| |
| 🔗 Stories, Tutorials & Articles |
| |
|
| |
| Please stop externalizing your costs directly into my face |
| |
| |
SourceHut spent 20–100% of weekly time mitigating hyper‑aggressive LLM crawlers. That work caused dozens of short outages and delayed core projects.
The crawlers ignore robots.txt. They hit costly endpoints like git blame. They scan full git logs and commits. They rotate random User‑Agents and thousands of residential IPs to blend in and evade mitigations.
Trend to watch: Large LLM crawlers that disregard robots.txt and mimic user traffic are shifting scraping tactics. That shift piles ongoing costs onto small forges. |
|
| |
|
| |
|
| |
| Building a Least-Privilege AI Agent Gateway for Infrastructure Automation with MCP, OPA, and Ephemeral Runners |
| |
| |
Introduces an AI Agent Gateway. It mediates agent requests, validates intent, enforces policy-as-code, and isolates execution in ephemeral runners.
Agents discover tools via MCP. They submit JSON-RPC calls and receive OPA decisions. Jobs queue and run in short-lived namespaces. Each run carries plan hashes, traces, and SLOs. |
|
| |
|
| |
|
| |
| The hunt for truly zero-CVE container images |
| |
| |
Chainguard's Factory 2.0 and DriftlessAF rebuild images from source on upstream changes. They produce 2,000+ minimal zero‑CVE images. Each image includes an SBOM and a cryptographic signature.
Docker's DHI builds on Debian and Alpine. It mirrors Debian's no‑DSA triage into VEX. It also suppresses real CVEs until Debian patches and rebuilds. |
|
| |
|
| |
|
| |
| The Only Claude Skill Every DevOps Engineer Needs |
| |
| |
The Terraform Claude Skill turns Claude Code into a Terraform expert. It enforces modularity, strict naming, and consistent tagging. It treats the state file as the single source of truth.
It wires in external tools: linting, security checks, and cost estimates. It forces real-doc validation and blocks insecure IAM policies and monolithic Terraform files. |
|
| |
|
| |
|
| |
| Chinese Vulnerability Database: CNVD vs CNNVD Analysis |
| |
| |
Investigation profiles CNNVD and CNVD echo CVE. They reveal manual errors and poor machine-readability.
China’s July 2021 RMSV mandates 48-hour reporting and bans pre-patch disclosure. Mapping gaps exist. The databases published about 1.4k entries ahead of CVE, with lead times measured in months. |
|
| |
|
| |
👉 Got something to share? Create your FAUN Page and start publishing your blog posts, tools, and updates. Grow your audience, and get discovered by the developer community. |