Skip to content

Instantly share code, notes, and snippets.

View louzt's full-sized avatar
🦇
Hard solutions over loose assumptions, always.

David Mireles louzt

🦇
Hard solutions over loose assumptions, always.
View GitHub Profile
@louzt
louzt / v1.en.md
Created September 12, 2026 22:10
android-dev-on-tablet (EN, 3 canonical sections: proot-Debian + CLI toolkit + agent onboarding)

Android dev experience on Termux + proot Debian

Three canonical guides for bringing Debian to an Android tablet or phone without rooting, mounting a persistent command-line toolkit, and leaving the machine ready for an autonomous agent to use it as a development endpoint.

The scope is empirical. Each recommendation was reproduced against Termux 0.95+, proot-distro on bionic and glibc, and an SSH server exposed on port 8022. The intent is to give the why for each piece

@louzt
louzt / v1.md
Created September 12, 2026 22:05
WS4 gist MVP: android-dev-on-tablet (ES-first, 3 secciones canónicas)

Android dev experience on Termux + proot Debian

Tres guías canónicas para llevar Debian a una tablet o teléfono Android sin rootear, montar un kit de herramientas de línea de comandos persistente, y dejar la máquina lista para que un agente autónomo la use como endpoint de desarrollo.

El alcance es empírico. Cada recomendación fue reproducida contra Termux 0.95+, proot-distro sobre bionic y glibc, y un servidor SSH expuesto en el puerto 8022. La intención es dar el por qué de cada

@louzt
louzt / rust-compile-resource-budget.es.md
Last active September 14, 2026 23:36
Presupuesto de recursos de compilación Rust en workstations con RAM limitada — settings empíricos para cargo, rust-analyzer, PSI y sccache que limitan el pico de RSS a <8 GB en lugar de 30+ GB sin sacrificar wall-clock.

Presupuesto de recursos de compilación Rust en workstations con RAM limitada

Compilar Rust sin que tu máquina de desarrollo sufra OOM — laptops, torres, servidores de desarrollo single-board, cualquier cosa que no sea un nodo CI bestia.

Los defaults de Cargo están calibrados para servidores CI con 128+ GB de RAM y un agente single-purpose haciendo un build a la vez. En una workstation con RAM limitada — una laptop de 32 GB, una torre compartiendo 64 GB entre dev + browser + IDE + agente, o un servidor

@louzt
louzt / rust-compile-resource-budget.md
Last active September 14, 2026 23:36
Rust compile resource budget on RAM-limited workstations — empirical settings for cargo, rust-analyzer, PSI, and sccache that cap peak RSS at <8 GB instead of 30+ GB without sacrificing wall-clock.

Rust compile resource budget on RAM-limited workstations

Compiling Rust without OOM-killing your dev machine — laptops, towers, single-board dev servers, anything that isn't a beefy CI node.

Cargo's defaults are calibrated for CI servers with 128+ GB of RAM and a single-purpose agent doing one build at a time. On a RAM-limited workstation — a 32 GB laptop, a tower sharing 64 GB between dev + browser + IDE + agent, or a single-board dev server with 16 GB — those same defaults OOM-kill the build, freeze the terminal for seconds at

@louzt
louzt / louzt-systemd-template-units.es.md
Last active August 12, 2026 14:00
Patrón systemd template units v2 (ES): 1 script + @.service + drop-in para work paramétrico. Hex Encoding canónico para paths con guiones internos (^[0-9a-f]+$); Dual-Decode preserva compatibilidad v1. Validador E2E (lzt-template-validator). 5 variantes de drop-in por mutabilidad. | v2 hex encoding canonical for path-based template instances; du…

Systemd Template Units para Agentes Autónomos e Infraestructura Paramétrica (v2)

Status: Producción (v2 — Hex Encoding canónico + Dual-Decode + Perfiles de mutabilidad) Target Architecture: Linux systemd user session (systemctl --user), Cgroups v2, Planos de ejecución agéntica


El problema: rutas sin sanitizar y primitivas con pérdida en workflows agénticos

Cuando agentes IA autónomos o automatización de operador invocan CLI tools para hacer acciones de sistema (auditorías, poda de storage, backups), el trabajo es paramétrico: misma lógica de ejecución, distinto target path o tag.

@louzt
louzt / systemd-template-units.md
Last active August 12, 2026 14:00
v2 (2026-08-12) hex-encoded %i canonical for paths with internal dashes; dual-decode preserves v1 instances. Drop-ins left as caps-only; 5-variant reference table describes the mutability options. Validator reports detected variant per template (WARN-not-FAIL).

Systemd Template Units for Autonomous Agents & Parametric Infrastructure (v2)

Status: Production (v2 — Canonical Hex Encoding + Dual-Decode + Mutability Profiles) Target Architecture: Linux systemd user session (systemctl --user), Cgroups v2, Agentic Execution Planes


The Problem: Unsanitized Paths and Lossy Primitives in Agentic Workflows

When autonomous AI agents or operator automation invoke CLI tools to perform system actions (audits, storage pruning, snapshot backups), the work is parametric: same execution logic, different target path or tag.

@louzt
louzt / v1.md
Created August 8, 2026 03:16
Atomic bidirectional sync — 3 patterns that actually work for laptop↔VPS (snapshot+apply, scp+manifest+3-way merge, sshfs FUSE write-through)

Atomic Bidirectional Sync — 3 patterns that actually work

A field guide for laptop↔VPS bidirectional file/database sync where both sides are mutable, both can crash mid-write, and one side runs a long-lived consumer that holds stale snapshots.

This is not a generic rsync tutorial. The three patterns below are the ones that survived real production use across SQLite databases, config directories, and dev-time bind mounts. Each solves a different failure mode; choosing the wrong one silently corrupts data.

@louzt
louzt / vps-self-hosted-runner-hardening-playbook.md
Last active August 12, 2026 13:49
VPS Self-Hosted Runner Hardening Playbook: Reproducible Architecture for Stall Detection + Production Hardening

title: "VPS Self-Hosted Runner Hardening Playbook: Reproducible Architecture for Stall Detection + Production Hardening" description: "Reproducible architecture for self-hosted GitHub Actions / GitLab / Jenkins runners on a VPS. TCP-level stall detection, 3-layer watchdog, systemd hardening cascade (capabilities, namespaces, kernel locks), auditd + sshd + sysctl layers. Production-tested patterns + 10 cross-cutting lessons learned from a real hardening sweep." author: "David Mireles (@louzt)" email: "[email protected]" license: "MIT-0" canonical_repo: "https://github.com/LOUST-PRO/lzt-broker-stall-reaper" tags: ["self-hosted-runner", "github-actions", "vps-hardening", "systemd", "stall-detection", "prometheus", "auditd", "sshd", "sysctl", "ci-cd", "devops", "sre", "infosec"] keywords: ["self hosted runner hardening", "vps hardening playbook", "tcp stall detection", "github actions runner hung", "systemd capability bounding set", "protect system strict", "memory deny write execute v8", "auditd rules", "ss

@louzt
louzt / tcp-long-poll-stall-detection-self-hosted-runner.md
Last active August 12, 2026 13:48
TCP Long-Poll Stall Detection for Self-Hosted CI Workers. Detect & reap stalled TCP long-poll connections on self-hosted CI runners. 3-layer watchdog, capability-aware ss parsing, shared sentinel file, atomic deploy with rollback, 5 guardrail layers. Production-tested reference architecture for GitHub Actions runners.

title: "TCP Long-Poll Stall Detection for Self-Hosted CI Workers" description: "Detect and reap stalled TCP long-poll connections on self-hosted CI runners. 3-layer watchdog, capability-aware ss parsing, shared sentinel file, atomic deploy with rollback, 5 guardrail layers. Production-tested reference architecture for GitHub Actions runners." author: "David Mireles (@louzt)" email: "[email protected]" license: "MIT-0" canonical_repo: "https://github.com/LOUST-PRO/lzt-broker-stall-reaper" tags: ["github-actions", "self-hosted-runner", "tcp-watchdog", "stall-detection", "prometheus", "systemd", "go", "sre", "devops", "ci-cd"] keywords: ["tcp stall detection", "self-hosted runner", "github actions runner hung", "broker connection stall", "ss kill cap_net_admin", "long-poll timeout", "watchdog pattern"] seo:

@louzt
louzt / NOTICE
Created August 7, 2026 05:26
Sovereign Agent Fleet Provenance & Git Claim Gates (F80.14) — Deterministic agent_id + Redis branch ownership registry + H16 hook guard for multi-agent Claude Code sessions. EN+ES, Apache-2.0.
Sovereign Agent Fleet Provenance & Git Claim Gates (F80.14)
Copyright 2026 David Mireles
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software