<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:base="https://s3c.ninja/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    
    <title>s3c.ninja</title>
    <link>https://s3c.ninja/</link>
    <atom:link href="https://s3c.ninja/feed.xml" rel="self" type="application/rss+xml" />
    <description>Security engineering, detection tuning, and other tech dispatches from Pat.</description>
    <language>en</language>
    <item>
      <title>Coding For Fun and For... Learning?</title>
      <link>https://s3c.ninja/posts/2026/08/07/rails-gift-experiment/</link><description>&lt;blockquote&gt;
&lt;p&gt;What happened to the &amp;quot;for profit&amp;quot; part?&lt;/p&gt;
&lt;p&gt;or: Sometimes, it&#39;s interesting to just do things for the sake of doing things, like building a holiday gift shopping tracker.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;While I&#39;m writing this in August 2026, I&#39;m already thinking about how I&#39;ll blink and it&#39;ll be the holiday season once again. Holidays mean gift shopping, and - a worry for me, at least, - not accidentally getting the same thing for a family member as someone else.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This post is &lt;em&gt;not&lt;/em&gt; a product pitch. I&#39;m not about to sell you an app that&#39;s the solution to all your gift-giving-coordination problems. I don&#39;t want to do that. What I &lt;em&gt;want&lt;/em&gt; to convey is that this scenario gave me a perfect opportunity to learn and practice some development skills.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Most of my development focus is usually centered around TypeScript or Python, as these languages are (currently) what&#39;s most useful in my day-to-day. (Not counting infrastructure and container management of my homelab with Docker and Ansible + some gitops). However, there&#39;s a language and framework that - up until this &lt;em&gt;past&lt;/em&gt; holiday season (... yeah, 9 months ago) I hadn&#39;t really thought much about - was an itch I now felt I &lt;s&gt;needed&lt;/s&gt; wanted to scratch.&lt;/p&gt;
&lt;p&gt;Ruby on Rails.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Ruby on Rails (RoR, or just Rails) is a Ruby-based web application framework. It follows the Model-View-Controller (MVC) architectural pattern, meaning there&#39;s an internal way of describing the application data (model), a rendered representation of the application for a user (view), and the logic that connects the two (controller). Rails is not the only framework that makes use of a design like this necessarily, but I found that I appreciate how easily Rails made it to adopt the pattern versus other web frameworks.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;As I mentioned, this is &lt;em&gt;not&lt;/em&gt; a product pitch. I should add, it&#39;s also not a tutorial. That being said, I&#39;ll still mention some commands and actions that I took throughout this project.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The idea was simple - I want to be able to have friends and family sign in to a web app, list if there&#39;s anything in particular that they&#39;d like as a gift, if anything, and then anyone else in a shared group with them can see what they might want, and what others already plan to get them. This way, as long as everyone participates, there&#39;s no gift duplication. (As I write this, I think this is less of a problem than I&#39;ve made it out to be, but once I asked myself the question &amp;quot;could I build this&amp;quot;, I needed to try).&lt;/p&gt;
&lt;p&gt;Getting the boilerplate code generated (with scripts, NOT an LLM, mind you) was quite easy! After installing Ruby and the Rails gem, scaffolding a new project was as simple as: &lt;code&gt;rails new gift-tracker&lt;/code&gt;. Rails&#39; great documentation helped me grasp what the many new files in front of me were: &lt;a href=&quot;https://guides.rubyonrails.org/getting_started.html#directory-structure&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;https://guides.rubyonrails.org/getting_started.html#directory-structure&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Rails also comes with plenty of scripts to get things moving fast:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;adding a database: &lt;code&gt;bin/rails db:create&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;running a local copy of the application for development and testing: &lt;code&gt;bin/dev&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;adding new data types to the model: &lt;code&gt;bin/rails generate model Gift name:string link:string&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In addition to what&#39;s built in with Rails, there&#39;s a great selection of gems to help add functionality - the one I used for authentication, for example, was &lt;a href=&quot;https://github.com/heartcombo/devise&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Devise&lt;/a&gt;. And to avoid an open internet-facing sign-up, I also used &lt;a href=&quot;https://github.com/scambra/devise_invitable&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;DeviseInvitable&lt;/a&gt; to send invitations by email to friends and family to enable them to register, rather than asking them to start the process on their own.&lt;/p&gt;
&lt;p&gt;Because this was a personal project that I had some time to explore, I also took the opportunity to try out &lt;a href=&quot;https://tailwindcss.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Tailwind CSS&lt;/a&gt; for styling the application. I didn&#39;t try to go for the most gorgeous UI possible, but it made adding styles to my views pretty easy without really having to write much CSS (a weak point for me).&lt;/p&gt;
&lt;p&gt;After developing the application, it needed to live somewhere. The quickest way to get it stood up was, magically, already almost ready. When Rails scaffolded the application, it included &lt;code&gt;config/deploy.yml&lt;/code&gt;, which allowed me to specify the server I wanted to deploy the web app to, and the hostname to expect for when I proxied traffic to it. This is the magic of &lt;a href=&quot;https://github.com/basecamp/kamal&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Kamal&lt;/a&gt;, a tool to help build the application in Docker and deploy the image + a proxy to the image wherever you want.&lt;/p&gt;
&lt;p&gt;I wanted to self-host this, so I spun up a VM in my homelab, pointed Kamal at it, and also installed Cloudflared on the VM to tunnel traffic to a domain my family and friends could visit through to the application.&lt;/p&gt;
&lt;p&gt;What I learned:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Rails&#39; &amp;quot;convention over configuration&amp;quot; approach genuinely sped things up - once a model existed, generators and scaffolding handled a lot of the boring parts that might require more manual work in TS or Python in my experience so far.&lt;/li&gt;
&lt;li&gt;Devise (and DeviseInvitable) handled almost all of the auth boilerplate - sessions, invites, and the like&lt;/li&gt;
&lt;li&gt;Tailwind was handy for getting something that looked decent without slowing down iteration - a nice balance for someone (me) who doesn&#39;t love writing CSS&lt;/li&gt;
&lt;li&gt;Kamal supports zero-downtime deploys out of the box, and I could set up a secondary staging environment to test changes before they hit prod&lt;/li&gt;
&lt;li&gt;I want to try more with Rails&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2&gt;tl;dr&lt;/h2&gt;
&lt;p&gt;For the 2025 holiday season, my gift to myself wasn&#39;t a &lt;em&gt;thing&lt;/em&gt;. It was giving Ruby on Rails a try, purely for the fun of learning something new. And it turned out to be a very fun framework to use, mostly because, above all else, it &lt;strong&gt;&lt;strong&gt;just worked&lt;/strong&gt;&lt;/strong&gt;.&lt;/p&gt;
</description><pubDate>Thu, 27 Aug 2026 22:00:00 +0000</pubDate>
      <dc:creator>s3cpat</dc:creator>
      <guid>https://s3c.ninja/posts/2026/08/07/rails-gift-experiment/</guid>
    </item>
    <item>
      <title>Insert Cliche &quot;Hello World&quot; Title Here</title>
      <link>https://s3c.ninja/posts/2023/10/19/hello-world/</link><description>&lt;blockquote&gt;
&lt;p&gt;All tech-oriented blogs must make this joke; it&#39;s required.&lt;/p&gt;
&lt;p&gt;The other required part: &lt;em&gt;opinions are my own.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;I&#39;ve rewritten this blog post in 2026 and updated the static site generation details. tl;dr - I use 11ty and deploy to Cloudflare Pages.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;p&gt;Hello to tech enthusiasts, hobby OR professional devs, and security practitioners out there!&lt;/p&gt;
&lt;p&gt;First, a warm welcome to my corner of the internet. I&#39;m Pat - a blue teamer focused on engineering and automation, a Penn State grad, and an avid learner. I&#39;ve worn multiple hats in the realm of information security across various industries, and now* I&#39;m also donning the writer&#39;s cap.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;*For context, I&#39;ve written blog posts for my employer before; this is my personal blog.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;Everybody Has a Blog (Except You)&lt;/h2&gt;
&lt;p&gt;Especially in the age of AI slop blog and LinkedIn posts, one might wonder, &amp;quot;Why bother trying to write?&amp;quot; The answer is simple: this blog is mine. It isn&#39;t an LLM&#39;s. Posts on this blog are based on my experiences - a challenge faced, a project built, or a curious tangent pursued. I&#39;ve been lucky to learn from countless professionals and human-written blogs. Now, I feel it is time to contribute to that collective knowledge (disclaimer again, on my personal blog this time).&lt;/p&gt;
&lt;h2&gt;What Can You Expect? (or, what do I hope)&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Dives into Security Topics&lt;/strong&gt;: Using Python in defensive security, designing cloud-based SIEM automation workflows, practicing creating or tuning detection rules, setting up lab/test environments...&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Adventures Beyond Security&lt;/strong&gt;: While security is a significant chunk of what I do, I&#39;m also intrigued by the broader landscape of technology. Expect some off-topic tech musings and adventures. For example, check out &lt;a href=&quot;https://jcompanion.app/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;JCompanion&lt;/a&gt;, a project where I started to explore TypeScript and modern web frontend frameworks like React (&lt;a href=&quot;https://github.com/s3cpat/JCompanion&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;code&lt;/a&gt;).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;A Blend of Formal &amp;amp; Casual&lt;/strong&gt;: Not every post here will be a scholarly article.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;How&#39;s This Blog Set Up?&lt;/h2&gt;
&lt;p&gt;For those interested in the technicalities:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Tech&lt;/strong&gt;: TypeScript + Eleventy (11ty) + markdown-it (plus a couple of plugins for Markdown attributes/processing) + Tailwind CSS, all living together in a pnpm workspace (I&#39;m sure this list will either grow or shrink over time, but at the time of writing, this is accurate).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Hosting&lt;/strong&gt;: Cloudflare Pages, deployed via a GitHub Action - every push to &lt;code&gt;main&lt;/code&gt; builds the site and ships it with Wrangler. Pull requests get their own workflow that lints, checks formatting, typechecks, and does a trial build before anything&#39;s allowed to merge.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Theme&lt;/strong&gt;: Minimal Tailwind layout with light and dark mode - it follows your system by default, with a toggle in the nav if you disagree with your OS.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Join Me on This Journey&lt;/h2&gt;
&lt;p&gt;So, here we go - the beginning of what I hope to be at least an interesting, if not genuinely enriching journey. If any of my posts resonate with you or if there&#39;s something you&#39;d like me to explore, feel free to send me a note via:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;blog [at] s3c [dot] ninja&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Your feedback and curiosity will shape this blog as much as my experiences.&lt;/p&gt;
&lt;p&gt;Until next time, happy coding, and stay secure!&lt;/p&gt;
</description><pubDate>Wed, 25 Oct 2023 03:00:00 +0000</pubDate>
      <dc:creator>s3cpat</dc:creator>
      <guid>https://s3c.ninja/posts/2023/10/19/hello-world/</guid>
    </item>
  </channel>
</rss>