad
Peter Ullrich @peterullrich.com · 25/05/2026
🚨 Update hackney 🚨 A **bunch** of vulnerabilities I reported in hackney were just disclosed. Please upgrade to 4.0.1 ASAP. I know this is gonna start dependency hell so please take some time for this. Please RT for reach. #ElixirLang cna.erlef.org/cves/
cna.erlef.org
List of Issued CVE’s
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
43023
Chad @chadfennell.com · 23/05/2026
Been on Kagi for a while now and I'll give up a lot of other services before I give up this one. No going back. arstechnica.com/gadgets/2025...
arstechnica.com
Dumping Google’s enshittified search for Kagi
Enough is enough: I’ve jettisoned Google in favor of a search engine that doesn’t treat me like a product.
020
Chad @chadfennell.com · 23/05/2026
Distracted boyfriend meme. Boyfriend looking at another woman. In this case the boyfriend is your repos, the other woman is GitLab and your girlfriend is GitHub
000
Reposted by Chad
Bart Blast @bartblast.com · 13/05/2026
Hey Elixir friends, funny how getting a feature down to a simple one-line call takes two weeks of design work. Sharing what that looked like for Hologram realtime.
Initial page mount + SSE attach
771
Chad @chadfennell.com · 13/05/2026
<chef's kiss>
000
Reposted by Chad
Peter Ullrich @peterullrich.com · 12/05/2026
🚨 New Blog Post 🚨 I wrote about how I got into finding CVEs and what's the plan going forward. Also, I open-sourced the prompts I've been using. peterullrich.com/what-the-cve
peterullrich.com
What the CVE?
How I'm using Claude Opus 4.7 to find and report CVEs in popular Hex packages to make the BEAM ecosystem safer.
43814
Chad @chadfennell.com · 12/05/2026
PSA www.stepsecurity.io/blog/mini-sh... Tips and tricks: * Pin/Lag slightly behind new releases * Containerize your dev env * Use few & scoped env vars (e.g. 1Pass service account w/select vault access) * Build in team rotation & visibility (e.g. 1Pass hydration script vs static .env file)
stepsecurity.io
TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages - StepSecurity
The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attac...
020
Chad @chadfennell.com · 10/05/2026
rtk is an excellent way to reduce token spend for agents running shell commands like "find" github.com/rtk-ai/rtk Love it.
github.com
GitHub - rtk-ai/rtk: CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies - rtk-ai/rtk
000
Reposted by Chad
Peter Ullrich @peterullrich.com · 09/05/2026
🚨 Update absinthe 🚨 Yesterday 2 CVEs for "absinthe" were released. The vulnerabilities can exhaust your CPU and atom tables. Update ASAP Thank you Curtis Schiewek and team for the quick fix and to @maennchen.dev for managing the release cna.erlef.org/cves/CVE-202... cna.erlef.org/cves/CVE-202...
cna.erlef.org
Quadratic fragment-name uniqueness check causes denial of service in absinthe
This project handles the CVE Numbering Authority (CNA) for the Erlang Ecosystem Foundation (EEF).
0155