Alex Leko
All content on this blog was created fully or partially using local AI (Apple MLX).

Recent Posts

Cloudflare blocked Keycloak JWKS requests from Python

How a Cloudflare 1010 block of Python JWKS requests caused Keycloak bearer-token 401s, and how a scoped Skip rule fixed it.

Transcribing podcasts locally with Parakeet TDT and ffmpeg

A local workflow for transcribing long podcast MP3s with NVIDIA's Parakeet TDT. It uses ffmpeg to split and compress audio, then a Bash script to send chunks for transcription and save the results without a cloud service.

Using the AWS CLI with Garage: large uploads and troubleshooting

Configure the AWS CLI for a Garage endpoint, including the checksum settings required since AWS CLI v2.23.0. The post covers stalled large uploads, multipart chunk sizing, InvalidAccessKeyId errors, requests sent to s3.amazonaws.com, and 504 timeouts with Traefik and Cloudflare. It includes Traefik labels and Cloudflare plan limits.

Modern identity, workload security, and agent authentication

This article explains how workload identity and token exchange can reduce reliance on static credentials for AI agents. It covers OAuth 2.0, OIDC, SPIFFE/SPIRE, and identity services from AWS, Microsoft, and Google Cloud, including authentication between agents, tools, and APIs.

How to Force Your Binary to Stay Alive on macOS

Migrating a background service from systemd to macOS launchd? You'll learn how to set up, enable, and run a persistent command-line tool as a background service on macOS.

Ignoring SSL certificate errors in Python requests

`requests` may fail to verify a server certificate when its certificate store is outdated or the server uses a self-signed certificate. This post covers updating the store, supplying a CA bundle, and disabling verification for testing, with a warning about the security risk.

Fine-tuning Superpowers skills for local models: Qwen3.6 35B A3B (part 4)

Tracks 21 defect classes found while adapting the Superpowers skills for Qwen3.6 35B A3B, including silent TOML failures, docstring-only stubs, and defects that returned in new forms. Reviews what the model handled well, what remained unresolved, which parts of the workflow were validated, and how to reproduce the runs.

Running the Superpowers skills on a local model: Qwen3.6 35B A3B (part 3)

Across six runs and six skill versions, gates that passed continued to hold as failures shifted from execution bugs to plan and spec coverage, constants, and falsifier grounding. This post tracks the changes and how the model's output eventually helped strengthen its tests.

Running the Superpowers skills on a local model: Qwen3.6 35B A3B (part 2)

This post describes a `-small` skill pack with `brainstorming-small`, `writing-plans-small`, and `executing-plans-small`. Its instructions use explicit checks, including a rule to copy code rather than retype it, a stop when task code conflicts with the interfaces, and a final audit that requires output for each requirement. The scorecard also includes a trap criterion for tasks the model has not implemented.

Running the Superpowers skills on a local model: Qwen3.6 35B A3B (part 1)

An implementation of the Superpowers skills for Qwen3.6 35B A3B passed its tests but had nine defect classes, including invalid TOML, ineffective deduplication, and tests that never exercised injection. This post examines how the plan and verification process let those defects through.