Tagged architecture
Every post on this blog tagged architecture. All posts
5 posts202662 minutes of reading
9 min
Put the rules in the API, not in the MCP server
APIs and MCP servers are layers, not rivals. A practical rule for architects: implement authentication, authorization, and business policy in the HTTP API exactly once, and build MCP servers as thin discovery layers that contain none of it.
12 min
Giving an AI agent write access to a live site
How to grant an AI agent real write access to a production site safely: one shared write path, a single human-reserved operation enforced in code, tamper-evident state in version control, and the draft leak that revealed the method's hardest problem.
20 min
Every Cloudflare product, and which ones this site runs on
Every Cloudflare developer product as of September 2026 in one table: what Workers, D1, KV, R2, Queues, Durable Objects, AI Search and the rest actually do, and which ones a complete site runs on, where, and why. With the refusals and the constraints, dated.
15 min
How this blog stores posts in git and serves them from D1
How to build a content pipeline where markdown in git is the source of truth and D1 serves every read: one deterministic renderer shared by the build and the Worker, a gate verified by breaking it, atomic commits through the GitHub API, and the two bugs to expect. Updated August 2026, when the committed artifact came out in favor of provenance hashes, a deploy-time drift table, and a self-repairing health check.
6 min
Where should a blog store its words?
Two content models for a Cloudflare-native blog, one database, and the four arguments that settled it.