← all publishers

serialexperimentslainnnn

@serialexperimentslainnnn source repo

224 published skills · page 3 of 3

  1. Vpn Standards · serialexperimentslainnnn
    VPN tunnels and remote access as a designed, operated service. Use when writing or reviewing wg0.conf and its AllowedIPs, PersistentKeepalive, Endpoint, PresharedKey or Table= keys, running wg genkey/pubkey/show/setconf or wg-quick up/down, choosing wg-quick versus systemd-networkd [WireGuard]/[WireGuardPeer] or NetworkManager wireguard profiles, swanctl.conf and ipsec.conf/ipsec.secrets with charon, IKEv2 proposals and esp/ah rekeying, phase-2 proposal mismatch, MOBIKE, ke1_mlkem768 and RFC 9370 hybrid key exchange, client.ovpn and server.conf with tls-crypt, tls-auth, dev tun, redirect-gateway and the ovpn-dco kernel module, tailscale up --advertise-routes/--exit-node and tailnet ACL grants, netbird up, headscale nodes/preauthkeys, nebula-cert sign and lighthouse config, zerotier-cli join, rosenpass psk exchange, split tunneling and DNS-leak decisions, short-lived client certificates versus permanent keys, overlapping site subnets, concentrator redundancy and session logging, or hardening an internet-facing
    0 installs
  2. Xen Standards · serialexperimentslainnnn
    The Xen hypervisor, XCP-ng and the XenServer legacy - dom0/domU, PV/HVM/PVH and when Xen is still the right answer. Use when running xl (xl create, xl list, xl info, xl dmesg, xl sched-credit2, xl vcpu-pin), editing /etc/xen/*.cfg domain config files or xl.conf, sizing dom0_mem, dom0_max_vcpus and dom0 pinning on the Xen command line, choosing between PV, PVH and HVM guests or using pv-shim, running xenstore-ls, xentop, xl debug-keys or the credit2/null schedulers, operating XCP-ng and XenServer hosts with xe CLI, xsconsole, xapi, toolstack, SR and VDI storage repositories (LVM, ext, thin provisioning, XOSTOR/LINSTOR), PIF/VIF/network objects and bonds, pool masters and HA, managing them with Xen Orchestra, XO Lite, XOA or xo-server, migrating from VMware into XCP-ng, tracking Xen Security Advisories (XSA) and the pre-disclosure list, or deciding between Xen and KVM for a new deployment.
    0 installs
  3. LLM Evaluation Standards · serialexperimentslainnnn
    LLM system evaluation standards
    0 installs
  4. Load Balancing Standards · serialexperimentslainnnn
    Load balancing as a failure-handling decision, not just traffic sharing — health checks, draining and TLS termination are where the value is. Use when designing or reviewing a load balancer or reverse proxy, haproxy.cfg with backend/server/option httpchk/http-check/observe/agent-check, nginx.conf upstream blocks with proxy_pass, keepalive and max_fails, an Envoy bootstrap or xDS cluster with outlier detection and panic threshold, Traefik static and dynamic configuration with healthCheck and serversTransport, a Caddyfile reverse_proxy with lb_policy and health_uri, an AWS ALB/NLB target group, Azure Application Gateway or Front Door, GCP backend service, choosing between layer 4 and layer 7, round-robin versus least-connections versus consistent hashing and maglev, session affinity and sticky cookies, shallow versus deep health check endpoints and a health check that queries the database, rise and fall thresholds, connection draining and graceful shutdown during a rolling deploy, TLS termination, re-encryption
    0 installs
  5. Object Storage Standards · serialexperimentslainnnn
    Object storage as a model distinct from block and file — the S3 API, its self-hosted implementations and its failure modes. Use when working with aws s3 / aws s3api, mc, or rclone remotes and rclone mount, s3fs, goofys or mountpoint-s3, designing bucket names and key prefixes for listing and throughput, bucket policies versus IAM versus ACLs, BucketOwnerEnforced object ownership, Block Public Access, presigned URLs and their TTL, SSE-S3 / SSE-KMS / SSE-C and TLS enforcement via aws:SecureTransport, Object Lock in governance or compliance mode, legal hold, bucket versioning with noncurrent-version expiration, lifecycle transitions to Glacier Instant Retrieval, Flexible Retrieval or Deep Archive and their restore latency, egress and per-request cost, multipart uploads and AbortIncompleteMultipartUpload, ETag pitfalls and CRC32C or CRC64-NVME checksums, cross-region or cross-provider replication, Storage Lens and request-level metrics, or running MinIO, Ceph RGW, Garage or SeaweedFS on-premise with erasure codin
    0 installs
  6. Search Engines Standards · serialexperimentslainnnn
    Text search and document indexing engines as infrastructure. Use when deciding between PostgreSQL full-text and a search cluster, comparing Elasticsearch, OpenSearch, Meilisearch, Typesense, Manticore, Vespa, Solr or Quickwit and their licences (Elastic License 2.0, SSPL, AGPLv3, BUSL enterprise editions, GPL), writing elasticsearch.yml, opensearch.yml, solrconfig.xml or a managed-schema, designing an explicit index mapping instead of dynamic mapping, analyzers, tokenizers, ascii folding and per-language stemming including Spanish, keyword versus text fields, the reindex API and index aliases for zero-downtime schema change, relevance tuning with field boosting, synonyms and judgment lists, shard and replica sizing and the too-many-small-shards trap, index lifecycle management with hot/warm/cold tiers, snapshot repositories and restore, major-version upgrades that force a reindex, deep pagination with search_after, wildcard-prefix and deep-aggregation query cost, or a search endpoint exposed to the internet w
    0 installs
  7. Soc Operations Standards · serialexperimentslainnnn
    Running the security operations function as an operation, not a product. Use when choosing between an in-house SOC, an MSSP or MDR provider and a hybrid model, sizing 24x7 shift coverage and follow-the-sun rotations, writing shift handover notes, managing the alert queue and its backlog, automated enrichment before triage, triage and escalation criteria, structured close codes and case management (TheHive, Cortex, IRIS, Shuffle, Tines, n8n, SOAR playbooks and what must never be automated), analyst tiering and why the tier model ages badly, alert fatigue and analyst burnout, actionable-alert ratio as a service-level indicator, the rule-retirement process, SOC metrics that survive scrutiny (time to detect, time to contain, telemetry coverage) versus vanity counts of closed alerts, SIEM ingest volume as the dominant cost driver and what to keep hot, warm or cold, scheduled threat hunting with a written hypothesis and a hunt report (PEAK, hunting maturity model), purple-team scheduling and deconfliction, SOC-CMM
    0 installs
  8. Backup Recovery Standards · serialexperimentslainnnn
    Backup and restore mechanics — how the copy is made, where it lands and how the restore is proven. Use when choosing or operating a backup tool (restic init/backup/forget --keep-*/prune/check --read-data-subset/repository format v2, Kopia snapshot/policy set/maintenance run, BorgBackup borg create/compact/check with --append-only, borgmatic.yaml, Duplicati, rsync/rsnapshot hardlink rotation, Bacula/Bareos bconsole and Director pools, tape/LTO, Veeam in a mixed estate), designing full/incremental/differential, forever-incremental and synthetic-full chains, deduplication and compression, file-level versus block-level versus whole-image versus application-consistent snapshots, quiesce with fsfreeze and pre/post hooks around a snapshot, 3-2-1 and 3-2-1-1-0 repository topology, append-only or WORM repositories, client-side repository encryption whose passphrase never lives on the copied host, write-but-not-delete agent credentials, GFS retention with prune and garbage collection, repository check/verify, automated
    0 installs
  9. Blockchain Web3 Standards · serialexperimentslainnnn
    Blockchain and web3 as infrastructure, custody and regulation — not as smart-contract code. Use when justifying whether a distributed ledger is needed at all versus a signed append-only database, evaluating permissioned ledgers (Hyperledger Fabric, LF Decentralized Trust, R3 Corda, Besu, Quorum), running or outsourcing nodes and JSON-RPC endpoints (geth, erigon, reth, nethermind, lighthouse, Infura, Alchemy, QuickNode, eth_call rate limits, archive versus full node, state growth, snap sync), choosing L1 versus L2 rollups and reading their trust assumptions (L2Beat stages, sequencer centralisation, 7-day optimistic challenge window, forced inclusion, escape hatch), cross-chain bridges and wrapped assets as a loss vector, key custody and signing process (hardware wallet, HSM, multisig, Safe, threshold MPC, seed phrase handling, signing ceremony, key compromise as the dominant theft cause), oracles and price-feed manipulation, MEV, sandwiching and private order flow at the application level, indexing and reorg-s
    0 installs
  10. Computer Vision Standards · serialexperimentslainnnn
    Applied computer vision as a data problem, not a model problem. Use when defining a vision task (classification, object detection, semantic versus instance versus panoptic segmentation, multi-object tracking, OCR, keypoint/pose estimation), building or auditing an image dataset and its label quality, inter-annotator agreement, annotating with CVAT, Label Studio, labelme, Roboflow, FiftyOne or supervision, converting between COCO JSON, YOLO .txt, Pascal VOC XML, YOLO data.yaml and instances_train.json, writing albumentations or kornia augmentation pipelines and spotting augmentation that breaks the label, choosing a detector or segmenter (Ultralytics YOLO/YOLO26, RT-DETR, RF-DETR, D-FINE, DEIM, YOLOX, Detectron2, MMDetection, SAM/SAM 2/SAM 3, Grounding DINO, DINOv2/DINOv3) and reading its weights licence before shipping, computing IoU, mAP@0.5:0.95, per-class confusion or PR curves, exporting to ONNX, TensorRT, OpenVINO, LiteRT or Core ML, matching train and serve preprocessing (resize, letterbox, BGR/RGB, nor
    0 installs
  11. Firewall Policy Standards · serialexperimentslainnnn
    Firewall policy as a governed engineering artifact. Use when writing or reviewing nftables rulesets (nftables.conf, nft -c -f, tables/chains/hooks/priorities, sets, maps, verdict maps, ct state, meters), firewalld zones, services, policies and rich rules (firewall-cmd), ufw profiles, DOCKER-USER chains and Docker firewall-backend published-port bypass, kube-proxy nftables mode, cloud security group and NSG rule sets as filtering policy, egress allow-listing, zone-to-zone flow matrices, rule ownership, expiry dates and change approval, shadowed, duplicate, orphaned or any/any rule review, conntrack table exhaustion and asymmetric-routing state loss, MSS clamping and NAT interaction with filtering, deny logging volume and forwarding, or IPv6 rule parity with IPv4.
    0 installs
  12. Healthtech Fhir Standards · serialexperimentslainnnn
    Clinical interoperability and health software engineering. Use when working with HL7 FHIR (R4 4.0.1, R5 5.0.0, R6 ballot), FHIR resources such as Patient, Encounter, Observation, Condition, MedicationRequest, DiagnosticReport, DocumentReference, Consent, AuditEvent and Provenance, StructureDefinition profiles and extensions, ImplementationGuide packages and the IG Publisher, hl7.fhir.us.core, hl7.fhir.uv.ips, hl7.fhir.uv.smart-app-launch, CapabilityStatement and $validate, Bundle transaction/batch/document, FHIR search parameters, _include, _revinclude, chained search and $everything, Bulk Data $export and NDJSON, FHIR Subscriptions and topic-based subscriptions, SMART on FHIR launch and scopes (patient/*.rs, user/*.rs, system/*.rs), HL7 v2.x pipe-and-hat messages (ADT, ORM, ORU, MSH/PID/OBX segments), MLLP interfaces and integration engines (Mirth/NextGen Connect, Rhapsody, Iguana, InterSystems Ensemble/HealthShare), CDA and C-CDA documents, IHE profiles (XDS.b, PIX/PDQ, ATNA, MHD), DICOM, DICOMweb, PACS, mo
    0 installs
  13. Home Automation Standards · serialexperimentslainnnn
    Engineering a home that keeps working when the internet, the vendor or the hub goes down. Use when designing or reviewing a smart home built on Home Assistant (configuration.yaml, automations.yaml, scripts.yaml, secrets.yaml, templates and Jinja2 triggers, HACS custom components, Home Assistant OS versus Container installs, add-ons/apps, the monthly 20XX.M release train and its backward-incompatible changes), openHAB, Node-RED, Zigbee2MQTT and its coordinator firmware, ZHA, ESPHome YAML device configs, MQTT and Mosquitto topics and retained state, choosing between Zigbee, Z-Wave, Thread and Matter (commissioning, border routers, fabrics, multi-admin) versus cloud-only Wi-Fi devices, putting IoT devices on their own VLAN with egress filtering, an abandoned device whose vendor stopped shipping firmware, cameras, microphones and presence detection inside a home, voice assistants and local speech processing, robust versus fragile automations (state versus event triggers, the automation that locks someone out or l
    0 installs
  14. Linux Hardening Standards · serialexperimentslainnnn
    Linux OS hardening baselines and their measurement. Use when applying or auditing CIS Benchmarks, DISA STIG, ANSSI-BP-028 or CCN-STIC/ENS on Linux hosts, running oscap/OpenSCAP with SCAP Security Guide profiles, Lynis, Wazuh SCA, ansible-lockdown or devsec.hardening roles, or editing sshd_config, sysctl.d, audit.rules/auditd.conf, pam_faillock, faillock.conf, login.defs, sudoers, modprobe.d blacklists, fstab mount options (noexec/nosuid/nodev), SUID audits, systemd unit sandboxing (systemd-analyze security), AIDE, Secure Boot/TPM/LUKS unattended unlock, unattended-upgrades/dnf-automatic or kernel livepatching.
    0 installs
  15. C Standards · serialexperimentslainnnn
    C language engineering standards (staff-level). Trigger on .c files and C-only headers, -std=c11/c17/c23/gnu23, gcc/clang C invocations, Makefile/CMakeLists.txt/meson.build building C targets, compile_commands.json, .clang-tidy, .clang-format, cppcheck, -fanalyzer, -fsanitize=address/undefined/memory/thread, valgrind/memcheck, libFuzzer/AFL++/OSS-Fuzz harnesses, MISRA C or CERT C compliance, Unity/CMocka/Criterion tests, glibc/musl/newlib targets, _FORTIFY_SOURCE and binary hardening flags, or extern "C" ABI headers.
    0 installs
  16. Project Map · serialexperimentslainnnn
    Build and maintain PROJECTMAP.md, the orientation index of whatever repository you are working in, so the same grep/find/read is never paid for twice. Use at the very start of work in ANY repository - before the first substantial task - whenever PROJECTMAP.md is missing, whenever it is stale or contradicted by the repo, whenever you catch yourself searching for where something lives, whenever structure changes (new directory, moved module, different build/test command, new convention), and whenever you hand work over to another session or a subagent. Covers what goes in the map, what must never go in it, how to size it for a code repo versus a content repo, how to generate it cheaply with a script instead of by hand, how to keep it honest, and where to put it so it does not pollute a repository that is not yours.
    0 installs
  17. R Standards · serialexperimentslainnnn
    Use when writing, reviewing or productionizing R code - .R/.Rmd/.qmd/.Rproj files, DESCRIPTION, NAMESPACE, renv.lock, .Rprofile, .lintr, _pkgdown.yml, testthat tests, roxygen2 blocks, tidyverse/dplyr/ggplot2 or data.table pipelines, non-standard evaluation with {{ }} and .data, CRAN/Bioconductor/Posit Package Manager repositories, Shiny apps (app.R, server.R, ui.R), Plumber APIs (plumber.R), Quarto or R Markdown reports, Rcpp/cpp11 native code, or rocker/r-base container images.
    0 installs
  18. Go Standards · serialexperimentslainnnn
    Go engineering standards (staff-level). Trigger on any Go work - files with .go extension, go.mod/go.sum, Makefile targets invoking go build/test, golangci-lint config, or frameworks/routers like net/http, chi, gin, echo, gRPC, and libraries like errgroup or sqlc. Apply when writing, reviewing, refactoring, or configuring CI for Go code.
    0 installs
  19. Xr Standards · serialexperimentslainnnn
    Virtual, augmented and mixed reality engineering where comfort, latency and biometric privacy are hard requirements. Use when building with OpenXR (xrCreateInstance, XrSession, XrSpace, xrWaitFrame/xrBeginFrame/xrEndFrame, XR_KHR_composition_layer_depth, XR_EXT_hand_tracking, XR_EXT_eye_gaze_interaction, XR_EXT_plane_detection, XR_EXT_spatial_anchor, vendor XR_FB_/XR_META_/XR_ANDROID_ extensions), Unity XR Interaction Toolkit and OpenXR plugin, Unreal VR templates and OpenXR runtime, Godot XR, or WebXR (navigator.xr, requestSession("immersive-vr"/"immersive-ar"), XRReferenceSpace, hit-test and anchors), motion-to-photon latency, reprojection, timewarp, Application SpaceWarp and stale frames, headset refresh rates and per-frame budget on standalone hardware, locomotion, teleport, snap turn, vignette and simulator sickness, room-scale guardian and boundary, seated versus standing play, hand tracking versus controllers, raycast interaction, gaze and pinch, passthrough and scene understanding, spatial anchors and
    0 installs
  20. Ada Standards · serialexperimentslainnnn
    Ada and SPARK for high-integrity software. Use when working with .ads/.adb specification and body files, .gpr GNAT project files and gprbuild/gprclean/gprinstall, alire.toml and the alr package manager, GNAT compilation with -gnat2012/-gnat2022/-gnatwa/-gnatwe/-gnata/-gnato/-gnatX, GNAT Pro versus GNAT FSF builds, gnatprove and SPARK_Mode with the Stone/Bronze/Silver/Gold/Platinum adoption levels, contract aspects Pre/Post/Contract_Cases/Type_Invariant/Predicate/Global/Depends/Loop_Invariant/Loop_Variant, subtype and range constraints with Constraint_Error, pragma Restrictions and pragma Profile (Ravenscar) or Profile (Jorvik), tasks protected objects entries and rendezvous, Ada.Containers Bounded and Formal containers, Unchecked_Deallocation and Unchecked_Conversion, representation clauses and Interfaces.C bindings, gnattest/AUnit, gnatcov coverage and gnatcheck/GNATformat, or evaluating Ada against Rust and Ferrocene for a DO-178C, EN 50128, IEC 61508 or ISO 26262 project.
    0 installs
  21. AWS Standards · serialexperimentslainnnn
    AWS architecture, security and FinOps standards. Use when working with AWS services (Lambda, ECS, EKS, Fargate, S3, RDS, Aurora, DynamoDB, SQS, SNS, EventBridge, VPC, IAM, KMS, GuardDuty, Security Hub, CloudWatch, Organizations, Control Tower), the aws CLI, SAM, or IaC files targeting AWS (CloudFormation templates *.yaml/*.json, CDK cdk.json/*.ts/*.py, Terraform *.tf with provider aws).
    0 installs
  22. Cpp Standards · serialexperimentslainnnn
    Modern C++ engineering standards (staff-level). Trigger on .cpp/.cc/.cxx/.hpp/.ixx/.cppm files, -std=c++17/20/23/2c or /std:c++latest, CMakeLists.txt with add_library/target_link_libraries, CMakePresets.json, vcpkg.json, conanfile.py/conanfile.txt, .clang-tidy with cppcoreguidelines-* checks, GoogleTest/Catch2/doctest suites, Google Benchmark, std::unique_ptr/shared_ptr/move semantics/concepts/constexpr/ranges/coroutines/std::expected, C++ modules and import std, Boost or Abseil usage, the C++ Core Guidelines and GSL, or C++ memory-safety profiles and hardened standard library decisions.
    0 installs
  23. Dns Standards · serialexperimentslainnnn
    DNS service architecture, zone design and DNS security. Use when editing zone files or named.conf, unbound.conf, knot.conf, kresd config, nsd.conf, pdns.conf, dnsmasq.conf or pihole.toml, designing SOA timers, TTL, delegation and glue, CNAME-at-apex with ALIAS/ANAME, CAA, HTTPS/SVCB, SSHFP, TLSA/DANE, PTR records, DNSSEC signing and KSK/ZSK rollover, NSEC3 parameters, RRL, TSIG-protected AXFR/IXFR, split-horizon views, anycast authoritatives, .internal or home.arpa naming, zone-as-code with dnscontrol or octodns, named-checkzone, kdig, dig +trace, DoT/DoH/DoQ resolver transport, dangling subdomain takeover, DNS tunneling exfiltration or registrar/NS hijack.
    0 installs
  24. GCP Standards · serialexperimentslainnnn
    Google Cloud (GCP) architecture, security and FinOps standards. Use when working with GCP services (Cloud Run, GKE, Cloud Functions/Cloud Run functions, Cloud SQL, AlloyDB, Spanner, BigQuery, Pub/Sub, Cloud Storage, Artifact Registry, VPC, IAM, KMS, Secret Manager, Security Command Center, VPC Service Controls), the gcloud/gsutil/bq CLIs, or IaC files targeting GCP (Terraform *.tf with provider google, Infrastructure Manager).
    0 installs