ppll

Kenton Varda

Engineer at Cloudflare who designed Workers, Durable Objects and Cap’n Proto; earlier the primary author of Protocol Buffers v2 at Google, and co-founder of Sandstorm.io.

Who they are on wiqqi

Kenton Varda did not write this page. ppll compiled it from their own words, each linked to the source. Is this you? · Report a mistake

Tell me when they publish

Latest Bluesky

What they believe

The bold line is korrents’ wording; the quote is theirs. These 2: what they wrote before what they said aloud, one per source, newest first.

All 26 beliefs, on korrents

Everything, newest first — across every channel.

Sources

27 September

Kenton VardaBluesky
  • Related

16 September

1 September

28 August

15 August

18 May

Kenton VardaBluesky
  • AI writingRelated

13 April

24 March

Kenton Varda
  • Bluesky

    blog.cloudflare.com

    Related

  • BlogSandboxing AI agents, 100x faster

    startupsAI agentsRelated

12 March

Kenton VardaRecommends
  • Recommendsrcmnd.app

    Money Stuff

    Their words

    here's my understanding, which comes almost entirely from reading Money Stuff, a daily column by Matt Levine. If you are a tech person who wants to learn about finance, I recommend it!

    news.ycombinator.com

18 February

Kenton VardaBluesky
  • youtube.com

    roboticsRelated

8 December 2025

13 November 2025

Kenton VardaBluesky
  • Related

12 November 2025

Kenton VardaBluesky
  • Related

23 October 2025

14 October 2025

Kenton VardaBluesky
  • blog.cloudflare.com

    benchmarksRelated

26 September 2025

Kenton Varda
  • Bluesky

    blog.cloudflare.com

    TypeScriptMCPRelated

  • BlogCode Mode: the better way to use MCP

    LLMsMCPRelated

23 September 2025

Kenton VardaBluesky
  • Related

  • Related

22 September 2025

Kenton Varda

19 September 2025

Kenton VardaBluesky
  • Related

24 July 2025

Kenton VardaBluesky
  • GoogleRelated

7 June 2025

Kenton VardaRecommends
  • Recommendsrcmnd.app

    Claude Code

    Their words

    I really recommend trying it rather than assuming. There's no learning curve, you just install Claude Code and run it in your repo and ask it for things.

    news.ycombinator.com

27 May 2025

Kenton VardaBluesky
  • Related

17 November 2024

Kenton VardaRecommends
  • Lovedrcmnd.app

    Celeste

    Their words

    Played Celeste. The results were very interesting. I didn't exactly perceive latency, but I did perceive that the game felt wrong. As a result, my favorite game of all time was not fun when playing on Stadia.

    news.ycombinator.com

16 November 2024

26 September 2024

Kenton VardaKorrents

From one piece Zero-latency SQLite storage in every Durable Object 2 beliefs · blog.cloudflare.com

5 April 2024

Kenton VardaKorrents

From one piece We've added JavaScript-native RPC to Cloudflare Workers 2 beliefs · blog.cloudflare.com

1 April 2024

Kenton VardaKorrents

From one piece Why Workers environment variables contain live objects 3 beliefs · blog.cloudflare.com

28 September 2023

Kenton VardaRecommends
  • Recommendstheir ownrcmnd.app

    Cloudflare Tunnel

    Their words

    But I definitely would recommend Cloudflare Tunnel or Authenticated Origin Pulls (with per-zone certificates) instead of allowlisting IPs.

    news.ycombinator.com

28 July 2023

Kenton VardaKorrents

From one piece Cap'n Proto 1.0 2 beliefs · capnproto.org

27 September 2022

Kenton VardaKorrents

From one piece Introducing workerd: the Open Source Workers runtime 2 beliefs · blog.cloudflare.com

14 January 2022

19 October 2021

Kenton VardaKorrents

From one piece Backwards-compatibility in Cloudflare Workers 3 beliefs · blog.cloudflare.com

12 October 2021

3 August 2021

17 April 2021

28 September 2020

The whole feed →

Beliefs

  • Korrents What they believe 26 beliefs — each backed by an exact quote.

    Each is a — compiled by korrents.com, not by them: the one-line wordings are korrents', the quotes are theirs.

    Recent

    Show 23 more
    • RPC's reputation as broken is outdated: it was earned in an era of synchronous calls, before promises and async/await.
      RPC is often accused of committing many of the fallacies of distributed computing. But this reputation is outdated. When RPC was first invented some 40 years ago, async programming barely existed. We did not have Promises, much less async and await. Early RPC was synchronous: calls would block the calling thread waiting for a reply. At best, latency made the program slow. At worst, network failures would hang or crash the program. No wonder it was deemed "broken".

      We've added JavaScript-native RPC to Cloudflare Workers Said 5 Apr 2024

      Full record — everyone who holds this →

    • RPC fits how programmers already think, in function calls, which frees them from constantly translating between mental models.
      The fact is, RPC fits the programming model we're used to. Every programmer is trained to think in terms of APIs composed of function calls, not in terms of byte stream protocols nor even REST. Using RPC frees you from the need to constantly translate between mental models, allowing you to move faster.

      We've added JavaScript-native RPC to Cloudflare Workers Said 5 Apr 2024

      Full record — everyone who holds this →

    • An auth key that is just a string can easily be leaked by the service holding it, and there is probably no practical way to tell when it has been.
      Even if you have systems in place to deliver auth keys to services securely (like Workers Secrets), if the key is just a string, the service itself can easily leak it. For instance, a developer might carelessly insert a log statement for debugging which logs the service's configuration – including keys. Now anyone who can access your logs can discover the secret, and there's probably no practical way to tell if such a leak has occurred.

      Why Workers environment variables contain live objects Said 1 Apr 2024

      Full record — everyone who holds this →

    • Connecting a server to a resource should be one step, not two: pointing the server at the resource and separately making the resource accept the server.
      Much of this pain comes about because connecting a server to a resource today involves two steps that should really be one step: Configure the server to point at the resource. Configure the resource to accept requests from the server.

      Why Workers environment variables contain live objects Said 1 Apr 2024

      Full record — everyone who holds this →

    • Designing code to be friendly to dependency injection can seem tedious, and it has been worth it every time.
      Designing code to be DI-friendly sometimes seems tedious, but every time I've done it, I've been incredibly happy that I did.

      Why Workers environment variables contain live objects Said 1 Apr 2024

      Full record — everyone who holds this →

    • Allowing an RPC call to be cancelled is almost always desirable in practice, and disallowing it can lead to subtle problems.
      As discussed above, this is opt-in today, but in practice I find it’s almost always desirable, and disallowing it can lead to subtle problems.

      Cap'n Proto 1.0 Said 28 Jul 2023

      Full record — everyone who holds this →

    • Cap'n Proto should have been declared 1.0 years earlier than it was.
      Frankly, I should have declared 1.0 a long time ago – probably around version 0.6 (in 2017) or maybe even 0.5 (in 2014).

      Cap'n Proto 1.0 Said 28 Jul 2023

      Full record — everyone who holds this →

    • Calling small services "functions" puts too much emphasis on syntax rather than on what the service logically does.
      Some in the industry prefer to call nanoservices "functions", implying that each individual function making up an application could be its own service. I feel, however, that this puts too much emphasis on syntax rather than logical functionality.

      Introducing workerd: the Open Source Workers runtime Said 27 Sept 2022

      Full record — everyone who holds this →

    • If the code that reaches internal services is explicitly different from the code that reaches the public internet, an application cannot be tricked into SSRF.
      First, we can now restrict the global fetch() function to accept only publicly-routable URLs. This makes applications totally immune to SSRF attacks! You cannot trick an application into accessing an internal service unintentionally if the code to access internal services is explicitly different.

      Introducing workerd: the Open Source Workers runtime Said 27 Sept 2022

      Full record — everyone who holds this →

    • On a serverless platform, a runtime upgrade must never break a live application, because developers have no control over when upgrades happen.
      In the old world, if the Node.js maintainers decide to make a breaking change to an obscure API between releases, it's OK. Downstream developers are expected to test their code before upgrading, and address any breakages. But in the serverless world, it's not OK: developers have no control over when upgrades happen, therefore upgrades must never break anything.

      Backwards-compatibility in Cloudflare Workers Said 19 Oct 2021

      Full record — everyone who holds this →

      JavaScript

    • When code passed its tests only because of a bug in the platform underneath, that is the platform's fault, not the developer's.
      But what if the test only worked because of a bug in the underlying platform that caused it to do the right thing by accident? Well, that's the platform's fault. The developer did everything they could: they tested their code thoroughly, and it worked.

      Backwards-compatibility in Cloudflare Workers Said 19 Oct 2021

      Full record — everyone who holds this →

    • Letting customers pin old runtime versions would undo part of the promise of serverless: that developers should not have to worry about updating their stack.
      Second, part of the promise of serverless is that developers shouldn't have to worry about updating their stack. If we start letting people pin old versions, then we have to start telling people how long they are allowed to do so, alerting people about security updates, giving people documentation that differentiates versions, and so on. We don't want developers to have to think about any of that.

      Backwards-compatibility in Cloudflare Workers Said 19 Oct 2021

      Full record — everyone who holds this →

      documentation

    • Concurrency is hard for novices and experts alike: even experts regularly get it wrong.
      Concurrency is hard. It doesn't matter if you're a novice or an expert: even experts regularly get it wrong. It's difficult to think about all the ways that concurrent operations might overlap to corrupt your application state.

      Durable Objects: Easy, Fast, Correct — Choose three Said 3 Aug 2021

      Full record — everyone who holds this →

    • The worst thing an application can do is tell a user their action succeeded when it did not.
      The worst thing an application can do is tell the user that their action was successful when it wasn't. If, for some reason, a write cannot be completed, then it's imperative that the application presents an error to the user, so that the user knows that something is wrong and they'll have to try again or look for a fix.

      Durable Objects: Easy, Fast, Correct — Choose three Said 3 Aug 2021

      Full record — everyone who holds this →

    • Security for a platform that runs other people's code is never finished: hard real-world problems often have no simple fix, only defences built thicker and thicker.
      Popular security culture often dwells on clever hacks and clean fixes. But for the difficult real-world problems, often there is no right answer or simple fix, only the hard work of building defenses thicker and thicker.

      Mitigating Spectre and Other Security Threats: The Cloudflare Workers Security Model Said 29 Jul 2020

      Full record — everyone who holds this →

    • No one has fixed Spectre, not even with heavyweight virtual machines; everyone is still vulnerable.
      A dirty secret that the industry doesn't like to admit: no one has "fixed" Spectre. Not even when using heavyweight virtual machines. Everyone is still vulnerable.

      Mitigating Spectre and Other Security Threats: The Cloudflare Workers Security Model Said 29 Jul 2020

      Full record — everyone who holds this →

    • Many more Spectre vulnerabilities exist than have been published, and a well-funded government agency could be uncovering far more of them than researchers do.
      It is abundantly clear that many more vulnerabilities exist, but haven't yet been publicized. Who might know about those vulnerabilities? Most of the bugs being published are being found by (very smart) graduate students on a shoestring budget. Imagine, for a minute, how many more bugs a well-funded government agency, able to buy the very best talent in the world, could be uncovering.

      Mitigating Spectre and Other Security Threats: The Cloudflare Workers Security Model Said 29 Jul 2020

      Full record — everyone who holds this →

      government

    • V8 is a wider attack surface than a virtual machine, but an extraordinary amount of effort goes into finding and fixing its bugs.
      On one hand, V8 is an extraordinarily complicated piece of technology, creating a wider "attack surface" than virtual machines. More complexity means more opportunities for something to go wrong. On the bright side, though, an extraordinary amount of effort goes into finding and fixing V8 bugs, owing to its position as arguably the most popular sandboxing technology in the world.

      Mitigating Spectre and Other Security Threats: The Cloudflare Workers Security Model Said 29 Jul 2020

      Full record — everyone who holds this →

    • The true dream of cloud computing is code that lives in the network itself and runs everywhere, not in one chosen region.
      We believe the true dream of cloud computing is that your code lives in the network itself. Your code doesn't run in "us-west-4" or "South Central Asia (Mumbai)", it runs everywhere.

      Cloudflare Workers Unleashed Said 13 Mar 2018

      Full record — everyone who holds this →

    • The most important reason to decentralize the web is software and developer diversity, more than privacy, security or data ownership.
      Privacy, security, ownership, and mobility are all important, but I feel there is a much more important goal that is often poorly understood: The most important reason to decentralize is software—and developer—diversity.

      Decentralization is about diversity Said 17 Aug 2016

      Full record — everyone who holds this →

      privacy

    • Decentralizing storage is not enough: software must be delivered as a package each user runs a private copy of, not as a service.
      The only way to solve these problems is by decentralizing the software (not just the storage). Software must be provided as a package – not as a service – with each user running their own private copy.

      Decentralization is about diversity Said 17 Aug 2016

      Full record — everyone who holds this →

    • Software-as-a-service and open source do not make sense together: it is not really open source if users cannot run modified code.
      Software-as-a-Service and open source just don’t make sense together. It’s not really open source if you can’t run modified code, and the high barrier to entry shuts out hobby projects or anything unwilling to be monetized.

      Open Source Web Apps Aren't Viable; Let's Fix That Said 21 Jul 2014

      Full record — everyone who holds this →

      open source

    • Under software-as-a-service, indie development is not viable; for low-budget software to succeed, users must be able to run their own instances at no cost to the developer.
      In today’s popular software-as-a-service model, indie development simply is not viable. People do it anyway, but their software is not accessible to the masses. In order for low-budget software to succeed, and in order for open source to make any sense at all, users must be able to run their own instances of the software, at no cost to the developer.

      Open Source Web Apps Aren't Viable; Let's Fix That Said 21 Jul 2014

      Full record — everyone who holds this →

      open source

    All 26 beliefs →

What is a korrent?

A korrent is a belief a person has stated in their own words: one sentence stating the claim, backed by a quote and a source, kept at korrents.com.

Under a name here, the quoted block is what they actually said. The korrent beneath it is the claim those words support, in korrents' wording — tap it to see the record, its source, and who else holds it.

Nobody here wrote their own korrents. They are compiled from public statements, and a person can change their mind, which is recorded too.

Recommends rcmnd

Where they publish

About the English under a post

Some people here publish in a language other than English. Where they do, this site shows a machine translation beneath the post, in this typeface — the site's own, not theirs.

The post itself is never changed, moved or hidden: what is set in the serif above is exactly what the person published, and it is what to quote them on. A translation can be wrong in ways that matter, especially about tone.

Only the post's own words are translated. A quoted post, a linked article and a belief on korrents.com are left in their original language.