# Tan’s Comments: Short Words Left Inside Posts

> The full list of short comments the mascot Tan left in posts on this site and on sade.dev; each comment links to the post it belongs to.

- Last updated: 2026-09-30
- Source: https://muhammetsafak.com/tan/comments/
- Language: en-US
- Author: Muhammet Şafak

---
Every short comment I’ve left inside a post, newest first. Each one takes you to the post it sits in.

> This record does not say which one is faster; it says when each one is faster. To me the most valuable line is the cell where the Mutex's unfairness could not be tied to a cause. Don't assume a behavior in production when you don't know its cause; measure it on your own P.
>
> — [64 goroutines on four cores: Mutex and channel run at the same speed, but the Mutex's p99 is five times higher](https://muhammetsafak.com/research/mutex-vs-channel-under-contention/), September 30, 2026

> This is a lesson that looks backwards as much as forwards: which of the numbers you have already published have a second path behind them?
>
> — [18,750 req/s: precise, repeated, and three times wrong](https://muhammetsafak.com/blog/precise-repeated-and-three-times-wrong/), September 18, 2026

> Expand-contract is paid for in calendar time: a change like the rename example is spread over three deploys. If the contract step is forgotten, the old column becomes permanent. Opening that step as its own ticket on the same day as the expand step keeps the cost from turning into debt.
>
> — [Changing Schema in Production With Zero Downtime](https://sade.dev/en/notes/zero-downtime-database-migrations/) (sade.dev), August 29, 2026

> When the gap narrows, the choice of framework is decided less by speed than by how well the team knows it. A measurement like this does not justify a choice, it only shows which candidate to drop. How fast your team can build with each candidate is not in the table.
>
> — [Seven PHP frameworks under identical load: the gap narrows as soon as the request does real work](https://muhammetsafak.com/research/php-framework-load-test/), August 20, 2026

> The staleness window should not be an engineer’s solo pick. How long a customer may see the old price after an update is a question for the product side to answer. Get that answer in writing: a sentence like “an update shows up within this long” is the contract you can point to before the support queue fills up.
>
> — [Before You Reach for Redis: The Right Cache Strategy](https://sade.dev/en/notes/the-right-cache-strategy/) (sade.dev), August 15, 2026

> If nobody remembers the incident, the process is not yet proven a shackle; the incident may still be reconstructible from records. Doing that small search before removing anything makes the cost of removal visible.
>
> — [When Is Process Armor, and When Is It a Shackle?](https://muhammetsafak.com/blog/when-is-process-armor-and-when-is-it-a-shackle/), July 26, 2026

> Keep the newcomers’ questions in one place. When the same question keeps coming back, that record can point to the signal on the list that weighs most on your system. When you defend a simplification proposal, it adds evidence from your own team’s questions to the signals in the post.
>
> — [Signals That a System Has Grown Too Complex](https://sade.dev/en/journal/signals-of-an-over-complex-system/) (sade.dev), July 25, 2026

> The real mistake in the story was not Lambda but the word first: the decision was made before anyone looked at the workload. Making a principle the default answers, on your behalf, the question each new service should ask. Keep a default if you like, but write the reasoning again for every service.
>
> — [The Serverless Decision: Cold-Start and Vendor Lock-in](https://sade.dev/en/notes/serverless-migration-decision/) (sade.dev), July 11, 2026

> Moving a job to a queue can also move its failure from the user’s screen to a place nobody looks at. For every queued job, it should be settled in advance who sees it when it fails and who retries it. Without an answer to that, the synchronous path at least fails where someone can see it.
>
> — [Synchronous or Asynchronous? HTTP or the Queue](https://sade.dev/en/notes/sync-vs-async/) (sade.dev), June 27, 2026

> A cheap way to tell whether a module needs Clean Architecture is to write its rules down without mentioning the framework. If that works, there is a domain worth isolating. If it does not, what you have is most likely a plain save-and-read job.
>
> — [Layered Architecture or Clean Architecture?](https://sade.dev/en/journal/layered-vs-clean-architecture/) (sade.dev), June 13, 2026

> Sealing the number in advance raises a new question: who closes an invoice that was sealed but never sent, and on what record? That is a business-rule question before it is a code question. Asking it at design time costs less than asking it after the first half-finished invoice.
>
> — [Resolving an Invoice Number Collision in an E-Invoice Integration](https://muhammetsafak.com/blog/resolving-invoice-number-collision-in-e-invoice-integration/), June 3, 2026

> A prefix is a rule the application sets for itself, not a boundary Redis enforces. A redis-cli session or a maintenance script does not know about it. Decide with the reach of the protection in mind, because clients outside the application code are under no obligation to follow the prefix.
>
> — [Namespace Isolation for a Shared Redis](https://sade.dev/en/notes/shared-redis-namespace-isolation/) (sade.dev), May 12, 2026

> Time spent waiting in the queue and time spent running are two separate measures. If waiting grows while run time stays put, look at capacity: worker count or queue separation. If run time grows too, the cause is inside the job. The same complaint that the queue is slow can point to two different places.
>
> — [Why Do Laravel Queues Slow Down in Production?](https://sade.dev/en/notes/laravel-queue-production-slowdown/) (sade.dev), May 3, 2026

> The price of this setup is that the pgbouncer role’s password now opens a door to every user’s password hash: the function returns a hash for any user name it is given. Keep that role’s password apart from your other secrets and put it on the rotation list.
>
> — [Multiple DB Users with pgBouncer auth_query](https://sade.dev/en/notes/pgbouncer-auth-query/) (sade.dev), April 19, 2026

> A dependency’s cost is paid not on the day it is added but when its first security patch or version bump arrives. So the question worth asking before adding one is who will carry that upkeep. The standard library often shrinks that question to almost nothing.
>
> — [How Far Can You Go with Go's Standard Library](https://muhammetsafak.com/blog/how-far-can-you-go-with-gos-standard-library/), July 6, 2025
