OpenResearch
We build digital products people love to use. Based in Vienna π¦πΉ, Prishtina π½π° & Croatia ππ·.
24/09/2026
Security isn't a feature you add later. It's built in from the start.
Practices that matter:
π Input validation - never trust user input
π Parameterized queries - SQL injection still happens
π« Least privilege - minimal permissions everywhere
π Dependency scanning - known vulnerabilities are free attacks
π Secrets management - not in code, not in env files
π Security logging - know when something's wrong
OWASP Top 10 isn't outdated. The same vulnerabilities persist because the same mistakes persist.
Automated scanning catches known issues. Manual review catches logic flaws.
Security is everyone's responsibility. Not just the security team's.
Regular updates matter. Unpatched systems are easy targets.
What's your security practice?
22/09/2026
Software has a carbon footprint. Every inefficient query, every over-provisioned server, every unnecessary data transfer.
We're thinking more about sustainable engineering:
π± Right-sizing cloud resources (don't over-provision)
β‘ Efficient code that does more with less
π Caching to reduce redundant computation
π Monitoring to catch waste
π Choosing green cloud regions when possible
It's not just about the environment. Efficient systems are also cheaper to run.
The cloud makes scaling easy. That's also made waste easy. Time to be more intentional.
Small optimizations add up across millions of users and billions of requests.
Is sustainability on your engineering team's radar?
17/09/2026
Development without process is chaos. Too much process is paralysis.
What actually helps:
π Clear priorities - know what matters most
π² Small work items - easier to estimate, easier to complete
π Visible progress - boards everyone can see
π Regular check-ins - short, focused, actionable
π Written requirements - assumptions become visible
Agile isn't the ceremonies. It's the principles. Responding to change. Working software. Collaboration.
Estimates are guesses. Acknowledge uncertainty. Ranges beat point estimates.
Technical debt is a project management concern. Make it visible. Budget time for it.
The best process is the one your team actually follows.
How does your team manage work?
15/09/2026
What if every deployment was just a Git merge?
That's the promise of GitOps, and it works.
How GitOps changes operations:
π Infrastructure and app config in Git
π Automatic sync to cluster state
π Audit trail for every change
π Rollback is just git revert
π₯ Developers don't need cluster access
We've spoken at DevFest Vienna about our GitOps journey. The learning curve is real, but the operational stability is worth it.
Tools like ArgoCD and Flux make this practical. Combined with Terraform for infrastructure, you get a fully declarative, version-controlled system.
No more kubectl apply from laptops. No more wondering what's running in production.
Is your team exploring GitOps?
10/09/2026
You can't fix what you can't see. Observability makes problems visible.
The three pillars:
π Metrics - quantitative measurements over time
π Logs - detailed event records
π Traces - request paths through systems
Open source tools that work together:
β‘ Prometheus for metrics collection
π Grafana for visualization
π Loki for log aggregation
π Jaeger or Zipkin for distributed tracing
Structured logging changes everything. JSON logs are queryable. Correlation IDs connect related events.
Alert on symptoms, not causes. High error rates matter more than CPU spikes.
Dashboards for humans. Alerts for incidents. Both need maintenance.
Observability is an investment that pays off during incidents.
What's your observability stack?
08/09/2026
Code review has a bad reputation in some teams. It shouldn't.
Done right, code review is the highest-leverage activity for improving team capability.
How we approach code reviews:
π Focus on understanding, not judging
π‘ Suggest, don't command
π Explain the "why" behind feedback
π Treat it as mutual learning
β±οΈ Review promptly: blocked PRs slow everyone
The best code reviews leave both parties smarter. The reviewer learns about the change. The author learns new perspectives.
We've found that constructive code review culture is one of the biggest factors in team growth.
What's your team's code review culture like?
03/09/2026
Redis is often added as a cache. Then you discover what else it can do.
Use cases beyond caching:
π Leaderboards - sorted sets make ranking trivial
π Pub/Sub - real-time notifications
π Task queues - lists with blocking pops
πΊοΈ Geospatial - location-based queries
π’ Rate limiting - atomic increments with TTL
π Time series - with Redis TimeSeries module
Each data structure solves specific problems elegantly. Sorted sets for ranking. HyperLogLog for cardinality. Streams for event logs.
Redis Cluster scales horizontally. Redis Sentinel provides high availability.
The speed is remarkable. Sub-millisecond latency for most operations.
Before adding another database, check if Redis already solves the problem.
What's your favorite Redis use case beyond caching?
01/09/2026
Summer's winding down. Teams are back at full capacity.
There's a certain energy in September, almost like a second January. A fresh start feeling.
It's the perfect time to ask:
π What's been sitting in your backlog all summer?
π§ Which technical debt have you been avoiding?
π― What ambitious goal could you achieve by year-end?
π₯ Does your team have the capacity to make it happen?
September through November is often the most productive period of the year. The holidays haven't hit yet, teams are focused, and there's still time to finish something meaningful.
Don't waste this momentum.
What's the one thing you want to ship before the year ends?
27/08/2026
API Gateways sit at the edge. They handle cross-cutting concerns so your services don't have to.
What gateways provide:
π¦ Routing - direct requests to the right service
π Authentication - verify identity once
β‘ Rate limiting - protect backend services
π Observability - centralized logging and metrics
π Protocol translation - REST to gRPC, etc.
Gateway options: Kong, NGINX, AWS API Gateway, Azure API Management. Cloud-native or self-hosted - both work.
Keep gateways thin. Business logic belongs in services. Gateways handle infrastructure concerns.
Gateway failures affect everything. Design for resilience. Consider multiple gateways for different clients.
The right abstraction simplifies both client and service development.
How do you handle API gateway concerns?
25/08/2026
Microservices are not automatically better than monoliths.
There. We said it. Now let's talk about when each actually makes sense.
We've built both. Here's when each makes sense:
**Microservices work when:**
π Different components need independent scaling
π₯ Multiple teams need to deploy independently
π You're at a scale where monolith coupling hurts
**Monoliths work when:**
π You're moving fast and need simplicity
π€ Small team, clear ownership
π Traffic patterns don't require differential scaling
The worst outcome? A distributed monolith: all the complexity of microservices with none of the benefits.
Start simple. Split when you have a real reason. Every boundary you add is a boundary you maintain.
What's been your experience with microservices?
Klicken Sie hier, um Ihren Gesponserten Eintrag zu erhalten.
Kategorie
Service kontaktieren
Telefon
Webseite
Adresse
Biberstrasse 9/10
Wien
1010
Γffnungszeiten
| Montag | 09:00 - 18:00 |
| Dienstag | 09:00 - 18:00 |
| Mittwoch | 09:00 - 18:00 |
| Donnerstag | 09:00 - 18:00 |
| Freitag | 09:00 - 18:00 |