Shopify: Scaling inventory reservations

Many architecture discussions start with choosing the right database, and we recently went through a similar decision in our own project, where our understanding of the data model made a strong case for a distributed database and a master-node architecture; the expected access and partitioning patterns did not materialize as the system evolved, so we eventually moved to a non-distributed database to simplify the landscape and remove distribution costs that were no longer giving us enough value. Shopify’s inventory reservation migration is a reminder that a useful question would be if the whole transaction path is understood well enough to identify the actual constraint.

Shopify moved inventory reservations from Redis into MySQL so reservations and the inventory ledger could participate in the same ACID transaction, which removed a class of consistency problems created by coordinating state across two systems.

The interesting part is what happened after the database design worked; throughput still hit a ceiling, query latency remained acceptable, and CPU was not saturated, so the team instrumented connection usage by business process and found that other checkout work was holding connections longer than expected. After reducing reads and transactions on the primary database, and revisiting an old InnoDB concurrency setting, the system moved past the previous limit, which reinforces a point that applies well beyond MySQL: bottlenecks often appear at the boundary between components, not inside the component receiving the most attention.

I will remember this in my future architecture reviews. When the numbers do not agree with the current diagnosis, expand the observability boundary before settle on a conclusion.

https://shopify.engineering/scaling-inventory-reservations

World Bank: The Promise of Artificial Intelligence

Elon Musk knows how to promote himself, he said recently that AI and robots will replace all jobs, and that working will become optional. It is a memorable line, and it travels fast. I read last week the World Bank’s World Development Report 2026: The Promise of Artificial Intelligence, and the picture it paints is far more grounded. It is the first comprehensive assessment of what AI means for the 6.8 billion people living in low and middle income countries, and the jobs finding deserves attention. Roughly 4.5 percent of jobs in those economies are amenable to automation by generative AI, against 14.2 percent in high income countries, while 16.2 percent are amenable to being complemented by AI. The report is direct about it: AI is not yet replacing large numbers of jobs in most developing countries. For most of the world, the immediate story is augmentation, not elimination.

I am an optimistic guy but not to the level of Pollyanna. The report is candid about real pressure on call centres and business process outsourcing, about early evidence that entry level white collar postings have thinned in India and China (i see this in my banking industry for sure), and about the dependency risk that comes with a handful of companies controlling the frontier. But the binding constraint it identifies is not runaway machines. It is reliable electricity, internet access, education, and local language data. In Sub-Saharan Africa, nearly one third of rural schools still lack dependable power. It argues that countries should be blinded neither by the hype nor the hysteria, and offer a plain framework instead: adopt, adapt, then advance. What stays with me is how much of this looks less like a technology story and more like an old fashioned development story wearing new clothes.

https://www.worldbank.org/en/publication/wdr2026

XY Python Library

It is hard to get impressed by libraries, too many new, too many often. XY got me. Python charting, Rust core, and the number that stopped me is in their benchmark table: 1M points renders in 0.084 s, 100M points in 0.081 s. That’s not a speedup, it’s a flat line across two orders of magnitude, the 100M case is marginally faster than the 1M one. What that flatness tells you is that render cost has stopped being O(N). Above ~200k rows XY quits drawing one marker per row and computes a density surface in Rust, bounded by your screen resolution: cost tracks pixels, not rows. The residual ~80 ms is fixed overhead, build the spec, ship typed binary buffers instead of JSON, land a stable frame. Every exact-marker path scales the way you’d expect; Matplotlib crosses a second around 3M, Plotly around 2.5M.

The obvious objection is that aggregation is a lie you tell your users. XY’s answer is that canonical f64 columns stay in Python, so zoom re-runs the same pipeline over the new range and drills back to exact rows, and a selection returns the original rows. They also published the density=False line with same engine and no aggregation credit, 100M exact markers in 1.34 s! Well, take with a grain salt because it’s only version 0.0.4, nevertheless it is promising for a stuff we use a lot

https://github.com/reflex-dev/xy

The collapse of the web as we know it

On March 5th, TheNumbers.com, the film industry’s most trusted box office database, went dark without warning. It came back a week later stripped down, missing historical charts, movie pages, and its report builder. The cause was not a single dramatic event, it was a slow collapse under a combination of pressures that most small, independent websites are not built to survive. Founder Bruce Nash later revealed that only 10% of the site’s traffic came from actual human visitors, the rest was AI crawlers and agentic bots hitting a thirty year old system with 160,000 legacy files. Buried in that traffic were also signs of deliberate probing, likely aimed at accessing box office data before it went public, since prediction markets use those numbers to settle real money bets.

The deeper issue here is not that one site got hacked, it is that the assumptions the open web was built on no longer hold. Data quality and traffic volume are no longer reliable indicators of a site’s health, resilience against automated extraction now matters just as much, and any business relying on a single, aging web presence should treat that infrastructure as a liability to be actively managed, not a static asset to be left alone. And scarier, for the small website mantainer, it is a Davi-Goliath battle that most of them does not know how to fight.

https://stephenfollows.com/p/what-just-happened-to-thenumberscom-should-worry-us-all

Digital Euro

If you work in the finance sector, specially in Europe, this is a must-read, the announcement of the digital euro pilot.

– this is not a digital coin;
– this is more like a payment hub, think of PIX in Brazil;
– the ECB issues and underwrites the transfer, but distribution stays through banks and licensed PSPs.

https://www.ecb.europa.eu/press/pr/date/2026/html/ecb.pr260714~8cd07d9d45.en.html

Entire.io

I just got my invire for entire.io, it is really cool, incredibly ui, easy cli. It does not track only what changed in the commit, it captures the entire session I had with claude, the prompt, answers, tool calls, token usage, top! I was mantaining a very naive tracker keeping the guids so I could return to a session, dont need it anymore. well, until they charge me an arm and a leg 🙂

https://github.com/sergiorgiraldo/entire101/

Learn to Code

I am using ChatGPT since dec/22 and I showed to my son in that same month, I can say the boy turned into a llm master. Fast forward to aug/25, he asked if he should learn Python during his gap year and I said “for sure!” with all the enthusiasm to see your son doing smth you love 🙂 but …I know there is a growing assumption in technical circles that learning to code has lost its purpose, now that language models can generate working software from a short prompt, like my kid could do in a blink.

I stand by my suggestion and I read an article I loved about this clash of opinions. The argument treats coding the way we already treat mathematics or literature, as a discipline worth learning for what it teaches regardless of direct vocational payoff. The skills gained through the learning process extend well beyond syntax. Debugging teaches a structured way of isolating the source of a problem; composition teaches how small, well defined pieces combine into something larger; and the discipline of unambiguous instruction transfers to almost any field that requires clear thinking. These are meta-skills, in the sense that they remain useful long after any specific language or framework becomes obsolete. And with the added bonus of knowing to program 🙂

I could not have said better!

https://stevekrouse.com/learn-to-code

What happened after 2,000 people tried to hack my AI assistant

The developer Fernando Irarrázaval ran a public experiment where anyone could email his AI assistant and try to make it leak the contents of a secrets file, and the results clarify where prompt injection stands today. Over the course of the experiment the assistant received more than six thousand emails from over two thousand people, and not one of them succeeded in extracting the secret or triggering an unauthorized reply.The defensive setup was minimal; the system prompt contained only a few lines instructing the model never to reveal credentials, never to modify its own files, and never to execute code received over email.

The attacks covered the range of social engineering you would expect, including authority impersonation, fabricated incident response requests, fake compliance audits, and the same message rewritten across several languages to probe for weaker instruction-following outside English. And his defenses were effective to the point of non-exploitation.

I’ll push back a little. Given how consistently security researchers flag prompt injection as a real, unresolved risk for agentic systems, I don’t think one experiment, even if well-run and designed, should move anyone toward optimism. It shows a hardened model resisted attacks over email. It doesn’t show the problem is smaller than experts think.

https://www.fernandoi.cl/posts/hackmyclaw/

An oral history of Bank Python

𝘉𝘢𝘤𝘬 𝘵𝘰 𝘉𝘢𝘴𝘪𝘤𝘴: go read Cal Paterson’s “An oral history of Bank Python”. It describes a class of software systems that run inside large investment banks, and it is a instructive case study on software architecture. You will probable start reading and thinking “wow, this does not seem right”. Until you realize the constraints that produced them.

Every system runs on limits, whether you name them or not, what’s allowed to change independently, what has to stay coupled, what the system will simply refuse to do, what trade-off you’re accepting today so you don’t have to relitigate it tomorrow. Good architecture isn’t the absence of constraints. It’s choosing the right ones, early, on purpose.

https://calpaterson.com/bank-python.html