<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Sergei Hanterov</title>
    <description>The latest articles on DEV Community by Sergei Hanterov (@sergei_hanterov_0b97cd30e).</description>
    <link>https://dev.to/sergei_hanterov_0b97cd30e</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4122457%2F3bea2889-393a-4adc-93b5-c304fd79efe5.png</url>
      <title>DEV Community: Sergei Hanterov</title>
      <link>https://dev.to/sergei_hanterov_0b97cd30e</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/sergei_hanterov_0b97cd30e"/>
    <language>en</language>
    <item>
      <title>Inside Plënka’s 43-Gate Jenkins Citadel: How I Keep Autonomous AI Agents from Ruining My Codebase</title>
      <dc:creator>Sergei Hanterov</dc:creator>
      <pubDate>Fri, 18 Sep 2026 05:54:55 +0000</pubDate>
      <link>https://dev.to/sergei_hanterov_0b97cd30e/the-whole-backend-is-written-by-ai-agents-heres-what-that-actually-means-day-to-day-55f4</link>
      <guid>https://dev.to/sergei_hanterov_0b97cd30e/the-whole-backend-is-written-by-ai-agents-heres-what-that-actually-means-day-to-day-55f4</guid>
      <description>&lt;p&gt;When your primary developers are AI agents operating on background loops, you cannot rely on trust. You need a paranoid, uncompromising, automated guillotine.My Jenkinsfile for Plënka has grown into 43 blocking quality gates. If an agent hallucinates, ignores an ADR, leaks memory, or attempts to comment out a failing test to pass CI, this pipeline crushes the build, collects the diagnostic logs, and sends the agent back to fix its mess.Here is the exact blueprint of all 43 gates.&lt;/p&gt;

&lt;p&gt;Group 1: Preparation (2 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Checkout: Workspace cleanup, repository clone, git submodules initialization, and report directory creation.&lt;/li&gt;
&lt;li&gt;Secrets Scan (BLOCKING): Three-tier secret detection using an inline scripts/secret-scan.sh, gitleaks with SARIF reporting/redaction, and detect-secrets with a baseline. A single leaked key immediately fails the build.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 2: Read-Only Rules &amp;amp; Schema Validators (9 Parallel Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Validate Schemas: Compiles all events/v1/*.json event schemas using ajv (draft2020).&lt;/li&gt;
&lt;li&gt;Validate Glossary: Verifies that both code and documentation strictly adhere to terms defined in docs/GLOSSARY.md (and blocks anti-glossary terms).&lt;/li&gt;
&lt;li&gt;Validate Features: Validates features/// directory structures, Gherkin syntax linting, and BDD coverage anchor alignment.&lt;/li&gt;
&lt;li&gt;ADR Compliance: Ensures every feature.md points to a valid Architecture Decision Record (ADR), and every ADR contains Quality Drivers and Compliance sections.&lt;/li&gt;
&lt;li&gt;No-Skip Check: Absolute ban on GTEST_SKIP(), DISABLED_*, or commented-out tests without explicit architectural justification (ADR-022 §A3). No sweeping bugs under the rug.&lt;/li&gt;
&lt;li&gt;Naming Lint: Enforces test naming convention matching TEST(_...).&lt;/li&gt;
&lt;li&gt;Validate Structure: Confirms the repository tree strictly matches the STRUCTURE.md manifest.&lt;/li&gt;
&lt;li&gt;RTM Uniqueness: Enforces single-use Test Case IDs across acceptance.md to prevent duplicate requirements.11. Validate Image Pins: Requires all Docker base images to be pinned by immutable SHA256 hashes (&lt;a class="mentioned-user" href="https://dev.to/sha256"&gt;@sha256&lt;/a&gt;:...).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 3: Static Analysis &amp;amp; Code Quality (7 Parallel Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;shellcheck: Static analysis for all Bash scripts in scripts/, tools/, and ci/.&lt;/li&gt;
&lt;li&gt;hadolint: Dockerfile linting configured at warning severity.&lt;/li&gt;
&lt;li&gt;yamllint: YAML validation against .yamllint.&lt;/li&gt;
&lt;li&gt;markdownlint: Documentation and ADR markdown linting.&lt;/li&gt;
&lt;li&gt;clang-format / clang-tidy: C++23 code formatting and static analysis integrated with vcpkg compilation databases.&lt;/li&gt;
&lt;li&gt;cppcheck (BLOCKING): Executed with --error-exitcode=1 covering warnings, style, performance, and portability. No legacy grandfathering allowed—tech debt must be fixed or explicitly suppressed.&lt;/li&gt;
&lt;li&gt;ESLint: Frontend linting where all warnings are treated as hard errors.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 4: Security Scanners (2 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;SCA (Trivy - BLOCKING): Filesystem dependency vulnerability scanning. Any HIGH or CRITICAL CVE fails the build and outputs SARIF reports.&lt;/li&gt;
&lt;li&gt;SAST (Semgrep - BLOCKING): Runs OWASP Top 10, CWE Top 25, and custom ci/semgrep.yml rulesets with --error enforcement.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 5: Build, Test &amp;amp; Sanitizer Matrix (4 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Build Frontend: Production Vite + Preact + TailwindCSS compilation.&lt;/li&gt;
&lt;li&gt;Frontend Tests: Vitest unit tests and Playwright E2E suites running against a live backend (no API mocking).&lt;/li&gt;
&lt;li&gt;DB Reset &amp;amp; Migrate: Fresh Postgres + Redis spin-up with database migrations applied in a single transactional block (ON_ERROR_STOP=1 --single-transaction).&lt;/li&gt;
&lt;li&gt;Build &amp;amp; Test Matrix (4 Parallel Branches):Coverage: Unit, property, and integration tests (Enforced thresholds: Line $\ge 80\%$, Branch $\ge 70\%$).ASan: AddressSanitizer + LeakSanitizer for memory corruption and leak detection.UBSan: UndefinedBehaviorSanitizer targeting undefined C++ behaviors.TSan: ThreadSanitizer for concurrency and data-race detection under load.Catch2 Unit Tests: Isolated core logic tests (Money, TraceId, Result types).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 6: Architecture &amp;amp; Defense-in-Depth (6 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Archcheck: Detects circular dependencies, god-headers, and god-classes (strict threshold: 150 lines per class).&lt;/li&gt;
&lt;li&gt;Binary Hardening (checksec): Verifies compiled binaries enforce PIE, RELRO, Stack Canaries, NX bit, and Fortify Source.&lt;/li&gt;
&lt;li&gt;SBOM &amp;amp; SCA (syft + grype): Generates Software Bill of Materials (SBOM) and performs vulnerability scanning directly against the SBOM.&lt;/li&gt;
&lt;li&gt;Secret Verification (Trufflehog): Scans for live credentials, validating active API keys against vendor endpoints.&lt;/li&gt;
&lt;li&gt;License Audit: Dependency license verification via trivy --license-full.&lt;/li&gt;
&lt;li&gt;Container Image Scan: Vulnerability scanning of fully assembled production container images.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 7: Fuzzing, Chaos &amp;amp; Load (4 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Fuzz (libFuzzer): In-process fuzzing of core C++ parsing and business logic functions (20-minute run).&lt;/li&gt;
&lt;li&gt;Fuzz (AFL++): External fork-server fuzzing against protocol endpoints (20-minute run).&lt;/li&gt;
&lt;li&gt;Chaos Engineering (Toxiproxy): Injects latency, packet loss, and connection dropouts to test backend resilience.&lt;/li&gt;
&lt;li&gt;Load Test (k6): Automated performance benchmarks enforced against SLAs in ci/k6-thresholds.json.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 8: Supply Chain Integrity (3 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Artifact Signing (cosign): Container image signing via Sigstore.&lt;/li&gt;
&lt;li&gt;Provenance (in-toto): Attestation generation for SLSA supply-chain compliance.&lt;/li&gt;
&lt;li&gt;Reproducible Builds: Verifies bit-identical output across isolated compilation passes.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 9: Infrastructure &amp;amp; Cloud Scanners (3 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Snyk (SCA + SAST): Advanced vulnerability intelligence scanning (Master/Release branches).&lt;/li&gt;
&lt;li&gt;IaC Scan (Checkov): Misconfiguration analysis for Infrastructure-as-Code (Terraform, Dockerfiles).&lt;/li&gt;
&lt;li&gt;Terraform Lint (TFLint): Static analysis for Terraform infrastructure configs.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Group 10: Final Verification &amp;amp; Quality Gate (3 Gates)&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Traffic Replay (GoReplay): Replays recorded production HTTP traffic against the local backend to catch edge-case regressions missed by unit tests.&lt;/li&gt;
&lt;li&gt;Native Quality Gate: Custom aggregator replacing SonarQube (per ADR-041). Consolidates findings from cppcheck, clang-tidy, jscpd (code duplication threshold $&amp;lt;3\%$), semgrep, trivy, grype, and checkov. Hard rule: NEW_ISSUES &amp;lt;= 1.&lt;/li&gt;
&lt;li&gt;DAST Baseline (OWASP ZAP): Staging environment vulnerability scan targeting XSS, CSRF, SQL Injection, and Open Redirects (configured via ci/zap-baseline.conf).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;How do you handle AI-generated code quality in your own projects? Do you let agents push directly, or do you run them through a similar meat grinder? Let me know your thoughts, feedback, or constructive criticism!&lt;/p&gt;

</description>
      <category>posts</category>
      <category>jenkins</category>
      <category>cicd</category>
      <category>cpp</category>
    </item>
    <item>
      <title>The 25-Minute Mouse Freeze: Building an AI Backend on a Dying Laptop</title>
      <dc:creator>Sergei Hanterov</dc:creator>
      <pubDate>Wed, 16 Sep 2026 06:37:17 +0000</pubDate>
      <link>https://dev.to/sergei_hanterov_0b97cd30e/the-25-minute-mouse-freeze-building-an-ai-backend-on-a-dying-laptop-3aa2</link>
      <guid>https://dev.to/sergei_hanterov_0b97cd30e/the-25-minute-mouse-freeze-building-an-ai-backend-on-a-dying-laptop-3aa2</guid>
      <description>&lt;p&gt;To be completely honest, I don't like my day job. It’s mostly just stress and waiting for the next corporate reprimand. But I can't leave just yet for a few reasons, so I won't get into that.&lt;br&gt;
​The real work starts when I get home. I boot up my laptop, load into Fedora 43 (I absolutely love Red Hat-based Linux), and that’s when the David Blaine street magic begins, haha.&lt;br&gt;
​The moment I log in, the system starts to choke. A million Docker containers spin up, RAM evaporates like water in a desert, and the CPU gets dangerously close to a kernel panic featuring a very stressed-out penguin. It’s brutal. I launch Devin Desktop, Firefox, and Hermes.&lt;br&gt;
​While my agents are writing code and scavenging the web for data to feed their hungry context windows, I hit make ci.&lt;br&gt;
​And then... everything dies.&lt;br&gt;
​The entire system freezes. The mouse cursor stops moving entirely, like it just saw a cat, haha. Honestly, I freeze along with it, experiencing my own personal kernel panic. 25 minutes of dead silence and staring at a frozen screen later—the agent finally finishes the task.&lt;br&gt;
​Here is the biggest lesson I’ve learned about LLMs during these 25-minute freezes: Cheap models are dumb. Expensive models are also dumb, they just forget the conversation slightly later (I’m exaggerating, but you get the point).&lt;br&gt;
​My current workflow? I use cheap models like GLM-5.3 Flash for the grunt work. But when it’s time for architectural review, I bring in Fable 5.1 and crank its... let's just say "reasoning dial" to the absolute maximum. Step by step, slowly but surely, my little worker bee agents are building Plënka.&lt;br&gt;
​In the next episode of this project, you’ll see—well, read (or have your AI voice assistant summarize for you)—exactly what is inside my Jenkins pipeline. I’ll break down how this strict methodology affects product quality, whether TDD actually helps AI agents, and most importantly, we'll take a look at what exactly is inside my agent.md file.&lt;br&gt;
​Drop your thoughts, suggestions, or constructive criticism below. How are you guys surviving local agent workflows without melting your hardware?&lt;/p&gt;

</description>
      <category>linux</category>
      <category>watercooler</category>
      <category>discuss</category>
      <category>ai</category>
    </item>
    <item>
      <title>From a Soviet Film Camera to C++23: Why I’m Bootstrapping a New Photo Marketplace</title>
      <dc:creator>Sergei Hanterov</dc:creator>
      <pubDate>Tue, 15 Sep 2026 18:20:48 +0000</pubDate>
      <link>https://dev.to/sergei_hanterov_0b97cd30e/from-a-soviet-film-camera-to-c23-why-im-bootstrapping-a-new-photo-marketplace-3did</link>
      <guid>https://dev.to/sergei_hanterov_0b97cd30e/from-a-soviet-film-camera-to-c23-why-im-bootstrapping-a-new-photo-marketplace-3did</guid>
      <description>&lt;p&gt;I’ve loved photography and cameras since the 90s. Back then, I subscribed to a print magazine simply called Photo (it’s long gone now). It was the dawn of Photoshop and digital editing, but the real magic was happening offline. Local film digitization shops were opening on every corner, and we were shooting everything on Kodak and Fujifilm.&lt;/p&gt;

&lt;p&gt;My camera of choice? An old Soviet "FED" rangefinder. For film, the quality it produced was absolutely incredible.&lt;/p&gt;

&lt;p&gt;Eventually, I grew up and went to university for computer networks and servers. I spent my days deep in Cisco and HP enterprise gear. Funny enough, I actually hated programming. Even in uni, I only wrote clunky Java scripts out of pure necessity for my own tasks. Back then, the idea that a machine could write code for you was pure sci-fi.&lt;/p&gt;

&lt;p&gt;Fast forward to today. LLMs have entered the arena, easily matching the output of junior and mid-level developers. I looked at the massive archive of photos I’ve accumulated since childhood and had a thought: Wait, I have the sysadmin background for AWS and Cloudflare. I have AI agents to write the code I don’t want to write. Why not build my own stock photo marketplace?&lt;/p&gt;

&lt;p&gt;That’s how Plënka was born (the name literally translates to film from Russian).&lt;/p&gt;

&lt;p&gt;If you look at my tech stack, you might ask: Why on earth are you writing the backend in ultra-low-level C++23 and pushing the frontend AI to WASM?&lt;/p&gt;

&lt;p&gt;The honest answer? Because they are blazingly fast—and because I simply don't have the VC money to pay for the massive, bloated infrastructure that the top stock monopolies use, haha.&lt;/p&gt;

&lt;p&gt;So, does anyone want to hear what happens next?&lt;/p&gt;

&lt;p&gt;Ah, well, I’m going to tell you anyway. In the next episode of this build-in-public journey, you’ll find out how I’m orchestrating this entire AI-driven development pipeline on a dying i5 laptop with 4 cores and 12GB of RAM.&lt;/p&gt;

&lt;p&gt;P.S. I’m not really "working" on it, I’m mostly just suffering, haha.&lt;/p&gt;

</description>
      <category>agents</category>
      <category>ai</category>
      <category>discuss</category>
      <category>startup</category>
    </item>
    <item>
      <title>The whole backend is written by AI agents. Here's what that actually means day to day.</title>
      <dc:creator>Sergei Hanterov</dc:creator>
      <pubDate>Sun, 13 Sep 2026 19:35:58 +0000</pubDate>
      <link>https://dev.to/sergei_hanterov_0b97cd30e/the-whole-backend-is-written-by-ai-agents-heres-what-that-actually-means-day-to-day-4h5o</link>
      <guid>https://dev.to/sergei_hanterov_0b97cd30e/the-whole-backend-is-written-by-ai-agents-heres-what-that-actually-means-day-to-day-4h5o</guid>
      <description>&lt;p&gt;Pre-launch founder here. Plënka is a stock photo marketplace where photographers keep 75% of the revenue — the industry standard is 15–40%. I live in Armenia, I've been here 8 years, and I work alone. Technically alone. In practice, a factory of AI assistants writes the entire backend, in C++23.&lt;/p&gt;

&lt;p&gt;People ask what that looks like day to day, so here is the honest version.&lt;/p&gt;

&lt;p&gt;The agents draft, review and rewrite each other's code. My actual job is direction and rejection: deciding what gets built, and throwing away what isn't good enough. The bottleneck isn't typing speed, it's judgment. Most days I write zero lines of code and make dozens of small decisions instead.&lt;/p&gt;

&lt;p&gt;What surprised me: the hardest part isn't the code at all. It's knowing which 20% of a feature actually matters to a photographer waiting for a fair payout, and cutting the rest. An agent will happily build all 100% if you let it. Saying "no" faster is the whole skill.&lt;/p&gt;

&lt;p&gt;The other surprise: C++ was a strange choice on paper and a good one in practice. I wanted the cost structure of a platform that can afford to pay 75% out — and that starts with not carrying a payroll, and with infrastructure that stays cheap and fast.&lt;/p&gt;

&lt;p&gt;Status: pre-launch, no investors, everything documented as I go. If the "one solo founder + AI agents" model fascinates or horrifies you, I'm happy to answer questions in the comments.&lt;/p&gt;

&lt;p&gt;And one honest note at the end: the project is funded by early supporters — voluntary contributions from $50, no equity, no returns, nothing in return but a fairer marketplace existing. If that resonates, the Ko-fi link is in my profile. If not, reading this far is already support.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Disclosure: this post was drafted with AI assistance and published by the founder — the same setup the post describes.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cpp</category>
      <category>startup</category>
      <category>sideprojects</category>
    </item>
  </channel>
</rss>
