
Kamil Gałązka
Software Engineer · Full-Stack Development

Production
8yr
Secure Systems
Five years inside a permission-controlled information system.
Polish National Police · Traffic Division · Warsaw
- Systems
- KSIP and operational terminals
- Data
- Personal, vehicle and operational records
- Constraint
- Strict confidentiality and procedure
- Access model
- Authenticated, permission-controlled; access followed authorization and responsibility
- Practice
- Cross-system verification, accurate digital documentation
- What it became
- Controlled access, data protection, traceability, accountability

Production
3yr
Operational Data
Three years reconciling data between systems that disagreed.
Hallingfrakt AS · Transport Operations & IT Systems Support · Norway
- Systems
- Timpex, DB Schenker, shipment terminals
- Data
- Shipments, customers, transport orders, identifiers, tracking status
- Daily work
- Investigating why two systems showed a different status for one shipment
- Repair
- Missing, incorrect and inconsistent records in shipment-processing workflows
- What it became
- System integration, data validation, troubleshooting from the operational side
Engineering
The vocabulary for what I had already been doing.
Coders Lab · Python Developer Course · Weekend Premium
- Covered
- Python core and advanced, databases, Django, JavaScript, advanced Django
- Focus
- Administration and access control
- Assessment
- Independent projects, final project defence, one-to-one oral examination

This was never a career change.It was one continuous line.
In the police I worked every day inside information systems where access depended on authentication, on role, and on the scope of your responsibility. I did not call it authorization or RBAC back then — that was simply how the work functioned. In logistics I met the same thing from the other side: data moving between systems, shipments, identifiers, statuses, and the discrepancies between them. When I started building my own applications, it turned out I was designing exactly the mechanisms I had spent ten years working inside.

mexicode.dev · Full-Stack Software Engineer · Self-employed
Smakspor
June 2026 – present
A bilingual platform for finding food trucks, and for operators to publish location, hours and menu from a single mobile panel.
Live in production · pilot phase

Live product · smakspor.no
Plan
What a person moves through
- Live map
- Mapbox, location search over PostGIS geometry
- Public profiles
- Operator page, menu, week plan
- Following
- Web Push notifications, transactional email via Resend
- Operator panel
- Mobile-first publishing of location, hours and menu
- Checkout
- Stripe Checkout with a signed webhook
Section
What holds it up
- Roles
- consumer · owner · staff · admin
- Authorization
- RBAC plus ownership checks; 401 and 403 are different answers
- Data boundaries
- PostgreSQL Row Level Security across multi-tenant data
- Identity
- Google OAuth and passwordless email sign-in
- Endpoint safety
- Validation, rate limiting, idempotency
- Critical paths
- Playwright end-to-end tests
- Delivery
- Vercel, production debugging
- TypeScript
- React
- Next.js
- Supabase
- PostgreSQL
- PostGIS
- Mapbox
- Stripe
- Resend
- Web Push
- Playwright
- Vercel
What I can defend
Weight on this page is rationed by evidence, not by enthusiasm. The heavier a line reads, the further I can be pushed on it before I run out of answers.
- strong
- Defends the decisions
- solid
- Explains the mechanism
- basic
- Present in the work
Ownership
- End-to-end product deliverySmakspor, from discovery to production
- Production deploymentVercel; smakspor.no is live
- Systems with permissions and sensitive dataFive years, Polish National Police, KSIP
- Integrations and data flow between systemsThree years, Hallingfrakt: Timpex, DB Schenker
Application
- TypeScriptSmakspor, in full
- ReactSmakspor, in full
- Next.jsSmakspor, in full
- Tailwind CSSResponsive interface work
- Python · DjangoCoders Lab; defended orally, 1:1
Delivery
- PlaywrightEnd-to-end tests on critical paths
- Git · GitHubDaily
- Production debuggingAcross the whole vertical
Access & safety
- Authentication vs authorizationFour roles; 401 and 403 answer different questions
- RBAC and ownershipRole-dependent panels
- Row Level SecurityPolicies protecting multi-tenant boundaries
- Signed webhooksStripe Checkout
- Rate limiting · idempotencyEndpoint protection
- OAuth · passwordless sign-inGoogle OAuth, one-time-code email
Data
- PostgreSQLRelational modelling, indexes, migrations
- PostGISGeospatial queries behind map and location search
- SupabaseDatabase, auth and storage layer
- REST APIsEndpoints, validation, error handling
What I have not done
Working alone builds different habits than working in a team, and these are the ones I did not get. You would find out in the first interview anyway; I would rather you read it here.
- Development inside a team, with code review and a release process
- Long-lived legacy systems
- CI/CD beyond what Vercel provides
- Unit testing at scale — the tests here are end-to-end


- Holder
- Kamil Gałązka
- Since
- 2016
- Based
- Norway
Still the right road.
I am looking for a full-time engineering role. If what you read above is the shape of the work, the fastest thing you can do is open the CV and email me.
- GitHub
- mexicode-dev
- in/kamil-galazka
- Languages
- Polish — Native · English — B2 · Norwegian — Shipped products in it
- Education
- Master's Degree in Theology, Cardinal Stefan Wyszyński University (UKSW), 2016
The other way onto this road
Most of what is above was built for a full-time engineering role, and that is what I am looking for. If instead you have a contract, a piece of a product that needs carrying end to end, or a system whose data boundaries are keeping someone awake, that conversation works too.