Skip to content
Jacob NolletteCloud & software engineer
Cloud & software engineer · Minneapolis

From the sky to the bedrock.

Fifteen years across the whole stack — AI agents, applications, cloud platforms, networks and the hardware underneath. I write up what I build, including the parts that went wrong.

Agents & AISelf-hostingInfrastructureReliabilityNetworkingClient work
Recently

What I’ve been building.

Four of the last few months’ projects. Every one of them has a write-up behind it rather than a claim.

Agents & AI

A Browser Farm for Agents

Ten Chrome browsers running in Kubernetes, each with a real profile and a real login, so an AI agent can use the web the way a person does.

Read the case study →

Reliability

Every Log in One Place

Container logs, hypervisor syslog and firewall events from three sites, in one lake — and the sizing decision that keeps the loud feed from erasing the quiet one.

Read the case study →

Networking

A Network Where People Cannot Reach Infrastructure

Three sites, a software-defined mesh, and a zone policy that removed a rule with 6.3 million hits on it.

Read the case study →

Infrastructure

Fifteen Pipelines Into One

A full microservice estate rebuilt onto a single trunk-based pipeline, taking a release from most of a working day to thirteen minutes.

Read the case study →

Where I’ve done it

Enterprise SaaS, media and IoT, agencies, small business, nonprofits.

  • IoT & enterprise SaaSTSI
  • Media appliancesNorth Shore Automation
  • Agency platform & hostingLuminFire
  • Lake healthLittle Sand Lake Area Association
  • Heritage nonprofitSteiger Heritage Club

Kubernetes · Terraform · GCP, AWS, Azure · Ceph · Proxmox · GitHub Actions, GitLab CI, Jenkins · Go, Python, Bash, PHP · Vault · Prometheus & Grafana

From the lab

What I’m building right now.

Short posts from the build log as the work happens, and long-form case studies once it’s done.

Build log Live from Mastodon

@jacob on feed.jacobnollette.com

  1. The takeaway: on a 1 gig line, the UniFi Dream Machine Pro was the bottleneck, not the ISP. A consumer VPN on most networks plus intrusion prevention on the backup VLANs was more than it could encrypt and inspect. One QoS rule now puts people first and lets backups have the rest. How the lab's main AZ does VPN needs rethinking, probably somewhere other than the router.

    View on Mastodon ↗
  2. Then the uploads hit the network. WAN latency spiked to 1.9 s, and I blamed inbound traffic, since QoS can't shape what has already crossed the ISP link, so I capped B2 downloads. Wrong. The router's CPU was at 93–97% from VPN encryption plus IPS inspecting every backup byte. With the VPN gone and IPS off the server VLANs, download hit 1 Gbit/s at 4–8 ms latency. Pulled the cap the same night.

    View on Mastodon ↗
  3. Rebuilt the backups today. Everything now goes from the cluster straight to B2 with restic — no more mirroring to an offsite box first. Cloud drives are backed up from read-only rclone mounts, so nothing gets staged on Ceph on the way. An 11 TiB archive tree became B2-only once its pinned snapshot passed a restic read check and all 297,369 file paths matched the manifest before deleting the local copy.

    View on Mastodon ↗
The full build log →
My studio

Software Donkey builds the agents and apps, and teaches small teams to do it too.

A standing team of six AI agents runs real work every day. The studio’s first apps are in private testing.

AtlasAdministration
FlintFacilities
JackMaintenance
RidgeHealth
FinFinance
WardSecurity
Next step

Let’s talk.

Whether that’s a role, a project, or a second opinion on something that keeps breaking.