$ man about

About

“Be curious. Read widely. Try new things. What people call intelligence just boils down to curiosity.” Aaron Swartz

codestinger builds and shares software, tools and engineering knowledge across security, system integration, automation, cloud and embedded systems. It publishes in-depth articles drawn from real projects and builds tools and applications that others can use. Everything it produces follows the same standard: well engineered, well documented and shared openly.

It is built on one belief: we learn by sharing. So much of what engineers know comes from people who documented their work and gave it away freely. codestinger exists to add to that body of knowledge.

Why “codestinger”#

codestinger takes its approach from the Zen of Python: there should be one obvious way to do it and if the implementation is easy to explain, it may be a good idea. It looks for that clear, simple solution, tests it thoroughly and documents it so the next engineer does not have to solve the same problem again. That is the purpose of codestinger.

“Our deepest fear is not that we are inadequate. Our deepest fear is that we are powerful beyond measure … And as we let our own light shine, we unconsciously give other people permission to do the same.” Marianne Williamson, A Return to Love

About the founder#

I'm Vandyk Fernandes, a software architect and the founder and owner of codestinger. Over more than ten years I have architected many products end to end while remaining a hands-on developer. I design the system, write a significant share of the code, set up the pipelines and infrastructure when DevOps is required and lead the teams that build and operate it.

My work centres on designing systems, integrating them and keeping them secure, performant and compatible. I automate everything that should not need manual effort while keeping the legacy systems that businesses depend on healthy and reliable.

My core languages are Python, Rust and C: Python for speed of delivery, Rust and C where performance, safety or direct hardware access matters. As an electronics engineer by training, I continue to work with hardware, robotics and microcontrollers alongside software. I am also a Certified Ethical Hacker (CEH).

What drives all of this is a love of building. I enjoy developing software most when it becomes a tool that helps others, making someone's work easier, safer or faster: a utility that removes hours of repetitive effort, a simulator that lets a team test before the real equipment is available or a library others can import and trust. Many of those tools start as solutions to a problem in front of me and grow into something colleagues and the wider community can rely on.

Much of what I know came from open-source communities and from the experienced architects and engineers I have had the privilege to learn from, people whose careers spanned fields as demanding as power plants and atomic research. They taught me to treat software with the same discipline as any critical system: clear separation of concerns, loosely coupled and highly cohesive components, well-defined interfaces and designs built for resilience from the start. From them I learned to build modular, reusable software on proven engineering principles while embracing modern paradigms.

Areas of expertise#

  • Information security: security designed in from the architecture onwards, not tested in at the end. I am a Certified Ethical Hacker (CEH) and have trained in the OSCP penetration testing methodology.
    • Vulnerability assessment and penetration testing (VAPT): planning and running assessments, writing VAPT reports with risk ratings and remediation guidance and following fixes through to verification.
    • Web application security: hardening Django, FastAPI and Flask applications against the OWASP Top 10, including authentication and authorisation, session management, CSRF, XSS, SQL injection, security headers and Content Security Policy.
    • Secure development: threat modelling, secure code review and automated static and dynamic testing (SAST and DAST) in CI pipelines.
    • Tooling: Burp Suite, Metasploit, Nmap, Nessus, OpenVAS, Nikto, Acunetix, AppScan and Wireshark.
    • Protection of data and software: encryption, secrets management and tamper detection for deployed applications.
  • Python connectors & integrations: reliable data exchange between ERP, MES, warehouse and serialization systems over SOAP, REST and FTPS, including systems that were never designed to work together. My connectors follow the ISA-95 and GS1 standards (GTIN, SSCC and EPCIS) behind serialization and traceability across the supply chain.
  • Web & desktop applications: web applications and APIs with Django, FastAPI and Flask on the back end and React on the front end, plus desktop applications with PySide6 and Rust with Tauri.
  • Regulatory compliance: designing and delivering systems that meet pharmaceutical serialization and traceability regulations across markets, including the EU Falsified Medicines Directive, Russia's cryptographic marking codes, India's DAVA export reporting and the traceability requirements of China and Brazil. I also build and operate software within HIPAA and SOC 2 security and privacy requirements, where compliance is designed in from the start rather than added at the end.
  • Legacy systems: keeping long-lived systems secure, performant and compatible through patching, upgrades, integration clean-up and step-by-step modernisation that preserves what already works.
  • Automation & DevOps: the full infrastructure lifecycle, from provisioning virtual machines, servers and cloud resources as code with Pulumi to configuration with Ansible, containers with Docker, orchestration with Kubernetes and Nomad, service discovery with Consul and routing with Traefik. This includes the CI/CD pipelines, build runners, monitoring and backups that keep platforms healthy, along with automation that removes repetitive work.
  • Cloud applications: designing and operating cloud-native applications and the platforms they run on, on Azure, AWS and DigitalOcean.
  • Data & analytics: data pipelines, sensor and IoT data, statistical analysis and visualisation with pandas, NumPy and scikit-learn, plus task queues with Celery and RabbitMQ for processing at scale.
  • Simulators & desktop tools: realistic industry simulators that generate the data other systems consume, enabling performance and end-to-end testing long before a platform goes live. I build tools to product quality, not prototype quality.
  • Hardware, robotics & embedded: device driver development, microcontrollers and microprocessors, Arduino and Raspberry Pi systems, sensors and motors, down to the layer where software meets the hardware.
  • Architecture, development & leadership: architecting products from initial design to production, including domain-driven and event-driven applications, contributing code alongside the team and managing the people and delivery that turn designs into working software.

How I work#

I see architecture as much about people as about systems. Before proposing a solution I work closely with the deployers, solution designers, product owners, development teams and clients involved, to understand what each of them needs and where each of us is strong. Then I design features around those people and keep the complexity of the implementation behind an experience that is simple and clear. I have written more about this in Architecture is a people job.

Architecture is my role, but I have never stopped building. When a product needs something complex (a Rust library, a C extension, an encryption scheme or a demanding integration), I often take that heavy lifting on myself and deliver it as a dependable building block the team can build on with confidence.

I would rather fix the potholes in front of people than chase distant stars. Practical improvements that make someone's work easier today matter more to me than grand visions that never arrive. I care deeply about people: how they think, how they feel and what they are going through. I am especially conscious of those who are less fortunate or cannot afford the tools and opportunities many of us take for granted. That is why I value software that is simple, accessible and genuinely useful. It is also why codestinger shares what it builds.

I value curiosity and teams built from very different minds, because the best designs come from that mix. I invest in mentoring, since much of what I know was passed on to me by experienced engineers. And I treat access to production systems and to other people's data as a responsibility, not a privilege: capability should always serve the people who depend on it.

Selected work#

  • Bindery (in development): a local-first writing and publishing application in which any note can become a professionally typeset publication (PDF, book, website or slides). It combines a Rust core, a Tauri desktop shell, a React and TypeScript editor built on CodeMirror 6 and an embedded Typst engine that renders a live, page-accurate preview. Features include a pluggable template system, citations and cross-references, tags, wikilinks and a knowledge graph, accessible tagged-PDF export and git-backed history, with continuous integration on Linux and Windows.
  • High-volume PDF generation: a Python wrapper I designed around Typst as the rendering backend, producing one million PDF pages in approximately 25 minutes for large-scale reporting.
  • Industry simulators: realistic simulators that generate the production data an enterprise platform consumes, used for performance and end-to-end testing (why I simulate first).
  • Security tooling: two generations of an in-house encryption scheme, the second built on AES-GCM and Argon2 (the approach), a password management system for production-line backups and disaster recovery, offline licensing resilient to clock rollback and tamper detection for deployed applications.
  • Rust-based Python libraries: a secure FTPS library for Python 2 servers, built in Rust on rustls and suppaftp with no dependency on OpenSSL. I built it personally so the team could keep working in Python (the full story).

Background#

I chose engineering out of a love for mathematics and studied Electronics and Telecommunication at Goa University, specialising in robotics and digital image processing. Engineering gave me the foundations I still rely on every day: signals and systems, microprocessors, control theory and the habit of reasoning from first principles.

Alongside my studies, computing became my passion. I became an early Linux enthusiast, wrote a blog and taught myself to build websites and applications. Learning that way made me resourceful and self-reliant. It also gave me a lasting love of open-source communities, where so much of that knowledge was shared freely.

The turning point was my final-year project: a pick-and-place robotic arm that sorted objects by colour, size and shape. A Raspberry Pi running Arch Linux handled the image processing (with GNU Octave as a low-cost, open-source alternative to MATLAB) and an Arduino drove the arm. It was my first experience with Python and it shaped the direction of my career, bringing electronics, Linux and software together in a single system.

Publications#

Other university projects included a GSM-based electricity billing system and a gesture and voice controlled wheelchair for people with physical disabilities.

Career#

  • 2014 to 2015, freelance developer. Websites and applications for clients with Python, Django, PHP and WordPress, including hosting on AWS and DigitalOcean and regular security audits.
  • 2015, data scientist. Smart-city data at a Goa start-up: electricity, water, street-lighting and weather sensor data, heat maps of accident-prone zones and Raspberry Pi and Arduino devices for real-time data collection.
  • 2015 to 2017, application developer in Dubai. Web platforms built with Django and Flask: content management, application processing, analytics dashboards, automated PDF reporting and user training.
  • 2017 to 2018, configuration and vision specialist. Serialization systems on pharmaceutical packaging lines: vision inspection, sensor and PLC integration and field support, with on-site training in Limerick, Ireland.
  • 2018 to 2021, consultant. Designing and delivering serialization and traceability connectors between packaging lines, site systems and enterprise platforms such as SAP, following ISA-95 and GS1, with an on-site assignment in Quebec, Canada.
  • 2022 onwards, senior consultant to software architect. Technical subject-matter expert for an integration platform, then technical lead for the tools and infrastructure behind it (GitLab CI/CD, Jenkins, Azure and internal package hosting). Now a software architect.

Along the way I have delivered solutions for pharmaceutical, veterinary, agricultural and beverage manufacturers across Europe, the Americas and Asia-Pacific, including first-of-their-kind integrations in new regions. I have been recognised repeatedly for resolving business-critical customer issues. Today I architect products end to end: I design them, contribute to their development, support DevOps where needed and manage the teams that deliver them.

Certifications#

  • Certified Ethical Hacker (CEH), EC-Council
  • Docker Essentials: A Developer Introduction, IBM
  • Web Application Penetration Testing, Cybrary
  • Offensive Security OSCP (PEN-200) penetration testing training
  • Advanced robotics programmes, including BRAINWAVE (Science Park, Korea) and RoboTryst 2013

The principle I would share with any engineer: curiosity gets you started, but discipline, persistence and the right opportunity are what build a career others can rely on.

Interests#

I am drawn to problems that sit between disciplines: how people think, how systems fail and how well-designed tools change the way people work. Outside of client work, that includes robotics, Arduino and Raspberry Pi prototyping and keeping up with new microcontrollers and chips. Electronics gave me a respect for the layers beneath the code, which is why C and Rust sit alongside Python in my toolkit.

I am always looking for under-served problems that deserve well-crafted software. I write here about what I learn along the way.

Inspiration#

A few people shaped how I think about software, products and the decisions behind them.

Aaron Swartz showed how much one curious person who shares knowledge freely can achieve. His belief that information should be open is the reason codestinger shares what it builds.

Linus Torvalds taught me that simplicity is a matter of taste. Describing good code in his 2016 TED interview, he explained that sometimes you can see a problem in a different way:

“…and rewrite it so that a special case goes away and becomes the normal case.” Linus Torvalds

That idea, together with the Unix philosophy Linux carries forward (small, focused components that do one thing well and work together), guides how I design systems: remove special cases, keep interfaces clean and let the design speak for itself. His well-known reply “Talk is cheap. Show me the code.” is a reminder that working software settles debates better than opinions do. In the same interview he described the kind of engineer I aspire to be:

“I am not a visionary, I’m an engineer. … I’m looking at the ground … I want to fix the pothole that’s right in front of me before I fall in.” Linus Torvalds

Steve Jobs shaped how I think about products and how they move forward. At WWDC in 1997 he put it simply:

“You’ve got to start with the customer experience and work backwards to the technology.” Steve Jobs

Every product decision I make starts from the people who will use it, not from the technology I would like to use. He also reminded us that design is not just appearance:

“Design is not just what it looks like and feels like. Design is how it works.” Steve Jobs

Guido van Rossum, the creator of Python and for many years its “Benevolent Dictator For Life”, built a language around readability. Python’s style guide, PEP 8, credits him with the insight that code is read much more often than it is written. I write code, documentation and designs with the next reader in mind, because that reader is usually a teammate, a customer or my future self.

Nature and the builders before us inspire me just as much: beavers that keep repairing their dams, bears that prepare for the lean season, the logistics behind the pyramids, the margins built into great bridges and the hard lessons of Chernobyl. I have collected these lessons in What pyramids, bridges and beavers teach software architects. Above all, nature's harmony (its restrained palettes, its proportions and the way every form fits its purpose) is the quality I want the systems I design to have.

Guiding principles#

  1. Keep it simple.
  2. Be disciplined.
  3. Envision something excellent, then work hard to build it.
  4. Stay focused.
  5. Pursue balance in every part of life.
  6. Listen more than you speak; speak up when it matters.
  7. Hear every perspective, then form your own judgement.
  8. The best way to learn is to teach.
  9. Progress is a marathon, not a sprint.
  10. Stay true to yourself and take ownership of your path.
  11. Keep a positive environment.
  12. Be patient with yourself.
  13. Take regular breaks, but never stop learning.
  14. Live, inspire and be inspired.

Open source#

I rely on open source every day, so I try to give back where I can. Most of that happens in issue trackers: detailed bug reports with reproductions, diagnosing root causes and testing fixes before they ship. That includes FTPS issues in suppaftp and rustls, packaging and tooling feedback for uv, wheel and Typst plus a long list of reports that kept popular Python libraries installable on the Python 2 systems some businesses still depend on.

For collaboration or enquiries, please use the contact page.