Skip to content
Jacob NolletteCloud & software engineer
Cloud & software engineer · Minneapolis

From the sky to the bedrock.

Fifteen years across the whole stack — AI agents, applications, cloud platforms, networks and the hardware underneath. I write up what I build, including the parts that went wrong.

Agents & AISelf-hostingInfrastructureReliabilityNetworkingClient work
Recently

What I’ve been building.

Four of the last few months’ projects. Every one of them has a write-up behind it rather than a claim.

Agents & AI

A Browser Farm for Agents

Ten Chrome browsers running in Kubernetes, each with a real profile and a real login, so an AI agent can use the web the way a person does.

Read the case study →

Reliability

Every Log in One Place

Container logs, hypervisor syslog and firewall events from three sites, in one lake — and the sizing decision that keeps the loud feed from erasing the quiet one.

Read the case study →

Networking

A Network Where People Cannot Reach Infrastructure

Three sites, a software-defined mesh, and a zone policy that removed a rule with 6.3 million hits on it.

Read the case study →

Infrastructure

Fifteen Pipelines Into One

A full microservice estate rebuilt onto a single trunk-based pipeline, taking a release from most of a working day to thirteen minutes.

Read the case study →

Where I’ve done it

Enterprise SaaS, media and IoT, agencies, small business, nonprofits.

  • IoT & enterprise SaaSTSI
  • Media appliancesNorth Shore Automation
  • Agency platform & hostingLuminFire
  • Lake healthLittle Sand Lake Area Association
  • Heritage nonprofitSteiger Heritage Club

Kubernetes · Terraform · GCP, AWS, Azure · Ceph · Proxmox · GitHub Actions, GitLab CI, Jenkins · Go, Python, Bash, PHP · Vault · Prometheus & Grafana

From the lab

What I’m building right now.

Short posts from the build log as the work happens, and long-form case studies once it’s done.

Build log Live from Mastodon

@jacob on feed.jacobnollette.com

  1. Rebuilt my site around case studies. What decided it: I counted the "proof" slots on the six service pages I'd written, and eight of fifteen linked to the contact form rather than to any actual work. Six pages claiming capability, backed by a form. They're gone — replaced with 21 write-ups and six topic tags, where a topic can't exist unless there are posts filed under it.

    View on Mastodon ↗
  2. Those feeds update several times a day and occasionally sweep in legitimate cloud infrastructure when an IP range changes hands. Disabled ciarmy and dshield — both carry higher false-positive rates than the Emerging Threats categories. Tailscale reconnected. The feeds had also been catching real inbound scanner traffic on the same network, so that's a tradeoff now.

    View on Mastodon ↗
  3. The search index had failed on 106,000 messages due to a field type conflict, so Graylog was returning zero for everything. Fell back to the raw syslog archive. Found that IP reputation feeds (ciarmy, dshield) get applied as kernel-level packet drops, not Suricata signatures — no alert, no syslog entry. The absence of a log wasn't exoneration, it was just how that mechanism works.

    View on Mastodon ↗
The full build log →
My studio

Software Donkey builds the agents and apps, and teaches small teams to do it too.

A standing team of six AI agents runs real work every day. The studio’s first apps are in private testing.

AtlasAdministration
FlintFacilities
JackMaintenance
RidgeHealth
FinFinance
WardSecurity
Next step

Let’s talk.

Whether that’s a role, a project, or a second opinion on something that keeps breaking.