At @fleetdm.bsky.social, we’re rolling out ACME-based attestation for Apple hosts, so this talk comes from real product work.
My NDC Security talk is now up:
www.youtube.com/watch?v=4oDB...
#ApplicationSecurity #ZeroTrust #MDM
Posts by Victor on Software
ICYMI. Our guide on HTTP Message Signatures (RFC 9421) is here:
www.youtube.com/watch?v=6Qxk...
#APIsecurity #WebSecurity #MessageSignatures #SoftwareEngineering
Tried to build a modular monolith. Three compromises later, the "modular" part disappeared. 🫠
Turns out team buy-in isn't enough. You need governance and an architect who doesn't walk away.
First attempt. Lessons learned.
www.youtube.com/watch?v=lrM3...
#SoftwareArchitecture #TechnicalDebt
HTTP Message Signatures (RFC 9421) are becoming a real standard. They solve problems that API keys, JWTs, and mTLS alone cannot.
Full guide: victoronsoftware.com/posts/http-m...
#APIsecurity #WebSecurity #MessageSignatures #SoftwareEngineering
🏗️ Tried to turn a 500K-line monolith into a modular monolith.
Three compromises later, the code seeped back into legacy.
First attempt. Won't be the last.
victoronsoftware.com/posts/modula...
#SoftwareArchitecture #TechnicalDebt #LessonsLearned
Why great software developers draw 🧠✏️
At #AIMHDC2025 I shared 4 diagrams every dev should know:
🧩 Sequence
🔄 Flowchart
🏗️ Class
🗃️ ERD
Because seeing the shape of your idea can be the difference between being heard & being understood.
🎥 youtu.be/ATGrRb9gCHo
#SoftwareDesign #DiagramsAsCode #FleetDM
I gave this talk at Heartland Developers Conference 2025 last week:
🎤 Will AI coding agents replace software developers?
👉 www.youtube.com/watch?v=z0r3...
AI isn’t replacing developers overnight. It’s changing what it means to be one.
#AI #Developers #SDLC #Engineering #AIMHDC2025
🎤 Spoke at #CYC25 last week on something I care deeply about: Radical Transparency: Leading Engineering With Openness.
📺 Watch here: www.youtube.com/watch?v=5IZq...
When priorities are unclear, engineers stall. I shared how we’re tackling this at @fleetdm.bsky.social + what you can do, too.
🤖 Can AI agents really make multitasking more productive, or is it just a trap?
We broke it down in this video: when to single-task, when to multitask, and how to keep your agents on track.
📺 Watch here 👉 youtu.be/HSDrhYvE3g0
#AI #AgenticAI #DeveloperExperience
Still one of my biggest lessons in engineering leadership:
Without transparency, even the best teams drift.
Make priorities visible. Make blockers public.
Everything else gets easier.
📺 www.youtube.com/watch?v=3oSd...
#Engineering #Leadership #Transparency
Still debugging with guesswork?
OpenTelemetry gives you full visibility. Even in dev. 🛠️
Why developers should use OpenTelemetry in dev
www.youtube.com/watch?v=1a8f...
Trace. Debug. Ship with confidence.
#OpenTelemetry #DevTools #Observability #Tracing #DevEx
🤖 Multitasking with AI agents: boost or distraction?
AI can code, debug & research in parallel, but should you?
🧠 When it works
⚡ When it fails
✅ How to stay efficient
Read more 👉 victoronsoftware.com/posts/multit...
#AI #DeveloperExperience #AgenticAI
💡 Engineering without transparency = driving in fog.
Once priorities went public, decisions sped up, trust grew, and work actually shipped.
victoronsoftware.com/posts/engine...
#Engineering #Leadership #Transparency
🤖 AI agents aren't replacing developers, but they are changing how we work.
A few weeks ago we broke down their real impact across the SDLC.
Missed it?
📺 Watch the video: www.youtube.com/watch?v=fdBx...
#AI #SoftwareEngineering #AIAgents #DevTools #LLMs
We used to think OpenTelemetry was just for prod.
Turns out, it’s a dev tool too. 🛠️
Why developers should use OpenTelemetry in dev:
→ victoronsoftware.com/posts/opente...
See how we:
✅ Trace API calls
✅ Debug SQL
✅ Correlate logs
✅ Catch errors early
#OpenTelemetry #DevTools #Observability
🔐 Still thinking about mTLS vs HTTP Message Signatures?
Breakdown + video:
✅ How they work
⚖️ Tradeoffs
📊 Comparison table
⚠️ Replay attacks, TLS termination, more
📺 Video: www.youtube.com/watch?v=aDMd...
#CyberSecurity #ZeroTrust #mTLS #SysAdmin
youtu.be/zwnznp5KeQs
🎥 Missed the TPM deep dive? We made a video walkthrough.
🔐 Key hierarchies
🔐 Parent/child keys
🔐 Signing with Go + tpm2-tools
▶️ youtu.be/zwnznp5KeQs
📖 victoronsoftware.com/posts/how-to...
#TPM #CyberSecurity #DeviceSecurity #Golang #SecureKeyStorage
Will AI agents replace software developers? 🤖
Not anytime soon.
They’re great at 💻 implementation & 🧪 testing but not in other areas.
Even full code automation = only 43% productivity gain.
Full breakdown 👉 victoronsoftware.com/posts/will-a...
#AI #AIAgents #DevTools #SoftwareEngineering #LLMs
🔐 mTLS vs HTTP Message Signatures: which should you use?
We break down the tradeoffs for device enrollment & secure APIs.
✅ How they work
⚖️ Pros & cons
📊 Comparison table
🆕 Why RFC 9421 matters
👉 victoronsoftware.com/posts/mtls-v...
#CyberSecurity #mTLS #ZeroTrust #SysAdmin #EndpointSecurity
I noticed the thumbnail is not showing up. Here is the link again (with a thumbnail this time).
www.youtube.com/watch?v=xfj_...
At #OSSummit 2025, I shared how radical transparency shapes how we build at @fleetdm.bsky.social — from open-sourcing internal docs to scaling trust across teams.
🎥 Full talk now up: www.youtube.com/watch?v=xfj_...
#OpenSource #EngineeringCulture #PublicByDefault #Transparency #Leadership
🔐 At @fleetdm.bsky.social, we’re taking endpoint security to the next level.
Just dropped a deep-dive on using TPM 2.0 for hardware-backed key storage — with real-world Go + tpm2-tools examples.
🧵👇
victoronsoftware.com/posts/how-to...
#CyberSecurity #DeviceSecurity #Golang #SoftwareDevelopment
Missed my first conference talk recap?
Top lessons:
✅ Prep is key
✅ Growth happens outside your comfort zone
✅ Best convos happen off stage
🔗 Article: victoronsoftware.com/posts/first-...
▶️ Video: www.youtube.com/watch?v=IaY9...
#DevDaysEurope #PublicSpeaking #TechCommunity
🎤 Just gave my first public keynote at #DevDaysEurope on "Readable Code"!
Covered what readability really means, why it matters, metrics, AI’s impact, and practical ways to improve codebases.
Watch here: www.youtube.com/watch?v=lQBY...
#SoftwareEngineering #DeveloperExperience
🎉 Excited to speak at Open Source Summit North America 2025 on June 23 and represent @fleetdm.bsky.social!
Radical Transparency: Lessons from Open-Sourcing Nearly All Company Documentation
🔗 ossna2025.sched.com/event/1zfgo/...
#OSSummit #LinuxFoundation
🧭 A few weeks ago, we shared how we built a free, full-featured engineering metrics dashboard.
Since then, we started using it at @fleetdm.bsky.social to spot patterns in how our team collaborates 💪
🎥 www.youtube.com/watch?v=okYO...
👉 victoronsoftware.com/posts/engine...
#Metrics #DevEx
🎤 Just gave my first conference talk at #DevDaysEurope—overseas, on a movie theater stage, in front of ~300 engineers.
Nerves, jet lag, and adrenaline were real, but so was the “speaker’s high.”
🔗 Read: victoronsoftware.com/posts/first-...
#PublicSpeaking #TechCommunity #ConferenceSpeaker
Track engineering metrics with real power—for free 💥
✅ GitHub Actions
✅ BigQuery
✅ Grafana
We built a dashboard with moving averages, filters, & drill-down links—all on free-tier tools.
👉 victoronsoftware.com/posts/engine...
#EngineeringManagement #Metrics #SoftwareDevelopment
🧠 What if your AI agent could learn to use your product, like a real teammate?
We taught an AI agent to use @fleetdm.bsky.social API—no commands, just natural language—using MCP.
Lessons learned, mistakes made. Full story here 👇
victoronsoftware.com/posts/introd...
#AgenticAI #MCP #AI #DevTools