Posts

Removing a Leaked SSH Key from Git History with BFG Repo-Cleaner

How to surgically remove an accidentally committed SSH private key from a Git repository's history using BFG Repo-Cleaner — the fast, focused alternative to git filter-branch

It happens to almost everyone, eventually.

You stage your changes, type git commit -am "wip", push — and a few minutes later realize that id_rsa (or .env, or credentials.json) was sitting in the working directory the whole time. The file is now in the remote, in every clone, in every CI cache, and worst of all: in the git history, where a simple git rm won’t touch it.

This post walks through fixing exactly that scenario with BFG Repo-Cleaner — a tool purpose-built for ripping unwanted blobs out of git history.

DevOps git security bfg

The Local AI Toolbox: 13 Tools That Run Entirely on Your Machine

A tour of the local-AI tooling I'd actually install in 2026 — runtimes, hardware-fit checkers, on-device speech and TTS, and document parsing, with the licenses and caveats that matter.

The interesting thing about local AI in 2026 isn’t that it’s possible — it’s that the boring parts finally work. A Mac with 16 GB of unified memory, or a PC with an 8 GB GPU, runs a 7B–13B model well enough for transcription, OCR, routine chat and the small repetitive tasks that make up most of the day. No API key, no per-token meter, no outage on someone else’s status page.

What follows is the toolbox: thirteen tools, grouped by what they actually do. I verified each one’s repository, language and license while writing this, because half the “top tools” lists circulating right now cite projects that have been renamed or abandoned. Where something surprised me, I say so.

AI ai llm self-hosted

The SSH Commands I Actually Use Every Day

A practical field guide to SSH: keys, agents, config files, tunneling, jump hosts, and the small commands that quietly make remote work tolerable

I have been using SSH for over twenty years and I still occasionally forget the flag for tunneling. Not because the syntax is hard, but because SSH has so many little features that you only reach for once every few months — and by the time you need them again, your fingers have moved on.

So this post is the field guide I wish I could hand to past-me. Not “how SSH works under the hood” — there are excellent treatises for that. Just the dozen or so commands and config patterns I genuinely reach for during a normal week of operations work.

Linux linux ssh tooling

My Claude Code Setup, From Zero

Installing Claude Code and wiring it up the way I actually use it: CodeGraph for code intelligence, MCP servers, plugin marketplaces, LSP, GitHub Spec Kit, and Herdr to keep the agents running.

A fresh Claude Code install is useful. A configured one is a different tool entirely. The gap between the two is maybe fifteen minutes of setup — a code index, a handful of MCP servers, two plugin marketplaces, a spec workflow, and a runtime to keep it all alive — and I keep re-doing it every time I move to a new machine. So here it is written down, in the order I run it.

AI claude-code ai mcp

A Guide to Upgrading Your Library to a Major Release in Go

Practical walkthrough of bumping a Go module to v2+: import paths, branches, tags, and what not to forget.

Bumping a Go library to a new major version is not just a git tag v2.0.0. Go’s Semantic Import Versioning makes the module path itself part of the version contract — so v2+ means rewriting go.mod, every internal import, and (often) reorganizing branches. This is the short, command-driven version of the official guide, with the operational steps that are easy to forget.

Golang golang modules semver