29. Advanced engineering practice without unnecessary theory

Published

October 3, 2026

This chapter names the next skills you need when moving from a local exercise to research-engineering or evaluation-infrastructure work. Do not mistake reading these definitions for demonstrated competence. Use the small exercises to build inspectable evidence.

NoteLearning objectives
  • Validate APIs, joins, and execution boundaries.
  • Explain queue recovery and container permissions.
  • Choose engineering depth from actual requirements.
TipTL;DR

Deepen APIs, joins, concurrency, containers, testing, and ML frameworks when your role requires them. Reading a concept is preparation; a tested artifact is evidence of competence.

APIs and structured boundaries

An API request has a schema and a permission context. Validate type, required fields, allowable values, size limits, and identity linkage. A response may be malformed, empty, delayed, or denied. Log the error category without exposing credentials.

Practice with a local fake service returning success, denied access, timeout, and malformed JSON. Your adapter should fail clearly or follow a declared recovery policy. It should not fabricate a result on error.

SQL and data joins

SQL queries retrieve and combine structured records. A join can duplicate rows or attach information to the wrong entity. Understand primary keys, foreign keys, uniqueness, null values, and one-to-many relationships before judging a data pipeline.

Exercise: create two synthetic tables of encounters and outputs. Include one duplicate encounter key and one unknown output key. Ask the agent to validate the join and report unmatched rows. Reject an implementation that silently drops unmatched records or counts duplicates as independent cases.

Concurrency and queues

Concurrency allows work to progress simultaneously. It does not guarantee speed when the provider rate limit or GPU is the bottleneck. A queue needs ownership, retries, cancellation, and a way to prevent two workers from performing the same side effect.

Exercise: represent each run with a unique ID and a claim/lease. Explain what happens if a worker disappears after receiving the task but before publishing the report. A correct design permits recovery without presenting a partial report as completed.

Containers and permissions

A container packages software and constrains an execution environment according to configuration. Verify the image, mounts, user privileges, network, resource limits, and hidden-reference access. “It runs in Docker” is not evidence that secrets or host files are protected.

Exercise: specify a read-only source mount, separate writable output mount, no real credentials, and a bounded execution timeout for a benign coding task. Have the agent explain how it will verify those boundaries before running untrusted code.

Testing beyond unit tests

A unit test checks a narrow component. An integration test checks components together. An end-to-end test checks a user workflow. A property test checks an invariant across many inputs. A mutation test deliberately alters code to see whether tests catch the defect.

Exercise: your scorer rejects unknown IDs in isolation. An integration test should prove that the CLI returns failure and does not publish a new success report on such input. Test the boundary the user actually runs, not only a private helper.

ML framework literacy

For model-training roles, inspect tensors (multidimensional arrays), device placement, batches, train/eval modes, gradients, and checkpoint versions. A small reproducible supervised-learning experiment can teach these without a large GPU bill. Use an approved dataset and budget, preserve splits, and compare against a simple baseline.

A coding agent can write the loop. You must explain which data updates parameters, which data selects settings, and which data remains withheld for acceptance. If those boundaries are blurred, the experiment is not trustworthy.