Theo Zourzouvillys
I’m half English and half Greek, but not fully at home in either. I build software, sail a boat up the west coast every summer, and write about both — mostly about what it takes to make things that last.
Read the long version →
A collection of essays, engineering field notes, poems, logbook entries, and half-finished thinking — numbered, dated, and kept current.
- Field NotesZFN-N72
Short, numbered positions on how to build software well — and the open problems I haven't settled yet.
- BlueprintsZBP-N8
Normative implementation specifications, versioned and numbered to the requirement, written to be handed to a builder and built from.
- Essays—9
Longer prose that takes a side — on engineering, leadership, the machines we are now building with, and the water.
- Poetry—14
The interior register — what the technical writing has no room for.
- Logbook—1
Short entries from the boat: where we are, what the water did, what it taught.
Latest
- Field NoteZFN-71signalProduct-led teams were vibe coding before the LLMs wereThe worries about LLM-written code — decisions nobody made on purpose, a data model that fell out, architecture by accident — describe how product-led teams have treated engineering for a decade. LLMs hide those decisions further, and the cure is the rigor we sidelined.
- EssayWas This Different Two Years Ago?LLMs are getting the blame for slop, bad reviews, bad architecture and even bad leadership. None of those problems are new. The rate of output changed, and every weakness an organisation already had now shows up ten times as often.
- Field NoteZFN-70Grifting is authority you haven't earnedGrifting is talking with more authority than your knowledge supports, usually without one false statement in it. Ambition isn't the problem and neither is inexperience. It costs the same when it's unwitting, so learn where your own edge is and be humble past it.
- Field NoteZFN-69Register the query shape, don't send itGraphQL is right that a developer should declare the fields and shape they want, and wrong about when. Register that document with the server instead of sending it: it can then be planned and indexed for, and the registered set is a schema you generate the caller's own SDK from.
- Field NoteZFN-68The frontend is three packagesThree packages, three reasons to change: a transport-agnostic client, headless hooks, components. Step-up auth is the test — the client returns the challenge as data, a host in context resolves it, the caller contributes intent and observes progress, never the mechanism.
- Field NoteZFN-67The API I'd build todayWhat a new API needs before the first endpoint: operations kept apart, idempotency keys that replay the response, state tokens, DPoP, quota in requests and in work, regions, an archive. Cheap to decide before you have callers, a migration afterwards. Specified in ZBP-7.
- BlueprintZBP-7v1 · draftThe cross-cutting contract of an API surfaceThe contract every operation on an API surface shares: operation taxonomy, request envelope, idempotent replay, state tokens, delegation chains, quota in two currencies, regional pinning, the request archive, and schema evolution — specified as day-one decisions.
- Field NoteZFN-66Agonize over the interface, not the choice behind itRe-implementing a decision now costs hours. Changing an interface costs everyone standing on it. Spend deliberation at the boundary; hold the choice behind it loosely — on one condition: you know a decision was made, and where it lives. Unnoticed ones are the expensive kind.
- BlueprintZBP-6v1 · draftA review gate for infrastructure changeHow to run an infrastructure plan, hold it, and apply exactly what was approved: the plan artifact as the unit of approval, an allow-list projection of the change, deterministic guardrails deciding eligibility, and an advisory reviewer that can only veto.
- BlueprintZBP-5v1 · draftA runtime for partitioned stateful servicesA specification for services whose per-key state lives in memory on one instance at a time: a published partition map rather than a hash function, epoch-fenced ownership leases, checkpoint-journal-stream recovery, live handoff on rollout, and operator-governed placement.
- Field NoteZFN-65Journal the write, apply it in micro-batchesIf nothing the caller does next depends on a write, it does not belong in the request path: append it to a durable ordered journal and apply it in micro-batches. The bill is ordering. Sequence comes from the journal, never the clock, and never two paths to one row.
- EssayFifteen Years of Bullet PointsExtraction and generation look identical from the outside. Forty-six of my field notes share a publication date, and the difference between the two is the only thing worth arguing about.
- EssayNobody Reviews the AssemblyNobody reviews the assembly a compiler emits. Increasingly nobody reads the code a model writes either, so the specification becomes the thing you review.
- Field NoteZFN-64A config change is a deployConfig changes cause outages as often as code — and ride to production with none of code's safeguards. Anything that changes production behaviour is a deploy, whatever file it lives in: versioned, validated, canaried, staged, observable, and revertible in one motion.
- Field NoteZFN-63Decouple deploy from release — and give every flag a death dateA deploy puts code on servers; a release changes what users see. Coupled, a deploy is a bet you can only unwind by redeploying. Decoupled by flags, deploys become boring and releases progressive and instantly reversible. But a flag is a loan: owner, death date, or Knight Capital.
- Field NoteZFN-62Expand, migrate, contract: schema changes in three movesEvery deploy runs two code versions against one database — and rollback runs yesterday's code on today's schema. No schema change may break either. So every migration is three shippable moves: expand (additive), migrate (backfill, verify), contract (remove, later, deliberately).
- Field NoteZFN-61Propagate the deadlineEvery request has a deadline whether you set one or not — the caller's patience. Make it explicit at the edge, carry it as remaining budget on every hop, check it before expensive steps, and cancel downstream when it dies. Work past the deadline is the fuel of cascading collapse.
- Field NoteZFN-60Drain before you die: graceful shutdown is a protocolSIGTERM isn't an emergency — it's every deploy and scale-in. Shutdown is a protocol: stop attracting work, drain while the balancer catches up, hand back in-flight work, release leases, exit before SIGKILL. But graceful is only the optimisation — crash-safe is the requirement.
- Field NoteZFN-59Two clocks: monotonic for durations, wall time for recordsYou have two clocks. Wall time names moments — and it jumps, slews, and runs backwards. The monotonic clock measures elapsed time — and means nothing across machines or reboots. Every timeout, lease, and cross-machine ordering bug is one clock doing the other's job.
- Field NoteZFN-58Errors are part of the contractError paths are the half of your API clients depend on most, and usually the half nobody designed. Enumerate error codes in the schema like any other type: stable code, retryable-or-not, whose fault, structured params. Machines branch on codes — anyone parsing prose is broken.
- Field NoteZFN-57Deletion is a feature: design it on day oneA deleted_at column is not deletion. Real deletion is a workflow with an SLA: it must reach every replica, projection, index, cache, log, and backup — and you must prove it ran. Partition by owner, propagate tombstones on the event rails, crypto-shred what you can't rewrite.
- Field NoteZFN-56IDs are an interface: prefix the type, randomise the bodyAn ID is read by more than your database: humans in logs, machines at boundaries, adversaries probing. Serve all three — a type prefix so IDs self-describe and misuse fails at parse time, a random body so nothing leaks or enumerates, time-ordered only when the index needs it.
- Field NoteZFN-55On AWS, the account is the unit of isolationIAM inside one account is access control; the account boundary is isolation. Quotas, billing, credential scope, and blast radius are all account-shaped, and cross-account access fails closed. One workload per account, guardrailed by SCPs and RCPs — plumbing friction is the point.
- Field NoteZFN-54Quarantine freshly published dependenciesThe dangerous dependency isn't the old one with a CVE — it's the version published an hour ago by whoever phished the maintainer. Malicious releases are mostly caught within days. Pin everything, and refuse to install anything younger than 72 hours. Freshness is exposure.
- Field NoteZFN-53Make abuse cost money: attack the unit economics, not the identityAbuse at scale is a business with a P&L. Detection is an arms race you eventually lose, because the attacker gets unlimited free queries against your classifier. Instead find the metered input they can't substitute away from, and inflate it — per attempt, dialled by risk.
Say hi
I work remotely from the boat in Alaska all summer, which is about as off-grid as it gets, and I really value the chance to talk to people. You don’t need a pitch or a project — just real conversation.
Schedule a call