惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Troy Hunt's Blog
Blog — PlanetScale
Blog — PlanetScale
Engineering at Meta
Engineering at Meta
F
Full Disclosure
Recorded Future
Recorded Future
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
博客园_首页
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Recent Commits to openclaw:main
Recent Commits to openclaw:main
H
Hacker News: Front Page
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 司徒正美
Webroot Blog
Webroot Blog
Google DeepMind News
Google DeepMind News
Help Net Security
Help Net Security
Cloudbric
Cloudbric
PCI Perspectives
PCI Perspectives
有赞技术团队
有赞技术团队
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
TaoSecurity Blog
TaoSecurity Blog
L
Lohrmann on Cybersecurity
量子位
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tailwind CSS Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
B
Blog RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
N
News and Events Feed by Topic
罗磊的独立博客
T
Threat Research - Cisco Blogs
Schneier on Security
Schneier on Security
T
Tor Project blog
IT之家
IT之家
M
MIT News - Artificial intelligence
S
Security @ Cisco Blogs
O
OpenAI News
AI
AI
S
Securelist
Simon Willison's Weblog
Simon Willison's Weblog
The Last Watchdog
The Last Watchdog
月光博客
月光博客
Security Archives - TechRepublic
Security Archives - TechRepublic
L
LINUX DO - 热门话题

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
28% glue code, a CI rule to keep it from growing
Michel Faure · 2026-04-30 · via DEV Community

Comic strip — Étienne, the majority-stakeholder partner from M&A software, reads Michel's metrics report and lands the Sculley punchline:

The day lib/ stopped being readable

One Sunday afternoon, I run ls lib/ in Rembrandt, the ERP I've been coding alone for L'Atelier Palissy for a month. A month ago, when I started, lib/ fit in one MacBook screen. I could scan the names at a glance and know what each one did. That Sunday, I count forty-one. Thirteen are adapters to third-party services — Supabase, Gmail, Brevo, Slack, Stripe, Meta CAPI, QStash, Push, PennyLane — and each one is between 120 and 260 lines of honest plumbing. Nothing crashes, everything works. And yet the folder that used to invite a reading now asks me to scroll.

I realize that every new integration I asked Claude Code for crystallized into an adapter file of this size, because an adapter is easy to generate: clear signature, no business invariant to protect, no test to write. My agent did exactly what I asked, every time, and through daily sedimentation it produced the kind of codebase that Sculley and his Google co-authors described in 2015 as ending up, in pathological systems, as 95% glue code for 5% business logic.

A few weeks ago, Gaspard — our long-time IT contractor — dropped by the office for a reason that escapes me today. I showed him an early lib/ on screen, proud of the progress. He scrolled for three seconds without sitting down, and said without looking up: « C'est de la plomberie, ça. »That's plumbing, right there. I nodded the way you nod at a technical remark you don't quite understand yet, assuming he meant a detail. Six weeks later I understand that he had just named, in two words, what Sculley and the technical-debt literature have been trying to articulate for ten years.


If you have 30 seconds. Glue code (adapters, format conversions, plumbing to external APIs) proliferates silently when you code fast, and even faster when you code with an LLM that happily produces adapters. The countermeasure: measure the glue/business ratio in lib/ with a 130-line script, and hook the CI to non-regression rather than an absolute threshold. This article gives the script, the CI pattern, and why non-regression beats a cap. Useful if you run a codebase that talks to many external services.

The framing I missed for three weeks

The paper Hidden Technical Debt in Machine Learning Systems (Sculley et al., NIPS 2015) describes a particular debt in ML systems: the code useful to the model is a tiny box at the center of a large plumbing ecosystem — data ingestion, normalization, serving, monitoring. The typical ratio they observe in production, 5/95. The authors don't claim glue is bad in itself; they claim that when it isn't named, it gets paid in hidden costs: every refactor becomes acrobatic, every migration is negotiated with ten files that shouldn't be concerned.

The framing is ML but the form extends far beyond. As soon as a system talks to five or six external services, it produces glue. A vertical ERP with six third-party integrations is structurally condemned to manufacture it, and the risk isn't that there is some — there will be — but that it gets counted as business code in the developer's mental equation. The day I reread lib/supabase-paginate.ts thinking it's a business brick, I've lost. It's an adapter, it must remain an adapter, it must be named as such, and its volume must enter a metric whose curve is entitled to worry me.

Nine years before Sculley, Moseley and Marks had laid down in Out of the Tar Pit (2006) the founding distinction that gives the problem its grid: essential complexity, which comes from the business, and accidental complexity, which comes from the technical solution chosen. Glue, in this grid, is accidental complexity in its purest form. It serves no business requirement; it only solves the fact that two systems don't speak the same language. It's this asymmetry — essential is paid once, accidental is paid at every reading, every refactor, every migration — that explains why glue becomes dangerous well before it becomes dominant.

The script, one hundred and thirty lines

I wrote scripts/glue-ratio.sh one afternoon, a bit against myself. Two hardcoded lists: the lib/*.ts files that are glue, and the ones that are business logic. Every new file I add must be consciously classified into one of the two. Nothing is automatic, and that's the only way every addition decision is a named decision.

GLUE_FILES=(
  "lib/supabase.ts" "lib/supabase-admin.ts" "lib/supabase-server.ts"
  "lib/supabase-paginate.ts" "lib/gmail.ts" "lib/gmail-api.ts"
  "lib/brevo.ts" "lib/slack.ts" "lib/stripe.ts"
  "lib/meta-capi.ts" "lib/pennylane.ts" "lib/qstash.ts"
  "lib/push.ts" "lib/rate-limit.ts" "lib/cache.ts"
  "lib/webhook-idempotency.ts" "lib/wordpress.ts" "lib/utils.ts"
  "lib/database.types.ts"
)

BUSINESS_FILES=(
  "lib/rembrandt.ts" "lib/rembrandt-tool-defs.ts"
  "lib/rembrandt-tool-handlers.ts" "lib/lead-pipeline.ts"
  "lib/email-outbox.ts" "lib/email-templates.ts"
  "lib/permissions.ts" "lib/contacts.ts"
  "lib/calendrier.ts" "lib/segments.ts"
)

Enter fullscreen mode Exit fullscreen mode

The rest of the script sums lines, computes two percentages (global, and excluding database.types.ts), and prints a short verdict. The --metric mode only outputs the types-excluded ratio, designed to be compared in CI.

The auto-generated types trap

lib/database.types.ts is a file auto-generated by Supabase from the schema. It weighs over twenty thousand lines in Rembrandt, and since it is entirely glue (TypeScript definitions of tables, nothing business), it tips the global ratio above 60% if counted. That would be accurate, and useless, because no one makes a decision by rereading that file. The rule I eventually settled on: the reference ratio is excluding database.types.ts. The script exposes both figures — global for the record, types-excluded to steer by. Current repo ratio: 28% excluding types on main. Target I set myself: under 25% durably.

glue/business ratio — lib/
==========================
  Glue:     22,183 lines (64%)
  Business: 12,487 lines (36%)
  Total:    34,670 lines

  (excluding database.types.ts: 2,183 glue / 14,670 total = 28%)

  OK: glue excl. types below 30% alert threshold (target 25%)

Enter fullscreen mode Exit fullscreen mode

The CI that blocks regression, not an absolute

Here's the choice that took me time to make, and that matters more than the script itself. CI guardrails are often written with an absolute threshold: if (glue > 30%) fail. It's seductive because it's simple, and it's a bad idea. A mature project at 35% glue that holds can be perfectly healthy. A project at 18% rising to 22% in a week is drifting. The absolute threshold doesn't see the drift, it only sees the arrival.

I hooked the CI to non-regression between HEAD and origin/main, with a tolerance of zero points. Any PR that raises the ratio above main fails, and the message asks the real question: "are you adding business logic that justifies more plumbing, or are you adding an adapter that nobody asked for?". If the former, you add business alongside, the ratio drops, the PR passes. If the latter, you look to extract, to share, to rename.

# scripts/glue-ratio-check.sh (excerpt)
current=$(bash scripts/glue-ratio.sh --metric)

tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT
mkdir -p "$tmp/scripts"
cp scripts/glue-ratio.sh "$tmp/scripts/"
git archive "$BASE_REF" lib/ | tar -x -C "$tmp"

base=$(cd "$tmp" && bash scripts/glue-ratio.sh --metric)
delta=$((current - base))

if [ "$delta" -gt "$TOLERANCE" ]; then
  echo "FAIL: glue ratio increased by ${delta} pts (tolerance +${TOLERANCE})."
  echo "Check if glue can be extracted into lib/mappings/ or lib/adapters/,"
  echo "or if a new file is miscategorized in scripts/glue-ratio.sh."
  exit 1
fi

Enter fullscreen mode Exit fullscreen mode

A secondary safety net, for pathological cases: above 40%, the script enters alert mode in the human output, which forces a team debate even if non-regression passes. But it's a net, not the main metric.

Why a rule written in CLAUDE.md isn't enough

I had first written a rule in my CLAUDE.md, phrased roughly as "prefer business logic over adapters, keep lib/ thin". That rule prevented nothing. It stood against no fact, and an adapter that seems necessary in the moment always wins against an abstract sentence read at the top of a constraints file. A numerical metric, on the other hand, pushes a material fact at the writer's head: +3 points on this PR. The debate becomes concrete, the rule becomes opposable, and the writer — human or LLM — becomes aware of what they are doing. That's exactly what the CLAUDE.md cannot produce as long as it remains text.

There's a lesson here that goes beyond the metric itself. Disciplines that hold all have a number the machine computes for you. Not an intention, not a principle, not a wish — a number. The rest erodes at the pace of developer fatigue and agent complacency.

What you can copy into your project

Both scripts and a CI workflow example live in the companion repo, MIT license: github.com/michelfaure/rembrandt-samples.

Four directly applicable moves if your codebase has many external integrations:

  1. Maintain two hardcoded lists in a shell script, glue and business, and force every new addition to be classified into one or the other. No automatic detection — the friction is the point
  2. Exclude auto-generated files from the denominator. Expose them as a global figure for the record, but steer on the types-excluded ratio
  3. Hook the CI to non-regression, not an absolute threshold. Zero-point tolerance, message that asks the real question of the PR writer
  4. Secondary safety net at 40% for pathological cases, but it's a net, not the rule

And a broader discipline: anything that isn't measured drifts. A rule in a constraints file is read, then forgotten; a numerical metric that blocks a PR is bypassed consciously or not, but it is seen. LLMs are no exception to this rule — they make it more urgent, because they produce faster what they aren't asked to moderate.

And you — which metrics actually drive your PRs, and which have stayed as intentions? I read the comments.


Companion code: rembrandt-samples/glue-ratio/ — the measurement script, the non-regression CI gate, and the GitHub Actions workflow, MIT, copy-pastable.