jcarr.dev

James Carr · systems operation and adversarial analysis

Something is probing this host right now. The interesting question is what for.

I don't get excited by building features. I get excited by the moment something is behaving strangely and nobody knows why yet – and on a machine facing the internet, the answer is usually that somebody is trying something.

What can be seen is what they asked for, how often, and whether they came back after being blocked. What cannot be seen is why. A log line will never tell you motive, and keeping those two apart – evidence on one side, judgement on the other – is most of the work.

Where they come from 29 COUNTRIES
United States – 48 detection(s) Australia – 41 detection(s) India – 25 detection(s) Germany – 25 detection(s) China – 22 detection(s) Vietnam – 17 detection(s) Hong Kong – 14 detection(s) Singapore – 13 detection(s) The Netherlands – 10 detection(s) Japan – 10 detection(s) Taiwan – 8 detection(s) South Korea – 8 detection(s) Luxembourg – 6 detection(s) Belgium – 6 detection(s) United Kingdom – 6 detection(s) France – 5 detection(s) Brazil – 5 detection(s) Andorra – 4 detection(s) Indonesia – 3 detection(s) Italy – 3 detection(s) Pakistan – 2 detection(s) Russia – 2 detection(s) Sweden – 2 detection(s) United Arab Emirates – 1 detection(s) Argentina – 1 detection(s) Bangladesh – 1 detection(s) Malaysia – 1 detection(s) Hungary – 1 detection(s) Austria – 1 detection(s) This host – London, UK (declared)
US United States 48 AU Australia 41 IN India 25 DE Germany 25 CN China 22 VN Vietnam 17 HK Hong Kong 14 SG Singapore 13

297 detection(s) from 31 registered countries, since 2026-09-14 17:28Z.

How to read this A marker shows where a network is registered – where somebody rented capacity, not where they are. Colour and size follow how many detections came from that country. An arc is drawn when a request arrives: it marks the two ends of that request, not the route it took. The host marker is the one declared position here; a machine cannot read its own latitude. 6 detection(s) could not be placed – no coordinates for the country, or no country recorded – and are counted in the total rather than shown on the plot.

Ask me anything

An AI, grounded in what I've written, honest about what it doesn't know

Ask about me 🤖 Ask James

Ask about my experience, skills, or background. This is an AI answering from notes I wrote about myself; it will not make things up, and if it does not know it will say so. For anything real, the contact link is always better than a bot.

This machine, right now

Full operations view →

Read from the host at the moment you loaded the page, and updated over the open connection while you read. Nothing here is a screenshot, a mock, or a number typed into the markup. Where a reading cannot be taken, the panel says so rather than showing a plausible default.

Host vitals 18:57:31 UTC
Load 1m / 5m / 15m Load average The average number of processes running or waiting on I/O, over 1, 5 and 15 minutes. It is not a percentage – the figure only means something against the core count, which is why load per core sits beside it. Comparing the three windows tells you whether a spike is building or clearing. 0.01 / 0.03 / 0.00
Per core (2) Load per core Load average divided by the number of CPU cores. Sustained above 100% means work is queuing rather than running, and the machine is behind. 0.5%
Memory used Memory used Derived from MemAvailable – the kernel's own estimate of memory obtainable for new work, including cache it can reclaim. More honest than 'free', which counts cache as used and makes a perfectly healthy machine look full. 54.7%of 1.6 GB
Disk / 8.1% of 58.7 GB
Disk /tmp 8.1% of 58.7 GB
Disk /var/lib/jcarr-app 8.1% of 58.7 GB
Network rx / tx 19.2 B/s / 0.0 B/s
TCP established TCP established Connections currently in the ESTABLISHED state, parsed from /proc/net/tcp. Only the count is taken: remote addresses are never read into anything the page can display. 6
Host uptime Host uptime Time since the kernel booted, distinct from how long the application has been running. Together the two tell you whether a service restarted or the whole machine did – a different problem with a different cause. 59d 21:25:17
Host identity X64
Operating system AlmaLinux 9.8 (Olive Jaguar)
Kernel Kernel release The running kernel version, read from /proc/version. In a container this is the host's kernel, not the image's – containers share the kernel and only bring their own userspace. 5.14.0-687.36.1.el9_8.x86_64
CPU Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
Logical processors 2
Architecture X64
Runtime .NET 10.0.10
Application uptime 56d 10:29:52
Watched units systemd unit A service managed by systemd, the init system on most modern Linux distributions. ActiveState says whether it is running; SubState says what it is actually doing, which is the more useful of the two when something is wrong. systemctl
APPLICATION ACTIVE / running
EDGE PROXY ACTIVE / running
DATABASE ACTIVE / running
INTRUSION FILTER ACTIVE / running
IP jail Jail A fail2ban ruleset: which log to watch, which pattern counts as a failure, how many failures earn a ban, and how long the ban lasts. 0 held

No addresses currently held. Bans are actioned by fail2ban at the edge from the same access log this page reads; this panel reflects the live jail.

Node declared + measured
Provider declared Declared, not measured A configured value rather than a reading. The application cannot determine which datacentre it occupies without asking an external service where its own address is, so this is labelled rather than quietly presented alongside figures that were genuinely measured. AWS Lightsail
Region declared eu-west-2
Site declared London, UK
Node clock 18:57:32 UTC
Node timezone UTC
Host uptime 59d 21:25:16

Every timestamp on this site is UTC, to the second. A distributed log is only as good as the clocks behind it, so the node runs in UTC rather than a local zone – there is no offset to reason about during an incident, and no hour that happens twice a year.

The opposition

Real traffic, grouped by actor · nothing here is seeded
Who has been trying full assessments
Source Masked source The final octet is zeroed before anything is stored or displayed. Enough to tell two sources apart and attribute a network, without retaining data that identifies a person. The full address exists only in memory, for the moment it takes to look up its country. Country Requests Days Assessment Campaign Related activity from one source network grouped over time, rather than counted as separate requests. A single probe says nothing; what an actor went looking for, how long they persisted and whether they returned is the part with analytical value.

Ranked by significance, not recency. A row opens to show the evidence behind its verdict. The diamond flags a source that returned after a block or has been active across more than one day – the signals that separate a passing scan from something deliberate, and which only appear with time.

Watching a machine and watching an opponent are different problems. A disk filling up does not change its behaviour because you noticed. An adversary does – which is why a signature only catches what somebody already catalogued, and fails on the first day of anything new.

So detection here is built on deviation from a measured baseline rather than a list of things to look for, and the reporting keeps what was observed apart from what has been inferred, with a confidence attached to the judgement.

How each source is assessed →

Blocking an address costs an opponent almost nothing – addresses are rented by the hour. Behaviour is far more expensive to change, so the durable detection is the pattern rather than the indicator. The clearest signal available is simply whether a source came back once its block expired: indiscriminate scanning never revisits.

Not every failure has an opponent behind it

Written by the detector as it observes, not composed in advance
Packet worker NOMINAL
Queue depth Queue depth How much work is waiting to be processed. A queue climbing steadily means the consumer has fallen behind the producer, and it is usually the earliest visible symptom of trouble – before anything has actually failed or thrown an error. 0
Processed 121,255,805
CRC failures CRC (cyclic redundancy check) A checksum computed across a payload and transmitted alongside it. Recompute it on receipt and compare: if the values differ, the data changed in transit. Cheap to calculate and reliable against accidental corruption, which is why it appears in everything from Ethernet frames to tactical radio protocols. 0 since reset
Failure rate (recent) Rolling failure rate Failures across the most recent packets, not across all time. A lifetime rate looks fine and is quietly useless: the denominator grows the longer the system stays healthy, until a real fault cannot move it past any sensible threshold – the detector gets worse at its job exactly as the system gets more stable. A fixed window keeps the denominator constant. 0.0% last 250
Mean latency Mean latency An exponentially weighted moving average – recent samples count for more than older ones. It reacts quickly to a genuine shift without needing a full history buffer, and without one old outlier skewing the figure indefinitely. 0.2µs
Heartbeat Heartbeat A periodic signal a worker emits to show it is still alive. The absence is the signal: a stale heartbeat means the worker is wedged, which is precisely the failure mode that produces no error message at all. 18:57:32 UTC
Auto-resolves after 45s. One trigger per source per 10 min.
Incident timeline append-only Append-only Rows are only ever added, never edited or deleted. An incident record that can be tidied up afterwards is not evidence of anything; this one is written by the code at the moment each condition is observed. · 7 shown
20:57:06 RECOVERED CONFIRMED Post-recovery sample: queue depth 0, failure rate 0.0%, mean latency 7.2ms across 25 packets. Nominal.
20:57:05 RESTART CONFIRMED Fault cleared after 45s. Worker queue drained from 627 packets and counters reset; processing resumed at full batch size.
20:56:23 ISOLATED INFERRED Fault scoped to the packet worker: host readings show no corresponding pressure (load 0.00, memory 45.4% used, 4/4 watched units active). Failures are confined to the worker.
20:56:23 QUEUE DERIVED Queue depth 42 and climbing — consumer no longer keeping pace with a steady 25 packet/s offered rate, 3s into the event.
20:56:23 ANOMALY DERIVED Packet failure rate 6.8% exceeds 5.0% threshold across the last 250 packets processed (17 CRC mismatches since the worker last reset).
20:56:21 DEGRADED DERIVED Worker health check DEGRADED: mean processing latency 61.8ms against 40ms threshold.
20:56:20 INJECTED CONFIRMED Fault injected into the packet worker by request. The detection service is not notified and does not read this record — it observes the worker's published metrics like any other consumer.

Sometimes a system is simply broken, and that needs the same discipline. Press the button and a background worker takes a real fault – genuine CRC failures, genuine added latency. A separate detection service, which knows nothing about the trigger, records each threshold crossing as it observes it. The fault clears itself after 45 seconds, and recovery is confirmed against measurements taken afterwards rather than assumed from the fact it cleared.

The thing that watches, so I don't have to

Ambient – no interaction required
Edge detections delayed Feed delay Detections are held briefly before appearing publicly. The evidence is identical a moment later, but an attacker no longer gets a live readout of which requests trip a filter or how close they are to being blocked. The exact delay is deliberately not published – printing it would give back what the delay is there to withhold. · sources masked Masked source The final octet is zeroed before anything is stored or displayed. Enough to tell two sources apart and attribute a network, without retaining data that identifies a person. The full address exists only in memory, for the moment it takes to look up its country.
Detections 24h
11
Bans 24h
1
Currently jailed fail2ban Watches log files for patterns that indicate abuse and blocks the source at the firewall for a set period. The block happens at the packet level, so a banned host never reaches the application at all.
0
Top sources 24h Geolocation Resolving an address to a country and network. Done here against a database file held on this machine, so the address never leaves the process – sending visitor addresses to a third-party lookup service would defeat the point of masking them.
United States 3
Hong Kong 3
Vietnam 2
15:00:03 UNBAN 117.5.151.xxx · VN · AS7552 Viettel Group
10:28:53 SSH-FAIL 170.64.145.xxx · AU Australia Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS14061 DigitalOcean, LLC
07:40:43 SSH-FAIL 116.98.50.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS24086 Viettel Corporation
07:40:43 SSH-FAIL 116.98.50.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS24086 Viettel Corporation
05:48:02 SSH-FAIL 34.78.241.xxx · BE Belgium Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS396982 Google LLC
05:10:10 BAN 65.181.92.xxx · HK · AS4760 PCCW IMS Limited
05:10:10 SSH-FAIL 65.181.92.xxx · HK Hong Kong Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS4760 PCCW IMS Limited
05:10:09 SSH-FAIL 65.181.92.xxx · HK Hong Kong Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS4760 PCCW IMS Limited
05:10:07 SSH-FAIL 65.181.92.xxx · HK Hong Kong Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS4760 PCCW IMS Limited
01:55:04 UNBAN 124.158.15.xxx · VN · AS38733 CMC Telecom Infrastructure Company
00:30:52 UNBAN 68.70.247.xxx · US · AS36103 Central Utah Telephone, Inc.
22:05:46 PATH-SCAN 23.100.83.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/hellopress/wp_filemanager.php · 308 · AS8075 Microsoft Corporation
22:05:15 PATH-SCAN 23.100.83.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/hellopress/wp_filemanager.php · 308 · AS8075 Microsoft Corporation
20:30:53 PATH-SCAN 23.100.83.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/hellopress/wp_filemanager.php · 404 · AS8075 Microsoft Corporation
20:10:21 PATH-SCAN 104.28.221.xxx · PF French Polynesia Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /xmlrpc.php · 400 · AS13335 Cloudflare, Inc.
19:48:41 UNBAN 34.126.173.xxx · SG · AS396982 Google LLC
18:52:11 PATH-SCAN 20.210.166.xxx · JP Japan Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/hellopress/wp_filemanager.php · 308 · AS8075 Microsoft Corporation
18:51:39 PATH-SCAN 20.210.166.xxx · JP Japan Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/hellopress/wp_filemanager.php · 308 · AS8075 Microsoft Corporation
18:49:06 PATH-SCAN 34.126.173.xxx · SG Singapore Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env · 404 · AS396982 Google LLC
18:49:06 INJECTION 34.126.173.xxx · SG Singapore Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /api/console/api_server · 404 · AS396982 Google LLC
18:48:42 BAN 34.126.173.xxx · SG · AS396982 Google LLC
18:48:35 INJECTION 34.126.173.xxx · SG Singapore Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /api/console/api_server · 404 · AS396982 Google LLC
18:48:35 PATH-SCAN 34.126.173.xxx · SG Singapore Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env · 404 · AS396982 Google LLC
17:22:43 PATH-SCAN 45.61.188.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /media/vendor/jquery/js/jquery.min.js · 404 · AS53667 FranTech Solutions
15:48:52 UNBAN 123.139.38.xxx · CN · AS4837 CHINA UNICOM China169 Backbone
15:07:58 PATH-SCAN 185.55.5.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /.git/HEAD · 404 · AS5650 Frontier Communications of America, Inc.
15:07:58 PATH-SCAN 31.204.31.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /.git/HEAD · 308 · AS209372 WS Telecom Inc
15:07:58 PATH-SCAN 66.207.177.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /.git/HEAD · 404 · AS996 JY Mobile Communications
15:00:03 SSH-FAIL 117.5.151.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS7552 Viettel Group
15:00:03 BAN 117.5.151.xxx · VN · AS7552 Viettel Group
15:00:00 SSH-FAIL 117.5.151.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS7552 Viettel Group
14:59:59 SSH-FAIL 117.5.151.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS7552 Viettel Group
14:59:07 UNBAN 129.146.127.xxx · US · AS31898 Oracle Corporation
13:59:21 PATH-SCAN 129.146.127.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /.env · 404 · AS31898 Oracle Corporation
13:59:07 BAN 129.146.127.xxx · US · AS31898 Oracle Corporation
13:58:47 PATH-SCAN 129.146.127.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /.env · 404 · AS31898 Oracle Corporation
12:39:40 PATH-SCAN 172.69.222.xxx · FR France Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /.git/config · 404 · AS13335 Cloudflare, Inc.
11:27:02 UNBAN 45.166.232.xxx · BR · AS268002 INFORME SERVIÇOS DE PROCESSAMENTO DE DADOS LTDA
10:12:10 PATH-SCAN 45.138.12.xxx · GB United Kingdom Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /.git/HEAD · 404
09:59:15 PATH-SCAN 49.204.117.xxx · IN India Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /xmlrpc.php · 400 · AS24309 Atria Convergence Technologies Pvt. Ltd.,
08:23:11 PATH-SCAN 20.196.88.xxx · KR South Korea Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/hellopress/wp_filemanager.php · 308 · AS8075 Microsoft Corporation
08:22:37 PATH-SCAN 20.196.88.xxx · KR South Korea Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/hellopress/wp_filemanager.php · 308 · AS8075 Microsoft Corporation
06:47:00 SSH-FAIL 34.79.75.xxx · BE Belgium Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS396982 Google LLC
02:54:21 PATH-SCAN 143.110.203.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wordpress/ · 308 · AS14061 DigitalOcean, LLC
02:53:49 PATH-SCAN 143.110.203.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wordpress/ · 308 · AS14061 DigitalOcean, LLC
01:55:04 BAN 124.158.15.xxx · VN · AS38733 CMC Telecom Infrastructure Company
01:55:04 SSH-FAIL 124.158.15.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS38733 CMC Telecom Infrastructure Company
01:55:02 SSH-FAIL 124.158.15.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS38733 CMC Telecom Infrastructure Company
01:55:01 SSH-FAIL 124.158.15.xxx · VN Vietnam Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS38733 CMC Telecom Infrastructure Company
00:30:52 BAN 68.70.247.xxx · US · AS36103 Central Utah Telephone, Inc.
00:30:52 SSH-FAIL 68.70.247.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS36103 Central Utah Telephone, Inc.
00:30:46 SSH-FAIL 68.70.247.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS36103 Central Utah Telephone, Inc.
00:30:39 SSH-FAIL 68.70.247.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · AS36103 Central Utah Telephone, Inc.
20:42:17 PATH-SCAN 173.239.214.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-login.php · 404 · AS62240 Clouvider Limited
18:56:20 PATH-SCAN 170.246.251.xxx · BR Brazil Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /xmlrpc.php · 400 · AS61870 Gcu Serviços de Provedor Ltda
16:48:56 PATH-SCAN 136.113.213.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /xmlrpc.php · 308 · AS396982 Google LLC
16:48:21 PATH-SCAN 136.113.213.xxx · US United States Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /xmlrpc.php · 308 · AS396982 Google LLC
16:38:26 PATH-SCAN 20.219.185.xxx · IN India Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/matomo-payment-simple/index.php · 404 · AS8075 Microsoft Corporation
16:37:55 PATH-SCAN 20.219.185.xxx · IN India Where this network is registered. It is not where the operator is – server capacity is rented anywhere, so the network below is the more useful identifier. · /wp-content/plugins/matomo-payment-simple/index.php · 404 · AS8075 Microsoft Corporation
15:48:52 BAN 123.139.38.xxx · CN · AS4837 CHINA UNICOM China169 Backbone

Every request reaching the edge lands in the proxy's access log. A worker tails that log, classifies what matters, enriches it against a geolocation database held on this machine, masks the source to a /24 and files it. The intrusion filter reads the same log through its own rules and blocks at the packet level. Nobody is watching any of it – the automation is the claim, not the monitoring. If you would like to appear in that feed yourself, there is a range set aside for it.

Don't take my word for any of it

Third-party verdicts · re-runnable by anyone

Everything else here is measured by this machine, which means you are trusting the machine. These are not: they are assessments by independent services, and the links re-run them live. If a grade below has slipped since it was recorded, the link will say so rather than this page.

External assessments OBSERVED 2026-08-12
Qualys SSL Labs → A+TLS 1.2 / 1.3
Certificate transparency → public logevery cert ever issued

Recorded when the link was last run, not read live – so unlike every other figure on this site, these are a claim rather than a measurement. That is exactly why each one is a link.

Get in touch

Open to operations, monitoring and incident work

If any of the above is the kind of work you need doing – running systems in real time, working out what something was actually trying to do, and building the automation that catches it next time – I'd like to hear about it.

Everything on this site runs on one small instance I own and operate. The source is public if you want to read how any of it works.

Background

Where this comes from

Years of high-responsibility operational work through long shifts, where monitoring, accurate logging and staying calm when something is wrong matter more than speed, and the cost of missing something is not a bad sprint.

Underneath it, a self-taught systems engineer who builds from bare metal up, an OS, an RTOS, this site, because understanding how something works at every layer is the point.

Current work

One of two core engineers on a B2B SaaS expense platform: owns production releases, monitors via Grafana and ELK, and investigates live incidents on systems other businesses depend on to pay people.

.NET and PostgreSQL day to day, on Linux, with the integration work that comes with talking to payroll and finance systems.

This system

Blazor Server on .NET 10, PostgreSQL, behind Caddy on RHEL-family Linux (AlmaLinux 9), running as an unprivileged service user.

The application can read a fixed, closed list of host files and commands and nothing else. No request-derived value ever reaches a command or a file path.

Connection to the server was lost. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.