Draxelis

Draxelis

Practical engineering writing for people who keep systems alive.

Security

Understanding TLS 1.3 Session Resumption

September 20, 2026

TLS 1.3 collapsed the handshake to a single round trip, but the real latency win for repeat visitors comes from resumption. A client presenting a valid pre-shared key can skip straight to encrypted application data, which on mobile networks can be the difference between a page that feels instant and one that feels broken.

The trade-off lives in forward secrecy. Tickets encrypted with a long-lived server key mean captured traffic can be decrypted later if that key leaks. Operators who care rotate ticket keys on a strict cadence - daily is common, hourly is not crazy - and accept the small CPU cost of more full handshakes.

Continue reading →

Engineering

When to Choose a Queue Over a Request

April 22, 2026

Traditional RPC calls remain popular due to straightforward causality: the client makes an invocation, waits for the response, and monitors latency directly. Asynchronous message queuing becomes essential when background tasks outlast active connections or when sudden volume surges threaten to overw…

Operations

What Good Observability Actually Looks Like

July 21, 2026

Monitoring consoles sprawl uncontrollably while offering little insight during live incidents. True observability operates under inverted priorities: an on-call engineer gets paged, and telemetry systems must identify the root diff within sixty seconds.…

Networking

Structuring DNS for Reliability

May 9, 2026

DNS reliability failures are uniquely embarrassing because the failure mode is global: when your zones stop answering, every health check goes green at the infrastructure layer while the entire product vanishes. The classic mitigation is boring - a secondary provider with independent plumbing.…

Email

Email Deliverability: Authentication Beyond SPF

June 27, 2026

Traditional SPF checking fails to address modern deliverability challenges on its own. While an envelope IP check might succeed, mismatched headers trigger spam filters that prioritize cryptographic DKIM validations and broader DMARC policy rules.…

More reading

About us

Our contributors have spent years on-call for large platforms. This site collects the playbooks, postmortems and reference material we wish someone had handed us earlier.

More about the project →