Skip to content

showcase.loust.pro

Hello — I'm Lou.

Thanks for taking the time to look around. This site is built for recruiters and hiring teams to navigate on their own during a phone screen or hiring conversation — no video call required, no agenda to follow.

Below are four routes that cover the work, the thinking, and the tradeoffs. Pick whichever one answers the question you came here with.

Built for recruiters, hiring managers, technical founders, and curious operators.

Right now I'm shipping SaaS for agencies (CRM, ERP, marketplace, custom domains); a national entrepreneurs directory at networking.loust.pro in collaboration with multiple Mexican organizations; MCP/plugin bridges for agents; and an academic track anchored in my public ORCID.

The bio

Lou, in long form

I'm David Alejandro Mireles Llamas — Lou for short. I've been building production systems since before it was fashionable to talk about them, and loust.pro is the umbrella under which I do it: a small systems-architecture firm running real infrastructure for real operators, not a portfolio site with mockups.

The work lives in three layers. Below the surface: a VPS substrate hardened from the bottom up, multi-tenant SaaS cores on Next.js + Astro + TypeScript over PostgreSQL with isolated namespaces, and the open research I index under my public ORCID. Between the surface and the operator: agentic AI infrastructure, network transport hardening under hostile transit, server-side attribution pipelines. Above the surface: the products, dashboards, and showcases you can click through.

Most of what I write runs in Go, Rust, or Python — the languages that earn their operational cost. The runtime choices follow the same rule: Kubernetes when the workload justifies the operator cost, containerized systemd-nspawn when it doesn't, distributed control planes when there's actual coordination to do. Observability is grounded in kernel PSI and copy-on-invalid patterns over native memory pools — these are not aspirations, they are the way the production systems stay debuggable at 3am.

I work at the seam where academic depth, operational seriousness, and production code meet. On the academic side I publish under ORCID 0009-0008-4374-2254 — the most recent work is the math foundation for byte-exact retrieval-augmented generation, anchored as a pre-submission paper. The core results — Chernoff-Hoeffding bounds over FNV-1a 128-dim + L2 + cosine, and the O(1) context-compaction analysis that follows from them — are live as Sovereign RAG math gists for peer review. On the engineering side I maintain a multi-tenant SaaS for agencies, an MCP/plugin layer that lets agents touch real infrastructure safely, and a transport-hardening track that survives hostile transit on Mexican carrier paths. The seam is not a metaphor — every public artifact lives at the intersection and is verifiable from its source.

Heritage matters to me. I am from Mérida, Yucatán, and the operational seriousness I bring to infrastructure work is in part inherited from a family line of small-business operators. It is why I optimize for practical cost, latency, throughput, and reliability — not for performative overengineering. Concretely: I hold my own infrastructure to the same kernel PSI / cgroup v2 budgets I document in the self-hosted runner hardening playbook.

Bridge work

Conecto creativos, agencias y tech

Most of my work happens where different operational grammars collide — agency-side brand language, founder-side product language, engineering-side runtime language. Each side optimizes for a different metric and speaks a different dialect of the same production. My job is to translate between them without flattening precision on either side.

Conecto creativos, agencias y tech. The sentence is shorthand for the work: turning a director's intent into a runtime spec, an agency brief into a deployable deliverable, an engineering constraint into a creative option. Concrete artifacts I have shipped at this seam: the CRM/ERP backbone for agency clients, the marketplace module, the agency dashboard with magic-link auth, multi-platform video pipelines, and the orchestration layer that ties them to the substrate. The transport underneath that orchestration is documented separately — see the 5-tier SSH evasion chain for the runtime that keeps an agency brief reachable when the carrier path is hostile.

When I take a brief, I read for the production underneath before I read the surface. The questions I ask are about ownership, success criteria, failure modes, and the path forward when the first attempt does not land — the same questions I ask on an infrastructure engagement, just dressed differently.

The stack

What I actually run

Five groups rotate through the headline stack — the languages, runtimes, and operator-tooling that show up across every loust.pro engagement.

Frontend

  • Next.js
  • React
  • TypeScript
  • Tailwind CSS

Component-driven UIs and the runtime that ships them.

Tooling

Skills

languages

Go— Production since 2018; transport and agentic plumbingRust— Production since 2021; systems-level work and local-first toolingPython— Production since 2014; orchestration, ML, and scriptingTypeScript / Node.js— Production since 2016; Next.js and bots

infrastructure

Docker, Kubernetes, systemd-nspawn, distroboxPostgreSQL, SQLite (sqlcipher), Redisnginx, haproxy, CaddyWireGuard, QUIC, TLS— Includes CA pinning patterns

ai agentic

Multi-agent orchestration— MCP-aware orchestration patternsTool-use protocols— MCP 2025-06-18Context compaction and semantic cacheEmbedding and retrieval— FNV-1a, cosine, RAG over TriG/Virtuoso

security research

DPI evasion patterns— Hysteria2 Brutal CC and QUIC connection migrationTLS hardening— CA pinning and Mutual TLSOperator-grade hardening— Debian-for-workstation

domains

B2B SaaS and multi-tenant platformsDistributed process automation and connectorsConversational systems and agentic workflowsReal-time and interactive systems— WebGL, UDP, QUIC, coturn

Trajectory

Experience

en

Founder & Principal Engineer

LOUST-PRO · 2022 → present; umbrella entry; overlapping dates are intentional

  • Build B2B infrastructure for real operators, including multi-agent orchestration, local-first security tooling, and transport hardening under hostile transit.
  • Deliver platforms, dashboards, automations, deployment pipelines, and hardened Linux environments.
  • Design distributed automation by nodes and connectors, conversational systems, and operational AI workflows.
  • Optimize backend, network, and infrastructure against practical cost, latency, throughput, and reliability KPIs.
en

Independent Systems Consultant

Independent · Parallel with LOUST when the work genuinely overlapped

  • Advise private companies, developer groups, and founders on architecture, automation, hardening, debugging, and infrastructure.
  • Enter existing codebases and disordered operations to translate technical debt into maintainable decisions.
  • Provide high-context implementation guidance rather than abstract recommendations alone.
en

OSS Systems Hardening & Public Engineering

Independent / Open Source · Parallel with founder work; dates intentionally unspecified in source

  • Contribute scoped hardening and runtime-debugging work where behavior depends on real execution context.
  • Work on isolation layers, diagnostics, launch paths, lifecycle bugs, and tooling reliability.
  • Focus public engineering on correctness, observability, startup behavior, and maintainability.
en

Community Lead & Technical Discussion Organizer

Independent / Community · Dates intentionally unspecified in source; may overlap

  • Lead discussion circles, online communities, broadcast lists, and technical or commercial exchange spaces.
  • Coordinate conversations, follow-up, change sharing, and connections around innovation and practical execution.
  • Collaborate with ethical-security and hardening communities through reproductions, changelogs, and concrete solutions.
en

Sales & Operations Team Leadership

Commercial and field operations · Earlier or parallel roles; exact dates intentionally unspecified in source

  • Lead commercial and execution groups with sales goals, bonus structures, objective tracking, and real operational pressure.
  • Develop practical judgment about incentives, coordination, performance, and aligning systems with operations.
  • Coordinate creative production, calendars, deliverables, campaigns, approvals, and execution across Mexico.

Research

Publications

Deterministic Sovereign RAG

Byte-exact, local-first verification and retrieval primitives for auditable RAG workflows.

  • RAG
  • local-first
  • verification
  • provenance

APQ Case Study

A practical case study in persisted-query behavior, payload reduction, and operational API discipline.

  • GraphQL
  • APQ
  • performance
  • B2B

Zero-Prefill Keep-Alive

An operator-focused transport pattern for keeping connections useful without unnecessary prefill work.

  • networking
  • transport
  • hardening
  • operations

Stance

Principles

  • B2B systems for real operators, not demo decks.
  • Local-first by default: data stays on disk, with zero SaaS telemetry and secrets in Bitwarden.
  • Hardening is a daily practice, not a deliverable.
  • OSS when the boundary is clean enough; operator-specific work stays private.
  • Less hype, more clean execution: optimize for measurable cost, latency, throughput, and reliability.

From the field

Concrete outcomes, not promises

Three production stories with one measurable outcome each. The full breakdowns live in /case-studies/; here are the headlines.

Outcome

Persisted queries at 90.9% cache hit

A 135,504-line GraphQL schema dropped to 25% of its request body on cached queries, with p95 latency from 25ms to 12ms — built and operated as a self-hosted Redis + Lua EVAL stack with cgroup v2 isolation for the compile runner.

90.9% hit rate · 12 ms p95

Outcome

Threat intel response — Salt Typhoon AA25-239A

Triaged, reproduced, and published an advisory on the Salt Typhoon AA25-239A cluster as part of a multi-stage pipeline that turns raw documentation into auditable graph-backed reports. Byte-exact reproducibility across runs.

0 missed evidence · ~45 min report draft

Outcome

Hero poster recovery for a production launch

When a hero poster asset broke under a last-minute carrier inspection on a Mexican ISP path, the recovery path was a transport tier downgrade with zero-downtime swap — kept the launch window intact.

0-minute downtime · 1 transport swap

Featured work

Ten curated entries — operator-built, runtime-verified. Swipe or use the arrow keys to browse.

Private

louzt/quic-tunnel

active

Multi-transport SSH fallback that survives hostile transit: layered QUIC, Hysteria2, gost, tls-direct, and direct SSH with CA pinning.

  • Go
  • QUIC
  • Hysteria2
  • TLS
  • SSH

Case-study showcase for the loust.pro stack: 16:9 visual essays of architecture, kernel, transport, RAG and applied quant mechanics.

Visual bits

Bits & motion

1 visual artifact on the shelf today — renders, motion studies, and design mockups. New bits drop in here as they ship.

cuda-garden-mesh@cudaoutofmemory

15-module inventory sourced from the published product registry on GitHub. Site is statically prerendered; no tracking, no cookies.