Sign in

Matteo Collina

@nodeland.dev
4.6K followers 374 following 1.8K posts

Platformatic.dev Co-Founder & CTO, Node.js TSC member, Lead maintainer Fastify, Board OpenJS, Conference Speaker, Ph.D. Views are my own.

PostsRepliesMedia
Matteo Collina @nodeland.dev · 28/09/2026
Nub's thread-pool PR has good bcrypt numbers for bumping the pool on the tested machines. But I disagree with auto-sizing it from CPU count. Before adding threads, we need to know what else is using the machine. 🧵
120
Matteo Collina @nodeland.dev · 18/09/2026
The key security idea: remove all permissions *before* compiling, importing, or running any caller-supplied code. 1️⃣ Acquire admission before inspecting caller input 2️⃣ Validate the boundary against allowlists 3️⃣ Build a restricted worker with the Permission Model on
110
Matteo Collina @nodeland.dev · 18/09/2026
`secure-eval-worker` uses Node's Permission Model + worker threads. The simplest API is `runUntrustedCode()`:
110
Matteo Collina @nodeland.dev · 18/09/2026
Running JavaScript at runtime is everywhere now: AI-generated changes, user automation, plugins, programmable app parts. The problem is that a regular `eval()` inherits all the host's permissions. We built something to help.
2112
Matteo Collina @nodeland.dev · 14/09/2026
What if you could execute a @nodejs.org package without ever unzipping it? What if npm had no central server, just a peer-to-peer mesh with cryptographic integrity baked in?
121
Matteo Collina @nodeland.dev · 03/09/2026
🎟️ NodeConf EU 2026 is in Bologna in 3 weeks, and tickets are running low. Sep 29-30. The Savoia Regency, an 18th-century villa set in a 10,000m² park, 5km from the city center. Pool between sessions, Emilia-Romagna food, and two days of real Node.js depth.
1103
Matteo Collina @nodeland.dev · 20/08/2026
Storage now handles more than 400 million uploads a day, with total requests topping a billion across all regions. Traffic surged 200x as AI-native builders adopted the platform. Did you know Storage is OSS? github.com/supabase/sto...
120
Matteo Collina @nodeland.dev · 19/08/2026
The catch was the round trips. Each query waits for the previous response before sending the next, so ten queries means ten waits. Pipelining fires them all and reads the answers back in order.
110
Matteo Collina @nodeland.dev · 11/08/2026
On my way to Atlanta for Render..!
1180
Matteo Collina @nodeland.dev · 05/08/2026
🔥 NEW BANTER: "Should You Block the Event Loop?" Day one of Node.js, you learn one rule: never block the event loop. A customer brought us a compression problem that turned that rule on its head. Async didn't just lose. It took the app down. Luca and I go through it. 📅 Aug 12th
120
Matteo Collina @nodeland.dev · 03/08/2026
🔥 NEW BANTER: "Nitro Builds the Server. Who Runs the Fleet?" Nitro gives you a clean, portable server. Consistent builds. Familiar routing. Great DX. Then you scale to five instances with a cron job and nobody is in charge. Luca, Paolo and I dig into @platformatic/nitro. 📅 Aug 5th
100
Matteo Collina @nodeland.dev · 29/07/2026
Undici security release is out: v8.9.0, v7.29.0 and v6.28.0. Five advisories, one high severity and four medium. If you use Undici directly or through fetch() in Node.js, upgrade. npm i undici@^8.9.0 (or ^7.29.0 / ^6.28.0) github.com/nodejs/undic...
132
Matteo Collina @nodeland.dev · 28/07/2026
🔥 NEW BANTER: "Your Bug Fix Will Never Reach the Runs That Need It" You find a critical bug. You fix it. You deploy. Meanwhile the 30-day subscription cycles, the compliance timers, the approvals waiting on a signature are all still running the broken workflow version. They never get your fix.
100
Matteo Collina @nodeland.dev · 16/07/2026
Run Eve agents on Kubernetes with @platformatic.dev. Eve gives you Markdown instructions, TypeScript tools, and durable workflows, but production needs more than just an HTTP server. 🧵
120
Matteo Collina @nodeland.dev · 06/07/2026
🔥 NEW BANTER: "Your Node.js Gateway Is Doing Twice the Work" You launch. Thousands hit the same link at once. The cache is cold. And your app builds the exact same response hundreds of times in parallel. Luca and I sit down with Paolo Insogna to make it stop. 📅 July 8th
110
Matteo Collina @nodeland.dev · 26/06/2026
🔥 NEW BANTER: "How Do You Build Skew Protection? Let's Unpack It" "Zero downtime" doesn't mean zero risk. You ship new code. Half your users still have the old version open in their browser. Then a checkout fails. 📅 July 1st 🔗 streamyard.com/watch/RnVyfV...
120
Matteo Collina @nodeland.dev · 22/06/2026
🔥 NEW BANTER: "Why Shipping Fast Breaks Your Users (and How to Stop It)" You deployed at 11am. A user who opened the app at 9am clicks a button. 404. You didn't break anything. You just shipped. Luca and I get into it. 📅 Jun 24th 🔗 streamyard.com/watch/VG7m2C...
120
Matteo Collina @nodeland.dev · 15/06/2026
A default set from May 2015 was just changed for the first time. One number. One constant. And it was quietly costing Node.js up to 26% of its throughput on the workloads you run every day: file reads, HTTP parsing, and stream chunking. streamyard.com/watch/9y9Q4G...
111
Matteo Collina @nodeland.dev · 08/06/2026
Memory vs performance. Everyone treats it like a fight where you have to pick a side. The new episode of The Node (and more) Banter asks a better question: can we have both instead?
110
Matteo Collina @nodeland.dev · 29/05/2026
Your Node.js service has rate limiting. You tested it. You shipped it. And it is quietly lying to you.
121
Matteo Collina @nodeland.dev · 20/05/2026
The name was easy. In Italian, "destino" means "doom". Paolo made the classic DOOM comment at the summit. Luca and I decided to run with it.
100
Matteo Collina @nodeland.dev · 18/05/2026
Bun rewrote itself from Zig to Rust. AI did most of the work. 98% of the test suite passed on the first run. The question isn't hypothetical anymore. Should we rewrite Node.js in Rust?
10402
Matteo Collina @nodeland.dev · 11/05/2026
🔥 NEW BANTER: "We Ran DOOM in a Node.js Terminal. Now There's No Excuse for Your Legacy Native Code" 35fps. With sound. Inside your terminal. Powered by Node.js FFI. 📅 May 13th 🔗 streamyard.com/watch/bagFGb...
130
Matteo Collina @nodeland.dev · 04/05/2026
Most teams think autoscaling is solved. Set a CPU threshold. Let Kubernetes do the rest. Then a 3-min spike hits, your pods take 2 min to boot, and the party is over before they show up. New episode of The Node (and more) Banter drops May 6th. 🧵
110
Matteo Collina @nodeland.dev · 01/05/2026
We also published a paper on this. arxiv.org/abs/2604.19705
000
Matteo Collina @nodeland.dev · 01/05/2026
Huge credit to Ivan Tymoshenko on this one. The math is genuinely beautiful. Full blog post with all the benchmarks: blog.platformatic.dev/ahead-of-tim...
100
Matteo Collina @nodeland.dev · 01/05/2026
Sudden spike test (0 → 800 req/s in 10 seconds) is even more telling. Nobody can predict a cold spike. But ICC recovers in seconds because it keeps building the trend even when ELU is pinned at 1.0. KEDA and HPA do their staircase for 2 full minutes.
100
Matteo Collina @nodeland.dev · 01/05/2026
Steady ramp test. 10 → 800 req/s on Next.js 16. ICC kept ELU below threshold the entire time. KEDA hit 0.92 average ELU at peak. HPA stayed elevated for most of the test.
100
Matteo Collina @nodeland.dev · 01/05/2026
So we asked a better question. Not "is my app overloaded right now?" But: "will my app be overloaded by the time a new pod is ready?" That's Platformatic ICC. It predicts.
100
Matteo Collina @nodeland.dev · 01/05/2026
Node.js doesn't degrade gracefully. The event loop falls off a cliff. At 70% ELU your app feels fine. At 95% latency grows hyperbolically At 100% the event loop starts queuing.
100
Matteo Collina @nodeland.dev · 01/05/2026
20x lower median latency than HPA. 6x lower than KEDA. 17x fewer failed requests than HPA. 9x fewer than KEDA. Same app. Same cluster. Same metric. The only thing we changed was the autoscaler. 🧵
121
Matteo Collina @nodeland.dev · 29/04/2026
Medusa is a flexible open source commerce platform for Node.js. It pushes you toward a multi-app architecture from day one: - backend API - admin UI - storefront - image optimizer - shared env vars - public + internal URLs The repo sprawl problem starts here.
140
Matteo Collina @nodeland.dev · 28/04/2026
Why is Claude Code so good? It's not just the model. It's that the harness runs in the same host where the code executes. Same filesystem. Same process tree. Same state. That co-location is the feature. And it's exactly what production agents lose.
241
Matteo Collina @nodeland.dev · 20/04/2026
🔥 NEW BANTER: "AI Agents, Kubernetes, and the Sandbox That Made It Possible" Most teams building AI agents treat Kubernetes like it is optional. Until someone asks how to scale it. Or govern it. @lucamaraschi and I did a full launch week debrief. 📅 April 22nd 🔗 streamyard.com/watch/9n4cF3...
100
Matteo Collina @nodeland.dev · 30/03/2026
I’m so stocked that Codemotion made me as a Magic card. 🥹 See you tomorrow at conferences.codemotion.com/roma/
3210
Matteo Collina @nodeland.dev · 24/03/2026
Readers spotted that compression was not applied consistently in our React SSR benchmarks. TanStack Start had it disabled while the others had it on. We disabled compression everywhere and re-ran the tests. Here are the corrected results.
4141
Matteo Collina @nodeland.dev · 23/03/2026
🔥 NEW BANTER: "Node.js VFS: Unlocking Dynamic Code, Testing, and Multi-Tenancy" 🔗 streamyard.com/watch/qjiaVX...
120
Matteo Collina @nodeland.dev · 19/03/2026
The ICC dashboard gives you full observability: real-time run status, step-level trace waterfalls, and a directed graph view of your workflow structure. You can replay completed runs, cancel running ones, and inspect hooks and events.
100
Matteo Collina @nodeland.dev · 19/03/2026
The fix: a dedicated service that owns the data. @platformatic/workflow is a Watt app backed by PostgreSQL that manages all state and queue routing. It knows about active runs, pending hooks, sleeping workflows, and queued messages. ICC only decommissions a version when all counts hit zero.
100
Matteo Collina @nodeland.dev · 19/03/2026
We tried extending our Intelligent Command Center (ICC) directly, but it couldn't tell when a version had no work left. A workflow can register a webhook and suspend. No memory use, no heartbeat. ICC sees nothing and kills the version. Hours later someone clicks the link and the pods are gone.
100
Matteo Collina @nodeland.dev · 19/03/2026
The problem: Workflow DevKit uses deterministic replay. When a workflow resumes, it reruns from the start, matching steps to cached results in the same order. Deploy a new version while runs are in-flight? The step order changes, correlation IDs break, and you end up with silent data corruption.
100
Matteo Collina @nodeland.dev · 18/03/2026
🧵 I wrote almost 19,000 lines of code for a Virtual File System in @nodejs.org core using Claude Code. It started over Christmas and has been refined over almost three months of review. A collaborator challenged whether AI-assisted contributions can meet the DCO requirements. Here's what happened:
272
Matteo Collina @nodeland.dev · 17/03/2026
Your coding agent keeps making the same mistakes? I built a fix. Introducing pi-self-learning: a pi extension that gives your coding agent actual memory. It extracts what went wrong after each task, scores learning by frequency/recency, and automatically injects them into context. 🧵 👇
2121
Matteo Collina @nodeland.dev · 16/03/2026
.@nodejs has always been about I/O. Streams, buffers, sockets, files. But there's a gap that has bugged me for years: you can't virtualize the filesystem. You can't import a module that only exists in memory. You can't bundle assets into a Single Executable without patching half of core. 👇
510817
Matteo Collina @nodeland.dev · 13/03/2026
🔥 NEW BANTER: "Why Node.js Is the Critical Enabler for AI Applications" Everyone's building AI apps. Almost nobody's talking about what runs them. Hint: it's not Python. @lucamaraschi and I make the case for Node.js as the backbone of production AI. 📅 March 18th
150
Matteo Collina @nodeland.dev · 12/03/2026
Think of it as having a seasoned developer pair program with you: except this one never forgets that obscure V8 flag you mentioned in 2022. Check it out: github.com/mcollina/skills
190
Matteo Collina @nodeland.dev · 11/03/2026
Grammarly uses AI trained on my talks to review articles. Especially my new articles. I find this flattering and amusing... but also a bit worried for the future. What would you do if they trained an AI after your style?
370
Matteo Collina @nodeland.dev · 10/03/2026
Are you hosting Next.js on K8s? Your Next.js image optimization is quietly killing your frontend performance. We (@platformatic) just shipped a way to fix it without changing a single line of your app code 🧵
101
Matteo Collina @nodeland.dev · 06/03/2026
The deployment lifecycle is a clean state machine. ICC monitors traffic on draining versions. When there's zero traffic (or the grace period elapses), it removes routing rules, scales to zero, and optionally deletes the old Deployment.
100
Matteo Collina @nodeland.dev · 06/03/2026
How it works: - Each app version runs as a separate, immutable K8s Deployment - ICC detects new versions via label-based discovery - A __plt_dpl cookie pins users to their deployment version - Old versions drain gracefully, then get cleaned up automatically
111