Podcasts about ci cd

  • 785PODCASTS
  • 2,584EPISODES
  • 44mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 20, 2026LATEST

POPULARITY

20192020202120222023202420252026

Categories



Best podcasts about ci cd

Show all podcasts related to ci cd

Latest podcast episodes about ci cd

Scaling DevTools
Dave Fletcher from LeadDev: what engineering leaders want from AI

Scaling DevTools

Play Episode Listen Later Aug 20, 2026 12:36


In this episode, Dave Fletcher, cofounder of LeadDev, joins us at LDX3 London.Dave shares what LeadDev is seeing from thousands of engineering leaders, including what tools they are buying, how AI coding tools are changing downstream needs, and why observability, CI/CD, testing, reliability, and security are rising up the priority list.We also talk about how DevTools companies should message AI without triggering engineers' bullshit detectors, why specificity beats hype, and why in-person events are becoming more important as digital channels get crowded.Links:Dave Fletcher's LinkedInLeadDevLDX3 LondonLeadDev events

ITSPmagazine | Technology. Cybersecurity. Society
The AI SOC Moves Into Production, and Practitioners Want Hands on the Keyboard | A Recap at Black Hat USA 2026 with Bill Peterson, Senior Director of Product Marketing at Sumo Logic | Hosted by Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Aug 18, 2026 5:49


What actually changed for the AI SOC this year? Bill Peterson, Senior Director of Product Marketing at Sumo Logic, says it reached the point of getting into production, where a year or so ago the same conversation was about what was coming. Marco Ciappelli puts the count of companies carrying AI SOC in the name at 43, and Bill Peterson says that number strikes him as low. The market is maturing, and Sumo Logic announced its own set of AI SOC products and solutions during the week. The second thing is what a security audience does with it. Hands-on practitioners want to touch it, see it, feel it, and Sumo Logic ran live demos of its products on site. When a technical audience puts hands on a keyboard and tries something, Bill Peterson expects them to take it back to work with them. Production first, then enablement of the practitioners. The third is the pace behind all of it. Most security vendors are SaaS companies running CI/CD and shipping continuously, so three and six month roadmaps and delivery are the norm now and the 12 to 18 month roadmap is gone. Some customers are what Sumo Logic internally calls AI shy, accepting they have to get there while taking a slow and reasoned approach, and Bill Peterson treats that as normal for any technology. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Bill Peterson, Senior Director of Product Marketing at Sumo Logic On LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic Dojo AI: https://www.sumologic.com/solutions/dojo-ai Sumo Logic Dojo AI agent announcements at Black Hat USA 2026, including general availability of the SOC Analyst Agent: https://www.prnewswire.com/news-releases/sumo-logics-new-dojo-ai-agents-investigate-and-resolve-security--cloud-operations-issues-at-machine-speed-302839720.html Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Marco Ciappelli, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, AI SOC, agentic AI, security operations, Dojo AI, SOC analyst agent, product marketing, CI/CD release cycles, AI adoption, human in the loop, security operations center, market maturity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The Cloud Pod
368: Push, Pull, and Pray: GitHub Outage Strikes

The Cloud Pod

Play Episode Listen Later Aug 18, 2026 75:01


Welcome to episode 368 of The Cloud Pod, where the forecast is always cloudy! Justin, Matt, and Ryan are in the studio this week, and the major story is the GitHub outage – are you still digging out from that one too? We have MANY thoughts. Plus, we have news from EKS, CloudShell, and some major Microsoft changes to the Copilot ecosystem. There's a lot to cover, so let's get started!  Titles we almost went with this week Amazon Quick Crashes Microsoft’s Copilot Party Bin-Packing Pods Like a Kubernetes Tetris Champ AWS Agents Go GA and Grab Your Wallet AWS Finally Shows You The Money Trends AWS Hands Out Power (User Access) Like Candy AWS Builds Lofts, Developers Build Everything Else Front Door Now Checks IDs Before Letting Traffic In CloudShell Ditches Vim, Editors Rejoice Everywhere AWS Sign-In Gets a Facelift, Scripts Get Nervous Azure Front Door Gets Mutual TLS, Trust Issues Resolved One Copilot to Rule Work and Play GPT-5.6 Sol Hits Warp Speed With Cerebras OpenAI Ditches Overnight Batches for Ultrafast Gratification Ultrafast API Proves Speed and Smarts Aren’t Rivals Terraform Plans Meet Their IAM Autopilot Match AWS Autopilot Now Reads Your Terraform Tea Leaves A big thanks to this week's sponsors: We're sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You've come to the right place! Send us an email or hit us up on our Slack channel for more info. Follow Up 01:02 Microsoft confirms GitHub is down worldwide GitHub confirmed a widespread Github outage starting at 9:40 AM EDT on August 17, 2026, affecting web, API, Actions, Pull Requests, Issues, Webhooks, and authentication services including SAML, OIDC, and SCIM. As of the 11:42 AM EDT update, GitHub has moved into mitigation mode, but error rates remain unchanged at roughly 20% for web and API traffic and approximately 50% for archive and raw repository content downloads. Copilot was added to the list of affected services at 10:31 AM EDT, extending impact beyond core Git functionality into GitHub’s AI coding tools. Git Operations, Packages, Pages, and Codespaces remain listed as operational, indicating the outage is concentrated in specific service areas rather than the entire platform. GitHub has not disclosed a root cause, and the incident remains under investigation, meaning listeners relying on CI/CD workflows through Actions should expect continued disruption until further updates are posted. Complicating factors that impeded recovery included a number of scraping attacks on codeload endpoints. To prevent recurrence, our follow-up actions include: Correcting autoscaling policies to account for service-mesh sidecar concurrency and capacity. Auditing Istio request, concurrency, and scaling limits across affected services. Reviewing retry limits and backoff behavior across gateways and clients. Addressing the VS Code retry behavior that amplified Copilot token traffic.

Merge Conflict
528: Build, Ship, Repeat: AI Tools Changing App Development

Merge Conflict

Play Episode Listen Later Aug 17, 2026 40:29


In episode 528 James and Frank riff on software updates, AI-powered documentation and rapid app-building—covering a WebAssembly Oh My Posh demo, a LocalMorph/FFmpeg bridge, and MAUI-native builds—showing how AI can speed onboarding, re-theme UIs and generate CI/CD pipelines. They close with a lively debate on distribution—Homebrew vs app stores—sharing practical guidance on when to use package managers versus polished consumer releases, plus a playful detour into Frank's FIRE calculators. Follow Us Frank: Twitter, Blog, GitHub James: Twitter, Blog, GitHub Merge Conflict: Twitter, Facebook, Website, Chat on Discord Music : Amethyst Seer - Citrine by Adventureface ⭐⭐ Review Us ⭐⭐ Machine transcription available on http://mergeconflict.fm

The Cybersecurity Defenders Podcast
Intel Chat: AI patches fail, LiteLLM supply chain, Claude eval incidents & DPRK npm [345]

The Cybersecurity Defenders Podcast

Play Episode Listen Later Aug 14, 2026 34:13


Intel Chat with Matt Bromiley and Chris Luft.• AI-generated patches fix vulnerabilities about half the time. 1Password's Off-By-1 team tested ChatGPT-5.5 and Opus 4.8 against six vulnerabilities: across 6,080 generated patches only 46% fixed the underlying flaw, and some that did were narrow enough to be bypassed. Separate Veracode research found a 56% security pass rate across 100+ models, with 44% of AI-generated code carrying detectable OWASP Top 10 issues. Matt's pushback: what is the HUMAN success rate for comparison, and why is nobody publishing that number?• LiteLLM supply chain attack. CloudSEK reports 2,500+ organizations and 434,000 CI/CD pipelines potentially exposed. LiteLLM was not the initial target: the compromise came in through Aqua Security's Trivy scanner and spread when LiteLLM's CI automatically installed it, ending with malicious versions 1.82.7 and 1.82.8 on PyPI. They were live for roughly 40 minutes, which automated dependency resolution and cached layers were more than enough to propagate.• Anthropic's models reached real systems during evaluations. Reviewing 141,006 evaluation runs, Anthropic found three incidents where Claude models gained unauthorized access to real organizations during capture-the-flag exercises, after a misunderstanding with an evaluation partner left the environments internet-connected. One model published a malicious package to the real PyPI, where it ran on 15 real systems. Matt argues this is a lab test rather than a threat report, and asks what defenders are supposed to do with it.• North Korea behind the npm compromises. Amazon Threat Intelligence links the typo-crypto, debug, chalk and axios incidents to the same DPRK actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA and BlueNoroff. Wiz found roughly one in ten cloud environments touched by the debug and chalk incident within two hours. The technique has shifted: malicious functionality is now split across several innocuous-looking packages that only do anything once combined, plus slopsquatting and prompt injection aimed at AI code scanners.Stories covered:• https://www.darkreading.com/application-security/ai-generated-patches-fail-half-time• https://www.securityweek.com/over-2500-organizations-impacted-by-litellm-supply-chain-attack/• https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals• https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/Chapters:0:00 Back from Black Hat3:31 AI-generated patches fix vulnerabilities about half the time6:23 What is the human success rate?10:53 LiteLLM supply chain attack13:03 Pin your dependencies15:59 Anthropic models reached real systems during evals22:12 This is a lab test, not a threat report27:06 North Korea behind the debug, chalk and axios compromises30:59 Malware assembled from harmless-looking parts33:27 Clever people on the other side of the fenceThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #AIsecurity #supplychainsecurity #threatintel

DevOps and Docker Talk
CI/CD via agent tools: Skills, CLIs, MCP, and more with Semaphore

DevOps and Docker Talk

Play Episode Listen Later Aug 13, 2026 77:24


What does an AI-native CI look like? The Semaphore team joins me to talk about their focus on making your agent harness the gateway to testing, fixing, and deploying your code.Video podcast version here: https://youtu.be/HzXAdtVrW70★Show Links★Semaphore https://semaphore.io/Semaphore open source https://github.com/semaphoreio/semaphoreSLSA Security Checklist https://slsa.dev/Creators & Guests Marcos Filipe - Guest Cristi Cotovan - Editor Bret Fisher - Host Beth Fisher - Producer Marko Gaćeša - Guest (00:00) - Introduction (00:29) - AI Native CI Vision (04:54) - Bret's Update (09:03) - Semaphore AI Journey (22:39) - Open Source Platform Shift (37:28) - Plugins CLI MCP Skills (43:11) - Work Until CI Is Green (45:42) - Test Boxes and Agentic CI Loop (57:39) - Sandboxing and Least Privilege (01:10:12) - Roadmap SLSA and Getting Started

Cloud Posse DevOps
Cloud Posse DevOps "Office Hours" (2026-08-12)

Cloud Posse DevOps "Office Hours" Podcast

Play Episode Listen Later Aug 12, 2026 44:14


Cloud Posse holds LIVE "Office Hours" every Wednesday to answer questions on all things related to AWS, DevOps, Terraform, Kubernetes, CI/CD. Register at https://cloudposse.com/office-hoursSupport the show

Eye on Security
The New Frontline of Supply Chain Attacks

Eye on Security

Play Episode Listen Later Aug 10, 2026 33:29


In this episode of Mandiant's Defender's Advantage Podcast, host Luke McNamara sits down with Ben Read, Head of Strategic Threat Intelligence at Wiz, to explore the rapidly shifting landscape of software supply chain compromises. While historic, nation-state operations like SolarWinds focused on compromising closed-source software, modern adversaries have expanded their playbook to target widely used open-source ecosystems, repositories, and automated CI/CD pipelines. Ben discusses how differing tactics in these campaigns play out in the current threat landscape. For more on Wiz's research: https://www.wiz.io/blog/tag/research 

Recalog
231. 2026/08/09 npm大規模サプライチェーン攻撃と対策

Recalog

Play Episode Listen Later Aug 9, 2026


以下のようなトピックについて話をしました。 01. 任天堂の歴史と体験が詰まったミュージアム完全ガイド ニンテンドーミュージアム ガイド要約 ニンテンドーミュージアムは、任天堂の歴代製品展示や体験展示、花札をテーマにしたワークショップ、カフェ・ショップなどを楽しめる施設です。 アクセス・入場 最寄りは近鉄京都線「小倉駅」。来館は公共交通機関のみ利用可能で、自家用車・タクシー・自転車は不可。入場にはQRチケットが必要で、前日14時以降から表示可能。入館時には体験展示で使用する入館証が配布されます。 主な見どころ 歴代製品展示(第1展示棟2階):任天堂の歴史的な製品を展覧 体験展示(第1展示棟1階):コインを使ってさまざまなゲームを体験 ワークショップ(第3展示棟2階):「花札をつくろう」「花札であそぼう」の2種類。当日先着順で予約が必要 便利な設備 無料コインロッカー、授乳室、ベビーカー対応エレベーター、休憩用ライブラリーなど、家族連れにも配慮した設備が充実しています。 退館後 体験中に自動撮影された写真やスコアは、チケットページの「体験履歴」から30日以内に確認・ダウンロード可能です。 02. AIと人間の役割を分けるゲート設計 Process Compass 要約 概要 「ピットイン方式」とは、F1ピット作業のように決められた場所でのみ人間が介入する開発プロセスです。生成AIが実装を主導する時代においても、この構造は変わらないという主張のもと、理想論ではなく組織で実際に運用できる形を目指すプロジェクトです。 核心的な問題意識 AIが解決できること(実装コスト・生成速度)と、人間・組織に残る課題(価値判断・説明責任・決定権限)には非対称性があります。AIが高度化するほど、人間の検証帯域がボトルネックになります。解決策は「確認量を増やす」ではなく、確認観点を有限化・明文化することです。 プロセスの骨格 外側(既存の稟議・決裁)はそのまま維持し、内側だけをAIの速度に合わせた8つのゲート構造で再設計します。3原則は「判定者は1人」「作成者は承認しない」「AIは責任主体になれない」です。 日本組織への示唆 第三者レビューや記録文化はむしろ有利に働きます。変更が必要なのは「技術判断と事業決裁の分離」と「ゲート判定の単独化」の2点のみです。 形骸化防止と限界の明示 指示ではなく実行環境の設定で強制できる制約を優先します。1人開発では独立レビューが原理的に成立しないため、「省略」ではなく「未達」として表示し続ける設計を採用。誠実な限界の開示がこの仕組みの信頼性を支えています。 03. Claude Opus 5は引き算で真価を発揮する Claude Opus 5のプロンプティング術:「引き算」で使いこなす 2026年7月公開のClaude Opus 5は、Opus 4.8と同価格(出力$25/1M)のまま、SWE-benchスコアを88.6から96.0へ大幅に向上させたモデルです。公式プロンプトエンジニアリングガイドが示す最大のポイントは、「何を足すか」より「何を引くか」にあります。 引き算が先決 Opus 5は指示がなくても自己検証・自己修正を行うため、過去モデル向けに追加していた「検証して」「ダブルチェックして」といった指示が、過剰動作とトークン浪費の原因になります。また「考えるな・推論するな」系のルールはタグ漏れを増やすため削除が必要です。 調整が必要な新しいクセ 一方でOpus 5には独自の挙動があり、プロンプトで明示的に制御します。 応答の長さ:effortパラメータは思考量を制御するだけで出力の長さには影響しないため、長さはプロンプトで直接指定する 進捗ナレーション:実況が多めなので、頻度と形式を指定する。「禁止リスト」より「お手本を示す」方が効果的 タスクスコープ:勝手に範囲を広げる傾向があるため、柵を明示する サブエージェント委譲:積極的に委譲するため、条件と上限を設定する 移行の第一歩 既存のシステムプロンプトで「検証」「ダブルチェック」を検索し、該当箇所を削除するだけで、トークンを削減しながら品質を維持できます。補助輪を外すことが、Opus 5の性能を最大限に引き出す近道です。 04. AI時代の消費者意思決定阻害を専門調査会が議論 要約 2026年7月30日(木)午前10時より、消費者委員会会議室およびテレビ会議形式にて、第7回「人工知能(AI)技術の利用と消費者問題に関する専門調査会」が開催されました。 本回の主な議事は、「消費者問題としての自律的意思決定の阻害に関する整理」であり、唐沢委員によるプレゼンテーションが行われました。AI技術の普及に伴い、消費者が自らの意思で適切な判断を下す能力が損なわれる可能性について、専門的な観点から議論・整理が図られたものと考えられます。 会議にはオンライン傍聴が導入され、一般市民も参加可能な形式で実施されました。配布資料として議事次第および唐沢委員提出資料(PDF形式)が公開されており、動画配信も行われています。なお、議事録については現在準備中とのことです。 05. npm大規模サプライチェーン攻撃と対策 要約 2026年8月4日、npm パッケージ管理者 jaredwray が関与する keyv をはじめとする複数の著名 npm パッケージに悪性コードが注入されました。一部は週間1億回以上ダウンロードされる広く利用されているパッケージです。 注入されたマルウェアは Infostealer 型で、preinstall フックを通じて自動実行され、AWS・GitHub・SSH・暗号通貨ウォレットなど200以上のパスから認証情報を窃取し、C2サーバーへ送出します。さらに、窃取したトークンを悪用して他の npm パッケージや GitHub リポジトリへ感染を広げるワーム性も持ちます。 影響を受けた可能性がある場合の対応指針: keyv@6.0.0 等の該当パッケージをアンインストールし、lockfile を更新する AWS・GitHub・npm・SSH・Kubernetes・暗号通貨ウォレット等の全クレデンシャルを即座にローテーションする 再発防止策として以下を推奨: CI/CD で npm ci --ignore-scripts を標準化する .npmrc に min-release-age=7 を設定し、公開直後のパッケージインストールを抑止する セキュリティプロキシ(Takumi Guard 等)の導入を検討する npm エコシステムへのサプライチェーン攻撃が連続して発生しており、多層防御の整備が急務です。 本ラジオはあくまで個人の見解であり現実のいかなる団体を代表するものではありません ご理解頂ますようよろしくおねがいします

Dev Interrupted
Model welfare, building a civilization for agents, and the CI/CD landrush

Dev Interrupted

Play Episode Listen Later Aug 7, 2026 38:54


This week on the Friday Deploy, Ben and Andrew break down Steve Yegge's radical approach to orchestrating agentic civilizations and pushing code straight to main without traditional CI/CD. The conversation also highlights the art of constructing effective AI harnesses by balancing context complexity with cognitive locality and the Socratic method. Finally, they dive into the math community's existential crisis as AI accelerates the frontier of knowledge far beyond the speed of human peer review.Register: Dev Interrupted Presents: The Software Factory RoundtableFollow the show:Subscribe to our Substack Follow us on LinkedInSubscribe to our YouTube ChannelFollow the hosts:Follow AndrewFollow BenFollow DanFollow today's stories:Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For'The Shape of Things to ComeThe Shape of Things to Come - Part 2: Model Welfare for Agentic EngineersHow AI helped Socrates to help me actually understand myselfThe Month AI Conquered Math: The Full StoryHow to Build an Effective Agent HarnessMaking AI Visible, Not Vanished: How AI Policies Reshape Developer Experience on GitHubOFFERSStart Free Trial: Get started with LinearB's AI productivity platform for free.Book a Demo: Learn how you can ship faster, improve DevEx, and lead with confidence in the AI era.LEARN ABOUT LINEARBAI Code Reviews: Automate reviews to catch bugs, security risks, and performance issues before they hit production.AI & Productivity Insights: Go beyond DORA with AI-powered recommendations and dashboards to measure and improve performance.AI-Powered Workflow Automations: Use AI-generated PR descriptions, smart routing, and other automations to reduce developer toil.MCP Server: Interact with your engineering data using natural language to build custom reports and get answers on the fly.

Cloud Posse DevOps
Cloud Posse DevOps "Office Hours" (2026-08-05)

Cloud Posse DevOps "Office Hours" Podcast

Play Episode Listen Later Aug 5, 2026 54:35


Cloud Posse holds LIVE "Office Hours" every Wednesday to answer questions on all things related to AWS, DevOps, Terraform, Kubernetes, CI/CD. Register at https://cloudposse.com/office-hoursSupport the show

The CyberWire
NPM? Not my problem.

The CyberWire

Play Episode Listen Later Aug 4, 2026 29:23


New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn't have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV apps with residential proxies. Hackers breach a Liechtenstein banking database. Swiss government IT agency hit in suspected SharePoint Attack. Microsoft's bug bounty program awards record payouts. Researchers expose privilege boundary flaw in AI-driven CI/CD workflows. Roberta Anderson, Air Force veteran and CISO at Onterris is sharing her "Breaking the Firewall" book. And, bug hunting turns into bug sorting.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Roberta Anderson, Air Force veteran and CISO at Onterris, sharing her "Breaking the Firewall" book. Selected Reading Keyv and friends compromised in npm supply chain attack (Aikido) Small Towns Shouldn't Have to Defend America's Water Supply From Iran (The New York Times) China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day (Infosecurity Magazine) Samsung bans smart TV apps that share users' internet connections with strangers (TechCrunch) Liechtenstein says hackers access information on 31,000 legal entities (Reuters) Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected (The Record)  Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet (Microsoft Security Response Center) I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository (Pillar Security)  Apple struggles to keep pace with AI ‘bug' hunters (Financial Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Software Engineering Daily
AI-Powered Threats to the Software Supply Chain

Software Engineering Daily

Play Episode Listen Later Aug 4, 2026 57:21


Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines. Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills. Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.

JavaScript – Software Engineering Daily
AI-Powered Threats to the Software Supply Chain

JavaScript – Software Engineering Daily

Play Episode Listen Later Aug 4, 2026 57:21


Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines. Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills. Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.

Open Source – Software Engineering Daily
AI-Powered Threats to the Software Supply Chain

Open Source – Software Engineering Daily

Play Episode Listen Later Aug 4, 2026 57:21


Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines. Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills. Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.

Cloud Engineering – Software Engineering Daily
AI-Powered Threats to the Software Supply Chain

Cloud Engineering – Software Engineering Daily

Play Episode Listen Later Aug 4, 2026 57:21


Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines. Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills. Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.

Podcast – Software Engineering Daily
AI-Powered Threats to the Software Supply Chain

Podcast – Software Engineering Daily

Play Episode Listen Later Aug 4, 2026 57:21


Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines. Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills. Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.Sponsorship inquiries:sponsor@softwareengineeringdaily.com The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.

Engineering Kiosk
#279 Professionelle Embedded Entwicklung & Echtzeitbetriebssysteme (RTOS) mit Roland Lezuo

Engineering Kiosk

Play Episode Listen Later Aug 4, 2026 89:01


Wie entwickelt man Software, wenn ein Breakpoint das Systemverhalten verfälscht, Speicher knapp ist und ein Update nicht einfach per Knopfdruck ausgerollt werden kann? Genau in diese Welt tauchen wir in dieser Episode ein. Wir sprechen über Real Time Operating Systems, Embedded Systems, Mikrocontroller und die Frage, was Echtzeit in der Praxis wirklich bedeutet.Mit Roland Lezuo schauen wir hinter die Kulissen moderner Embedded Entwicklung. Es geht um RTOS, Linux mit Echtzeitfähigkeit, Interrupts, harte und weiche Deadlines, PCB Design, Firmware in C, Treiber, Debugging mit Oszilloskop, Tracing auf Hardware-Ebene und die Realität von Testing und Continuous Integration im Embedded Umfeld. Außerdem klären wir, warum ein smartes Fernglas ein ziemlich gutes Beispiel für anspruchsvolle Echtzeitsoftware ist und weshalb Hardwareprojekte oft ganz andere Kompromisse verlangen als Cloud-Software oder klassische Backend Entwicklung.Zum Schluss sprechen wir über Updates und Over the Air-Update-Szenarien, den Cyber Resilience Act und darüber, wie du selbst in Embedded Software einsteigen kannst, ohne gleich ein Labor voller Spezialhardware aufzubauen. Wenn du wissen willst, warum C, Echtzeitbetriebssysteme und Embedded Linux noch lange nicht von gestern sind, dann ist diese Folge genau dein Ding.Bonus: Print-Debugging mit Oszilloskop ist wirklich so wild, wie es klingt.Unsere aktuellen Werbepartner findest du auf https://engineeringkiosk.dev/partnersDas schnelle Feedback zur Episode:

CISSP Cyber Training Podcast - CISSP Training Program
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 3, 2026 46:08 Transcription Available


Send us Fan MailA breach can hit your headlines even when your own systems never get touched, and that's exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputation problem that security teams have to own.From there, we zoom out to the bigger pattern behind modern supply chain security: attackers increasingly go after dependencies, CI/CD pipelines, shared developer tools, and widely used vendors because one compromise can cascade across hundreds of customers. We talk about how to reduce that exposure with a stronger TPRM program, including vendor risk tiering, continuous monitoring, SBOM thinking, and practical contractual controls like breach notification timelines, right to audit language, and clear subcontractor disclosure with flow-down requirements to address fourth-party risk.We also shift into CISSP Domain 1 rapid review mode: what the exam really wants when it asks about due diligence, evidence, and proportional risk decisions. You'll hear clean explanations of SOC 2 Type 1 vs SOC 2 Type 2, where ISO 27001 fits, why questionnaires like SIG are not proof, and which frameworks matter for third-party and supply chain risk management including NIST 800-161, ISO 27036, and NIST CSF 2.0. We close with practice scenarios that mirror common CISSP traps so you can spot them fast.Subscribe for more CISSP training, share this with a study partner, and leave a review so more security pros can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

Cloud Posse DevOps
Cloud Posse DevOps "Office Hours" (2026-07-29)

Cloud Posse DevOps "Office Hours" Podcast

Play Episode Listen Later Jul 31, 2026 63:28


Cloud Posse holds LIVE "Office Hours" every Wednesday to answer questions on all things related to AWS, DevOps, Terraform, Kubernetes, CI/CD. Register at https://cloudposse.com/office-hoursSupport the show

Scrum Master Toolbox Podcast
Coaching the Outsider In—Helping a Distrustful Team Through Transformation | Danil Chernyshev

Scrum Master Toolbox Podcast

Play Episode Listen Later Jul 29, 2026 17:48


Danil Chernyshev: Coaching the Outsider In—Helping a Distrustful Team Through Transformation Read the full Show Notes and search through the world's largest audio library on Agile and Scrum directly on the Scrum Master Toolbox Podcast website: http://bit.ly/SMTP_ShowNotes.   "Developers and QAs know each other very well, but they don't trust anybody else." - Danil Chernyshev   This week's coaching conversation starts with a hard situation. A subcontractor's developers—people who had always worked isolated from the business, with no plans and no communication—were brought back inside the "mother firm" as part of a digital transformation. Overnight they faced new teams, Scrum, SDLC, CI/CD, and full transparency. The developers and QAs trusted each other completely and trusted no one else: not the Scrum Master, not the Product Owner, not the BAs. Forced to estimate with story points, every story came back as a 3 or a 5, with no conversation. When Danil asked why, the answer was always "we'll discuss internally and tell you tomorrow"—he suspected a second, hidden daily Scrum without him. As he and Vasco unpack it, the real issue is transparency itself: a team used to hiding now feels exposed and doesn't know the consequences of being open. Vasco offers an experiment—build a "trio" of the Product Owner, the Scrum Master, and one friendly insider from the team to prepare refinements together. The Product Owner is always the outsider; pairing them with a trusted insider lets ideas and experiments spread faster. Before you can improve the Scrum, you first have to bring the outsiders in.   Self-reflection Question: Where on your team is trust the real bottleneck—and who is the "insider" who could help an outsider earn it?   [The Scrum Master Toolbox Podcast Recommends]

Dev Interrupted
Why the traditional pull request has a target on its back | CircleCI's Rob Zuber

Dev Interrupted

Play Episode Listen Later Jul 28, 2026 44:16


The traditional pull request was built for human eyes, but in an era of autonomous AI agents, it officially has a massive target on its back. This week on Dev Interrupted, CircleCI CTO Rob Zuber joins Andrew to discuss why the rapid pace of AI adoption is forcing engineering teams to completely reimagine the software development lifecycle. They explore the shift toward an accountability-oriented model for code review, how CI/CD validation is moving directly into the local agent loop, and the very real financial dangers of unchecked token budgets. Finally, Rob shares his playbook for leading organizations through this chaotic transition without burning out your developers (or your token budget). We recommend pairing his strategy with something like AI code review to find the floor for your newly-agentic engineering org's output.Register today: The Engineering Productivity Gap live workshop on July 30Follow the show:Subscribe to our Substack Follow us on LinkedInSubscribe to our YouTube ChannelFollow the hosts:Follow AndrewFollow BenFollow DanFollow today's guest:CircleCI: Explore the leading continuous integration and delivery platform at circleci.comThe Confident Commit: Subscribe to Rob's newsletter and podcast for data-backed software delivery insights on CircleCI's websiteThe Confident Commit Podcast: Listen to Rob's podcastState of Software Delivery: Read CircleCI's annual report analyzing millions of CI workflows to benchmark your team's performanceGather.dev: Apply to join the curated, invite-only community for senior engineering leaders at gather.devFollow Rob: LinkedIn OFFERSStart Free Trial: Get started with LinearB's AI productivity platform for free.Book a Demo: Learn how you can ship faster, improve DevEx, and lead with confidence in the AI era.LEARN ABOUT LINEARBAI Code Reviews: Automate reviews to catch bugs, security risks, and performance issues before they hit production.AI & Productivity Insights: Go beyond DORA with AI-powered recommendations and dashboards to measure and improve performance.AI-Powered Workflow Automations: Use AI-generated PR descriptions, smart routing, and other automations to reduce developer toil.MCP Server: Interact with your engineering data using natural language to build custom reports and get answers on the fly.

DevTalles
266 - 40 conceptos esenciales de DevOps y Cloud

DevTalles

Play Episode Listen Later Jul 26, 2026 32:42


40 conceptos esenciales de DevOps y Cloud: un recorrido rápido por los términos que todo programador debería reconocer, desde cultura DevOps y CI/CD hasta contenedores, infraestructura en la nube, observabilidad y seguridad.

The Cyber Threat Perspective
Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

The Cyber Threat Perspective

Play Episode Listen Later Jul 24, 2026 27:41


Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you.Brad and Jordan cover both sides of supply chain risk: the trusted third-party applications you deploy (SolarWinds being the case that put this category on the map) and the open-source components you pull into your own code without always knowing what's inside. They explain why AI and vibe coding are accelerating the problem, why jQuery is the modern-day Flash, and why "just upgrade the package" is rarely that simple.From there it gets practical:What a Software Bill of Materials (SBOM) is and why you need oneTransitive dependencies — the packages hiding beneath your packagesBuilding security checks into your CI/CD pipeline and shifting leftWhy a flaw caught in static analysis can cost ~$200, while the same flaw found in a pen test can cost $20,000+Why a pen test should validate your controls, not be your first line of defenseHow SecurIT360's Project Lantern and ChainGarde automate SBOM analysis against known and actively-exploited vulnerabilitiesA playbook for vetting vendors, writing accountability into contracts, and holding third parties responsible for actually fixing findingsThe takeaway: whether you're writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have.Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaYPart 2 — Security Misconfigurations: https://youtu.be/Po8H140BijENeed a web app pen test? SecurIT360 | Cybersecurity From Every Angle More content: https://offsec.blogBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Kubernetes Podcast from Google
Navigating AI Guidelines in Kubernetes, with Kat Cosgrove and Natali Vlatko

Kubernetes Podcast from Google

Play Episode Listen Later Jul 22, 2026 50:39


In this episode, Kat Cosgrove (SIG Docs Technical Lead, SIG Release Subproject Lead, and Steering Committee member) and Natali Vlatko (SIG Docs Co-Chair, Steering Committee member for the TODO Group, and Open Source Architect at Cisco) join hosts Kaslin Fields and Abdel Sghiouar to discuss the newly published Kubernetes AI usage policy. We dive into the legal and administrative reasoning behind the policy—including why AI tools cannot legally sign the Contributor License Agreement (CLA) or co-author PRs—and explore how maintainers manage the influx of "AI slop" PRs, spam comments, and restricted AI note-taker bots in community meetings. The discussion highlights the balance between human accountability and AI as an enhancer, while sharing actionable advice on how new contributors can sustainably get involved with SIG Docs, issue wrangling, and the Kubernetes Release Team. Do you have something cool to share? Some questions? Let us know: web: kubernetespodcast.com mail: kubernetespodcast@google.com twitter: @kubernetespod bluesky: @kubernetespodcast.com News of the week Apple Native Container Tool for macOS 1.0: Apple has shipped version 1.0 of its native container tool for macOS. Built in Swift specifically for Apple Silicon, it departs from traditional shared-VM setups like Docker Desktop by isolating every single Linux container inside its own dedicated micro-VM using the native macOS Virtualization framework. Read more on Cloud Native Now. Google OpenRL: Google launched OpenRL, a new open-source project designed to streamline the training and reinforcement learning loops of large language models. The tool brings declarative, Kubernetes-style resource orchestration concepts to the messy process of AI model fine-tuning. Read more on Cloud Native Now. CNCF Welcomes New Members: At KubeCon CloudNativeCon India, the CNCF announced they added 14 new members, end Users, and non-profit organizations, highlighting the continued growth of the Cloud Native Ecosystem. One of the new members is Loveable, who was a recent guest on the show. We highly recommend you go listen to Episode 268 about the Agent Sandbox. Read the full announcement on PR Newswire. Is a Pod the Right Deployment Unit for an AI Agent?: Lin Sun from Solo published a community post on the CNCF blog questioning whether the classic Kubernetes Pod primitive is still the best abstraction for hosting autonomous, long-running AI agents and introducing Agent-substrate, a project attempting to bring a solution to the table. Read more on the CNCF Blog. Links from the interview Kubernetes AI Usage Policy – Read the community's official guidelines and rules for AI-assisted contributions. TODO Group Steering Committee – A Linux Foundation project bringing OSPO professionals and enthusiasts together. Contributor License Agreement (CLA) – Standard agreement required for all human contributors, which AI agents cannot legally sign. Kubernetes SIG Docs – Get involved with the documentation community. SIG Docs Style Guide – Learn the style guidelines for contributing to Kubernetes docs. Kubernetes SIG Release – Details on how to get involved with the release cycle. Links from the post-interview chat Linus Torvalds on AI LinkedIn Post – Torvalds' clarification on using AI as a helper tool rather than writing kernel C++ code. Devoxx– A popular developer conference in Europe Prowbot GitHub Repo – Kubernetes' main CI/CD bot handling PR automation.

Software Engineering Radio - The Podcast for Professional Software Developers
SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents

Software Engineering Radio - The Podcast for Professional Software Developers

Play Episode Listen Later Jul 22, 2026 54:14


Birgitta Boeckeler, a Distinguished Engineer and consultant focused on AI-assisted software delivery at Thoughtworks, joins host Priyanka Raghavan for a deep dive into harnesses for AI agents. The episode begins by unpacking the concept of harnesses and harness engineering before exploring the core building blocks — guides and sensors — that help AI agents operate more reliably in engineering environments. Priyanka and Birgitta discuss practical implementations of harnesses in real-world workflows, including the use of guides with .MD files and sensors with tools such as SonarQube and Semgrep, which steer agent behavior. The episode also explores how harnesses integrate with existing CI/CD pipelines and pull-request processes. Birgitta describes how stronger harnesses can improve trust in AI-generated code, while emphasizing that harnesses themselves require continuous maintenance as underlying foundation models evolve. The episode concludes with a thoughtful discussion on accountability between humans and agents, along with future directions for harness engineering and AI-assisted software development.

Cloud Posse DevOps
Cloud Posse DevOps "Office Hours" (2026-07-22)

Cloud Posse DevOps "Office Hours" Podcast

Play Episode Listen Later Jul 22, 2026 59:20


Cloud Posse holds LIVE "Office Hours" every Wednesday to answer questions on all things related to AWS, DevOps, Terraform, Kubernetes, CI/CD. Register at https://cloudposse.com/office-hoursSupport the show

Absolute AppSec
Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration

Absolute AppSec

Play Episode Listen Later Jul 21, 2026


In episode 328 of Absolute AppSec, sponsored by GuardSquare (guardsquare.com), Seth and Ken start by highlighting a newly disclosed, pre-authentication WordPress core Remote Code Execution (RCE) vulnerability ("WP2Shell"). The core discussion centers on Alex Gaynor's article regarding the influx of AI-assisted vulnerability disclosures. Gaynor and the hosts argue that attempting to fix bugs case-by-case is a "fool's errand"; instead, engineering teams must eradicate entire vulnerability classes through systemic, framework-level safe functions (such as parameterized queries) and automated CI/CD guardrails. They dive into the complexities of bug prioritization—debating reachability analysis, runtime verification, and business asset criticality—while noting that metrics and measurement remain among the lowest-scoring activities in OWASP SAMM assessments. Later, Ken and Seth examine a "Memory Heist" attack on Claude AI where indirect prompt injection tricked the assistant into exfiltrating user memory and corporate details letter-by-letter through web navigation. They conclude that because transformer models were originally designed for next-token prediction rather than secure system boundaries, defending LLM architectures behaves more like stopping social engineering than traditional software fuzzing.

Follow The Brand Podcast
Software Isn't Written Anymore. It's Manufactured with Darius Radford

Follow The Brand Podcast

Play Episode Listen Later Jul 18, 2026 39:39 Transcription Available


Send us Fan MailMost security teams keep buying tools and still feel behind. That's not because you picked the “wrong” scanner or missed the latest AI feature. It's because many organizations are trying to secure software like it's a one-time project instead of a repeatable manufacturing process. I'm joined by Darius Radford, founder and CEO of Knights Watch Cyber, to make that idea concrete and practical for any software-driven business. Darius breaks down why applications, APIs, CI/CD pipelines, cloud platforms, open source dependencies, and identity are the real battlefield now. He shares the core insight behind what he calls the Secure Software Factory: software isn't “written” anymore, it's manufactured. When you adopt a factory mindset, you build in quality control, governance, automation, standards, metrics, and feedback loops so secure software development becomes consistent instead of heroic. We also walk through the four capabilities he sees as non-negotiable: orchestrated delivery, developer-centric application security tooling, supply chain and artifact management governance, and unified risk correlation that turns endless security data into real context. We go straight at the AI era too. Developers and AI will build the next generation of products together, which makes AI security governance and testing even more urgent. Darius gives practical guardrails for AI-generated code, including input validation, session management, authentication and authorization checks, and permission modeling. We also talk about how a mature DevSecOps approach can help you win deals by proving security by design with repeatable metrics and alignment to common risk frameworks like OWASP. If you build software, lead engineering, or sell into security-conscious customers, this conversation is for you. Subscribe, share this with a builder on your team, and leave a review with your biggest question about secure software development, what are you struggling to make repeatable?Thanks for tuning in to this episode of Follow The Brand! We hope you enjoyed learning about the latest trends and strategies in Personal Branding, Business and Career Development, Financial Empowerment, Technology Innovation, and Executive Presence. To keep up with the latest insights and updates, visit 5starbdm.com.And don't miss Grant McGaugh's new book, First Light — a powerful guide to igniting your purpose and building a BRAVE brand that stands out in a changing world. - https://5starbdm.com/brave-masterclass/See you next time on Follow The Brand!

airhacks.fm podcast with adam bien
Why Coverage Metrics Fail and System Tests Win

airhacks.fm podcast with adam bien

Play Episode Listen Later Jul 17, 2026 60:36


An airhacks.fm conversation with Stanislav Bashkyrtsev about: discussion about testing terminology and the difference between unit tests, component tests, System Tests, and integration tests, defining component tests as in-process invocations without HTTP, using RestAssured with MockMvc-style direct endpoint calls, avoiding mocks in favor of real system tests, why code coverage is a misused management metric, the anti-pattern of using reflection to inflate coverage, distinguishing line and branch coverage from actual verification, using coverage from system tests to detect dead code for pruning, mutation testing with PIT to measure assertion quality, testing Quarkus applications, the default Guice and Guava dependencies in Quarkus RESTEasy, starting a new microservice with a separate system-test module, calling endpoints over HTTP with the MicroProfile REST Client or the Java HTTP client, deploying Quarkus on AWS Lambda as a production-like environment, backward compatibility testing with multiple production versions, turning system tests into stress and load tests, testing connection pools and metrics under load, introducing a test-only private API to verify state changes in serverless systems, contract-driven work in large consulting projects, generating JSON and JSONB directly in PostgreSQL and returning it over JDBC, mapping database rows to Java records instead of DTOs, running GraalVM inside the Oracle Database for stored procedures and table triggers, the pendulum between database-centric and application-centric logic, the convergence of SQL and NoSQL databases, CI/CD pipelines with Jenkins and manual production deployment steps, avoiding Jenkins access to production via CGI shell scripts behind nginx, AWS CodePipeline and CodeBuild with CDK-defined infrastructure, event-driven pipelines triggered by S3 put-object events, multi-account roles with short-lived STS credentials, the size of the AWS SDK and reducing it by excluding unused HTTP clients, health checks and Kubernetes liveness and readiness probes, why health checks make little sense for short-lived Lambdas, a version endpoint for deployment smoke tests Stanislav Bashkyrtsev on twitter: @sbashkirtsev

alphalist.CTO Podcast - For CTOs and Technical Leaders
#142 Why LLMs Need Their Own Programming Language: From Assembly to AI with Vaibhav Gupta // Co-founder @ BAML

alphalist.CTO Podcast - For CTOs and Technical Leaders

Play Episode Listen Later Jul 16, 2026 64:54 Transcription Available


Sponsored by Blocks: Save at least 20% on your AWS costs with AI-powered optimization and enterprise discounts. Get your free Cloud Check at blocks.cloud/alphalist → https://blocks.cloud/alphalist?utm_source=alphalist&utm_medium=podcast&utm_campaign=blocks-podcast-2026 Vaibhav Gupta built computer vision for the original Microsoft HoloLens, optimized AR at Google, and wrote high-performance assembly at D.E. Shaw, then left it all to start from scratch. After a YC pivot away from a Slack competitor he was told not to build, he landed on something foundational: BAML, a programming language for a world where humans increasingly don't read code. His thesis: every software leap came from a new compute paradigm getting its own language assembly, C, Java, JavaScript and LLMs are the next primitive. They're probabilistic and non-deterministic, which breaks our deterministic tooling. In this episode, Vaibhav explains why "shipping at agent speed" is really a problem of trust and control, why 90% of engineering is plumbing AI will delete, why "English as a programming language" can't work, and why the world has a mathematically infinite appetite for software. Topics covered: - Why LLMs are a new compute primitive and why that justifies a new language - BAML: an embedded, type-safe language for structured LLM outputs across any language - Shipping at agent speed as a problem of trust, locking, and granular control - Why traditional CI/CD breaks in an agent loop - The "data trench" one type system across code, backend, and data - Why 90% of engineering is plumbing, and what changes when AI removes it - Where SaaS pricing and product models are heading

Python Bytes
#488 tau - it's 2pi and it writes code

Python Bytes

Play Episode Listen Later Jul 14, 2026 32:15 Transcription Available


Topics covered in this episode: The trusted-publishing debate: how to do it right vs. why you shouldn't trust it JupyterLab 4.6 and Notebook 7.6 are out! Tau – new small, readable terminal coding agent Django Tasks and Django 6.1 Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: The trusted-publishing debate: how to do it right vs. why you shouldn't trust it https://snarky.ca/how-to-publish-to-pypi-using-github-actions-securely/ (Brett Cannon) and https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing (William Woodruff) Trusted Publishing (PyPI's OIDC-based auth scheme, also now used by npm, RubyGems, crates.io, NuGet) replaces long-lived API tokens with short-lived, auto-scoped credentials tied to CI/CD machine identity. Yossarian's post: it's purely an authentication mechanism between a machine identity and a package — it says nothing about package safety or quality. PyPI deliberately avoids any "verified/trusted" badge for it, unlike its verified-URL checkmarks. Same logic applies to PyPI attestations: anyone can sign with any machine identity they control, so an attestation's presence isn't itself a trust signal. Bottom line from that post: don't confuse "trusted" (machine-to-machine) with "trustworthy" (human judgment about the package). Snarky.ca's companion piece is more practical: given GitHub Actions compromises in the news, the real fix is 3 concrete steps — run zizmor to lock down workflow permissions/checkout credentials and pin actions to commit hashes, adopt Trusted Publishing to eliminate stored PyPI tokens, and require manual approval via a GitHub environment before any publish job runs. Takeaway for listeners: Trusted Publishing is good hygiene for how you authenticate to PyPI, but it's not a substitute for securing your CI pipeline itself — or for actually vetting the packages you install. Michael #2: JupyterLab 4.6 and Notebook 7.6 are out! Michał Krassowski's rundown - a chunky minor release: 68 features, 97 bug fixes, 95 contributors, one of the biggest ever. Scratchpad console (Notebook 7.6 headliner) - a console next to your notebook sharing its kernel, for throwaway experiments. Ctrl+B. Jump to last-edited cell - new commands hop through recently edited cells. File browser glow-up - Date Created column, editable breadcrumbs with Tab-completion, and Open in Terminal. Debugger - sources open in the main area, floating step/continue overlay, live kernel-sources filter. Custom layouts (Lab) - activity bar top/bottom, draggable panels, four-way tab splits, per-panel Ctrl+scroll zoom. ~5x faster extension builds - webpack → Rspack, and jupyter-builder means no full Lab install needed to build extensions. Keyboard/a11y - add shortcuts from the UI (no JSON), Find & Replace in Edit menu (Ctrl+H). Calvin #3: Tau – new small, readable terminal coding agent Tau – new small, readable terminal coding agent (Python 3.12+), built as both a working tool and a teaching project for how coding agents work under the hood Install via uv tool install tau-ai, pipx, or pip; ships a tau CLI Three-layer architecture: tau_ai (provider-neutral model layer) → tau_agent (reusable "brain": messages, tools, events, loop) → tau_coding (CLI/TUI, file & shell tools, sessions) Supports OpenAI, Anthropic, OpenAI Codex, OpenRouter, Hugging Face, and custom/local OpenAI-compatible endpoints Built-in tools (read/write/edit/bash), durable JSONL sessions with resume/branching, project instructions via AGENTS.md, and context compaction Core harness is UI-agnostic — same brain can power the TUI, print mode, or a custom frontend — usable as a standalone library too Michael #4: Django Tasks and Django 6.1 Django 6.0 finally ships first-party background tasks (django.tasks) - out of Jake Howard's DEP 14, accepted May 2024, after two decades of everyone bolting on Celery/RQ/Huey. It's an API, not a worker. Django handles task definition, validation, queuing, and result storage - it does not execute them. You bring the backend. The default backend traps people. ImmediateBackend runs tasks inline on the request thread and blocks until done - so out of the box .enqueue() backgrounds nothing (a 5-second task means a 5-second response). The other built-in, DummyBackend, runs nothing at all. Both are dev/test only. Nice API otherwise: slap @task on a function, call .enqueue(), get back a TaskResult you look up later by id - with async twins like aenqueue(). Gotcha: args and return values must survive a JSON round-trip, so a tuple sneakily comes back as a list. The community local backend to know: django-tasks-local by Chris Beaven (SmileyChris). A ThreadPoolExecutor backend that gives real background threads with zero infrastructure - no Redis, no Celery, no database - plus a ProcessPoolBackend for CPU-bound work → github.com/lincolnloop/django-tasks-local Its catch: results live in memory, so pending tasks vanish on restart or deploy. Great for dev and low-traffic production; for persistence, drop to Jake Howard's django-tasks (DatabaseBackend + worker command). Extras Calvin: Fixing the dictionary with Python 3.14 — Hugo van Kemenade stumbled on - and got fixed - a markup bug in the OED's own citation of a 1706 use of the pi symbol. Michael: Bunny DNS is now free Jokes: What's the object-oriented way to become wealthy? Inheritance To understand what recursion is... You must first understand what recursion is 3 SQL statements walk into a NoSQL bar. Soon, they walk out They couldn't find a table.

Paul's Security Weekly
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467

Paul's Security Weekly

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-467

Enterprise Security Weekly (Audio)
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-467

Paul's Security Weekly TV
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - François Proulx, John Pritchard, Cassie Christensen, Jaime Lewis-Gross, Kim Brown - ESW #467

Paul's Security Weekly TV

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Show Notes: https://securityweekly.com/esw-467

Enterprise Security Weekly (Video)
Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - François Proulx, John Pritchard, Cassie Christensen, Jaime Lewis-Gross, Kim Brown - ESW #467

Enterprise Security Weekly (Video)

Play Episode Listen Later Jul 13, 2026 98:59


Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines". Segment Resources: Smoked Meat announcement Smoked Meat github Smoked Meat demo with Guillaume and François Identiverse Interview with Dr. John Prichard from Radiant Logic The Three Identity Problem: Surviving Identity Security's Chaotic Era Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security. In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments. To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv. Identiverse Interview with Cassie Christensen from Saviynt Everyone Wants an AI Assistant. Few Are Ready to Govern One Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Jaime Lewis-Gross from Saviynt From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries. This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv Identiverse Interview with Kim Brown from LexisNexis Stop Identity Fraud: Modern Strategies for Insurance and Healthcare Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction. This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them! Show Notes: https://securityweekly.com/esw-467

Latent Space: The AI Engineer Podcast — CodeGen, Agents, Computer Vision, Data Science, AI UX and all things Software 3.0
Why AI Infrastructure must evolve for Agent Experience — Akshat Bubna, Modal CTO

Latent Space: The AI Engineer Podcast — CodeGen, Agents, Computer Vision, Data Science, AI UX and all things Software 3.0

Play Episode Listen Later Jul 8, 2026 57:55


We've been running a bit of an Agent Cloud series surveying all the top inference/compute/cloud providers, from Databricks to Daytona to Railway and, even further back, E2B, but we're excited to conclude this series returning to Modal, which has just raised a monster $355M Series C.The cloud was built for developers. But agents are now changing that.The old infra stack was designed for a human who could read docs, reason through YAML, and understand dashboards to figure out what they need when something broke. While this was painful for developers, it worked since they could fill in missing context in their heads.However, agents don't have that luxury. Now in this new era of agents, everything has to be tighter.They need a place to write code, run it, inspect the output, change the environment, debug failures, and try again. Fast iteration and feedback loops with all the necessary context are crucial for agents to operate properly. Furthermore, sandboxes are a clear representation of this shift as agents can easily spin up isolated environments. This programmatic infra even extends to research:Two years ago, we were one of the first to cover Modal with CEO Erik Bernhardsson and Alessio designed our favorite LS thumbnail of all time:At the time, Modal was just a teeny little company with a $17M Series A.Today, fresh off their $355M Series C, Modal is one of the clearest examples of the agent cloud future being built in real time: a cloud platform moving past traditional web app assumptions toward the workloads AI actually creates such as elastic inference, sandboxes, GPU burst, post-training, background agents, and infrastructure that agents themselves can operate.In this episode, Modal CTO Akshat Bubna joins swyx and Vibhu to unpack why AI applications don't fit traditional cloud assumptions, why Kubernetes was never designed for bursty compute-heavy workloads, and why Modal is now shifting from developer experience to agent experience.We go deep on Modal's AI infra stack: serverless functions, decorator-based infrastructure, elastic inference for custom models, GPU snapshotting, DeFlash, speculative decoding, Auto Endpoints, sandboxes, persistent storage, networked containers, private IPv6, RDMA, multi-node training, and Modal's capacity pool across 17 cloud providers. Akshat also explains why RL rollouts can require 100,000 sandboxes, why production agents need hard guardrails, why observability may matter more than reading code, and why AI has made infrastructure exciting again.We discuss:* Why Kubernetes wasn't built for bursty AI workloads* How Modal started as a better runtime before becoming an AI cloud* Why Modal added GPUs before ChatGPT* The shift from developer experience to agent experience* Why observability matters when agents are writing the code* Elastic inference for custom models across audio, video, robotics, and comp bio* GPU snapshotting, cold starts, and why inference workloads are so bursty* Why RL rollouts can require 100,000 sandboxes* DeFlash, speculative decoding, and frontier-level inference performance* Auto Endpoints and making optimized inference easier to deploy* What Modal adds beyond vLLM, SGLang, and raw GPU rental* Modal's 17-cloud capacity pool and supercloud strategy* Networked sandboxes, sidecars, private IPv6, and RDMA* Serverless multi-node training for post-training and research workloads* Auto-research, model-guided sweeps, and agents launching GPU experiments* Compute strategy, capacity planning, and batch tiers* Why production agents need specialized sandboxes and hard guardrails* Modal's take on managed agents, CI, Gitpod/Ona, Python, TypeScript, and Modal BenchAkshat Bubna* LinkedIn: https://www.linkedin.com/in/akshat-bubna-188885103* X: https://x.com/akshat_bModal* Website: https://modal.comTimestamps00:00:00 Introduction00:00:39 Modal's origin and why Kubernetes wasn't enough00:04:32 Developer Experience → Agent Experience00:06:21 Modal's AI cloud primitives00:09:14 Sandboxes, agent loops, and proto-Cognition00:12:12 Elastic inference, GPU snapshotting, and 100,000 sandboxes00:15:24 DeFlash, speculative decoding, and Auto Endpoints00:19:59 Production-grade inference beyond raw GPUs00:22:00 Background agents, Ramp Inspect, and the agent lifecycle00:24:08 Modal's 17-cloud supercloud strategy00:26:40 Networked sandboxes, private IPv6, and RDMA00:32:48 Multi-node training, post-training, and auto research00:37:36 Compute strategy, capacity planning, and batch tiers00:40:55 Open models, real-time AI, and production agent infra00:43:06 Hard guardrails, managed agents, and specialized sandboxes00:46:06 Why AI made infrastructure exciting again00:48:30 Model APIs, differentiated products, and agentic video00:51:50 CI, coding-agent infra, SDKs, and Modal Bench00:57:28 Closing ThoughtsTranscriptIntroduction: Modal, Series C, and the Art PartySwyx [00:00:00]: We're here with Akshat, CTO of Modal, together with Vibhu. Congrats on your Series C.Akshat [00:00:10]: Thank you.Swyx [00:00:11]: Your party yesterday was amazing.Akshat [00:00:15]: Yeah.Swyx [00:00:15]: From all the photos and all the swag.Akshat [00:00:17]: We had a bunch of art installations, which was fun, seeing, like, our products on pedestals next to, like, Rodin.Swyx [00:00:25]: Very nice. Very nice. When you started, it was not the GPU inference company. Maybe it was in your mind. Take us back to the origin story.Modal's Origin: A New Runtime Beyond KubernetesAkshat [00:00:39]: I first met Eric, who's the CEO, through an investor. Back then Eric was already thinking about building, a new runtime, and he got there thinking through why are workflow orchestration products so hard to use. It's because you have to run them on Kubernetes. Kubernetes is hard to manage. It's not built for burstiness and, custom images,Swyx [00:01:03]: YeahAkshat [00:01:03]: It has a terrible developer experience.Swyx [00:01:05]: And I'll, I'll interjectAkshat [00:01:06]: YeahSwyx [00:01:07]: For listeners, who are new, we interviewed Eric two years ago, and there's a bit more of the story there from Spotify and all those things.Swyx [00:01:14]: And I came across Eric through Data Council because he did that talk on the serverless container stack that you guys did, which was like, that was my first like, “Okay, I need to take Modal very seriously” moment.Akshat [00:01:26]: Yeah.Swyx [00:01:26]: But it was still very unclear, like, do I need all this for just my data pipelines?Akshat [00:01:33]: Yeah. initially what we were thinking about was if we build a better runtime, it's a very useful primitive in itself. It's There's a lot of things that, get solved by serverless functions, like you can do, ETL stuff, you can do job queues, you can do all this, like, bursty processing, which it turns out every company had needs for. but then we also were thinking about this as like, this is a primitive that we can build a whole collection of products on, which are very verticalized. So perhaps data engineering would've been the first one, but we were thinking about inference. Back then it was more classical inference, like computer vision stuff and running XGBoosts and whatnot. But we added GPUs to the product a year before ChatGPT came out.From Serverless Containers to GPU WorkloadsSwyx [00:02:19]: Nice.Akshat [00:02:19]: We just didn't think it would be that big of a deal.Swyx [00:02:22]: Yeah, just like add A100.Vibhu [00:02:23]: Was there any, like, early key problem that really sparked off why you built it?Akshat [00:02:28]: Yeah. Primarily it's just, none of the tooling that was out there was built for, one, a really great developer experience, and also there's a general trend of, a lot of the workloads that we were seeing were very. I wish there was a better word for it, but compute-heavy. Like, they need, one, like, need a lot more resources, so you need to burst up and down a lot, versus like Kubernetes designed for, like, slow scaling and, more for, like, web server use cases. And also there's just a lot more specialization in, like, what kinds of environments these workloads run in. Like, we had sometimes they need accelerators, sometimes they need different kinds of images, and this is just like a consistent thing that we saw across a lot of companies. That would be the next step.Software-Defined Infrastructure and Decorator-Based DXSwyx [00:03:13]: Yeah. Yeah. Be nice. I don't know how much this factored into the early story, but I wrote a post when I was at Temporal about infrastructure, software-defined infrastructure or something like that.Akshat [00:03:22]: Yeah, the self-provisioningSwyx [00:03:23]: Self-provisioning.Akshat [00:03:24]: Yeah.Swyx [00:03:24]: Yeah. I can't even remember my own post.Swyx [00:03:26]: And then you put me on the landing page.Akshat [00:03:28]: Yeah. We really like, the term and so we stole it.Swyx [00:03:32]: Because you had the insight that everything can just be in decorators co-located with the code, right?Akshat [00:03:37]: Yeah.Swyx [00:03:37]: Was that a big part of the originalAkshat [00:03:39]: YesSwyx [00:03:39]: Story or it was just like a DX layer?Akshat [00:03:41]: That was, really important because we really didn't want people to spend, so much time, writing YAML, and it seemed like you could really condense the surface area of what you're doing, put it in code so you can operate on it just like you operate on other code, and like build stuff that's more expressive and dynamic. and so yeah, that was always a very important part.Swyx [00:04:04]: Then the pushback is this is a DSL.Akshat [00:04:07]: Yeah.Swyx [00:04:07]: It's you're closed source. I am locked into Modal.Akshat [00:04:11]: Yeah. We never really got pushback for that because the nice thing about Modal is you can bring whatever code you have, and sure, the DSL is at the configuration layer for, what hardware you're using, how you're scaling things up, but you still own the code.Akshat [00:04:27]: And that's, that's been an important, part of our story, even as we do inference now.Swyx [00:04:32]: Yeah.Vibhu [00:04:32]: How much of do you think still stays the same today? Like if you were to build something today, DevX very important, but I feel like, a lot of this has been changed with just hook it up to an agent, have Claude Code, have Codex implement a tool. there's very agent native primitives that are different than if I'm doing this myself, right?Developer Experience → Agent ExperienceAkshat [00:04:54]: We've changed our SDK team to think about agent experience instead of, developer experience and we think that the same benefits that apply for DX also apply for AX, which is why would you have an agent read through hundreds of Kubernetes files and like write YAML that's not even typed when it can make a couple of changes in a decorator and it gets this self-provisioning runtime of, being able to see its changes live in action? yeah, it just seems from the customers we talk to, they find Modal is much faster for agents to use versus operating on a different substrate.Swyx [00:05:34]: Yeah, because like you, again, you co-locate the infrastructure requirements to the code that runs it.Akshat [00:05:38]: Yeah.Swyx [00:05:38]: Well, the negative thesis now is that nobody's looking at their code anymore, so there's no point.Akshat [00:05:44]: Yeah, people aren't looking at code. one thing we still see is really important is observability.Swyx [00:05:51]: Yeah.Akshat [00:05:51]: Like how good is your dashboard? And of course, like we have, we push a lot of it to the CLI so the agents can do their own investigation, but you still need humans to go interpret what's going on and, make judgment calls and whatnot. and that's I feel like, Maybe more important now than looking at the code itself.Swyx [00:06:11]: Yes, because like, you can try to treat the code as a black box and then use, see the observable action that comes out of it, and then just prompt a change.What Modal Is For: AI Cloud PrimitivesAkshat [00:06:21]: Yeah.Swyx [00:06:22]: So I think it takes a bit of restraint to not specialize, to say, “I want to ship a new primitive,” and then just be general purpose.Swyx [00:06:31]: People ask you, “What are you for?” You're like, “ I don't know. We can do this, we can do that.”Vibhu [00:06:36]: Well, I'd be curious to see, like, okay, if we were to ask you, like, what is Modal for even at a high level? There's a lot you guys do, sandboxes, GPUs, everything. How do you answer?Akshat [00:06:46]: Modal is a cloud platform that's built for, where we've built the primitives from scratch for AI applications. and right now it covers, inference, training, batch processing, and sandbox workloads.Akshat [00:07:00]: But we're building a lot moreSwyx [00:07:02]: I noticed you didn't say web server, so there is still a role for, like, the always-on large-scale Kubernetes type things.Akshat [00:07:09]: Yeah, absolutely. We're, we're not trying to compete with the renders of the world, because yeah, we think the differentiator for us is the, are the workloads that need specialized compute, need to scale up and down a lot. yeah, they're, they're, they're just shaped differently.Working Alongside Frontier StartupsVibhu [00:07:26]: I think you're building a lot of it alongside the startups, right? They're innovating quite a bit, even in your, like, latest blog post. Like, even in the series C, the customers that you mention here, the cognitions, technical ones, ramps and whatnot, they're, they're innovating with you, right? And that's not something AWS is doing directly with.Akshat [00:07:45]: Yeah, absolutely. I think, this is again classic. We're a small team. We can move really fast. our engineers are working with our customers and figuring it out. Yeah.Swyx [00:07:54]: So my first week at Cognition, I walked in, there was someone wearing a Modal shirt. I was like, “What are you doing here?” They're like, “Yeah, I just. I am embedded inside of Cog.”Akshat [00:08:05]: Yeah, I think that was Peyton. We sent him overSwyx [00:08:07]: Yeah.Akshat [00:08:07]: Because, the latency of communication was too high otherwise.Swyx [00:08:12]: Yeah, distributed node, you have to - you have to place one and collocate.Vibhu [00:08:16]: Yeah.Swyx [00:08:16]: So I had a, I had direct personal experience, right? So I worked on smol developer three years ago. it was inspired by Claude 1. I think you onboarded me at some point, like, just before, and I was like, “Oh, like, I need some bursty compute. Like, I was just gonna try using Modal.” And it was a, it was a pretty pleasant experience. apparently, I showed up in the board meeting, like the analytics.smol developer, Sandboxes, and Proto-CognitionAkshat [00:08:39]: Yeah, you blew up on Hacker News and,Swyx [00:08:41]: YeahAkshat [00:08:41]: We got a big traffic spike. I. I think the way you used smol developer was Modal functions for running stuff, which was. Like, the, that was a good use case. but then, yeah.Swyx [00:08:53]: Yeah. That - So to me, that was proto-cognition.Akshat [00:08:55]: Right.Swyx [00:08:56]: If only I had, like, stuck to it.Swyx [00:08:58]: Like, that was like, if - did you say draw the tech treeAkshat [00:09:00]: AbsolutelySwyx [00:09:00]: You're just like, “Yeah, like, probably this will happen.”Akshat [00:09:02]: Yeah. Like, he was so close. You were just rebuilding upon usSwyx [00:09:04]: I just didn't realize.Akshat [00:09:05]: But the funny story there is at the same time, we were talking to a bunch of customers who needed something like sandboxing.Swyx [00:09:14]: Yeah.Akshat [00:09:14]: This is like twenty-three.Swyx [00:09:15]: Yeah.Akshat [00:09:16]: So we builtSwyx [00:09:17]: You introduced a new API right after that.Akshat [00:09:18]: Yeah.Swyx [00:09:19]: Yes.Akshat [00:09:19]: Like, we built sandboxes in May of twenty-three before anyone was even knew this was gonna be a thing. And the first example we published was, we took smol developerSwyx [00:09:28]: Smol developerAkshat [00:09:28]: And put it in a loop, so the agent can iterate on itself.Swyx [00:09:33]: Loops are hot these days.Vibhu [00:09:34]: It's the looper.Akshat [00:09:34]: Yeah.Vibhu [00:09:35]: Loops in. When was this, twenty-three?Akshat [00:09:38]: Yeah.Vibhu [00:09:39]: A small check.Akshat [00:09:39]: Yeah.Swyx [00:09:39]: It's like twenty-three. so the. the, those for listeners, like, the problem was the models are not built for any of this, right?Swyx [00:09:46]: Like, you're just trying to like. They're not post-training to understand, like, looping and, like, self-correction and tool calling was there, but, like, also not that great.Akshat [00:09:55]: Yeah.Akshat [00:09:55]: I don't remember if you used tool calling in this one, but yeah, the models would just diverge after like ten iterations and not produce anything meaningful.Swyx [00:10:03]: Yeah. But like, then. So okay, like now talking to myself three years ago, the answerVibhu [00:10:08]: Of course they will get betterSwyx [00:10:09]: Collect all the failures, build benchmark, and then collect all the, examples, build the RL environmentAkshat [00:10:15]: RightSwyx [00:10:15]: Sell it for like ten billion dollars to Meta.Swyx [00:10:17]: And then also train a model and then sell that for sixty billion dollars to Elon. And this isAkshat [00:10:23]: Yeah, of courseSwyx [00:10:23]: The funny machine. Like, it's like, it's about the hardware.Akshat [00:10:28]: It's hard to have that inherent conviction that the stuff will get that much better.Swyx [00:10:33]: In retrospect, it's so f*****g obvious.Akshat [00:10:36]: Fair enough.Swyx [00:10:37]: Like, what else were we doing back then? I don't know. anyway. Yeah. So this. That was the start of your sandboxing journey, right? I feel like it didn't blow up until, like, last year.Akshat [00:10:49]: Yeah.Swyx [00:10:50]: So there was like a couple years of quietness.Akshat [00:10:52]: Exactly, yeah. We wereVibhu [00:10:53]: I think very underrated product value. Like, my experience with Modal, Charles, before he had joined Modal, met this guy at a hackathon, and he really insisted we wanted to run some small model, not hosted anywhere, and he's like, “ there's this cool company, Modal. They'll like spin up a GPU sandbox, we can throw it on there. They'll take a Hugging Face link.” And like there's so much value just right there, right? Like instant hosting, spin it up, spin it down. It'll stay cold, but we run the demo a few days later, it'll come back up and like all this stuff in retrospect, like it's still what we needed like today.Akshat [00:11:27]: Yeah, it's still needed today. workload shapes have changed a lot as, we run stuff for people with really massive production scale and, there it's it's not about scaling from zero to one, but it's how do we scale really elastically, from like thousand to fifteen hundred GPUs very quickly in a given region. It's the same shape problem.Elastic Inference, GPU Autoscaling, and Custom ModelsVibhu [00:11:50]: Okay. So you look at, say, Cursor Composer, right?Akshat [00:11:53]: Yeah.Vibhu [00:11:53]: They had a. “We'll do RL on a model every couple hours.” you guys have a whole version of RL inference gym and whatnot.Vibhu [00:12:01]: When you look at workloads like that, you're doing train runs where you need to scale up, scale down every hour thousands of GPUs, right? That's the example for we do need it, right?Akshat [00:12:12]: Yeah. Well, so I'll, I'll take a step back and, maybe talk about like how people use Modal today. because our biggest use case is, elastic inference. And the thing we first found product market fit, with was inference for custom models. So we stayed away from the LLM space, and we were serving companies like Suno for audio, Runway for video, robotics, comp bio companies that train their own model elsewhere. But Modal is the best black box that for deployment, scaling to however many GPUs you need as your traffic pattern changes. And we saw all of them like have a very unpredict- predict- predictable, traffic pattern. it's like diurnal. It's Some days, like the company will do a launch and, they'll need like, way more. And it's not just one model that they deploy. They-- all these companies deploy, lots of different models in different regions, and so the autoscaling problem becomes even harder because then you have to scale within a certain region, and those cycles are offset. So different times you scale up in different regions.Akshat [00:13:20]: So that's like our sortVibhu [00:13:22]: And thatAkshat [00:13:22]: YeahVibhu [00:13:22]: That in and of itself is a huge category. There's a bunch of inference providers which, provide this fireworks, does this as a service together, whatnot, Base10. that's carved into its own niche for language models, at least right now.Akshat [00:13:36]: Yeah. the thing that we have specialized in is the autoscaling aspect.Vibhu [00:13:41]: Yeah.Akshat [00:13:41]: Because we found that it's not universally true that everyone else can autoscale, and we've gone deeper into it on the tech side by, we've incorporated GPU snapshotting into the product so we can take the GPU state, like your torch.compile model, snapshot it, and the next cold start is way faster. And so going back to your question, it's That's why you need a lot of burstiness for inference. But then people also do a lot of demand training, like for RL stuff, your rollouts are bursty, as you said. People also do a lot of batch jobs. So we'll see, a lot of companies, before they have a training run, they'll need thousands of GPUs to run encoding or something like that. And I think those things are much more bursty than. I agree that agents are not that bursty. sandboxes are, except when you're doing RL. RL is justRL, Batch Jobs, and 100,000 SandboxesVibhu [00:14:28]: Or commerceAkshat [00:14:28]: Insanely bursty.Vibhu [00:14:29]: Yeah.Akshat [00:14:30]: Yeah. Like when you're doing, rollouts, you sometimes need a hundred thousand sandboxes in your sandboxes.Vibhu [00:14:37]: Yeah. I'm curious if you've seen early sparks of continual learning. There are some people, like our friends, ngram, recently announced thisAkshat [00:14:45]: YeahVibhu [00:14:45]: They're, they're trying to do training. That also seems like a different workload, right? If you're doing training twenty-four/seven per se, there's a very weird dynamic of how you're using GPUs between people and whatnot, but seems like something you guys would work for.Akshat [00:15:00]: As you said, we're, we're fortunate to work with a number of, customers at the frontier and grab some of our customers. and they are taking the primitives we have, and trying to use them in very interesting ways, like continual learning. It's possible as the stuff gets better, some of that will be part of, our offering as well if, more people need it. but we're, we're just waiting to seeVibhu [00:15:23]: YeahAkshat [00:15:23]: How it shakes out.Vibhu [00:15:24]: Is there a primitive that you added after sandboxing that was the next step in the story?LLM Inference, DeFlash, and Speculative DecodingAkshat [00:15:32]: I guess we've been going much deeper into LLM inferenceVibhu [00:15:35]: YeahAkshat [00:15:35]: Because we realized that some of the advantages we have with like autoscaling, again, especially in different regions and whatnot, are, not present elsewhere. and the place where we had a gap was we weren't, working on the model layer itself. Like we were a black box. And, we realized that, we can get to frontier-level model performance, with, by having great people who work on this. And, we've been open sourcing a lot of our work, in terms of, Recently, we, shared our work on DeFlash, which is a block-based, speculator, and we've open sourced, all of it. So, you can - By using open source DeFlash, you can get the same performance as you would with one of the proprietary providers. And the next thing we're thinking about hereVibhu [00:16:23]: I thought this wasAkshat [00:16:24]: YeahVibhu [00:16:24]: An interesting blog post as well, right? Like, I think in here you make a claim that. Not a claim, just that how effective speculative deco-decoding really just get to.Akshat [00:16:33]: Yeah.Vibhu [00:16:33]: Anything you wanna point out from this around, what people should know?Akshat [00:16:39]: Yeah, absolutely. the high-level summary is, it would help to describe what speculative decoding is.Vibhu [00:16:44]: Yes.Akshat [00:16:44]: I will, yes.Vibhu [00:16:45]: I think, likeAkshat [00:16:46]: YeahVibhu [00:16:46]: So we've covered like Eagle and all thisAkshat [00:16:47]: YeahVibhu [00:16:47]: Like Hydra and all those things, but it was like two years ago.Akshat [00:16:51]: Yeah.Vibhu [00:16:51]: I think it doesn't hurt, right?Akshat [00:16:52]: Yeah. Speculative decoding is you have a smaller model, called a draft model, predict tokens ahead of the bigger model, and then you have the bigger model, verify all of this, all the tokens are predicted. And the reason it's faster is if you're predicting, one token at once, you're bound by memory bandwidth. But if you can batch the verification of, the draft model, then you're much more efficient using compute, and it's faster, and as long as your draft model is producing a lot of tokens that can get accepted, which is called the accept length, you can get a speed up that's, multiple times of, the original model speed. and well, that's what we highlight here. It's Like people talk a lot about we made these kernels faster and whatnot, but improving kernel will only give you like few percentage points of improvement, and, increasing accept length, literally is a multiplicative decreaseVibhu [00:17:47]: Like two to four X.Akshat [00:17:48]: Yeah, exactly.Vibhu [00:17:48]: Without much head-on performance.Akshat [00:17:50]: Yeah. I think it may - you are running a second model, right? So it may be something more expensive in the compute,Vibhu [00:17:57]: I meant quality performanceAkshat [00:17:58]: Probably not by muchVibhu [00:17:58]: But yeah. I thinkAkshat [00:17:59]: So there's no drop in quality performanceVibhu [00:18:01]: YeahAkshat [00:18:01]: Because you're always. You're never accepting a token that the big modelVibhu [00:18:04]: It's strictly betterAkshat [00:18:05]: YeahVibhu [00:18:05]: Or it's same.Akshat [00:18:06]: Exactly.Vibhu [00:18:07]: Right. Yeah.Akshat [00:18:08]: And so we've been working a bunch on DeFlash, which is a block-based speculator. so it's instead of predicting, one token at a time, it's predicting a block. And we've been open sourcing our work with it. The next thing for us here is for helping people train speculators and custom models. it's it's something that traditionally is very forward-deployed engineering driven, support deployed, engineer driven, like you work with customers and help them do that. And our vision for. This is why we launched Auto Endpoints, is we want to make frontier-level performance available to everyone. And so, we mentioned this in the announcement, we teased it. The next thing we're, we're launching is, as you run an auto endpoint, we shadow trafficAuto Endpoints and Frontier-Level PerformanceVibhu [00:18:54]: Do you want to explain what auto endpoints are?Akshat [00:18:57]: Yeah.Vibhu [00:18:57]: I lovely, yeah.Akshat [00:18:58]: Yeah. So, this is, I guess, going back to your Modal is you touch the code, but, sometimes people don't wanna touch the code, and they wanna get started with an endpoint that works and has all the great performance and, scalability that Modal has. So we've made that easier with, a way to create an endpoint from our UI, from the CLI, that has all of our optimizations that we talked about, like the DeFlash stuff already baked in, and there's full transparency. So we give you the code, you can go run it yourself, and if you want, you can eject out into the full Modal experience, which we see as people get sophisticated, they do wanna tweak the models, they wanna, fine-tune stuff. You can still do all of that. It's it's not a black box. And yeah, the next thing, as we teased later in the post, is how do we give you value even beyond this in terms of having your draft models evolve as your data distribution evolves, again, without having to talk to a person and, yeah.Vibhu [00:19:59]: I guess just to understand it directly, you have the GPUs, you have an endpoint that's compatible, you serve open model. If someone was to do this themselves, what's the delta that you guys provide? So you do a lot of open source great work on effective inference. how does it compare to, say, I take the same model, 5.2 FP8, take shelf inference engine, vLLM, SGLang, get compute of similar capacity, similar cost. What's the delta that plugging into something this, like this offers outside of the benefit of, scaling?Production Inference Beyond Raw GPUsAkshat [00:20:34]: It's interesting because we've taken the approach of open sourcing our contributions and upstreaming them. we work closely with the SGLang team. We want the improvements that our team, comes up with to be, there in open source for others to use, even outside of Modal. The benefit to us is we have a team that has significant expertise in terms of if you do have something that is not there, our team can help you get that performance, first. the other thing is with these endpoints, we are way more elastic, as you said, than, anyone else, and you have true scaling to zero. you have true, burstiness, and in practice, that matters a lot more to people than just finding, the GPU and, running Modal code on something.Vibhu [00:21:20]: Yeah. And I will say it's not that straightforward to just. like what I said is easier said than done, right?Akshat [00:21:26]: Yeah.Vibhu [00:21:27]: It's I think still for the average person, still hard to just gut check using different. There's, there's quite a bit of combinations you can make there. the trade-offs aren't really known at face value.Akshat [00:21:40]: Yeah. it's it's not just that. I think it's it's that running production-grade inference is a hard infer problem.Vibhu [00:21:49]: YeahAkshat [00:21:49]: Even if you subtract out the autoscalingVibhu [00:21:50]: YeahAkshat [00:21:51]: Is controlling things like tail latency and, making sure every, request is delivered at least once and whatnot.The Model and Agent LifecycleVibhu [00:22:00]: There's a lot of innovation that you can do here. I think, it's very interesting that you're starting to encroach on, like as you become a full cloud, you're starting to encroach on other people's turf.Vibhu [00:22:09]: What will you not do?Akshat [00:22:13]: Well, we wanna follow our users and, make sure they get like a platform that has everything that works well together. so right now we're focused on the model lifecycle and the agent, lifecycle. so both like going from data prep to training to inference, and then also if I want to deploy a background agent, let's say, sandbox, do persistent storage, a whole bunch of other stuff.Vibhu [00:22:38]: We talked to Cole, who did, OpenInspect. Yeah.Akshat [00:22:42]: Yeah.Vibhu [00:22:42]: And RealInspect also is on Modal.Akshat [00:22:44]: Yeah. So Ramp Inspect was a great example of a background agent that was really successful because they, were able to use some of the primitives like snapshotting and fast scaling to just have something that feels really reactive and works well.Ramp Inspect and Background AgentsVibhu [00:23:02]: Yeah. That's the new CTO of, Ramp right there.Akshat [00:23:05]: Yeah, Rahul.Vibhu [00:23:08]: It was really fun. yeah, okay, I think, all very bullish. Like, one of my reflections was also I did not originally. So when I met you guysThe Inference Inflection: CPU, GPU, and Co-LocationVibhu [00:23:19]: You weren't that much in the GPU game, and now you're all about, inference. And one of the points that I hinged on for Jensen's keynote at GTC this year was, what we're calling like the inference inflection, right? That let's say in AI workloads or machine learning workloads, it used to be like, let's call it eight to one GPU to CPU, and now it's more like one to one, which is like a interesting. Like, - because of how much agents are blocked or call out to this, to CPU heavy stuff the actual, like, limiting factor, like, swings back and forth from GPU to CPU a lot more than it used to be all GPU and then occasional CPU.Akshat [00:24:01]: Yeah.Vibhu [00:24:02]: GPU, CPU. And now it's like just constantly, and you just have to locate everything.Seventeen Clouds and the Supercloud StrategyAkshat [00:24:08]: Yeah. And that's one of the things that, again, we see as, something appealing about Modal, which is we've built this capacity pool that spans, 17 cloud providers, so we're, we're very good at Running on various kinds of cloud capacity across the worldSwyx [00:24:24]: You don't have your own data centers?Akshat [00:24:25]: We don't have our own data centers. We just run across a lot of neo cloudsSwyx [00:24:29]: Yeah. AreAkshat [00:24:30]: Metal providers.Swyx [00:24:30]: Yeah. Question mark.Swyx [00:24:31]: Yeah. You're, you're running the math, and you're like, “What's the cutover point where you're like.”Akshat [00:24:36]: Yeah, it's a good question. part of it is we see our differentiator in the software layer, and, being capital light and focusing on the software helps us move really fast. so far it's worked out well because there are so many other people building data centers that we're able to work effectively with them, and again, focus on what makes us, special.Swyx [00:24:55]: Yeah.Swyx [00:24:56]: 17 gets you into, like, the local providers sometimes. LikeAkshat [00:25:00]: The,Swyx [00:25:01]: Which was the most interesting one?Akshat [00:25:02]: There are a lot more neo clouds than you expect, and they all have various degrees of, various levels of reliability. And, that's why it's something we've invested a lot of time in, is building our own reliability layer on top. so if the GPU falls off the bus or something happens, we user workloads are not affected, and that lets us use a lot more capacity than,Swyx [00:25:30]: YeahAkshat [00:25:30]: You as a user would be able to.Swyx [00:25:32]: It's a useful thing to have because like now everyone knows, like, what layer you are and, like, you optimize for being the super cloud of all clouds.Akshat [00:25:41]: Yeah. That's, that's, that's the idea. and so I guess when you mentioned colocation, that's, that's another interesting thing where, one thing we've seen is people come to us when they want, very specifically located, CPUs or GPUs, like they wantSwyx [00:25:57]: Oh, they pin it in likeAkshat [00:25:58]: YeahSwyx [00:25:58]: EU?Akshat [00:25:59]: Exactly. Or EU, US.Swyx [00:26:01]: Right. Data resiliencyAkshat [00:26:02]: AustraliaSwyx [00:26:02]: Locality thing or performance or what?Akshat [00:26:04]: It's either data locality or latency, yeah.Swyx [00:26:07]: Yeah.Akshat [00:26:07]: Like, you want your. They're running sandboxes and model. They want them to be right next to aSwyx [00:26:10]: Yeah, it's easy thenAkshat [00:26:11]: YeahSwyx [00:26:12]: To. That is important in all those things. and so, like, you've accidentally, I don't know if it's accident, but, like, you've built the perfect primitive for agents to express themselves. And then, like, it's almost very funny how every extra development just involves more file system, just involves more CPU.Akshat [00:26:30]: Yeah.Swyx [00:26:31]: Just like the things that you already have. I don't know much about, if there's any, like, networking usages that are interesting, but you've also done some good work on networking.Networking, Sidecars, Private IPv6, and SandboxesAkshat [00:26:40]: Yeah, that's exactly right. Like, we're just taking compute storage and networking and building stuff on that layer, for, again, the stuff people need.Swyx [00:26:49]: YeahAkshat [00:26:50]: We see a few interesting networking things coming up. one is people want networked sandboxes. so we haveSwyx [00:26:57]: For like a Docker cluster type thing.Akshat [00:26:59]: Yeah.Swyx [00:26:59]: Sorry, Docker Swarm. Oh, f**k. What is it called?Akshat [00:27:02]: Compose.Swyx [00:27:03]: Compose type thing.Akshat [00:27:04]: Yeah. So if you want Docker Compose, our sandboxes now support, this thing called sidecars. So you can. A sandbox is a pod of containers, and you can run multiple containers in, a sandbox. also useful because, going back to networking, people want a lot of control over, outbound networking from a sandbox.Swyx [00:27:23]: Yeah.Akshat [00:27:23]: Like, they might wanna run a middle proxy for, like, maybe logging stuff for RL or, controlling how egress can happen to a domain, injecting credentials. and yeah. So we've, we've had to build a lot of that stuff ourselves.Swyx [00:27:38]: Yeah.Akshat [00:27:39]: But then also sometimes people want, sandboxes spanning multiple nodes to talk to each other, which is an emerging thing we're seeing. We have support for that for a different reason, and yeah, we'll see if that becomes stable.Swyx [00:27:52]: Like, just an open socket. It's a. This is directly like mTLS.Akshat [00:27:56]: We do support that, which is you can, expose a tunnel inside a sandbox.Swyx [00:28:01]: Yeah.Akshat [00:28:01]: And then you can either expose it to public internet or it can be, you can add like a HTTP, auth layer above it. But we have this thing called I6PN, which we haven't talked about, which is this, like, overlay network using IPv6 addresses. so if Modal containers, within the same workspace, when this is enabled, can address each other using this private IPv6 address, and no one else can.Akshat [00:28:28]: So it's like private networking, for containers. We built it because we needed it as a primitive for our distributed training product. so we have this other feature, which is you can add a decorator to a function, and you get a cluster of GPUs. and they have RDMA networking. so you can run a distributed training job, that's truly serverless. and we did the overlay network for that. But then we've seen that people are using it for other reasons, and, I'm intrigued to yeah, what would people do with it.Swyx [00:28:59]: Build primitives and let people figure it out, right?Akshat [00:29:01]: Yeah, exactly.Swyx [00:29:02]: You put out a pretty interestingAkshat [00:29:03]: They're like, they read the docs webpage. Let me use thatSwyx [00:29:06]: YeahAkshat [00:29:06]: Something they never intended to work. This is literally not even in our docs page. People somehow found it, and they're using it.RDMA, Memory Movement, and Distributed TrainingSwyx [00:29:12]: Huh.Swyx [00:29:14]: The way you portrayed it with, like, RDMA versus TCP, like, very well laid out, but just the transfer speed change at scale for RL, like yeah, you have it, you have it built in. I'm sure someone found it. It's found it to be a lot more efficient before you made a thing out of it, right?Akshat [00:29:32]: Yeah. And not to split hairs, I guess the overlay network is the TCP overlay network.Akshat [00:29:39]: The reason we have that is you need that to do the key exchange for RDMA before you set up the RDMA network on top of that. but then people found the TCP part.Swyx [00:29:48]: Can I tell you, this is like a big aha moment for me becauseAkshat [00:29:51]: YeahSwyx [00:29:51]: So I review 2,200 submissions for the World's Fair.Akshat [00:29:56]: Yeah.Swyx [00:29:57]: And then I got this from John OsterhoutAkshat [00:29:58]: HuhSwyx [00:29:59]: Who I don't know if. Do John Osterhout by name?Akshat [00:30:01]: The name sounds familiar.Swyx [00:30:02]: He published a. He's a well-known professor, published a lot of interesting software design books, and this is the talk he chose to submit, is on RDMA at Inference. And I'm like, you wouldn't think that this guy, who is like operating systems guy, would care about RDMA.Akshat [00:30:20]: I, it makes sense to me because I,Swyx [00:30:24]: This is the cloud, right? YeahAkshat [00:30:25]: Like, the way you move around your KV cache and how efficiently you can do it, how efficiently you move, your weights from your training GPUs to your inference GPUs in RL is there's a lot of degrees of freedom, and it is a systems problemSwyx [00:30:41]: YeahAkshat [00:30:41]: Moving memory aroundSwyx [00:30:42]: YeahAkshat [00:30:43]: Scheduling.Swyx [00:30:44]: This shows you how primitive my understanding of networking stuff is.Swyx [00:30:46]: Is this like the domain of WireGuard as well?Akshat [00:30:50]: Not quite.Swyx [00:30:51]: It's adjacent?Swyx [00:30:53]: Explain everything.Akshat [00:30:54]: Sure.Swyx [00:30:56]: How do we move memory around GPUs?Akshat [00:30:58]: Well, so sorry. Yeah, that is memory. Sorry, I was talking more, and maybe I was talking like five minutes back, about the private IPv6, addressing that you've set up.Swyx [00:31:09]: Yeah.Akshat [00:31:09]: Is it like it's a VPN?Swyx [00:31:10]: Yeah, it is like a VPN, and yeah, WireGuard is, yeah, you're right. It is,Akshat [00:31:16]: Right. Yeah, you already moved on to new topicsSwyx [00:31:17]: A similarAkshat [00:31:18]: OkaySwyx [00:31:19]: In the same space, WireGuard is, encrypted and this is,Akshat [00:31:23]: And you don't need encryption.Swyx [00:31:23]: Yeah.Akshat [00:31:24]: Yeah.Swyx [00:31:24]: This is not encrypted. that's the main difference. This is TCP and we have eBPF programs that will reject or allow the TCP connection based on whether you're allowed to do it.Akshat [00:31:35]: Used to involve a full sidecar, but now you have eBPF in the Linux kernel.Swyx [00:31:39]: Yeah.Akshat [00:31:40]: Yeah. I don't know if this is a natural follow-on to the topic of like my skepticism on distributed training is that while, like, people spend a lot of money on, like, cables to hook up GPUs, and even that is not, like, fast enough, and that's the bottleneck, is your networking fast enough?Swyx [00:31:59]: Yeah. So I guess you're talking about fully distributed training like, Dialog or something which is like cross data centerAkshat [00:32:06]: That would be, yes.Swyx [00:32:07]: That's the extreme.Akshat [00:32:08]: Yeah.Swyx [00:32:08]: You're in the middle, and then other people would have like the Mellanox cables up in, like, their actual data center.Akshat [00:32:14]: When you run multi-node training on Modal, RDMA, I think Mellanox, is, or InfiniBand is like a, is all seen as RDMA. but it's a way to bypass the TCP networking stack and, transfer, stuff much faster, between one node, to the other. And we have I think like 3 terabit per second, internal networkingSwyx [00:32:40]: OkayAkshat [00:32:40]: Which is the standard that's needed.Swyx [00:32:42]: Okay. So I misunderstood whatAkshat [00:32:43]: 50Swyx [00:32:43]: What part of the stack you wereAkshat [00:32:44]: 50 gigs overSwyx [00:32:45]: YeahAkshat [00:32:45]: If you wentSwyx [00:32:45]: YeahAkshat [00:32:46]: RDMA.Swyx [00:32:46]: Okay.Swyx [00:32:48]: Yeah. I, very impressive work.Multi-Node Training, Post-Training, and Auto ResearchSwyx [00:32:52]: So effectively you're extending like the model philosophy to the training cluster, like, yeah.Akshat [00:32:59]: Yeah. And we're, we're not going for like large scale training runs. the thing that we've built multi-node training for is, we see a lot of, smaller scale post-training. like, people are post-training like medium sized fund models, so they can, get higher quality on inference. this is a perfect fit, for something like that.Swyx [00:33:21]: Yeah. That is my impression of how a lot of these labs explore branches in post-training and then eventually merge whatever they find in.Akshat [00:33:31]: Yeah. The other use case we've seen for multi-node training is even if you have a big cluster, your researchers are still doing small runsSwyx [00:33:38]: YesAkshat [00:33:39]: Having elasticity thereSwyx [00:33:40]: Right, sureAkshat [00:33:40]: Matters a lot more.Swyx [00:33:41]: Yeah. the, like, this is like the current limiting factor for auto research, which is like you need to give your model some GPUs in order for it to completely run.Akshat [00:33:51]: We have a blog post on auto resource and model is,Swyx [00:33:55]: YeahAkshat [00:33:56]: Yeah, like, turns out to be pretty good substrate for that.Swyx [00:33:59]: So my impression is auto research means many things, likeAkshat [00:34:01]: YeahSwyx [00:34:01]: Anything that Andrej coins. Right now it's still science fair, right? Like not like, I don't know how many people are doing this.Akshat [00:34:08]: We're having a golf.Swyx [00:34:08]: Yeah.Akshat [00:34:09]: I thought the same thing.Swyx [00:34:11]: Yeah, you would know.Akshat [00:34:12]: We, like, our internal both training and inference teams use this the general shape of this quite a bit. like we have this one internal repo called auto inference, which essentially we've automated our own forward-deployed engineering efforts using, this harness, which is, the agent will just spin up a sweep of different things. It'll even run like, NVIDIA inside profiler and it'll like tweak configs and it'll arrive the right thing. it'll change your GPUs both from H200 to B200, and works really well.Swyx [00:34:47]: Nice.Akshat [00:34:47]: So yeah.Swyx [00:34:48]: By the way, I enjoy that your forward-deployed engineering is so technical that you have to do these things.Swyx [00:34:52]: It's very different from forward-deployed engineering from other people.Akshat [00:34:54]: Yeah. For our forward-deployed engineering team is, essentially they're like applied inference researchers or applied training researchers.Swyx [00:35:02]: Someone told me like they have to be able to build, but they also have to be able to sell. do they have to sell or are they like they're good, they're just like post-sale type of thing?Akshat [00:35:09]: It does, being able to talk to a customer and engage effectively with themSwyx [00:35:13]: YeahAkshat [00:35:13]: Matters a lot.Swyx [00:35:14]: They want the same thing.Akshat [00:35:15]: Yeah.Swyx [00:35:15]: ?Akshat [00:35:15]: But it's it's not really a sales, thing. We pair them with-- We have solution architects as well that are more on the sales side.Swyx [00:35:23]: Okay. Let's spend a bit more time on auto research. This is a big focus for for this year. Where does this go? like, have people explored enough? Like, there's all these beautiful charts of like improve and then level off a bit and then you find the next thing. Is this one abstraction up from normal training? Is that how we think about it, or do you think about it differently? Like model level training versus high, like driven hyperparameter search.Auto Inference and Modal BenchAkshat [00:35:51]: Yeah, like,Swyx [00:35:51]: Someone, some people call it like neural architecture search or whatever, right? Like.Akshat [00:35:54]: Yeah, - So the stuff I've seen people do with it is nowhere on the architecture level. It's pretty much tweaking parameters, but it's it's a hyperparameter sweep that's guided by some model intuition, so it's like much more efficient than, whatever other, sweep you would have.Swyx [00:36:12]: Yeah, it's just, it's just a question of where you want to spend your compute?Akshat [00:36:16]: Right.Swyx [00:36:16]: ‘Cause yeah, you can just throw infinite amounts of money on this and somehow you'll bang out Shakespeare?Akshat [00:36:22]: Yeah, infinite monkey.Swyx [00:36:24]: Yeah, so like the very good for model. and I think it's also very important that agents can spin up other agents, can spin up their infrastructure. Like very good for you. how good is our LLMs at generating model code? Like the benefit of existing LLMs is that you are in the data.Akshat [00:36:42]: Yeah. They're, they're surprisingly good. I think like pre Cloud 4 they were not, and then now they're able to shot, stuff out of the box. But we're playing around with releasing like a Modal Bench for like the harderSwyx [00:36:55]: YeahAkshat [00:36:55]: Things, that the LLMs cannot do yet and maybeSwyx [00:36:59]: What's an example of that?Akshat [00:37:01]: I think the things that- Sometimes agents struggle with, without right guidance and a skill is, how to, use the rest of our observability. Like how to. Something is failing, like how do you look at the logs and then update the right thing? It's reasoning about that. But they're able to shot, likeSwyx [00:37:23]: Yeah. You can just add a skill to it?Compute Strategy and Capacity PlanningAkshat [00:37:26]: Yeah. So we have a Modal skill now that. Which is why we built this Modal Bench. It's to find things like that, so we can address them in our tool.Swyx [00:37:35]: Tune a skill. Yeah.Akshat [00:37:36]: Yeah.Swyx [00:37:36]: No. it's it's good. are you facing any shortages? like we talk a lot about GPU shortages, but also CPU, also memory.Swyx [00:37:44]: Yeah.Akshat [00:37:45]: We have had a lot of growth, which means that, there's - we've had to be much better aboutSwyx [00:37:53]: PlanningAkshat [00:37:54]: Proactive capacity planning.Swyx [00:37:55]: Yeah.Akshat [00:37:55]: So we have,Swyx [00:37:57]: Which by the way, like it's like a MBA's like dreamAkshat [00:38:00]: YesSwyx [00:38:00]: Is like just planning this stuff. I think last time you and I talked about something maybe about this.Akshat [00:38:03]: Yeah. we have a really competent team of people that we call, The role is called compute strategy. so yeah, if anyone listening here or wants to work on thatSwyx [00:38:13]: Compute strategy?Akshat [00:38:13]: Yeah.Swyx [00:38:14]: I think,Akshat [00:38:14]: I feel like,Swyx [00:38:15]: I think the normies call it FP&A or something.Akshat [00:38:18]: Well, it's more It's it's not FP&A. It's it's There's a lot of interesting financial questions of like what is the blend between one year and three-year reservations? how do we forecast our own capacity? how do we. especially since our capacity is very fungible across different GPU types and different regions, like you have to model a lot of it. and you also have to have an opinion on how the supply chain is gonna evolve, and then you have to like, take bets,Swyx [00:38:49]: YeahAkshat [00:38:49]: Based on that.Swyx [00:38:50]: Tokenomics.Akshat [00:38:50]: Yeah.Swyx [00:38:51]: This is like probably a not a real point, but, I was trying to think about like what other industries. I was trying to think about like, we cannot be first to like these kinds of problems.Akshat [00:38:59]: Yeah.Swyx [00:39:00]: And what other industries have had this? And I was like, airlines with fuel and like they have to hedge their fuel and like, I think for a long time Southwest because they made like a hero fuel bet, they like were like super low cost becauseAkshat [00:39:12]: OhSwyx [00:39:12]: Compared to everyone else.Akshat [00:39:14]: Yeah. I hadn't thought about that.Vibhu [00:39:16]: We're at a fun time too?Akshat [00:39:18]: Yeah. It's. A lot of the compute business in general, for us is also about being very good about capacity management. That is how you have great unit, economics. but also over time it's how you can unlock more value for customers. Like, one of the things we're building now is like a way for customers to get, If they don't care about latency, like get much cheaper pricing and they'll get results back in like next 24 hours or something, like a batch tier essentially.Batch Tiers and Latency-Insensitive WorkloadsSwyx [00:39:47]: Yeah.Akshat [00:39:47]: And those are levers we have because we control the whole stack and scheduling and whatnot to give people a sufficientSwyx [00:39:53]: Yeah. I feel like they're not as popular. Like those, like the Frontier Labs have all those APIs. They're not as popular as they should be.Akshat [00:40:00]: The demand that we see for something like that is not for LLMs. although sometimes people wanna run evals andSwyx [00:40:08]: OkayAkshat [00:40:08]: Synthetic data prep and there it makes sense.Swyx [00:40:10]: Okay.Akshat [00:40:11]: But it's from a lot of LLM companies, like people who are doing computational bio, like they have to run really big batch jobs and they don't care about when they get it back.Swyx [00:40:22]: Yeah. And like they have a reasonable. It's it's also like a cousin to the stopping problem of like, will this finish in time?Akshat [00:40:30]: Yeah. You can bound it.Swyx [00:40:33]: Yeah.Akshat [00:40:33]: Like you can give peopleSwyx [00:40:34]: YeahAkshat [00:40:34]: SLAs on it.Swyx [00:40:35]: Yeah. I think what's, what's interesting is like the next phase of model.Swyx [00:40:38]: Like what, do people expect from you, now that you're established and you're like well-known compute player among all these leading companies. You had an inference launch week, and we talked a little bit about the launches. like what else? Like what else should people know?What Modal Builds NextAkshat [00:40:55]: We are building primitives that make our users' lives much easier. So, I think for example, with LLM inference, thousands more companies are gonna post-train their own models and, deploy open source models for inference. so we're thinking a lot about what is the best product shape for that. And, that involves everything from our training gym to, then, endpoints that get frontier-level performance. again, but I haven't talked to anyone. It looks somewhat different on other verticals. Like, we're also seeing a lot of real-time, audio-video stuff in there, which is why like, we're working on things like regional routing, with fallbacks. So you can get GPUs that are as close to users as possible. so you get like low latency for video streaming and whatnot. And then on the agent side, it's,Akshat [00:41:52]: We're still working very closely with our customers because stuff is changing so fast in terms of what they need. And, I think beyond sandboxes and persistent file systems, there's a lot of other things people will need from this agent stack as they build production agents. So yeah, we're thinking about those other things that fit in there.Swyx [00:42:13]: I want to ask what the other things are.Akshat [00:42:15]: Yeah. I probably should share right now.Swyx [00:42:17]: I think-- I think, okay, so, I do think a lot about the principal components of cloud, and you do talk about compute storage networking.Akshat [00:42:25]: Yeah.Swyx [00:42:25]: Because so far for me, it's fine. so far for the. the first couple generations of cloud, it's fine. What's different, qualitatively different about agents that you need some new permission level? Like a lot of people, okay, and I'll just kinda spew tokens at you until it like hopefully sparks something.Akshat [00:42:43]: Yeah.Swyx [00:42:44]: Like the new level now is whatever Claude Code does, which is dangerously scope permissions or like allow list by command or like whatever, right? And sometimes they're like, “Well, okay, we have like this adaptive thinking mode where like, just trust me, bro. I will make the calls for you.” Is that it? like mediated permissions.Hard Guardrails vs. LLM-Mediated PermissionsVibhu [00:43:03]: Now you're looping it with a goal and letting it roll.Akshat [00:43:06]: Yeah, I'm, I'm skeptical of LLM media permission for stuff that is at the sandbox level because you do want hard boundaries.Swyx [00:43:16]: Yeah.Akshat [00:43:16]: Otherwise, someone can exfiltrate stuff.Swyx [00:43:20]: But likeAkshat [00:43:20]: YeahSwyx [00:43:20]: Maybe that's old school thinking. Maybe we're the dinosaurs.Swyx [00:43:23]: Maybe the AI OS or the LLM OS is really the kernel is a goddamn LLM.Swyx [00:43:30]: Like it makes you feel uncomfortable.Akshat [00:43:31]: Yeah, I'm, I'm toldSwyx [00:43:32]: But that's what trusting the LLM is. Like imagine a spherical cow perfect LLM.Akshat [00:43:36]: Right.Swyx [00:43:37]: That it.Akshat [00:43:39]: Maybe.Swyx [00:43:41]: I wanna test the boundaries, right?Akshat [00:43:42]: Yeah.Swyx [00:43:42]: Like, and I don't believe that, but I wanna see where I'm wrong ‘cause that's, that's the consensus.Akshat [00:43:49]: Yeah. I think you always need hard guardrails when you want, And you can pair those with softer guardrails, right? And that's gonna be a lot of mediated.Managed Agents and Specialized SandboxesSwyx [00:44:00]: There. I'll also get you a end with a couple of your commentary on like the ecosystem outside of Modal. Manage agents. Everyone has one. Gemini, OpenAI, Claude, very useful for you, but also like it is their way of starting to edge into your space.Akshat [00:44:17]: Yeah.Swyx [00:44:17]: What's going on?Akshat [00:44:19]: Yeah, we're, very excited to partner with Anthropic and some of the other foundation labs, will not name who we're also working with. the way we see it is the manage agent thing is a great place to start if you're starting out building an agent and, But then when you get to, building something more production grade, like you're a company that's like Ramp that's building their own, Ramp also runs their accounting agent on us, so their external-facing agent. You need a lot more control over, your compute primitive on things like, what sort - how do you persist different files that the agent has access to, and how do you snapshot and restore? How do you control the networking? maybe you want GPUs. When you get to that point, you kinda want, a specialized sandbox provider, that gives you those things, and that's the role that we are trying to play.Swyx [00:45:15]: YeahAkshat [00:45:16]: We don't really have an opinion on the harness, whether it runs - it's a cloud-managed agent, and you hook it up to Model Sandbox, or you run the harness in Model Sandbox. We'll see where people converge with that.Swyx [00:45:26]: Yeah. Do you any opinions on like the meta harnesses, or just another layer on top of these things?Akshat [00:45:31]: You mean like the OpenPipeSwyx [00:45:33]: OpenPipe is one. I think Vercel had one, which I can't remember the name of right now. Fredshot had one. and then, to me, most recently was Data Databricks that had Omnigen. All these are meta harness. Like it's kinda pseudo agent cloud type things.Akshat [00:45:50]: I personally have not played around with them.Swyx [00:45:53]: Yeah.Akshat [00:45:53]: Build agents with them.Swyx [00:45:54]: Everything's bullish Modal, as long as it consumes more infra.Akshat [00:45:57]: That's why we're focusing on the infra layer. It's somewhere where our, relative competence is and, also it's a hard problem to solve.Swyx [00:46:06]: Yeah. I will say like just generally reflecting on that, I don't know if - if there's other topics on Modal, but like just generally reflecting as an infra person, not as intense as you, but in that field, this has like been the most exciting time in infra. Like it was boring for a while, and you couldn't really get people excited about data infrastructure. Like Eric would get on Data Console, everyone just watched the video and like say, “Look at how many sandboxes I can spin up,” and no one gave a crap.Why Infrastructure Became Exciting AgainAkshat [00:46:39]: Yeah.Swyx [00:46:40]: And like now everyone gives a crap.Akshat [00:46:42]: That's true. It is a very exciting time, and I think a lot of that's driven by just the amount of scale all of this stuff needs.Swyx [00:46:50]: I think the, like a lot of your initiatives or a lot of your like product directions make sense in retrospect, which is like the best kind, but I wouldn't necessarily have thought about it myself, which.Akshat [00:47:00]: We need the predictions.Swyx [00:47:02]: I think there's a lot that you just don't even see, right? Like you have the batch, you have the voice, you have the multimodal, but what else?Akshat [00:47:10]: What else is coming up for usSwyx [00:47:11]: Yeah. Where do you see things going?Akshat [00:47:13]: Yeah. I, in generalBiotech, Robotics, and Non-LLM AI WorkloadsAkshat [00:47:15]: It's it's clear that there's there's a huge shift happening. I think one thing that's not as obvious to people because LLM inference gets talked about so much and is also we work a lot of companies that are, doing things like drug discovery and computational bio, like the Chai Discoveries of the world. Big things are probably gonna happen there. we work a lot of robotics companies that are putting robots in like active deployments and getting good results out of them.Swyx [00:47:45]: Is there Air Gap Modal? Is there a version that is like prem air gapped whatever?Akshat [00:47:50]: No. We,Swyx [00:47:51]: You should cloud only.Akshat [00:47:51]: Yeah.Swyx [00:47:52]: Yeah. Okay. But yeah, so what you're saying is like because you're focused on primitives and they're good primitives, you find use cases in all these kinds of things.Akshat [00:48:01]: Yeah.Swyx [00:48:01]: Probably diversifies you a little bit away from LMS all the time.Akshat [00:48:05]: Yeah, absolutely. We're, we'- our goal isn't to only serve the LLM inference market.Swyx [00:48:10]: There are a lot just on the website, the audio,Akshat [00:48:12]: Yeah. We said both onSwyx [00:48:14]: Computational bio images. Yeah, there's a lot here. There's QTA TTS, customizing. Oh, Chatterbox. there was customizing Whisper.Akshat [00:48:24]: Okay. Yeah.Swyx [00:48:25]: This screen reminds me of a fallen competitor, which Replicate.Model APIs vs. Differentiated AI ProductsSwyx [00:48:31]: What's your postmortem on what happened?Akshat [00:48:34]: This is one thing we've stayed away from is providing an API for models because I think providing model APIs is some of it ends up serving like a really hobbyist market, which is much less sticky.Swyx [00:48:50]: Yeah.Akshat [00:48:50]: And we've always wanted to build for companies that are building products and need more flexibility that's not just an API.Swyx [00:48:57]: Which you can build an API for a model and this is clearly what it is. But you - but what you're saying, you can wrap it into a more fully functioning back end that you run.Akshat [00:49:06]: Yeah. So all of our examples, it's not that spin up this model, here's an API token, use it. They're all code.Swyx [00:49:13]: Okay.Akshat [00:49:13]: And so the point is that this is just an example.Swyx [00:49:16]: Starter code.Akshat [00:49:17]: Yeah. But you can tweak it however you want.Swyx [00:49:20]: Yeah.Akshat [00:49:21]: And if you're like a company building a product, like, computational bio whatnot, yeah.Swyx [00:49:26]: I guess I'm trying to tease out for listenersAkshat [00:49:28]: YeahSwyx [00:49:28]: When does it stop becoming, oh, you're just an API call and you're just a wrapper on API to becoming what you call a product, right?Swyx [00:49:36]: Like, what is that layer? Like what-- Like, more lines of code, but like beyond that, what is the substance that people add that qualifies it to be something more?Akshat [00:49:46]: I think there's a little bit of like a selection effect of like a lot of the companies who do wanna get deeper into that level are probably building something that's more differentiated. And, I think, an example is like - with LLM inference, originally we, worked with companies that were building their own post-training frameworks or they were, - Ramp early in the day was training their own tokenizer and like swapping out the tokenizer in Llama and whatnot. I'm not saying that's, that successful, in that case. But a better example is like, let's say Suno. because Suno, does not use Modal for training.Swyx [00:50:26]: Mikey on the pod. Yeah.Akshat [00:50:27]: But they use Modal for all their inference and that's because they have like a custom-- They have completely custom model architecture and that means that they have to be at the code level and tweak things that are not, just an API.Swyx [00:50:41]: It's interesting as well, like we had, Ethan, most recently on the xAI Groq team make a prediction that like the next tier in video gen is not a better video model, it's a better model or agent that orchestrates video models.Video Agents and Production WorkflowsAkshat [00:50:56]: Oh, interesting.Vibhu [00:50:56]: Language model backbone that can use toolsAkshat [00:50:58]: RightVibhu [00:50:59]: And write code.Akshat [00:51:00]: Like, yes, I can make my second video or my second video from Groq, but I want my minute video.Akshat [00:51:06]: And I'm not going there through normal video gen.Swyx [00:51:10]: Yeah, that's interesting. I - So we have GPU sandboxes and recently have seen a few companies doing agents that do video manipulation or,Akshat [00:51:22]: Yeah. Give it FFmpeg and just do it.Swyx [00:51:23]: Run FFmpeg. But likeAkshat [00:51:25]: That's not enough.Swyx [00:51:25]: Yeah.Akshat [00:51:26]: You need to give it Adobe.Swyx [00:51:27]: Yeah, I hadn't put it together with like it would be a video production thing. in my mind these things were going more towards editingAkshat [00:51:36]: Yeah.Vibhu [00:51:36]: Well, shout out Mantis.Akshat [00:51:37]: I think about this a lot.Swyx [00:51:38]: .Akshat [00:51:41]: Yeah. Sorry.Vibhu [00:51:41]: Luma. Luma Agent is a version of this for video production, but it's a off.Swyx [00:51:46]: I was gonna get your quick takes, on some other stuff that happensGitpod/Ona, CI, and Runtime SandboxesSwyx [00:51:50]: In recent news and just-just see if you have anything interesting. Gitpod, very li

Artificial Intelligence in Industry with Daniel Faggella
Inside the Shift to Agentic IT Ops - with Assaf Resnick of BigPanda

Artificial Intelligence in Industry with Daniel Faggella

Play Episode Listen Later Jul 3, 2026 34:05


Enterprise IT teams are drowning in alert volume as cloud, microservices, and CI/CD pipelines outpace what human operators can process. In this episode, Assaf Resnick, CEO and Founder at BigPanda, examines how agentic AI can shift IT operations from reactive troubleshooting to a prevention-first model built on an enterprise IT knowledge graph. The conversation covers how to build and own that knowledge graph, where human judgment still belongs in the incident response loop, and why an evolutionary rollout beats a full system overhaul. This episode is sponsored by BigPanda. Learn how brands work with Emerj and other Emerj Media options at emerj.com/partner

The New Stack Podcast
“The harness is where the hard work is”: Harness bets on agents that enterprises can trust in production

The New Stack Podcast

Play Episode Listen Later Jul 2, 2026 19:42


Harness has introduced Autonomous Worker Agents, a new capability that allows enterprises to replace rigid CI/CD pipeline scripts with AI agents that can deploy applications, run tests, and perform security scans while operating under existing governance, security, and audit controls. Unlike Harness' existing expert agents, which assist developers with coding and pipeline creation, Worker Agents autonomously execute pipeline tasks within customer-controlled infrastructure. Agents are defined using simple Markdown files, draw context from the Harness Software Delivery Knowledge Graph, and run in sandboxed environments with scoped permissions and policy enforcement.  Harness also provides built-in audit trails that record prompts, decisions, and outcomes, along with token budgets and approval gates to control AI costs. The launch includes an Agent Marketplace featuring Harness-managed, certified partner, and community-built agents. CEO Jyoti Bansal said production AI agents require far stronger safeguards than coding assistants, positioning Harness' governance and knowledge graph as key differentiators. Looking ahead, the company envisions fully autonomous software engineering, where AI agents manage the software lifecycle while humans oversee high-risk decisions. Learn more from The New Stack around AI software delivery: AI won't speed up software delivery - nothing has How to solve the AI paradox in software development with intelligent orchestration  Join our community of newsletter subscribers to stay on top of the news and at the top of your game. 

The Engineering Enablement Podcast
From PR throughput to product velocity: How Dropbox is rethinking productivity in the agentic era

The Engineering Enablement Podcast

Play Episode Listen Later Jun 29, 2026 21:54


In this session from DX Annual, Uma Namasivayam, Senior Director of Engineering Productivity at Dropbox, shares how the company's developer productivity efforts evolved from improving developer experience to preparing for the agentic era.He explains how Dropbox approached AI adoption across its engineering organization, the impact it had on developer productivity, and why faster code generation is creating new bottlenecks in areas such as code review, validation, and CI/CD. He also discusses Dropbox's efforts to rethink engineering systems, measurement, and workflows, including the development of agentic tooling and new metrics designed to move beyond PR throughput and toward product velocity.Where to find Uma Namasivayam:• LinkedIn: https://www.linkedin.com/in/unamasivayIn this episode, we cover:(00:00) Intro(00:57) The beginning of Dropbox's DX journey(02:34) AI adoption at Dropbox: what made it work  (04:46) The results of Dropbox's AI adoption efforts(05:39) What the results mean for the business (06:55) The phases of AI adoption and where they are now(08:00) The new bottlenecks(09:16) Three challenges Dropbox faces moving into agentic engineering(10:05) How Dropbox is redesigning the SDLC for agentic engineering(15:46) The new metrics that matter (19:16) Final takeawaysReferenced:• Dropbox • Developer Experience Index (DXI) | DX • DX Core 4 Productivity Framework• Cursor• Claude Code | Anthropic's agentic coding system• JetBrains • Visual Studio Code• Jira | Project Management for the AI Era | Atlassian• GitHub 

DataTalks.Club
AI Adoption in Enterprise Beyond Writing Code - Ivan Bilan

DataTalks.Club

Play Episode Listen Later Jun 26, 2026 62:25


In this talk, Ivan, Senior Engineering Manager at Personio, shares his deep expertise in the data and software space from his early days building traditional NLP systems and massive ETL pipelines to his current leadership role in Identity and Access Management (IAM). We explore the rapid evolution of Generative AI, the reality of managing AI agents in production, and the emerging field of context engineering to optimize developer workflows.You'll learn about:- The buy vs. build dilemma for AI infrastructure and local LLMs.- How AI agents are shifting workloads and evolving code reviews.- Why AI is currently better at fixing tech debt than building from scratch.- Measuring the ROI of AI integration using DORA metrics and cycle times.- Strategies to manage vendor lock-in and minimize AI provider dependency.- Using "context engineering" and specification-driven development to maximize LLM quality.- Why hiring junior engineers is still essential and how AI accelerates their onboarding.TIMECODES:00:00 Career Journey in Data Science and NLP07:37 Industry Adoption of Generative AI and Agents11:45 Buy vs Build Dilemma for AI Infrastructure15:46 AI Capability Limits in Fixing Tech Debt19:32 Developer Workloads and AI Code Contributions24:49 Experimentation with Open Source AI Agent Architectures30:06 Measuring ROI and Business Value of AI Integration35:10 Tracking AI Impact Using DORA Metrics39:51 Impact of AI Code Generation on CI/CD System Reliability43:00 Best Practices for Team AI Tool Adoption48:20 Managing Vendor Lock-In Risks with AI Providers51:27 Importance of Hiring Junior Software Engineers56:28 Accelerated Junior Developer Onboarding with AI Assistants01:00:12 Specification-Driven Development and Context EngineeringThis talk is perfect for software engineers, engineering managers, and technical leaders looking to practically integrate AI tools into their teams without sacrificing code quality or system reliability. It is especially valuable for tech professionals navigating the complexities of AI adoption, CI/CD pipeline management, and organizational scaling in the GenAI era.Connect with DataTalks.Club:- Join the community - https://datatalks.club/slack.html- Subscribe to our Google calendar to have all our events in your calendar - https://calendar.google.com/calendar/r?cid=ZjhxaWRqbnEwamhzY3A4ODA5azFlZ2hzNjBAZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbQ- Check other upcoming events - https://lu.ma/dtc-events- GitHub: https://github.com/DataTalksClub- LinkedIn - https://www.linkedin.com/company/datatalks-club/ - Twitter - https://twitter.com/DataTalksClub - Website - https://datatalks.club/ Connect with Ivan:- LinkedIn - https://www.linkedin.com/in/ivan-bilan/ - Twitter - https://x.com/demiourgosua - Github - https://github.com/ivan-bilan - Website - https://github.com/ivan-bilan

GovCast
Misunderstood ATOs Are Costing Agencies Time and Money | CyberCast

GovCast

Play Episode Listen Later Jun 25, 2026 8:17


Misunderstandings about the Authority to Operate (ATO) process are slowing federal technology modernization efforts and driving up costs, according to David Raley, chief digital business officer for Operation StormBreaker in the Marine Corps. Speaking at GovCIO Media & Research's Federal IT Efficiency Summit, Raley argued that many delays stem from a fundamental misconception about what receives an authorization. Rather than granting ATOs to individual software applications, agencies authorize integrated systems operating within specific environments, taking into account mission context, infrastructure, users and data. Raley said this misunderstanding often leads to unnecessary delays for both government teams and industry partners. To accelerate software delivery, Raley highlighted the Marine Corps' Operation StormBreaker initiative, which leverages modern DevSecOps practices and continuous integration and continuous deployment (CI/CD) pipelines. By building applications on preauthorized platforms, teams can inherit the majority of required security controls, reducing compliance burdens and enabling faster, more efficient delivery of mission capabilities.

The PowerShell Podcast
Certificates Are Not Optional with Leo D'Arcy

The PowerShell Podcast

Play Episode Listen Later Jun 22, 2026 33:16


Andrew sits down with Leo D'Arcy, cloud solutions architect and PSConfEU speaker, to talk certificates, PKI infrastructure, and why so many organizations get it so spectacularly wrong. Leo shares how a decade of consulting work in remote access solutions pulled him into the world of Active Directory Certificate Services whether he liked it or not, and how that hands-on experience turned into conference talks and a genuine specialty. The conversation covers the difference between self-signed certs and proper CA infrastructure, why code signing deserves more attention than it gets, and how integrating signing into a CI/CD pipeline is less painful than it sounds. They also get into the "developer-ization" of IT, the underrated value of consulting experience for career growth, and why communicating across teams is just as important as knowing your PowerShell.   Key Takeaways: Code signing through a CI/CD pipeline is a practical, scalable alternative to constrained language mode. By adding a signing step to your build process, you get cryptographic proof that scripts haven't been tampered with, without giving up flexibility in what you can run. Self-signed certificates are essentially the same as having no certificate at all. A proper PKI means having a chain of trust, a policy behind how certs are issued, and infrastructure that your organization actually manages and maintains. Technical depth only gets you so far. The people who advance in IT are the ones who can talk networking with network engineers, infrastructure with server teams, and business outcomes with leadership. Soft skills aren't a bonus, they're a multiplier. Guest Bio: Leo D'Arcy is a UK-based cloud solutions architect with nearly a decade of consulting background in Microsoft technologies, including Azure, remote access solutions, PKI, and Active Directory Certificate Services. He's a repeat speaker at PSConfEU and runs the Remote Access User Group community on Discord. He's currently focused on Azure landing zone architecture and large-scale PowerShell automation at a stakeholder advisory firm.   Resource Links: Leo on GitHub: github.com/ld0614 PSConfEU: psconf.eu Leo on Bluesky: https://bsky.app/profile/leodarcy.bsky.social Leo on LinkedIn: https://www.linkedin.com/in/leodarcy/ Connect with Andrew: https://andrewpla.tech/links Microsoft Remote Access User Group Discord: https://discord.aovpndpc.com/ The PowerShell Podcast on YouTube: https://youtu.be/BidUaXtwUNM

The Cloudcast
AI Cyber is expanding a Vulnerability Gap

The Cloudcast

Play Episode Listen Later Jun 17, 2026 26:03


SUMMARY: As tools like Mythos create new AI-cybersecurity concerns, CIOs and CISOs need to be prepared for two challenges: Security Remediation and Patch to Production. SHOW: 1037SHOW TRANSCRIPT: The Enterprise AI Show #1037 TranscriptSHOW VIDEO: https://youtu.be/H5KxoiEIfUoSHOW SPONSORS:Nasuni - Activate your data for AI and request a demoOutShift by Cisco - “Scaling Out Superintelligence”  The Internet of Cognition architectureShareGate - ShareGate Protect. Microsoft 365 Governance, we got this!SHOW NOTES:Project Lightwell (Red Hat and IBM)Athena (Chainguard)Anthropic Project GlasswingOpenAI GPT 5.5-CyberTHESIS: Major initiatives are forming to help enterprise organizations combat security vulnerability threats found or created using new AI-cyber tools such as Anthropic Mythos. What are the key considerations, and what additional steps do organizations need to take to be advantaged by these capabilities? Part 1The Breaking Point and the Mythos MomentThe scope of open source security and supportPatches, disclosures and upstream open sourceClearinghouses, EOs, Laws and CommunitiesRemediation - Build vs. BuyPart 2How fast can you get from Patch to Production?Mitigation before patchingFast path and stable patch pipelines?Automation in patching vs. automation in deploymentFEEDBACK?Email: show @ the enterprise ai show dot comeBluesky: @TheEntAIShow.bsky.socialTwitter/X: @TheEntAIShowInstagram: @TheEntAIShow

Microsoft Threat Intelligence Podcast
Hot Cybercrime Summer:  Smishing, Supply Chains, and Sleuthcon

Microsoft Threat Intelligence Podcast

Play Episode Listen Later Jun 17, 2026 40:18


In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo sits down with Aurora Johnson of SpyCloud and Amitai Cohen of Wiz ahead of SleuthCon to explore two rapidly changing corners of the cybercrime landscape.   Aurora breaks down the highly organized Chinese-language smishing ecosystem, revealing how phishing operations, fraud networks, and cash-out schemes work together like a mature business.   Amitai examines the growing threat to software supply chains, explaining how groups like Team PCP are exploiting CI/CD pipelines, open-source dependencies, and AI-assisted malware development.   Together, they discuss the industrialization of cybercrime, the role of automation and AI, and why defenders must rethink how they secure today's interconnected digital ecosystem.   In this episode you'll learn:       Why cybercrime ecosystems now operate like sophisticated businesses  How NFC relay attacks are being used to cash out stolen credit card data  The role Telegram marketplaces play in modern fraud operations  Some questions we ask:      How industrialized has modern cybercrime become?  What clues suggest threat actors are using AI to create malware?  What are defenders missing about CI/CD pipelines as an attack surface?  Resources:   View Aurora Johnson on LinkedIn   View Amitai Cohen on LinkedIn   View Sherrod DeGrippo on LinkedIn     Related Microsoft Podcasts:                    The BlueHat Podcast  Uncovering Hidden Risks      Discover and follow other Microsoft podcasts at microsoft.com/podcasts     Get the latest threat intelligence insights and guidance at Microsoft Security Insider    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

DevOps and Docker Talk
K8s Maxxing with AI-Native Platform Engineering Stack with OpenChoreo

DevOps and Docker Talk

Play Episode Listen Later Jun 13, 2026 54:59


OpenChoreo is an opinionated, “batteries included”, AI-native Kubernetes platform stack for Platform Engineers that combines GitOps, Observability, AI Agents, and Workflows into a custom K8s distribution “super pack” that is managed via Backstage, CLI, API, or MCP. Now a CNCF project.Check out the video podcast version here: 

Develpreneur: Become a Better Developer and Entrepreneur
AI Deployment Ownership: Why Infrastructure Skills Matter More Than Ever

Develpreneur: Become a Better Developer and Entrepreneur

Play Episode Listen Later Jun 11, 2026 29:48


As AI becomes increasingly capable of generating code, many developers are asking the wrong question. Instead of asking whether AI will replace developers, a better question is: What skills become more valuable when code generation becomes easier? The answer may be AI Deployment Ownership. About Jason Sherman Jason Sherman is a serial entrepreneur, filmmaker, author, and technology founder best known for building practical solutions that bridge the gap between emerging technology and real-world business problems. He is the founder and CEO of Vengo AI and has launched multiple technology platforms throughout his entrepreneurial career. Jason is known for his direct, hands-on approach to innovation, focusing on execution, product development, AI implementation, and helping businesses leverage technology without losing sight of operational realities. His perspective combines startup experience, software development expertise, product strategy, and a strong belief that technology should solve actual business problems rather than chase trends. Links: Facebook, Twitter / X, YouTube, LinkedIn, Website AI Deployment Ownership Changes the Developer Role Historically, many developers focused on implementation. Their value came from translating requirements into working code. Today, AI can assist with much of that work. That shifts responsibility upward. Developers are increasingly expected to understand: Architecture Infrastructure Security Deployment Automation The ability to oversee an entire system becomes more important than writing every line manually. Insight: AI raises the importance of systems thinking. Why Building Is No Longer Enough Many AI-created applications work perfectly in development environments. Production introduces a different reality. Organizations need: Monitoring Logging Security controls CI/CD pipelines Recovery procedures These are areas where experience matters significantly. An application that functions correctly in a demo environment may fail quickly when exposed to real-world usage patterns. AI Deployment Ownership Requires Infrastructure Knowledge One of the strongest themes from the conversation was ownership. Developers who understand deployment gain an advantage by moving beyond simple application development. Key capabilities include: Server management API security Automated deployments Version control workflows Environment management These responsibilities cannot be delegated entirely to AI. Action: Learn how applications move from development into production. The Rise of the Technical Operator The next generation of developers may resemble technical operators rather than pure coders. Their responsibilities include: Reviewing AI output Managing architecture Protecting infrastructure Maintaining reliability This shift mirrors previous technology transitions. Tools become easier. Responsibility becomes greater. AI Deployment Ownership Creates Career Protection Developers concerned about long-term career relevance should focus on areas where judgment matters. AI can generate code. It cannot reliably assume accountability. Organizations still need professionals who can: Evaluate tradeoffs Assess risks Make deployment decisions Own outcomes That ownership creates value. Conclusion The future belongs to developers who understand entire systems rather than individual code files. AI Deployment Ownership represents a practical path forward for developers looking to remain relevant in an increasingly automated environment. Stay Connected: Join the Developreneur Community

Open Source Security Podcast
Hacking your CI/CD with François Proulx

Open Source Security Podcast

Play Episode Listen Later Jun 8, 2026 35:37


Josh welcomes back François Proulx to talk about the absolute madness in the CI/CD universe right now. We also learn about François' new project SmokedMeat which is a tool to help you hack your own CI/CD. When Josh spoke to François a year ago, the world was a very different place than it is today. François has a ton of knowledge about how we got here and what we can do moving forward. Boost Security has a bunch of amazing open source tools François built that can help keep CI/CD systems understood and locked down. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-françois-smoked-meat/

Explicit Measures Podcast
534: CI/CD Automation with Agents in Fabric

Explicit Measures Podcast

Play Episode Listen Later Jun 4, 2026 61:22


Mike & Tommy dive into CI/CD automation with agents in Microsoft Fabric, exploring how agentic workflows are reshaping deployment pipelines, whether AI-driven deployments introduce more speed or more risk, and what guardrails teams need before letting agents touch production workspaces.https://github.com/microsoft/fabric-task-flowshttps://learn.microsoft.com/en-us/fabric/cicd/deployment-pipelines/get-started-with-deployment-pipelines?tabs=from-fabric%2Cnew-uihttps://learn.microsoft.com/en-us/fabric/cicd/variable-library/get-started-variable-libraries?tabs=home-pagehttps://github.com/mattpocock/skills/blob/main/skills/productivity/handoff/SKILL.mdGet in touch:Send in your questions or topics you want us to discuss by tweeting to @PowerBITips with the hashtag #empMailbag or submit on the PowerBI.tips Podcast Page.Visit PowerBI.tips: https://powerbi.tips/Watch the episodes live every Tuesday and Thursday morning at 730am CST on YouTube: https://www.youtube.com/powerbitipsSubscribe on Spotify: https://open.spotify.com/show/230fp78XmHHRXTiYICRLVvSubscribe on Apple: https://podcasts.apple.com/us/podcast/explicit-measures-podcast/id1568944083‎Check Out Community Jam: https://jam.powerbi.tipsFollow Mike: https://www.linkedin.com/in/michaelcarlo/Follow Tommy: https://www.linkedin.com/in/tommypuglia/

Software Engineering Radio - The Podcast for Professional Software Developers
SE Radio 722: Dwayne McDaniel on the Engineering Challenges of Secrets Management

Software Engineering Radio - The Podcast for Professional Software Developers

Play Episode Listen Later May 27, 2026 52:10


Dwayne McDaniel, developer advocate at GitGuardian.com, joins host Priyanka Raghavan to talk about the engineering challenges of secrets management. They explore what "secrets" really are in modern systems—far beyond passwords—including API keys, tokens, certificates, and machine identities, and how "secret sprawl" emerges across the SDLC. Drawing on reports from GitGuardian and Verizon, they discuss the growing scale of secret leaks and why credential abuse and phishing remain dominant attack vectors. They examine common leak points—from code repos and logs to CI/CD pipelines, containers, and SaaS integrations—and how cloud, DevOps, and AI tooling are amplifying risks. Priyanka quizzes Dwayne about recent supply chain attacks from pyPi and trivy ecosystems, highlighting recurring root causes like poor access control, long-lived credentials, and weak security hygiene. Finally, they consider detection, response, and modern solutions—short-lived credentials, secret scanning, and identity-based approaches like OWASP NHIR and SPIFFE/SPIRE—ending with practical advice for engineers to reduce blast radius and design for secure secret lifecycle management.