Cloudflare blocked Keycloak JWKS requests from Python
How a Cloudflare 1010 block of Python JWKS requests caused Keycloak bearer-token 401s, and how a scoped Skip rule fixed it.
How a Cloudflare 1010 block of Python JWKS requests caused Keycloak bearer-token 401s, and how a scoped Skip rule fixed it.
A local workflow for transcribing long podcast MP3s with NVIDIA's Parakeet TDT. It uses ffmpeg to split and compress audio, then a Bash script to send chunks for transcription and save the results without a cloud service.
Configure the AWS CLI for a Garage endpoint, including the checksum settings required since AWS CLI v2.23.0. The post covers stalled large uploads, multipart chunk sizing, InvalidAccessKeyId errors, requests sent to s3.amazonaws.com, and 504 timeouts with Traefik and Cloudflare. It includes Traefik labels and Cloudflare plan limits.
This article explains how workload identity and token exchange can reduce reliance on static credentials for AI agents. It covers OAuth 2.0, OIDC, SPIFFE/SPIRE, and identity services from AWS, Microsoft, and Google Cloud, including authentication between agents, tools, and APIs.
Migrating a background service from systemd to macOS launchd? You'll learn how to set up, enable, and run a persistent command-line tool as a background service on macOS.
`requests` may fail to verify a server certificate when its certificate store is outdated or the server uses a self-signed certificate. This post covers updating the store, supplying a CA bundle, and disabling verification for testing, with a warning about the security risk.
Tracks 21 defect classes found while adapting the Superpowers skills for Qwen3.6 35B A3B, including silent TOML failures, docstring-only stubs, and defects that returned in new forms. Reviews what the model handled well, what remained unresolved, which parts of the workflow were validated, and how to reproduce the runs.
Across six runs and six skill versions, gates that passed continued to hold as failures shifted from execution bugs to plan and spec coverage, constants, and falsifier grounding. This post tracks the changes and how the model's output eventually helped strengthen its tests.
This post describes a `-small` skill pack with `brainstorming-small`, `writing-plans-small`, and `executing-plans-small`. Its instructions use explicit checks, including a rule to copy code rather than retype it, a stop when task code conflicts with the interfaces, and a final audit that requires output for each requirement. The scorecard also includes a trap criterion for tasks the model has not implemented.
An implementation of the Superpowers skills for Qwen3.6 35B A3B passed its tests but had nine defect classes, including invalid TOML, ineffective deduplication, and tests that never exercised injection. This post examines how the plan and verification process let those defects through.