OpenResearch

OpenResearch

Teilen

We build digital products people love to use. Based in Vienna πŸ‡¦πŸ‡Ή, Prishtina πŸ‡½πŸ‡° & Croatia πŸ‡­πŸ‡·.

24/09/2026

Security isn't a feature you add later. It's built in from the start.

Practices that matter:

πŸ” Input validation - never trust user input
πŸ”’ Parameterized queries - SQL injection still happens
🎫 Least privilege - minimal permissions everywhere
πŸ“‹ Dependency scanning - known vulnerabilities are free attacks
πŸ”„ Secrets management - not in code, not in env files
πŸ“Š Security logging - know when something's wrong

OWASP Top 10 isn't outdated. The same vulnerabilities persist because the same mistakes persist.

Automated scanning catches known issues. Manual review catches logic flaws.

Security is everyone's responsibility. Not just the security team's.

Regular updates matter. Unpatched systems are easy targets.

What's your security practice?

22/09/2026

Software has a carbon footprint. Every inefficient query, every over-provisioned server, every unnecessary data transfer.

We're thinking more about sustainable engineering:

🌱 Right-sizing cloud resources (don't over-provision)
⚑ Efficient code that does more with less
πŸ”„ Caching to reduce redundant computation
πŸ“Š Monitoring to catch waste
🌍 Choosing green cloud regions when possible

It's not just about the environment. Efficient systems are also cheaper to run.

The cloud makes scaling easy. That's also made waste easy. Time to be more intentional.

Small optimizations add up across millions of users and billions of requests.

Is sustainability on your engineering team's radar?

17/09/2026

Development without process is chaos. Too much process is paralysis.

What actually helps:

πŸ“‹ Clear priorities - know what matters most
πŸ”² Small work items - easier to estimate, easier to complete
πŸ“Š Visible progress - boards everyone can see
πŸ”„ Regular check-ins - short, focused, actionable
πŸ“ Written requirements - assumptions become visible

Agile isn't the ceremonies. It's the principles. Responding to change. Working software. Collaboration.

Estimates are guesses. Acknowledge uncertainty. Ranges beat point estimates.

Technical debt is a project management concern. Make it visible. Budget time for it.

The best process is the one your team actually follows.

How does your team manage work?

15/09/2026

What if every deployment was just a Git merge?

That's the promise of GitOps, and it works.

How GitOps changes operations:

πŸ“ Infrastructure and app config in Git
πŸ”„ Automatic sync to cluster state
πŸ“‹ Audit trail for every change
πŸ”™ Rollback is just git revert
πŸ‘₯ Developers don't need cluster access

We've spoken at DevFest Vienna about our GitOps journey. The learning curve is real, but the operational stability is worth it.

Tools like ArgoCD and Flux make this practical. Combined with Terraform for infrastructure, you get a fully declarative, version-controlled system.

No more kubectl apply from laptops. No more wondering what's running in production.

Is your team exploring GitOps?

10/09/2026

You can't fix what you can't see. Observability makes problems visible.

The three pillars:

πŸ“Š Metrics - quantitative measurements over time
πŸ“ Logs - detailed event records
πŸ”— Traces - request paths through systems

Open source tools that work together:

⚑ Prometheus for metrics collection
πŸ“ˆ Grafana for visualization
πŸ“‹ Loki for log aggregation
πŸ” Jaeger or Zipkin for distributed tracing

Structured logging changes everything. JSON logs are queryable. Correlation IDs connect related events.

Alert on symptoms, not causes. High error rates matter more than CPU spikes.

Dashboards for humans. Alerts for incidents. Both need maintenance.

Observability is an investment that pays off during incidents.

What's your observability stack?

08/09/2026

Code review has a bad reputation in some teams. It shouldn't.

Done right, code review is the highest-leverage activity for improving team capability.

How we approach code reviews:

πŸ‘€ Focus on understanding, not judging
πŸ’‘ Suggest, don't command
πŸ“š Explain the "why" behind feedback
πŸŽ“ Treat it as mutual learning
⏱️ Review promptly: blocked PRs slow everyone

The best code reviews leave both parties smarter. The reviewer learns about the change. The author learns new perspectives.

We've found that constructive code review culture is one of the biggest factors in team growth.

What's your team's code review culture like?

03/09/2026

Redis is often added as a cache. Then you discover what else it can do.

Use cases beyond caching:

πŸ“Š Leaderboards - sorted sets make ranking trivial
πŸ”” Pub/Sub - real-time notifications
πŸ“‹ Task queues - lists with blocking pops
πŸ—ΊοΈ Geospatial - location-based queries
πŸ”’ Rate limiting - atomic increments with TTL
πŸ“ˆ Time series - with Redis TimeSeries module

Each data structure solves specific problems elegantly. Sorted sets for ranking. HyperLogLog for cardinality. Streams for event logs.

Redis Cluster scales horizontally. Redis Sentinel provides high availability.

The speed is remarkable. Sub-millisecond latency for most operations.

Before adding another database, check if Redis already solves the problem.

What's your favorite Redis use case beyond caching?

01/09/2026

Summer's winding down. Teams are back at full capacity.

There's a certain energy in September, almost like a second January. A fresh start feeling.

It's the perfect time to ask:

πŸ“‹ What's been sitting in your backlog all summer?
🚧 Which technical debt have you been avoiding?
🎯 What ambitious goal could you achieve by year-end?
πŸ‘₯ Does your team have the capacity to make it happen?

September through November is often the most productive period of the year. The holidays haven't hit yet, teams are focused, and there's still time to finish something meaningful.

Don't waste this momentum.

What's the one thing you want to ship before the year ends?

27/08/2026

API Gateways sit at the edge. They handle cross-cutting concerns so your services don't have to.

What gateways provide:

🚦 Routing - direct requests to the right service
πŸ” Authentication - verify identity once
⚑ Rate limiting - protect backend services
πŸ“Š Observability - centralized logging and metrics
πŸ”„ Protocol translation - REST to gRPC, etc.

Gateway options: Kong, NGINX, AWS API Gateway, Azure API Management. Cloud-native or self-hosted - both work.

Keep gateways thin. Business logic belongs in services. Gateways handle infrastructure concerns.

Gateway failures affect everything. Design for resilience. Consider multiple gateways for different clients.

The right abstraction simplifies both client and service development.

How do you handle API gateway concerns?

25/08/2026

Microservices are not automatically better than monoliths.

There. We said it. Now let's talk about when each actually makes sense.

We've built both. Here's when each makes sense:

**Microservices work when:**
πŸ”„ Different components need independent scaling
πŸ‘₯ Multiple teams need to deploy independently
πŸ“ˆ You're at a scale where monolith coupling hurts

**Monoliths work when:**
πŸƒ You're moving fast and need simplicity
πŸ‘€ Small team, clear ownership
πŸ“Š Traffic patterns don't require differential scaling

The worst outcome? A distributed monolith: all the complexity of microservices with none of the benefits.

Start simple. Split when you have a real reason. Every boundary you add is a boundary you maintain.

What's been your experience with microservices?

Wollen Sie Ihr Service zum Top-Computer- Und Elektronikservice in Wien machen?
Klicken Sie hier, um Ihren Gesponserten Eintrag zu erhalten.

Telefon

Adresse


Biberstrasse 9/10
Wien
1010

Γ–ffnungszeiten

Montag 09:00 - 18:00
Dienstag 09:00 - 18:00
Mittwoch 09:00 - 18:00
Donnerstag 09:00 - 18:00
Freitag 09:00 - 18:00