<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Rhay Parra — Trade-offs</title><description>Working notes on architecture, AWS and AI — what each decision cost and whether I&apos;d make it again.</description><link>https://rhynl.io/</link><language>en</language><item><title>Flipping the auth provider without logging everyone out</title><link>https://rhynl.io/notes/flipping-the-auth-provider-without-logging-everyone-out/</link><guid isPermaLink="true">https://rhynl.io/notes/flipping-the-auth-provider-without-logging-everyone-out/</guid><description>Changing identity providers is a one-way door if you get the order wrong. A checklist for cutting over with a live fallback and a real rollback.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>Auth</category><category>Security</category><category>AWS</category><author>mail@rhynl.io</author></item><item><title>Don&apos;t let the model decide the checkout</title><link>https://rhynl.io/notes/dont-let-the-model-decide-the-checkout/</link><guid isPermaLink="true">https://rhynl.io/notes/dont-let-the-model-decide-the-checkout/</guid><description>In a chat-led app, some actions have to appear at the right moment every single time. That&apos;s not a job for tool calls. Here&apos;s the pattern we used instead.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><category>AI</category><category>Architecture</category><category>Next.js</category><category>NestJS</category><author>mail@rhynl.io</author></item><item><title>El deploy &quot;exitoso&quot; que no estaba en producción</title><link>https://rhynl.io/notes/el-deploy-exitoso-que-no-estaba-en-produccion/</link><guid isPermaLink="true">https://rhynl.io/notes/el-deploy-exitoso-que-no-estaba-en-produccion/</guid><description>Un pipeline en verde no significa que tu código está sirviendo. Cómo verificar de verdad que un cambio llegó a producción.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><category>AWS</category><category>DevEx</category><author>mail@rhynl.io</author></item><item><title>La redacción de logs no es un checkbox</title><link>https://rhynl.io/notes/la-redaccion-de-logs-no-es-un-checkbox/</link><guid isPermaLink="true">https://rhynl.io/notes/la-redaccion-de-logs-no-es-un-checkbox/</guid><description>Un patrón de redacción como *.campo no siempre cubre lo que creés. Cómo mantener datos sensibles fuera de los logs en serio, y no solo en apariencia.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>Observability</category><category>Security</category><category>NestJS</category><author>mail@rhynl.io</author></item><item><title>Every string from the outside needs a maximum length</title><link>https://rhynl.io/notes/every-string-from-the-outside-needs-a-maximum-length/</link><guid isPermaLink="true">https://rhynl.io/notes/every-string-from-the-outside-needs-a-maximum-length/</guid><description>An unbounded string field on an unauthenticated endpoint is a bug. But the fix has a failure mode that can reject perfectly valid requests.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><category>Security</category><category>TypeScript</category><category>Testing</category><author>mail@rhynl.io</author></item><item><title>Decisiones con fecha: por qué escribo ADRs aunque seamos dos</title><link>https://rhynl.io/notes/decisiones-con-fecha-por-que-escribo-adrs-aunque-seamos-dos/</link><guid isPermaLink="true">https://rhynl.io/notes/decisiones-con-fecha-por-que-escribo-adrs-aunque-seamos-dos/</guid><description>Un Architecture Decision Record no es burocracia. Es la única forma que conozco de que un sistema siga explicándose a sí mismo cuando ya nadie recuerda por qué se hizo así.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>ADRs</category><category>Architecture</category><category>Team</category><author>mail@rhynl.io</author></item><item><title>Fail soft by default: integrating an LLM with systems that can go down</title><link>https://rhynl.io/notes/fail-soft-by-default-integrating-an-llm-with-systems-that-can-go-down/</link><guid isPermaLink="true">https://rhynl.io/notes/fail-soft-by-default-integrating-an-llm-with-systems-that-can-go-down/</guid><description>An AI feature is only as reliable as its least reliable dependency. Here&apos;s how I make LLM integrations degrade quietly instead of taking the request down.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>AI</category><category>Architecture</category><category>Node.js</category><author>mail@rhynl.io</author></item><item><title>The sidecar I didn&apos;t build</title><link>https://rhynl.io/notes/the-sidecar-i-didnt-build/</link><guid isPermaLink="true">https://rhynl.io/notes/the-sidecar-i-didnt-build/</guid><description>The RFC said ClamAV in a container. The research said GuardDuty. Here&apos;s what changed, what it cost, and the parts of a HIPAA upload pipeline nobody puts on the diagram.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>AWS</category><category>Compliance</category><category>Architecture</category><category>Cost</category><author>mail@rhynl.io</author></item><item><title>The subscription that went deaf</title><link>https://rhynl.io/notes/the-subscription-that-went-deaf/</link><guid isPermaLink="true">https://rhynl.io/notes/the-subscription-that-went-deaf/</guid><description>Our Salesforce event subscription stopped delivering after a few days of uptime, with no errors and a green health check. The bug was in the transport, and the lesson was about what &quot;healthy&quot; means.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>Integrations</category><category>Observability</category><category>NestJS</category><category>AWS</category><author>mail@rhynl.io</author></item><item><title>Cache-Control will not save you from a bandwidth bill</title><link>https://rhynl.io/notes/cache-control-will-not-save-you-from-a-bandwidth-bill/</link><guid isPermaLink="true">https://rhynl.io/notes/cache-control-will-not-save-you-from-a-bandwidth-bill/</guid><description>A marketing site went from 32 GB to 32 TB of video traffic in nineteen days. The headers we added did nothing, and understanding why is the whole lesson.</description><pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate><category>Cost</category><category>AWS</category><category>Next.js</category><category>Architecture</category><author>mail@rhynl.io</author></item></channel></rss>