Location
経歴
Pragmatic Technologies
Full-Stack Developer · 2023 – Present
Multi-client delivery
Supplyframe (Siemens)
Full-Stack Engineer · 2019 – 2023
B2B SaaS for Meta, TI, Garmin
Caltech – Van Valen Labs
Software Engineer · 2018 – 2019
Published in Nature Methods
YoyoChinese.com
Full-Stack Developer · 2018 – 2019
138% revenue increase
Loading data...
技術スタック
得意な技術スタック
JavaScript Node.jsエコシステム、AWS、Google Cloud、Docker、PostgreSQL、MongoDB、Redis、Python、Golangを中心に活動しています。
実績
138%
Revenue increase at YoyoChinese
1000s
Engineers using products built at Supplyframe
Nature
Published in Nature Methods (Caltech)
言語
Projects
Milestones in our customer solutions
Each project is a new relationship with a trusting client.
Explore how we are leveraging the latest in web technologies to create new business system solutions.

2023
BJJDex: The First Interactive Knowledge Map of Brazilian Jiu-Jitsu
Built with React.js, users can explore and navigate the first ever data-catalog of the myriad intricate positions of Brazilian Jiu-Jitsu.
続きを読む
2024
PedroSauer.com: Corraling a Global Organization
E-commerce, Video Streaming Platform, Association and Payment Management - all in one?
続きを読むBlog
Learning, Building, and
Documenting
Insights and experiences from our journey as developers, small business owners, and martial artists—exploring ideas,
overcoming challenges, and sharing lessons learned along the way.
A Comprehensive Testing Strategy: Unit, End-to-End, and Load Testing
How to build a practical testing pyramid with isolated unit tests, seeded end-to-end flows, and load testing that enforces performance thresholds before release.
- testing
- playwright
- jest
- performance
Cost-Safe Security Hardening for Public Edge Deployments
A practical look at how to reduce bot abuse, limit cost-amplification risk, and add emergency shutdown controls to a public web deployment without overcomplicating the stack.
- security
- devops
- vercel
- web
Defense in Depth: Layered Rate Limiting and Security Hardening for Production APIs
How to combine edge filtering, reverse proxy controls, application rate limiting, request sanitization, CSRF protection, challenge-based bot checks, and safe logging into a practical layered defense model.
- security
- node.js
- devops
Containerizing the Application Layer with Docker and Compose
A practical breakdown of multi-container application design, network segmentation, health checks, resource limits, and environment-aware Compose workflows.
- docker
- docker-compose
Railway-Oriented Programming and Functional Pipeline Composition in Node.js
How composable sync and async pipelines can replace long imperative route handlers, improve testability, and make server-side flows easier to reason about.
- node.js
- functional-programming
- typescript
- architecture
In-Memory Caching and Strategic Denormalization for Document Database Performance
How to combine startup-time lookup maps, denormalized visibility flags, cache invalidation, and aggregation pipelines to remove expensive joins from hot API paths.
- mongodb
- caching
- performance
- architecture
Multi-Currency Payment Architecture for Subscriptions and One-Time Purchases
How to design a payment system that handles multiple currencies, recurring and one-time plans, entitlement updates, caching, and operational safety around live billing.
- payments
- node.js
- architecture
Why Nginx Still Matters in Multi-Container Deployments
A practical guide to using Nginx as a reverse proxy in a multi-container architecture to reduce public attack surface, isolate services, and enforce HTTP policy before requests reach application code.
- nginx
- docker
- devops
- security
Building a Custom OAuth2 Server with Cookie and Header-Based Authentication
How to implement a custom OAuth2 storage model, scope-based access control, browser/mobile authentication strategies, and CSRF protection without relying on a hosted auth vendor.
- oauth2
- security
- node.js
- authentication
Security Response Headers That Actually Matter
A beginner-friendly guide to the browser security headers worth knowing, what each one does, why they matter, and how they work together in a production web app.
- security
- nginx
- web
- devops
Self-Hosted CI/CD, Container Orchestration, and Zero-Downtime Deployment
How to build a self-hosted deployment pipeline with dedicated runners, isolated end-to-end environments, multi-stage container builds, backup automation, and safer production releases.
- devops
- docker
- ci-cd
SSL Termination, Cloudflare, and Why a Second TLS Hop Is Worth It
A beginner-friendly guide to using Cloudflare in front of a custom Nginx server with TLS on both hops, real client IP restoration, and safer origin protection.
- cloudflare
- nginx
- security
- devops
Tokenized Video Embeds and Basic Anti-Piracy Controls for Streaming Applications
How expiring embed tokens, playback authorization, and lightweight DRM-style controls can raise the cost of casual video theft without pretending piracy can be eliminated entirely.
- streaming
- security
- javascript