home.social

Search

4 results for “prutser”

  1. Additionally, the pod is wrapped in a Kubernetes network policy that blocks all egress traffic except to the internet, to block a malicious agent from connecting to the cluster API, or other tenant pods.

    The upgrader is actually deployed as any other user app (`freepod deploy`), that might also run adversarial code.

    freepod.dev/

  2. Now having an agent scour the internet puts it at risk of prompt injection and so you may not want to also give it push access to the main repo. Yet, it still needs to create PRs.

    To be able to create PRs, the private key to the upgrader's GitHub App bot account is in the container's environment vars.

    To make this safe, we treat the agent session as adversarial code. The agent (Pi) is spawned as a different, non-root user and does not inherit the parent's environment. This way there's nothing to exfiltrate, nor can it push to github.

    The agent is told to commit its changes in its local clone only, and exit. The parent (regular code, not an agent) then creates a branch and opens the PR.

  3. In the morning I review the PRs which usually are just revving a docker tag, but can sometimes include significant changes to the custom helm charts we have for deploying each product to Freepod's Kubernetes cluster.

    For instance when an application adds a new sidecar container, upgrades database versions, changes config env vars / secrets, etc.

    Merging makes the updated Helm chart the default for new deployments, but upgrading the existing user instances is done with a rolling script.

  4. Freepod runs a nightly upgrader service that updates the curated product catalog for any product that has had a new release.

    This service is really an agent that scours github, dockerhub, compose files, helm charts, and release notes for new (stable) releases of each product and then opens a PR against Freepod's catalog files with the necessary Helm chart updates.

    Doing this manually for a growing catalog is very tedious, but keeping internet facing services up to date is essential.

    So putting the (local) clanker to work here is just so satisfying.

Share
Share on Mastodon

Enter the server where you have an account.