amigo@fps:~$ ls projects/

Projects

Things I've built, in rough order of how much of my life they took.

Ocelotiq — AI gateway

An OpenAI-compatible API gateway. One endpoint, many providers: you point your existing OpenAI client at it and get GPT-4o, Claude, Gemini or Llama without touching your code.

  • Unified REST layer that normalizes requests and responses across providers.
  • Auth, API-key management and per-key quotas.
  • Routing that picks a provider by availability, latency and price.
  • Analytics on tokens, spend, error rates, response time and uptime.

Python · PostgreSQL · Docker · Linux

ocelotiq.ru ->

Chaff — tunneling protocol

My own protocol and a Rust client/server implementation. IP traffic is carried inside browser sessions on port 443 — TLS 1.3 + HTTP/2 or QUIC. The handshake fingerprint and request pattern match Chrome.

  • Two transports on one port: HTTP/2 over TCP and QUIC DATAGRAM over UDP. Auto mode tries UDP and switches to TCP when it is unavailable.
  • Packets are encoded into asset-download and analytics-beacon streams. No custom headers are sent; the link id is encoded in the request path hash.
  • Ed25519 auth carried in a cookie. On a wrong key the connection is proxied to a decoy site.
  • ChaCha20-Poly1305, keys bound to the connection's TLS exporter. 2048-entry sliding anti-replay window. In-band rekeying on the TCP transport; QUIC uses its own key updates.

Performance

The codec batches packets into 16 KB records — one HTTP/2 DATA frame and one TLS record. Coalescing is adaptive: with a shallow queue packets are sent without delay, bulk transfer adds up to 1 ms of batching; ICMP and bare ACKs are not delayed. The key schedule is built once per stream and sealing is performed in place.

Traffic is split into two classes: interactive is served by a separate queue ahead of bulk, in both directions. Congestion control is set per direction: BBR on download, CUBIC on upload.

Path MTU is derived from the connection's current capacity on every packet; a packet that does not fit is fragmented. Traffic is spread across four parallel links with each TCP flow pinned to one, and fragments of a datagram travel over the same link. Queue depths and buffer sizes are derived from the path's bandwidth-delay product.

throughput, QUIC234 Mbps
throughput, TCP110/84 Mbps
loaded latency95 ms against a 68 ms idle RTT
jitter, interactive traffic5.5 ms
loss, interactive under load1.5 %
codec, single core9.5 Gbit/s

Rust · TLS 1.3 · HTTP/2 · QUIC · TUN · ChaCha20-Poly1305

Source is closed.

Robotics & automation

Production work at Indrobo: software for robotic platforms and industrial automation lines.

  • Control software and integration of sensors, controllers and embedded devices.
  • Deployment and maintenance infrastructure for the hardware in the field.

Rust · C/C++ · Python · Linux

Full-body tracking

A home-made full-body tracker built from scratch, because the commercial ones cost more than I wanted to spend.

  • Own hardware design using infrared transmitters and receivers.
  • Embedded firmware and a custom communication protocol between the nodes.

C · embedded · custom PCB work

More

Smaller things live on GitHub. If something here is interesting, write to me.