[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1y3y6zsdzzjji":3,"$fanuq43nlrv5g":56},{"slug":4,"title":5,"body":6,"summary":7,"tags":8,"author":14,"cover_url":15,"published_at":16,"seo_title":17,"seo_description":18,"reading_minutes":19,"related":20},"cloudflare-traces-trace-rules-debug-one-customer","Why was that request blocked? Tracing one customer at 100% with Cloudflare Traces and Trace Rules","\u003Cp>A customer writes in: their checkout request was blocked, or it took eight seconds, and they sent a screenshot with a Ray ID. Until now, answering that meant stitching together Security Events, cache analytics and your own origin logs by timestamp. Cloudflare Traces, announced in open beta on October 2, puts those steps into one trace: security rule evaluations, request transforms, cache decisions, routing, Workers and the origin call, as nested spans.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac338822cb6b40613ac2bec\">\u003Cvideo src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338832cb6b40613ac2bf2-0-a93624df.mp4\" autoplay muted loop playsinline preload=\"metadata\">\u003C\u002Fvideo>\u003C\u002Ffigure>\n\u003Cp>This is a recipe for the support case above: keep tracing cheap for normal traffic, capture 100% of requests for the one host or customer you are debugging, join Cloudflare's spans to your backend's, and ship them to an OpenTelemetry collector you run. It is built from Cloudflare's announcement and the Traces documentation; the feature is a beta, so check the dashboard labels against the docs links at the end if anything has moved.\u003C\u002Fp>\n\n\u003Ch2>What a trace contains\u003C\u002Fh2>\n\u003Cp>According to the docs, Traces currently covers spans for Rules, request routing, Cache, Workers and origin connections. The announcement shows span names such as \u003Ccode>http_request_transform\u003C\u002Fcode> and \u003Ccode>workers_routing\u003C\u002Fcode>, with cache, upstream and origin spans nested underneath. The four questions Cloudflare says it is built to answer are the ones support tickets usually ask:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac338072cb6b40613ac2b82\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338072cb6b40613ac2b87-0-cc546518.png\" alt=\"A conceptual visualization of a request flowing through various network layers.\" loading=\"lazy\">\u003Cfigcaption>A conceptual visualization of a request flowing through various network layers.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cul>\n\u003Cli>Which security rule blocked or challenged this request?\u003C\u002Fli>\n\u003Cli>Did a Transform Rule rewrite the URL before it reached the app?\u003C\u002Fli>\n\u003Cli>Which Page Rule, Snippet or Worker handled it?\u003C\u002Fli>\n\u003Cli>Was it a cache hit, and how was the time split between Cloudflare, the origin and the application?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>One naming trap: \u003Cstrong>Cloudflare Trace\u003C\u002Fstrong> (singular) is an older tool that simulates how your configuration would treat a hypothetical request. It does not show production traffic. \u003Cstrong>Cloudflare Traces\u003C\u002Fstrong> records real requests. Use the second one for a customer complaint.\u003C\u002Fp>\n\n\u003Ch2>Step 1: enable tracing with a low baseline\u003C\u002Fh2>\n\u003Cp>Tracing is enabled per domain. The configuration page has a \u003Cstrong>Default sample rate (%)\u003C\u002Fstrong>: at 10%, roughly 10 of every 100 requests are traced. For a small site, start low. Cloudflare's own example of normal operation is 1%, which still gives you a steady sample of what typical requests look like without filling your ingestion allowance.\u003C\u002Fp>\n\u003Cp>Head sampling means the decision is made when the request arrives. A request that was not sampled is not recorded, even if it later turns out to be the one a customer complains about. That is why the next step matters.\u003C\u002Fp>\n\n\u003Ch2>Step 2: a Trace Rule that captures 100% of one slice\u003C\u002Fh2>\n\u003Cp>Trace Rules override the default rate for requests that match an expression written in the same Rules language you use for WAF custom rules and Transform Rules. Cloudflare uses the \u003Cstrong>first matching rule\u003C\u002Fstrong>, so put the narrow debug rules above any broad ones.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac338072cb6b40613ac2b8c\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338072cb6b40613ac2b91-0-2c7ec7d8.png\" alt=\"Isolating a specific request for detailed analysis.\" loading=\"lazy\">\u003Cfigcaption>Isolating a specific request for detailed analysis.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cp>Three rules that cover most support cases. A whole hostname that is misbehaving:\u003C\u002Fp>\n\u003Cpre class=\"code-block\">\u003Ccode class=\"hljs\">http.host eq \"checkout.example.com\"\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>One customer's office or a test machine, by source IP:\u003C\u002Fp>\n\u003Cpre class=\"code-block\">\u003Ccode class=\"hljs\">ip.src eq 203.0.113.42\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>A debug header that you, or the customer's support contact, add on purpose:\u003C\u002Fp>\n\u003Cpre class=\"code-block\">\u003Ccode class=\"hljs\">any(http.request.headers[\"x-debug-trace\"][*] eq \"1\")\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Set each to a sample rate of 100%, deploy, and reproduce the problem. The header rule is the most useful one day to day: anyone on your team can force a full trace from a terminal without touching the configuration again.\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">curl -sS -o \u002Fdev\u002Fnull -w \u003Cspan class=\"hljs-string\">&quot;%{http_code} %{time_total}s\\n&quot;\u003C\u002Fspan> \\\n  -H \u003Cspan class=\"hljs-string\">&quot;x-debug-trace: 1&quot;\u003C\u002Fspan> \\\n  \u003Cspan class=\"hljs-string\">&quot;https:\u002F\u002Fcheckout.example.com\u002Fapi\u002Fcart&quot;\u003C\u002Fspan>\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Two cautions. A header anyone can send means anyone can raise your trace volume, so remove or narrow the rule when the investigation ends. And an IP rule only helps while that customer's address is stable.\u003C\u002Fp>\n\n\u003Ch2>Step 3: find the request\u003C\u002Fh2>\n\u003Cp>In the Traces view, filter by Ray ID to open the trace for one request. You get the full request path as a tree of spans; expanding a span shows its status, service, trigger, and the span and trace IDs. For a block, look for the security span with an error status and the rule that matched. For a slow request, compare the duration of the origin span with the total: if most of the time is under the origin, the problem is yours, not Cloudflare's.\u003C\u002Fp>\n\n\u003Ch2>Step 4: join the trace to your backend\u003C\u002Fh2>\n\u003Cp>Traces speaks W3C Trace Context, with two separate switches:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac338072cb6b40613ac2b96\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338072cb6b40613ac2b9b-0-824ba733.png\" alt=\"Connecting edge network spans with backend application spans.\" loading=\"lazy\">\u003Cfigcaption>Connecting edge network spans with backend application spans.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cul>\n\u003Cli>\u003Cstrong>Incoming trace context.\u003C\u002Fstrong> The default policy is \u003Cstrong>Reject\u003C\u002Fstrong>: Cloudflare ignores a \u003Ccode>traceparent\u003C\u002Fcode> header sent by the client and starts its own trace. You can switch it to accept, so that a trace started in your frontend or mobile app continues through Cloudflare. The docs warn that incoming context is unverified, and joined traces are treated as untrusted. Accept only if you need client-side spans.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Forward to origin.\u003C\u002Fstrong> Turn this on and Cloudflare includes trace context in the request it sends to your origin. If your backend is instrumented with OpenTelemetry, its spans become children of Cloudflare's spans in the same trace.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Before you trust the join, check that the header actually arrives. A temporary log line at the origin is enough; for example, in an nginx \u003Ccode>log_format\u003C\u002Fcode>:\u003C\u002Fp>\n\u003Cpre class=\"code-block\">\u003Ccode class=\"hljs\">log_format traced '$remote_addr \"$request\" $status traceparent=\"$http_traceparent\"';\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Send a request with the debug header and confirm the log shows a value in the form \u003Ccode>00-&lt;trace-id&gt;-&lt;span-id&gt;-01\u003C\u002Fcode>. If it is empty, forwarding is off or the request was not sampled.\u003C\u002Fp>\n\n\u003Ch2>Step 5: export over OTLP to your own collector\u003C\u002Fh2>\n\u003Cp>Export is configured in two places. At the account level you create a destination: a name (for example \u003Ccode>grafana-traces\u003C\u002Fcode>), the type \u003Cem>Traces\u003C\u002Fem>, the OTLP endpoint, and any authentication headers your backend needs. Then, in each domain's settings, you add that destination under \u003Cstrong>Export destinations\u003C\u002Fstrong>. Cloudflare lists Honeycomb, Grafana Cloud, Axiom, Sentry, Datadog, New Relic, SigNoz and others as supported providers.\u003C\u002Fp>\n\u003Cp>One detail matters if you run your own collector: Cloudflare does \u003Cstrong>not\u003C\u002Fstrong> send binary (protobuf) OTLP, so the receiving endpoint must accept OTLP\u002FHTTP with JSON. The OpenTelemetry Collector's OTLP HTTP receiver does. A minimal collector config that receives from Cloudflare, checks a bearer token, and forwards to a Tempo instance:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"yaml\">\u003Ccode class=\"hljs language-yaml\">\u003Cspan class=\"hljs-attr\">extensions:\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">bearertokenauth:\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-attr\">token:\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;${env:CF_TRACES_TOKEN}&quot;\u003C\u002Fspan>\n\n\u003Cspan class=\"hljs-attr\">receivers:\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">otlp:\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-attr\">protocols:\u003C\u002Fspan>\n      \u003Cspan class=\"hljs-attr\">http:\u003C\u002Fspan>\n        \u003Cspan class=\"hljs-attr\">endpoint:\u003C\u002Fspan> \u003Cspan class=\"hljs-number\">0.0\u003C\u002Fspan>\u003Cspan class=\"hljs-number\">.0\u003C\u002Fspan>\u003Cspan class=\"hljs-number\">.0\u003C\u002Fspan>\u003Cspan class=\"hljs-string\">:4318\u003C\u002Fspan>\n        \u003Cspan class=\"hljs-attr\">auth:\u003C\u002Fspan>\n          \u003Cspan class=\"hljs-attr\">authenticator:\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">bearertokenauth\u003C\u002Fspan>\n\n\u003Cspan class=\"hljs-attr\">processors:\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">batch:\u003C\u002Fspan> {}\n\n\u003Cspan class=\"hljs-attr\">exporters:\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">otlp:\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-attr\">endpoint:\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">tempo:4317\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-attr\">tls:\u003C\u002Fspan>\n      \u003Cspan class=\"hljs-attr\">insecure:\u003C\u002Fspan> \u003Cspan class=\"hljs-literal\">true\u003C\u002Fspan>\n\n\u003Cspan class=\"hljs-attr\">service:\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">extensions:\u003C\u002Fspan> [\u003Cspan class=\"hljs-string\">bearertokenauth\u003C\u002Fspan>]\n  \u003Cspan class=\"hljs-attr\">pipelines:\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-attr\">traces:\u003C\u002Fspan>\n      \u003Cspan class=\"hljs-attr\">receivers:\u003C\u002Fspan> [\u003Cspan class=\"hljs-string\">otlp\u003C\u002Fspan>]\n      \u003Cspan class=\"hljs-attr\">processors:\u003C\u002Fspan> [\u003Cspan class=\"hljs-string\">batch\u003C\u002Fspan>]\n      \u003Cspan class=\"hljs-attr\">exporters:\u003C\u002Fspan> [\u003Cspan class=\"hljs-string\">otlp\u003C\u002Fspan>]\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The \u003Ccode>bearertokenauth\u003C\u002Fcode> extension ships in the collector's contrib distribution, so run the \u003Ccode>otel\u002Fopentelemetry-collector-contrib\u003C\u002Fcode> image. Put TLS in front of port 4318 (your reverse proxy is fine), use \u003Ccode>https:\u002F\u002Ftraces.example.com\u002Fv1\u002Ftraces\u003C\u002Fcode> as the endpoint in the Cloudflare destination, and add the header \u003Ccode>Authorization: Bearer &lt;token&gt;\u003C\u002Fcode>. Your origin's own OpenTelemetry SDK can send to the same collector, which is what makes the joined trace show up as one tree in Grafana.\u003C\u002Fp>\n\n\u003Ch2>What it costs from December 1\u003C\u002Fh2>\n\u003Cp>Traces is free while in beta. Cloudflare's published pricing starts on December 1, 2026:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Free plan:\u003C\u002Fstrong> 0.5 GB of ingestion per day, 7 days of retention, no overage. When you hit the allowance, you stop ingesting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Paid and Enterprise:\u003C\u002Fstrong> 50 GB of ingestion and 10 GB-month of storage included per billing cycle, retention up to one year, then $0.25 per GB ingested and $0.10 per GB-month stored.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Cloudflare prices by gigabytes, not by trace, and trace size depends on how many rules, Workers and subrequests a request touches. So measure, do not guess: run your normal baseline for a week during the beta and read the ingested volume. As plain arithmetic on the published rates, a Paid zone that ingests 2 GB a day (about 60 GB a month) would pay for 10 GB over the allowance, $2.50 a month for ingestion. If you export to your own collector and do not need traces kept in the Cloudflare dashboard, storage is the line to watch.\u003C\u002Fp>\n\n\u003Ch2>The short version\u003C\u002Fh2>\n\u003Col>\n\u003Cli>Enable Traces on the domain with a 1% default sample rate.\u003C\u002Fli>\n\u003Cli>Add a 100% Trace Rule on a debug header (and, when needed, one host or one IP), placed first.\u003C\u002Fli>\n\u003Cli>Reproduce with \u003Ccode>x-debug-trace: 1\u003C\u002Fcode>, open the trace by Ray ID, and read the security, cache and origin spans.\u003C\u002Fli>\n\u003Cli>Turn on \u003Cstrong>Forward to origin\u003C\u002Fstrong>; leave incoming context on Reject unless you need client spans.\u003C\u002Fli>\n\u003Cli>Export to an OTLP\u002FHTTP JSON endpoint you run, then remove the broad debug rules when the ticket is closed.\u003C\u002Fli>\n\u003C\u002Fol>\n\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fblog.cloudflare.com\u002Fcloudflare-tracing\u002F\">Cloudflare blog: Cloudflare Traces (open beta, pricing)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fobservability\u002Ftraces\u002F\">Cloudflare docs: Traces overview and inspecting a trace\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fobservability\u002Ftraces\u002Fconfiguration\u002F\">Cloudflare docs: Traces configuration (sampling, Trace Rules, trace context)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fobservability\u002Fexport\u002Fopentelemetry\u002F\">Cloudflare docs: OpenTelemetry export destinations\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fruleset-engine\u002Frules-language\u002F\">Cloudflare docs: Rules language\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>","Cloudflare Traces (open beta) shows a request's path through WAF rules, transforms, cache, Workers and origin as one trace. A recipe: low baseline sampling, a 100% Trace Rule for one host or debug header, traceparent to your origin, OTLP export to your own collector, and what December pricing means.",[9,10,11,12,13],"cloudflare","observability","opentelemetry","tracing","ai-assisted","if.codes","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338052cb6b40613ac2b7c-0-2294d114.png","2026-10-05T06:22:19.055Z","Tracing one customer at 100% with Cloudflare Traces and Trace Rules","Debug a blocked or slow request: 1% baseline, a 100% Trace Rule on a debug header, traceparent to origin, OTLP export to your collector, Dec 1 pricing.",6,[21,33,43],{"slug":22,"title":23,"type":24,"summary":25,"tags":26,"author":14,"cover_url":31,"published_at":32,"updated_at":32},"copyescape-cve-2026-17106-patch-docker-cp","CopyEscape (CVE-2026-17106): patch docker cp, and stop copying out of running containers","blog","A race in docker cp lets a malicious container write files anywhere the copying process can write on the host. That matters for CI runners and AI-agent sandboxes that copy results out. Check your versions, patch, and change copy-out jobs to stop the container first.",[27,28,29,30,13],"docker","security","cve","ci","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218ebfd770659725abe68-0-eee7c8f7.png","2026-10-04T23:51:14.689Z",{"slug":34,"title":35,"type":24,"summary":36,"tags":37,"author":14,"cover_url":40,"published_at":41,"updated_at":42},"protected-quick-tunnels-vs-tailscale-funnel","Share localhost with three named people: Cloudflare's Protected Quick Tunnels vs Tailscale Funnel","cloudflared 2026.9.3 adds --allowed-mail: your quick tunnel now sits behind an email one-time PIN, checked against an allow-list on your own machine, free and without a Cloudflare account. The commands, what it protects, and when Tailscale Serve or Funnel is the better fit.",[9,38,39,28,13],"tailscale","tunnels","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218d8fd770659725abe3a-0-40f8cb2e.png","2026-10-04T23:19:14.764Z","2026-10-04T23:19:14.765Z",{"slug":44,"title":45,"type":24,"summary":46,"tags":47,"author":14,"cover_url":53,"published_at":54,"updated_at":55},"si-domains-super-intelligence-data",".si after 'Super Intelligence': did one UN speech move a ccTLD?","Trump renamed AI 'super intelligence' at the UN on 22 September 2026 and Slovenia's .si went from about 190,000 names to almost 276,000 in a month. Registry numbers, prices, and 87 WHOIS checks: the obvious AI names were gone years ago; the compounds went in days.",[48,49,50,51,52,13],"domains","si","tld","data","ai","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaee53e21d5cbd14d442d-0-d6243bc5.png","2026-10-04T22:36:14.598Z","2026-10-04T22:36:14.599Z",[57,60,63,66,68,82,94,106,117,128,137,149,160,169,180,190,199,209],{"slug":4,"title":5,"type":24,"summary":7,"tags":58,"author":14,"cover_url":15,"published_at":16,"updated_at":59,"reading_minutes":19},[9,10,11,12,13],"2026-10-05T06:22:19.056Z",{"slug":22,"title":23,"type":24,"summary":25,"tags":61,"author":14,"cover_url":31,"published_at":32,"updated_at":32,"reading_minutes":62},[27,28,29,30,13],5,{"slug":34,"title":35,"type":24,"summary":36,"tags":64,"author":14,"cover_url":40,"published_at":41,"updated_at":42,"reading_minutes":65},[9,38,39,28,13],4,{"slug":44,"title":45,"type":24,"summary":46,"tags":67,"author":14,"cover_url":53,"published_at":54,"updated_at":55,"reading_minutes":19},[48,49,50,51,52,13],{"slug":69,"title":70,"type":24,"summary":71,"tags":72,"author":14,"cover_url":78,"published_at":79,"updated_at":80,"reading_minutes":81},"palantir-agent-stack-python","Steal Palantir's agent stack: typed tools, one LLM gateway, swappable models","An X thread boils Palantir's AIP docs down to four agent patterns. We check each one against the docs, then build them in one stdlib-only Python file: typed business-object tools, a gateway that masks PII, caches and retries, a model set in config, and schedule\u002Fevent\u002FAPI triggers.",[73,74,75,76,77,13],"ai-agents","llm","python","architecture","palantir","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f9c951ea7137fa3872-0-48eb7eee.png","2026-10-01T23:05:10.531Z","2026-10-01T23:05:10.532Z",10,{"slug":83,"title":84,"type":24,"summary":85,"tags":86,"author":14,"cover_url":90,"published_at":91,"updated_at":92,"reading_minutes":93},"claude-code-effort-levels","Effort levels in Claude Code: when max effort pays off and when it just burns tokens","Anthropic's effort deep dive (Terminal-Bench 3.0 plus three builds) shows higher effort mostly buys verification and edge-case testing, not smarter code. A rule of thumb per task type, the commands to set effort, and a script to measure cost vs pass rate on your own repo.",[87,88,74,89,13],"claude-code","ai-coding","developer-tools","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88edc951ea7137fa3804-0-2716005a.png","2026-10-01T22:32:14.139Z","2026-10-02T04:44:58.001Z",9,{"slug":95,"title":96,"type":24,"summary":97,"tags":98,"author":14,"cover_url":102,"published_at":103,"updated_at":104,"reading_minutes":105},"agentic-inbox-cloudflare-setup","Self-host an AI email agent on Cloudflare Workers: agentic-inbox set up and costed","Cloudflare's open-source agentic-inbox runs a full email client on Workers, with one SQLite Durable Object per mailbox and a Kimi K2.5 agent that drafts replies. Covers the post-deploy steps people miss (Access, sending, routing, mailbox first) and the cost.",[9,99,73,100,101,13],"workers","email","self-hosting","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dac951ea7137fa378b-0-5b0ec96d.png","2026-10-01T08:17:18.646Z","2026-10-05T05:56:11.919Z",8,{"slug":107,"title":108,"type":24,"summary":109,"tags":110,"author":14,"cover_url":114,"published_at":115,"updated_at":116,"reading_minutes":105},"audit-ai-agent-public-traces","Nearly a million leaked links: auditing what your AI agents leave on the public web","OpenAI's agent swarm left almost a million public shortener URLs holding credentials. Here's a tested shell + gitleaks audit to find the shortlinks, pastes and webhooks your own agents created, scan them for secrets and close the channels.",[28,111,112,113,74,13],"agents","secrets","gitleaks","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaad873e21d5cbd14d4397-0-0f4f51f7.png","2026-10-01T07:43:19.642Z","2026-10-01T08:44:43.041Z",{"slug":118,"title":119,"type":24,"summary":120,"tags":121,"author":14,"cover_url":125,"published_at":126,"updated_at":127,"reading_minutes":105},"mikrotrick-check-patch-mikrotik","MikroTrick: check and patch your MikroTik in 15 minutes","Two chained RouterOS bugs give anyone who can reach SSH full admin, no password needed, and attacks started before the patch. Find exposed SSH, check the version, grep for the published IoCs, patch and move management behind WireGuard.",[28,122,123,124,101,13],"mikrotik","routeros","ssh","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c0838b650cb96b3d10-0-6cd107e0.png","2026-10-01T07:02:15.03Z","2026-10-01T08:44:41.391Z",{"slug":129,"title":130,"type":24,"summary":131,"tags":132,"author":14,"cover_url":134,"published_at":135,"updated_at":136,"reading_minutes":105},"agent-sandbox-dns-egress-lockdown","Your agent sandbox leaks through DNS: lock down egress in 15 minutes","An OpenAI model escaped its sandbox by tunnelling questions through DNS. Here is a tested Docker Compose setup for coding agents: a DNS allowlist, a logging egress proxy and a kill switch that actually fires.",[28,27,111,133,101,13],"dns","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaca13e21d5cbd14d4306-0-cb93fe1b.png","2026-10-01T03:00:15.943Z","2026-10-01T08:44:43.165Z",{"slug":138,"title":139,"type":24,"summary":140,"tags":141,"author":14,"cover_url":145,"published_at":146,"updated_at":147,"reading_minutes":148},"who-blocks-ai-crawlers-robots-txt","Who blocks AI crawlers? robots.txt vs the network edge, with numbers","I scanned robots.txt on the top 300 sites: 33 of 138 block GPTBot, 14 block training but allow AI search. What each AI bot directive controls, why robots.txt is only a request, and a copy-paste policy plus nginx rule for small SaaS sites.",[52,142,143,9,144,13],"robots-txt","seo","saas","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c1838b650cb96b3d1b-0-11f94198.png","2026-09-30T21:00:20.673Z","2026-10-01T20:47:34.092Z",7,{"slug":150,"title":151,"type":24,"summary":152,"tags":153,"author":14,"cover_url":157,"published_at":158,"updated_at":159,"reading_minutes":65},"bullet-time-with-first-last-frame-video","Bullet time with first\u002Flast-frame video: orbiting a frozen moment from three stills","A freeze-frame camera orbit built from generated stills: one action shot, two camera-move angles, two first\u002Flast-frame clips between them, stitched and ping-ponged. The pipeline, the seams, and where the model re-imagines the water.",[52,154,155,156],"comfyui","video-generation","flowdsl","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abae46c45201648bfd477a7-0-6f4d036e.png","2026-09-28T22:42:41Z","2026-09-28T22:42:41.6Z",{"slug":161,"title":162,"type":24,"summary":163,"tags":164,"author":14,"cover_url":166,"published_at":167,"updated_at":168,"reading_minutes":148},"an-ai-media-pipeline-that-shows-its-work","An AI media pipeline that shows its work: ComfyUI presets, FlowDSL routing and the misses","How the images on my sites are generated: four ComfyUI presets behind one Go module, job rows as state, FlowDSL flows for routing, per-post media in the admin — and the bugs and model misses I hit shipping it. This post's own images were made the same way.",[52,156,154,165],"image-generation","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6aba8ba317ceba3543925be4-0-2f6b8a5c.png","2026-09-28T15:57:50Z","2026-10-01T20:47:34.327Z",{"slug":170,"title":171,"type":24,"summary":172,"tags":173,"author":14,"cover_url":176,"published_at":177,"updated_at":178,"reading_minutes":179},"openai-embeddings-python-mongodb","Transforming Text into Vectors: OpenAI Embeddings in Python","Learn how to generate text embeddings with the OpenAI API in Python to power semantic search, recommendations, and more. Includes practical examples with MongoDB integration and cost analysis.",[174,52,75,175],"openai","mongodb","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c2d-0-2e60b732.png","2024-11-23T00:00:00Z","2026-09-28T22:31:01.385Z",3,{"slug":181,"title":182,"type":24,"summary":183,"tags":184,"author":14,"cover_url":186,"published_at":187,"updated_at":188,"reading_minutes":189},"check-pricing-availability-ing-domains","Last Chance to Grab Short .ING Domains: The Extended List Part II","Welcome back to the second part of our exciting exploration into the .ING domain zone! This time, I've expanded our horizons to bring you an even larger selection of .ING domain names. List of over 24,000 domain names inside.",[48,185],"business","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c38-0-c55f4c8d.png","2023-12-14T00:00:00Z","2026-09-28T22:31:01.453Z",1,{"slug":191,"title":192,"type":24,"summary":193,"tags":194,"author":14,"cover_url":195,"published_at":196,"updated_at":197,"reading_minutes":198},"impressive-ing-domains","Unveiling the Impressive .ING Domains","Discover the vast potential of the new .ING domain zone in my latest blog post! I've used AI and a Python script to unearth a treasure trove of available domain names. From budget-friendly picks to exclusive premium domains, there's something for every ambition. Plus, a special list of unique, lesser-known domains awaits.",[48,185],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c43-0-03be24b7.png","2023-12-11T00:00:00Z","2026-09-28T22:31:01.527Z",2,{"slug":200,"title":201,"type":24,"summary":202,"tags":203,"author":14,"cover_url":206,"published_at":207,"updated_at":208,"reading_minutes":179},"secured-web-server-in-5-minutes","Fortify Web Server Security in 5 Minutes with Tailscale","Tailscale revolutionizes secure networking with its user-friendly approach, effortlessly connecting devices across diverse networks.",[204,38,205],"firewall","webserver","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c4e-0-eae6f62d.png","2023-11-03T00:00:00Z","2026-09-28T22:31:01.597Z",{"slug":210,"title":211,"type":24,"summary":212,"tags":213,"author":14,"cover_url":216,"published_at":217,"updated_at":218,"reading_minutes":19},"lets-encrypt-free-ssl","How to Secure Your Website with Free SSL Certificates for a Lifetime","Let’s Encrypt certificates have revolutionized internet security by providing free, automated, and widely trusted SSL\u002FTLS certificates. The non-profit Certificate Authority (CA) has significantly contributed to a more secure web environment by simplifying the process of securing websites with HTTPS.",[214,215,205],"ssl","https","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c59-0-bf2a9a0a.png","2023-11-01T00:00:00Z","2026-09-28T22:39:13.555Z"]