# Ryan Spletzer > Ryan Spletzer's blog on software engineering and technology. Ryan Spletzer is a Distinguished Engineer at Autodesk. This site is his personal blog. All posts are written by Ryan and licensed CC BY 4.0. Every post is a single HTML page at a stable URL of the form `https://www.spletzer.com/YYYY/MM/slug/`. Posts are listed newest first. ## Posts - [Don't Put an LLM Behind an MCP Server](https://www.spletzer.com/2026/07/dont-put-an-llm-behind-an-mcp-server/): MCP took off because it solved a real problem: getting context out of external systems and into your agent. Then people started hiding entire LLMs behind a tool call. It's slow, it's opaque, and it inverts the point of the protocol. Don't do this. - [The Markdown Tamer](https://www.spletzer.com/2026/07/the-markdown-tamer/): AI coding tools are fast, but they emit feral Markdown—300-character lines, mangled lists, headings that skip levels, jagged tables, and more idiosyncrasies that I can't stand. Here are the practices I use to tame it: a linter as the feedback loop, semantic line breaks, and teaching the agent to clean up after itself. - [It's the DevOps Handbook All Over Again](https://www.spletzer.com/2026/06/its-the-devops-handbook-all-over-again/): Gene Kim and Steve Yegge's Vibe Coding makes the case that the DevOps Handbook's teachings—fast flow, fast feedback, discipline—matter more in the AI era, not less. - [How to Disable OTP on Your YubiKey](https://www.spletzer.com/2026/04/how-to-disable-otp-on-your-yubikey/): That mysterious string of characters someone just pasted into Slack? That's a YubiKey's OTP slot firing. Here's how to disable it via the ykman CLI or YubiKey Manager GUI, and why it won't affect FIDO2, OpenPGP, or anything else you actually use. - [A No-Nonsense Guide to GPG Commit Signing with a YubiKey](https://www.spletzer.com/2026/04/a-no-nonsense-guide-to-gpg-commit-signing-with-a-yubikey/): GPG-signed Git commits prove that code actually came from you, and storing your signing key on a YubiKey means the private key never persists on your filesystem. This guide walks through setting it all up on macOS, Windows, and Ubuntu. - [The Time I Accidentally Dropped a Database](https://www.spletzer.com/2026/04/the-time-i-accidentally-dropped-a-database/): A story about accidentally dropping a shared dev database, asking a DBA to revoke my own permissions, and why the principle of least privilege matters more than ever in the age of AI agents. - [Jevons Paradox and the Future of Software Engineering](https://www.spletzer.com/2026/03/jevons-paradox-and-the-future-of-software-engineering/): When things get cheaper, we use more of them, not less. William Stanley Jevons figured this out about coal in 1865. The cloud proved him right. AI will too, and that's good news for software engineers. - [Curating My Own Algorithm](https://www.spletzer.com/2026/03/curating-my-own-algorithm/): A follow-up to my previous post on information diets. This time I get specific about the tools, feeds, and habits that make up my personal approach to cutting through the noise and the slop. - [Shedding Dead Context](https://www.spletzer.com/2026/03/shedding-dead-context/): More plugins, more extensions, more context doesn't mean better results. It often means worse. Your AI's context window is finite memory, and most people are wasting it before they've typed a real prompt. - [A New No-Nonsense Guide to Setting Up Python Environments](https://www.spletzer.com/2026/03/a-new-no-nonsense-guide-to-setting-up-python-environments/): Almost two years ago I wrote a guide to setting up Python environments with pyenv and pyenv-virtualenv, and I reserved the right to change my mind later. uv came along and I'm cashing in that reservation—it's faster, simpler, and finally makes Windows not weird. - [A Tale of Acceleration and Compound Engineering](https://www.spletzer.com/2026/02/a-tale-of-acceleration-and-compound-engineering/): A dev machine setup script practice I carried across jobs for years took me months to modernize with GitHub Copilot last summer. This year, Claude Code wrapped it in CI in ninety minutes and added a new distro in under an hour. The speedup isn't just better models—it's the compounding effect of practices like testing and CI that AI helps you put in place. - [The Angel in the Marble](https://www.spletzer.com/2026/02/the-angel-in-the-marble/): Software has always been a subtractive art—chipping away at possibility until the right shape emerges. AI coding tools gave us faster chisels, but taste is still the thing that separates a statue from a pile of dust. - [Fear, Paranoia, and Vibe Risk Management](https://www.spletzer.com/2026/02/fear-paranoia-and-vibe-risk-management/): Risk-oriented enterprise teams may block AI coding agents (and agents in general) based on fear of the unknown while ignoring fundamental controls that actually reduce blast radius. The real risk isn't the agent—it's the policy friction that lets competitors ship while you debate. - [One Day, Nine Phases, 93% Less CSS](https://www.spletzer.com/2026/02/one-day-nine-phases-93-percent-less-css/): For years my blog ran Bootstrap 3.2.0 despite needing almost none of it. A single day with Claude Code fixed that—and a whole lot more. - [McDonald's, Burger King, and the Innovator's Dilemma](https://www.spletzer.com/2026/02/mcdonalds-burger-king-and-the-innovators-dilemma/): Startups scout ahead, big companies follow. The AI developer tools market is playing out the Innovator's Dilemma in real-time—and we're all just deciding between Quarter Pounders and Whoppers. - [Tidying Your Home for Your AI Guests](https://www.spletzer.com/2026/01/tidying-your-home-for-your-ai-guests/): I want you to imagine the place that you live in. - [Is It Safe to Write a Blog Post That Is Not About AI?](https://www.spletzer.com/2025/12/is-it-safe-to-write-a-blog-post-that-is-not-about-ai/): I have a confession to make... - [Visualizing the OAuth & OpenID Connect Spec Graph](https://www.spletzer.com/2025/11/oidc-oauth-spec-graph/): I created an OpenID Connect and OAuth spec graph in a Mermaid diagram in a GitHub repository. - [Pinocchio is Not a Real Boy](https://www.spletzer.com/2025/09/pinocchio-is-not-a-real-boy/): LLMs didn't make code literacy optional—they raised the bar for what you need to learn so that you can effectively steer these AI assisted tools. - [Ask vs Act: Applying CQRS Principles to AI Agents](https://www.spletzer.com/2025/08/ask-vs-act-applying-cqrs-principles-to-ai-agents/): Asking an AI agent a question is a whole different ballgame from letting it take action. - [MCP is a USB Port, Not a Hard Drive](https://www.spletzer.com/2025/08/mcp-is-a-usb-port-not-a-hard-drive/): Or: why your "just grab every Slack link since 2017" request is going to hurt. - [Your Information Diet in the Age of AI](https://www.spletzer.com/2025/07/your-information-diet-in-the-age-of-ai/): I was on a call with a colleague, walking through some Wardley Maps I'd drawn for various AI tools. Partway through my overview, he stopped me and asked a question I've heard a couple of times before: "How do you find out about these things?" I paused, realizing that the answer has less to do with any magic trick and more to do with habits— essentially, what I choose to read, watch, and listen to on a daily basis. In other words, it comes down to my information diet. - [The Many Contexts of Model Context Protocol](https://www.spletzer.com/2025/05/the-many-contexts-of-model-context-protocol/): Or: why "where" your MCP server runs matters just as much as "what" it does. - [Enterprise Search and the Myth of the Silver Bullet](https://www.spletzer.com/2025/05/enterprise-search-and-the-myth-of-the-silver-bullet/): Enterprise Search has always been a hard problem – one that lacks any "silver bullet" solution. - [Zero to Trusted: SPIFFE and SPIRE, Demystified](https://www.spletzer.com/2025/03/zero-to-trusted-spiffe-and-spire-demystified/): I vividly remember one of the first tasks my engineering manager handed me: figure out how to automate rotating the client_secret for an App Registration in Entra ID (the product formerly known as Azure AD). - [How to Build a Team from Scratch](https://www.spletzer.com/2025/02/how-to-build-a-team-from-scratch/): I have observed several avoidable missteps when people try to build a brand-new engineering team from scratch, and I believe there are a few rules of thumb that can help. - [How to Get Your client_id and client_secret from Entra ID](https://www.spletzer.com/2025/01/how-to-get-your-client-id-and-client-secret-from-entra-id/): Since I am not a scalable replacement for ChatGPT or Google, and because I felt this would be helpful beyond my own company, I felt compelled to write this post due to the sheer volume of questions I get on an almost daily basis about how to get a client_id and client_secret for an app registration from Entra ID (formerly known as Azure AD). - [Running SpinRite on Apple Silicon](https://www.spletzer.com/2024/12/running-spinrite-on-apple-silicon/): I was trying to run SpinRite 6.1 on some drives from an old Drobo 5N NAS that bit the dust a few years back, but I didn't have an x86 machine handy, but after a bit of research I found a very elegant way to do this with QEMU. - [San Diego](https://www.spletzer.com/2024/11/san-diego/): All has been quiet on the blogging front, since life has been busy: on top of my wife and I moving houses in August, as part of the COO Leadership Development Program (LDP) at Autodesk I had the opportunity to travel to Tokyo in May, met with my business challenge team in London in July, and experienced the culmination of our program with a presentation in beautiful San Diego before AU, the Design and Make conference. - [Tokyo](https://www.spletzer.com/2024/06/tokyo/): I would be remiss if I wrote my next blog post without reflecting on a recent amazing and profound experience I had in Tokyo, as part of Autodesk's COO Leadership Development Program. - [A No-Nonsense Guide to Setting Up Python Environments](https://www.spletzer.com/2024/04/a-no-nonsense-guide-to-setting-up-python-environments/): Python has become the lingua franca for developing various AI/ML solutions (and more), but getting started with setting up a proper Python environment can be tricky and involve several hours of research or asking colleagues how they go about it, and many "getting started with Python" guides tend to gloss over these aspects, which is why I hope in this post to give a no-nonsense, guide to setting up Python environments. - [Threading the Needle](https://www.spletzer.com/2024/03/threading-the-needle/): Back in the early part of my career, I found myself thrust into an environment that in retrospect was entirely predicated upon a waterfall design methodology. We would do big design up front, in excruciating detail, often without understanding the implications of what was even feasible, with the usual overruns that would happen in terms of time and money to go along with that. - [I Have No PATs](https://www.spletzer.com/2024/03/i-have-no-pats/): I have pushed the content of this blog post to GitHub Pages with zero use of a personal access token (fine-grained or otherwise) or even an SSH key. How is this possible? - [AI is Frosting on the Data Cake](https://www.spletzer.com/2024/02/ai-is-frosting-on-the-data-cake/): Chefs have a saying: mise en place, or "putting in place." This is a great analogy and philosophy for data in an enterprise as well... - ['Hi'](https://www.spletzer.com/2023/12/hi/): Time and attention and energy are utterly precious and fleeting resources. Following that, there are few things you can do that are more egregiously and flagrantly detrimental to a colleague's time, attention, and energy than DM-ing them with a simple "Hi" or "Hello" with no context, expecting a response from that alone towards something you are seeking to accomplish. - [The Power of the Code Name](https://www.spletzer.com/2023/12/the-power-of-the-code-name/): Whether for your team, or for your product or service, a designated code name provides maximum flexibility in the face of what is an ever-present constant in our lives: change. - [DRY IaC](https://www.spletzer.com/2023/10/dry-iac/): Point solution infrastructure as code (IaC) templates get very tiresome very fast, because they're not reusable. - [Real Vendor Lock-in](https://www.spletzer.com/2023/08/real-vendor-lock-in/): In a previous post, I discussed the topic of vendor lock-in with cloud providers, and why I thought it was over-emphasized. I'd like to further highlight my stance using a real-life example of actual vendor lock-in, which, in my opinion, is more concerning. - [Constraint Driven Development](https://www.spletzer.com/2023/08/constraint-driven-development/): In the last few systems and services I've designed for cloud, I've taken an approach of starting with the limits and working backwards. - [My Themed Terminal Setups and Source Controlling Dotfiles](https://www.spletzer.com/2023/07/my-themed-terminal-setups/): People have been wondering about how I created my themed terminal setups, so I thought I'd make a post about it. - [OpenAI Enterprise Deployment Approaches](https://www.spletzer.com/2023/05/openai-enterprise-deployment-approaches/): I wanted to capture some thoughts on deployment approaches for OpenAI in a large enterprise. - [Connection](https://www.spletzer.com/2023/05/connection/): We are better as people and as organizations when we connect with each other. - [PowerShell + DevOps Global Summit Conference 2023](https://www.spletzer.com/2023/04/powershell-conf/): This week I am at a conference I've admired from afar but have not yet had the chance to go to, until now: the PowerShell + DevOps Global Summit. - [Getting Burned](https://www.spletzer.com/2023/04/getting-burned/): The year was 2013. I was less than one year into my first job, and Google had just released Google Glass. - [Why Not Both?](https://www.spletzer.com/2023/04/why-not-both/): As engineers, we're always in search for the One True Way to accomplish a task, when more often I believe we should be focusing on supported options. - [ChatGPT and the Curious Absence of Marketing](https://www.spletzer.com/2023/03/chat-gpt-marketing-bs/): There are some things that I search in real search engines that have real answers out there, but the top 10 results from Google and Bing are all marketing silliness. - [Vendor Lock-in](https://www.spletzer.com/2023/03/vendor-lock-in/): Do you use an API of any kind? Congratulations, you have vendor lock-in. - [The Return](https://www.spletzer.com/2023/03/the-return/): Getting started is hard. - [Hello World](https://www.spletzer.com/2017/02/hello-world/): This has been a long time coming, but after a few years I finally have a new blog. ## Pages - [About](https://www.spletzer.com/about/): Bio, career history, and areas of interest - [Archive](https://www.spletzer.com/archive/): Every post grouped by year - [Tags](https://www.spletzer.com/tags/): Every post grouped by tag - [Linkfarm](https://www.spletzer.com/linkfarm/): Curated reading list ## Feeds - [RSS](https://www.spletzer.com/feed.xml): Latest 20 posts, RSS 2.0 - [Atom](https://www.spletzer.com/atom.xml): Latest 20 posts, Atom - [Sitemap](https://www.spletzer.com/sitemap.xml): XML sitemap of every indexable page