# Arthur Silva (ARXDSILVA)

> Senior Principal Engineer at Questrade, working on crypto trading. Writing on Golang, distributed systems, PostgreSQL, and engineering career growth. Maintainer of pREST, an open-source Go REST API and MCP server for PostgreSQL. Open to fractional CTO conversations.

## About
- Bio: https://arxdsilva.com/bio
- Schedule a call: https://arxdsilva.com/schedule
- Full post text: https://arxdsilva.com/llms-full.txt (each post is also available as Markdown at https://arxdsilva.com/blog/<slug>.md)
- Feed: https://arxdsilva.com/feed.xml

## Staff Engineer guide
- [What is a Staff Software Engineer?](https://arxdsilva.com/blog/what-is-staff-software-engineer): What a Staff Software Engineer does: cross-team technical leadership on the IC track, when companies need one, and how it differs from Senior.
- [Who is a Staff Software Engineer? Understanding the Person Behind the Title](https://arxdsilva.com/blog/who-is-staff-software-engineer): Beyond the job description: the characteristics, traits, and career patterns of successful Staff Software Engineers in the tech industry.
- [Which Level is Staff Software Engineer? Understanding Engineering Levels](https://arxdsilva.com/blog/which-level-is-staff-software-engineer): Software engineer levels explained: junior to staff, principal and distinguished, how Google, Meta and Amazon map them, and how long each step takes.
- [Staff Software Engineer vs Senior Software Engineer: Key Differences](https://arxdsilva.com/blog/staff-vs-senior-software-engineer): Staff engineer vs senior engineer: the difference in scope, autonomy, day-to-day work, pay and influence, and how to know if you are ready to move up.
- [How to Become a Staff Software Engineer](https://arxdsilva.com/blog/how-to-become-staff-software-engineer): How to become a staff engineer: the skills, cross-team projects and visibility that get you promoted, a realistic timeline, and what stalls seniors.
- [Staff Engineer Interview: The Four Rounds and What Interviewers Actually Score](https://arxdsilva.com/blog/staff-engineer-interview-four-rounds): A Staff engineer interview has four rounds: coding, system design, behavioral and a project retrospective. What panels score, and how strong Seniors fail.
- [Staff vs Principal vs Distinguished Engineer: How the Titles Map Across Companies](https://arxdsilva.com/blog/staff-vs-principal-vs-distinguished-engineer): Staff, Principal and Distinguished are the IC rungs above Senior, but the same word means different scopes at Google, Amazon, Microsoft and a startup.

## First developer job guide
- [University to First Developer Job: A 12-Week Roadmap](https://arxdsilva.com/blog/university-to-first-developer-job-12-week-roadmap): A 12-week roadmap from university to your first developer job: pick a lane, build two portfolio projects, fix your resume, apply and prep interviews.
- [No Internship? How to Land Your First Developer Job Anyway](https://arxdsilva.com/blog/no-internship-first-developer-job-playbook): How to get your first developer job with no internship: proof of work that replaces internships, a 30-day plan, resume framing and where to apply first.
- [Junior Backend Portfolio That Gets Interviews (Not Just Likes)](https://arxdsilva.com/blog/junior-backend-portfolio-that-gets-interviews): Junior backend developer portfolio projects that get interviews: an auth API, a job queue and a rate-limited API, plus the README and architecture notes.
- [GitHub Profile Optimization for Your First Developer Job](https://arxdsilva.com/blog/github-profile-for-first-developer-job): How to set up a GitHub profile that gets you a first developer job: profile README, which three repos to pin, what hiring engineers check, common mistakes.
- [Junior Developer Resume Teardown: What Gets Interviews in 2026](https://arxdsilva.com/blog/junior-developer-resume-teardown): Junior developer resume teardown with before and after examples: the bullet formula, what to include and cut, and what recruiters scan for in 20 seconds.
- [Your First 50 Developer Applications: A System That Actually Works](https://arxdsilva.com/blog/first-50-developer-applications-system): How many applications it takes to get a junior developer job, realistic response-rate benchmarks, and a 50-application system to track and improve odds.
- [How to Ask for Developer Referrals Without Sounding Awkward](https://arxdsilva.com/blog/how-to-ask-for-developer-referrals): How to ask for a job referral as a junior developer: copy-paste scripts, a 60-second personalization framework, follow-up timing and what to do after a no.
- [How to Pass Software Engineering Take-Home Assignments](https://arxdsilva.com/blog/pass-software-engineering-take-home-assignments): How to pass a take-home coding assignment: what reviewers score, a 5-step workflow, a timeboxing template and the submission checklist that gets a yes.
- [First Developer Interview Prep Pack: 2-Week Plan](https://arxdsilva.com/blog/first-developer-interview-prep-pack): A 2-week junior developer interview prep plan: coding fundamentals, portfolio deep-dives, API and system basics, behavioral stories and a day-of checklist.
- [International Student to First Developer Job in Canada: Practical Playbook](https://arxdsilva.com/blog/international-student-first-developer-job-canada): How international students in Canada land a first developer job: stating work eligibility, building local signal fast, weekly networking, interview prep.
- [First 90 Days as a Junior Developer: What to Focus On](https://arxdsilva.com/blog/first-90-days-junior-developer): A 30-60-90 day plan for your first job as a junior developer: what to learn, when to take ownership, habits that build trust and early mistakes to avoid.

## Fractional CTO guide
- [Fractional CTO for Canadian and US Startups: What It Is, What It Costs, When You Need One](https://arxdsilva.com/blog/fractional-cto-canada-us-startups): A fractional CTO is a senior technology leader who works for your company part time. What they do, what they cost in Canada and the US, when to hire one.
- [Technical Due Diligence Checklist for Non-Technical Founders](https://arxdsilva.com/blog/technical-due-diligence-checklist-founders): A one-week technical due diligence checklist a non-technical founder can run with a borrowed engineer: ownership, code, data, security, ops, team, cost.

## pREST — PostgreSQL REST API and MCP server
- [pREST in 10 Minutes: Docker Compose to REST API to MCP Endpoint](https://arxdsilva.com/blog/prest-in-10-minutes): Run pREST v2.4.2 with Docker Compose, query a Postgres table over REST, turn on JWT auth and a table ACL, add a bound custom query and call /_mcp.
- [pREST v2 Guide: Versions, Upgrade Path and Where to Start](https://arxdsilva.com/blog/prest-v2-guide): pREST is an open-source Go server that turns PostgreSQL into a REST API and a read-only MCP endpoint. Every v2 release, the advisories, and where to start.
- [pREST v2.4.1 and v2.4.2: You Cannot Blacklist Your Way Out of SQL Injection](https://arxdsilva.com/blog/prest-v2-4-1-v2-4-2-release): pREST v2.4.1 patched an SQL injection with a keyword blacklist and blanked 17.5% of one catalog. v2.4.2 switches to parameter binding. Why blacklists fail.
- [Postgres MCP Servers Compared: Read-Only Posture, Auth and Auditability](https://arxdsilva.com/blog/postgres-mcp-servers-compared): Six Postgres MCP servers compared on write posture, auth and audit trail: Anthropic's archived reference, Postgres MCP Pro, Supabase, Neon, pgEdge, pREST.
- [pREST v2.4.0: pgvector Search, OpenTelemetry, and Six More SQL Injection Fixes](https://arxdsilva.com/blog/prest-v2-4-0-release): pREST v2.4.0 adds pgvector nearest-neighbor search, opt-in OpenTelemetry tracing, metrics and logs, and closes six SQL-injection-adjacent gaps.
- [pREST v2.3.0: Critical SQL Injection Fix and the Adapter Registry](https://arxdsilva.com/blog/prest-v2-3-0-security-release): pREST v2.3.0 fixes an unauthenticated SQL injection in _select affecting v2.0.0 to v2.2.0 (CVSS 9.8), moves JWKS to jwx v3 and completes the registry.
- [pREST v2.2.0: Studio, Database Queries, and TimescaleDB](https://arxdsilva.com/blog/prest-v2-2-0-release): pREST 2.2.0 ships an embedded Studio UI, database-backed custom queries and first-class TimescaleDB support for instant Postgres APIs.
- [pREST vs PostgREST: An Honest Comparison From pREST's Maintainer](https://arxdsilva.com/blog/prest-vs-postgrest): pREST and PostgREST both turn PostgreSQL into a REST API. PostgREST is Haskell and RLS-first; pREST is Go with config ACL, multi-database routing and MCP.
- [pREST AI Tooling — MCP Adapter, Cursor Plugin, and OpenClaw Skills](https://arxdsilva.com/blog/prest-ai-plugins-mcp-adapter): pREST ships a prest-mcp stdio adapter, Cursor plugin rules and skills, and OpenClaw skills, giving agents read-only PostgreSQL access via /_mcp.
- [How to Use pREST's MCP Server — Query PostgreSQL from Cursor, Claude, or curl](https://arxdsilva.com/blog/prest-mcp-server-tutorial): Set up pREST's read-only PostgreSQL MCP server over HTTP and connect Cursor, Claude Desktop or curl with ACL-aware SELECT queries. No separate MCP process.
- [pREST v2.0.0 and v2.1.0 — PostgreSQL REST API with Multi-Database and MCP](https://arxdsilva.com/blog/prest-v2-multi-db-mcp): pREST v2.0 and v2.1 explained: a Go PostgreSQL REST API with a multi-database registry, hardened connections and a read-only MCP endpoint for AI agents.
- [pREST v2.0.0-rc6 — Hexagonal Architecture and the Adapter Refactor](https://arxdsilva.com/blog/prest-v2-hexagonal-architecture): How pREST v2 applied hexagonal architecture in Go: splitting a monolithic Adapter into port interfaces and dependency-injected handlers, compatibly.

## PostgreSQL, MCP and AI agents
- [Vault: A Search-First File Manager to Replace Finder](https://arxdsilva.com/blog/vault-search-first-file-manager): Vault is an open-source, search-first file manager (a Finder alternative) built with Go and Wails: 353ms cold start, keyboard-only navigation, MCP server.

## Go in production
- [Go Microservices in Production: Lessons From Building a Distributed Platform From Scratch](https://arxdsilva.com/blog/go-microservices-in-production-lessons): Go microservices hold up when each service owns its data, every call has a timeout and a request is traceable end to end. Lessons from LodgeLink and 90POE.
- [How the Go Scheduler Works: G, M and P Explained With What You See in pprof](https://arxdsilva.com/blog/how-the-go-scheduler-works-gmp): The Go scheduler multiplexes goroutines (G) onto OS threads (M) via per-P run queues, with a global queue, work stealing and handoff on blocking syscalls.
- [easypprof: Production-Safe pprof for Go Services](https://arxdsilva.com/blog/easypprof-production-safe-pprof-go): easypprof serves Go's pprof on a loopback listener with token auth, duration caps, concurrency limits and audit logs, so you can profile production safely.

## Payments and trading systems
- [Idempotency Keys for Money Movement: Preventing Double Charges](https://arxdsilva.com/blog/idempotency-keys-money-movement): An idempotency key is a client-generated value that lets a payments API recognize a retry and replay the original result instead of charging twice.

## Engineering and industry commentary
- [What Git 3.0's SHA-256 Migration Gets Wrong About Real Attacks](https://arxdsilva.com/blog/git-sha256-migration-real-attacks): Git 3.0 makes SHA-256 the default hash. Scott Chacon says the migration cost outweighs a never-exploited attack. Which developer pushback actually held up.
- [When AI-Assisted Code Reinvents a Protocol, Badly](https://arxdsilva.com/blog/ai-scaffolded-protocol-reinvents-xmpp): An AI-built federated chat network shipped with tests and docs. Reviewers found it reinvents half of XMPP without XMPP's years of hardening.
- [What Government NixOS Migrations Get Right About Vendor Lock-In](https://arxdsilva.com/blog/vendor-lock-in-nixos-government-migrations): The Netherlands, France and Germany are moving desktops to declarative Linux. Developers say the OS was the easy swap, and point to where it will stall.
- [AI-Written PR Descriptions: Why Reviewers Stop Reading](https://arxdsilva.com/blog/ai-written-pr-descriptions-reviewers-stop-reading): Why AI-generated PR descriptions lose reviewers, the strongest pushback from the Hacker News thread, and what to write yourself instead.

## Developer tools and open source
- [win95 v2.0.0 and v2.0.1: A Windows 95 Theme for VS Code and Cursor](https://arxdsilva.com/blog/win95-v2-0-0-v2-0-1-release): win95 is a free Windows 95 color theme for VS Code, Cursor, VSCodium and Windsurf. v2.0 reworks the palette for readability; v2.0.1 ships on Open VSX.

## Products (Insurgency Labs)
- [DeliveryCompass — Engineering Intelligence for GitHub PR Delivery](https://arxdsilva.com/blog/deliverycompass): DeliveryCompass gives engineering managers read-only GitHub pull request metrics: throughput, lead time and review health per team, without spreadsheets.

## More
- [Reviewing AI-Generated Pull Requests: A Staff Engineer's Checklist](https://arxdsilva.com/blog/reviewing-ai-generated-pull-requests-checklist): How to review AI-generated pull requests: read the diff before the description, check that tests assert something, find hidden scope and invented APIs.
- [First-Ever Golang Calgary Meetup: Full Room, Great Talks, Strong Start](https://arxdsilva.com/blog/first-golang-calgary-meetup): Recap of the first Golang Calgary meetup: 30+ Go developers, a talk on concurrency vs parallelism, a session on the Go scheduler, and how to join next.
- [Building an Internal Hackathon Management Platform with Go and Buffalo](https://arxdsilva.com/blog/building-internal-hackathon-platform): How I built an open-source internal hackathon management platform with Go, Buffalo and PostgreSQL: RBAC, audit logging, team formation, admin dashboard.

## Media
- Videos: https://arxdsilva.com/videos
- YouTube: https://www.youtube.com/channel/UCQsZQ8zhPvZFXM1SeyyxFbQ
