westerweel.work

Mark Westerweel — Platform & DevOps consultant.

I build and fix infrastructure for Dutch organizations that take sovereignty seriously. Kubernetes, Proxmox, ArgoCD, ISO 27001. Open source where possible, own hardware where necessary.

Notes here, RCAs, and pieces on work I’ve put real time into. No hot takes, no AI content marketing, no LinkedIn cross-posts.

Documentation that lies is worse than no documentation

Stale documentation has always been a slow-burning problem, but now that AI agents read that documentation as ground truth, it has become an acute one. How we made documentation ’living’ with an enforceable contract, gates that block unverified changes, and an MCP server that gives agents context with provenance — so they cite instead of guess. From 63 findings to zero. And why this pattern doubles as the foundation for a chatbot on your cluster: talking to the devops colleague who is on holiday, with sources attached.

July 14, 2026 · 8 min · Mark Westerweel

Ricin breaks your model. Not your data.

Why the most popular AI safety test secures the front door while leaving the back door wide open. Output safety and data confidentiality are technically two completely different mechanisms — and conflating them is exactly what’s behind the confusion on the work floor. Here’s how models actually handle your data, and what to arrange instead of the theatre.

June 17, 2026 · 9 min · Mark Westerweel

Curated, shareable skillsets for AI agents

A skill for an AI agent is a markdown file. That’s exactly the problem: anyone can drop one, nobody knows if it’s any good. Here’s how I turn them into a curated, signed, shareable library — and why the point isn’t the skills, it’s the curation.

June 15, 2026 · 4 min · Mark Westerweel

Five config lines against supply-chain attacks (npm + PyPI)

npm yanks malicious versions within 24-48 hours; PyPI quarantines new uploads within hours. A seven-day cooldown — five config lines — turns that window into your defence.

May 18, 2026 · 4 min · Mark Westerweel

Claude Code from your phone — how I built it

An LXC, Tailscale, tmux, and an SSH key per device. Persistent, multi-device, nothing in a black box.

May 17, 2026 · 3 min · Mark Westerweel

First post — why a place of my own

Why I want a place of my own next to GitHub and LinkedIn — and what’ll show up here.

May 14, 2026 · 1 min · Mark Westerweel