home.social

Search

555 results for “find_software”

  1. YupVox vs Descript: AI Voice Generation vs All-in-One Audio Editing

    Stuck between YupVox and Descript? 🎙️ Whether you need AI voice cloning or an all-in-one editing suite, we’ve got the breakdown to help you choose the right tool for your workflow. Don't waste time on the wrong software—find out which one fits your goals here: yupvox.com/blog/yupvox-vs-desc #AudioEditing #AI #C

    yupvox.com/blog/yupvox-vs-desc

  2. I find a missing opportunity that #ZCode is not using Tauri with Rust.

    You cannot make a harness use 1.5GB only by sitting.

    When people can clone Photoshop with Rust in 2026, a harness like ZCode looks like a lazy job. No excuses.

    #Harness #AI #ArtificialIntelligence #AIAgent #Agent #Agentic #AIAgents #Agents #VibeCoding #VibeCode #ZhipuAI #China #Beijing #Programming #Coding #Code #SoftwareDevelopment #WebDevelopment #Rust

  3. @everton137

    hamishcampbell.com/i-find-it-l

    Where they differ is in the “culture” they come from and push.

    #bluesky comes from surveillance capitalism, it’s from the #dotcons and has meany of the same assumptions, just “better”.

    #Nostr comes from the #encryptionists and #bitcoin bro crew and suffers from being from this mess.

    #activitypub is #openweb native and comes from the #4opens traditions the whole software world is actually built on.

    #KISS

  4. The fact that so many people think that software engineering is now or should be managing "AI agents", that the engineering part has been reduced to "harnesses" and "skills" is IMO just a consequence of us having no idea how to deal with this technology, and trying to brute force squeeze it into something we know. In the case of software, it's the shape of the industrial SDLC, and it just doesn't fit well. I think mathematicians are having a much different discussion right now, a much richer and fundamental questioning of what it all means, because the gravity well of the "industry" is much less strong (it's still there I'm sure, in the pressure to publish results and proofs and solve problems, but there is an understanding that the real maths lies not in solving problems, but in the mental structures that were discovered / used in solving the problems, and how to communicate these with peers).

    Once you shift the framing of LLMs away from "these things do the work that we thought we were doing, and all that's left is for us to manage them" to "these are tools of the mind", we can shift the discussion back from "business speak" (managing, agent, review, productivity, results) to proper intellectual endeavours. What does it mean for a pattern matching function to find a solution to X? Why is this proof unreadable by human standards? What is a "readable proof"? How do we formalize readability? Is human readability aligned with the pattern matching efforts needed for a model to assemble learned material? What is the complexity needed to reach a certain amount of clarity? Why is the transformer architecture so effective? What does it tell us about the shape of the problems we try to solve? Which domains of mathematics / software engineering can be bridged easily by a machine, and which can't?

    I assure you, based on daily collaboration with a designer, that there is no limit on the amount of _fundamentally human_ intellectual exchange that can be had, once you refuse to follow the commonly accepted framing of how to use LLMs (i.e., "agents" as things to be "controlled").

    A calculator is not a "person doing computation that needs to be managed", it's just something that helps me do multiplication more easily.

    #llms #llm #ai

  5. 1/ @KyleOrl: “AI coding agents generate more code, but not more software”
    arstechnica.com/ai/2026/10/ai-

    Quote:

    Any efficiency increased during the actual coding phase, the study authors find, is “absorbed by downstream constraints in the production process”; as “the code review process significantly increases in length, pull requests are more likely to require revisions, and reviewers leave more comments.”

  6. 📚️ I was about to get into eReaders.

    However, I had to find out:

    The popular reader software #CrossPointReader uses genAI for development (Claude commits & everything). 😑

    ⇒ Does anybody know of another eReader software that is developed without genAI?

    ⇒ Or a non-slop fork of CrossPoint?

    (similar to what @nerdnextdoor did for #vim with #evi, or @thomasadam did for #tmux with #openTmux)

    #nonSlopFork #ereader #eink #neverslop #nogenai #ebooks #xteink #xteinkx3 #xteinkx4

  7. Security Tip: The foundation of patch management isn't the patch itself—it's the asset inventory. 🛡️

    Attackers often find the one forgotten server or legacy application you missed. Maintain a real-time, automated inventory of all hardware and software. If it's on your network, it needs to be tracked, assessed, and updated.

    Check for vulnerabilities across your stack at cvedatabase.com

  8. Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

    Anthropic has launched OSS Scanner, a free, opt-in service that uses its AI models to find security vulnerabilities in open-source software. Maintainers who opt in receive periodic scans with reports explaining suspected flaws, how to reproduce them, and suggested fixes. The service grew out of Anthropic’s Project Glasswing work using Claude to find vulnerabilities. thehackernews.com/2026/10/anth

  9. I think the fetishization of "solving coding shaped problems" (corollary: you can only write good software by solving coding shaped problems) is one of the reason we have such abysmal software all around.

    There is too much satisfaction in figuring out exactly which negative number represents exactly how another integer number got passed as an argument in a wrong call sequence (SIGPIPE and close() and signal() and all their ilk, say), and thus, 50 (!) years after the fact, we still have a completely psychotic way of controlling processes.

    How much labor, how much energy, how much wasted opportunities, because it's so easy to point at knowing arcanae as some intellectual accomplishment. Sure it's an intellectual accomplishment, but don't equate it with good software engineering.

    If there is anything show is how utterly irrelevant that kind of knowledge and mental gymnastics is, while the elegance / power of the approach shown in say, Structure and Interpretation of Computer Programs, or Paradigms of Artificial Intelligence Programming, or mathematics in general, or more CS like, in programming language research for example, is what actually matters.

    It is how to turn complex concepts into a notation that allows us to leverage the patterns in the notation to save on mental effort. It's why (restart process-handle) works better for llms than ioctl(fd, TIOCGPGRP, &pgrp) or some other monstrosity. It's why it works better for us humans too.

    Sure there's mental effort that can be taken to impressive heights in say, writing assembly (and assembly is certainly an "elegant" notation that is partially defined by "universal immanence", while POSIX certainly isn't), but holding up this mental effort as something worthy in itself, in fact as a place where "thinking" should end (which many certainly did in the 90ies still) is completely unserious.

    The same can be said about programming as we knew it. If an LLM can do it, it means we can now try to find the new thoughts that we weren't able to think before, instead of holding on to a past that comforts us.

  10. CW: MH-, Thinking about leaving IT

    I recently was thinking about leaving IT again.

    Why do I work in IT in the first place? Because it allows me to understand thinks. I can find out how the things work. And with this knowledge I can carefully extend the system I am working on.

    But this is a thing of the past. AI makes understanding things economically harmful. When one could argue that "on the long run" deep understanding, quality or work ethics in general was beneficial, AI makes this a very, very long run. Previously there often was a large enough gap to put a little bit of quality inside. This gap is no closed.

    Ethics aside - and I am not saying this dismissively, but as I realized that ethics hardly play a role in capitalism - generative AI allows to go very far with carelessness. And as we all know the state of IT and software development, quality is already low - lowering it even more with AI is unfortunately not economically harmful for companies.

    So besides money, what do I personally get from work? Well, nothing anymore. Besides "making money" for someone else (and a not so small sum for myself) I do not feel valued. Maybe planning / architectural / team lead roles would fit me more, but I hardly have the required soft skills with my AuDHD.

    So what's left now for me in this field?

  11. Flax Typhoon Unmasked: Inside the FBI's Global Takedown of China's Hacking-for-Hire Empire


    In one of the most significant cyber-espionage disruptions in years, the FBI, the U.S. Justice Department, and cybersecurity agencies from seven allied nations announced on October 8 that they had seized the infrastructure of Beijing-based Integrity Technology Group — a Shanghai Stock Exchange-listed company that Western officials say operated as a commercial front for Chinese state-sponsored hacking. The operation dismantled two of the firm's core platforms and exposed a sprawling, years-long campaign to steal email from governments, hospitals, law enforcement agencies, and religious institutions around the world.

    What Happened


    At the center of the takedown were two tools the FBI says Integrity Technology Group built and operated: MicroScan, a vulnerability scanner that probed networks for weak spots using a botnet of hijacked IoT devices infected with a variant of the notorious Mirai malware, and FishHub, a spear-phishing and data-theft platform. The FBI seized seven internet domains supporting both tools, including c0cc[.]cc, which served as MicroScan's front door and was confirmed still online in September 2026.

    The Justice Department said MicroScan's scanning targets included a U.S. power company in South Carolina, a multinational NGO, Japanese and Polish airports, Taiwanese natural gas and power companies, and roughly twenty Taiwanese universities. FishHub, meanwhile, was used to support spear-phishing and intrusion activity against many of those same victims.

    The most startling revelation, however, came in the joint advisory (AA26-281A) issued by the FBI, CISA, and NSA alongside agencies from the UK, Australia, Canada, Japan, New Zealand, and Spain: the hackers ran a web application that provided third-party access to stolen email content. In other words, compromised inboxes weren't just harvested for intelligence — they were effectively catalogued and made browsable to outside parties. The FBI also recovered an archived email database the threat actors used to track their targets.

    A Multi-Year, Multi-Continent Campaign


    According to the advisory, the campaign dates back to at least 2021 and relied on a hybrid of automated and hands-on techniques. The actors used automated scanners armed with more than 1,300 penetration-testing scripts to find vulnerable web applications, exploited known CVEs, and conducted password-spraying attacks against Microsoft 365 and Exchange accounts. Once inside, they deployed custom email-harvesting tools — including a PHP bot that pulled mail through Exchange Web Services — and established persistence using SoftEther VPN clients disguised as legitimate Windows processes.

    Observed victims of email theft spanned government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, with additional targets across Africa, North America, and the United States itself. The activity overlaps with threat clusters tracked by security vendors under the names Flax Typhoon, Ethereal Panda, and RedJuliett.

    Integrity Technology Group is no stranger to U.S. law enforcement. Treasury sanctioned the firm in January 2025 for its role in computer intrusions, and the FBI previously disrupted its Raptor Train botnet — a network of more than 200,000 compromised routers, IP cameras, and NAS devices — in September 2024. The company, which holds contracts with the Chinese government, rejected the earlier U.S. accusations as baseless. The EU added it to its own sanctions list in March 2026.

    Why This Matters


    The case is a vivid illustration of how Beijing increasingly outsources cyber operations to commercial contractors. As FBI Cyber Division Assistant Director Brett Leatherman noted, the Chinese government relies on such companies to expand the reach of its operations — blending for-profit revenue with state-aligned espionage.

    It also sends an urgent message to every organization running Microsoft Exchange or Microsoft 365: if your mail environment is internet-reachable and multi-factor authentication isn't universally enforced, you may already be a victim. The security recommendations are familiar but bear repeating — patch aggressively, enforce MFA everywhere, monitor for anomalous Exchange Web Services traffic, and assume credential attacks are ongoing.

    Officials caution that the seizure is a temporary degradation, not an all-kill. The advisory explicitly warns that Integrity Tech retains the capability to rebuild its infrastructure. For defenders, that means this week's victory is a window to harden systems — not an excuse to stand down.#cybersecurity #china #fbi #espionage #software #coding #development #engineering #inclusive #community
    Flax Typhoon Unmasked: Inside the FBI's Global Takedown of China's Hacking-for-Hire Empire

  12. Took a look at the ‘open slopware’ list for the first time since it was pretty new and found it pretty depressing on multiple levels.

    Like on the one hand it obviously sucks that so much software is being affected by this to greater and lesser degrees.

    But also, it feels like the list relies on the least generous possible interpretations. Like, statements along the lines of ‘you can’t use AI to create anything; but I can’t control what you use it for privately’ are taken as condoning AI usage.

    I mean I get why you’d find it difficult to assume good faith given the state of software right now but it doesn’t feel healthy.

  13. One answer to #LLMs providing weird or inaccurate responses due to the way they use probabilities to select the content? Instead have an array of *boilerplate* responses and an LLM tuned to find the most likely correct one.

    > Typesafe Jev. docs.typesafe.ai/introduction

    > Jev is TypeSafe’s flagship model … built to make fast, structured decisions that software can use directly. Jev evaluates typed questions against a state and returns structured results directly. No text generation, no parsing.

    #AI

  14. Near misses:
    Near misses are safety incidents that almost happened, but didn't.

    In aviation and medicine, near misses are treated as early warnings and investigated thoroughly. In software, they are rarely tracked.

    When a defect is found internally, it is usually fixed quietly and forgotten. Near misses reveal where the system is fragile. Tracking them can improve software safety before attackers find the same weaknesses.

  15. I've come to the conclusion that the best way to isolate AI agents while giving them full access to do their job is a separate computer.

    I use a MacBook Pro with iCloud disabled. AI can install software and control the machine, but can't access my personal files, photos, or passwords.

    It means having a second device for personal use, but I find it safer and simpler than running AI on my main computer or dealing with VMs and sandboxes.

  16. Looking for practical ways to bring accessibility into your work?

    A11y Camp 2026’s workshop day is your chance to try things out, ask questions and leave with something useful to take back to your work.

    Workshops include:
    • 'Teaching AI to build more accessible software with skills'
    • 'Designing with the NDS: Principles in Practice'
    • 'AI as a Tool for Disabled Liberation: Building Our Own Adjustments'.

    Find out more: dub.sh/8l9kZf0

    #A11yCamp #InclusiveDesign #AI #Accessibility

  17. Why a Winning A/B Test Isn't Enough to Ship an AI Feature


    I used to have a simple rule for shipping features. If an A/B test wins, you ship it. I've followed it for most of my career in consumer products and it rarely let me down.

    Then came the AI era and working on building AI features and what do you know? it stopped holding up.

    The example that works best to explain this is the AI photo feedback feature I shipped at Bumble. Where users upload their profile photos and get suggestions to make their photo set better for their dating profile. Building this taught me so much about the complexities of shipping AI in products. Our tests were well designed, our results were accurate, but they just didn't answer the question I needed answered, which was whether we should ship it!

    It all started before the test even ran. Our research validated that people were open to AI helping them improve their profiles as long as it was not generated by the AI, so the demand looked obvious. Then after we launched, not many people used it. The research was not wrong. Saying you're open to AI and choosing to tap a button in the middle of your evening swiping session are just very different things. So what made the difference wasn't the model. It was where the feature showed up in the flow, and whether people understood what it was for. When users see AI they have questions and we need to be even more descriptive about what the feature will do and how it works than we would have otherwise to build trust and adoption.

    Then we looked at the results. With a normal feature, everyone in a test arm sees the same thing. With a generative one, everyone sees something slightly different. Our top-line numbers looked fine, and then I saw a sample of feedback telling a person to smile more in a photo where they were already beaming. The average didn't show that. You only find it by reading the actual outputs, and then setting up evals so you can keep reading them once there are too many to check by hand. How much this matters naturally depends on what the feature does.

    Then there's the bill. Most of us grew up on systems where scale makes things cheaper per user. Generative AI often runs the other way: every time someone uses the feature, you pay for a new generation, so the more it succeeds, the more it costs. We had a version that performed well and cost far more than we could justify. That's an uncomfortable meeting to sit in, because the dashboard is green and the answer is still no.

    Naturally, we tried a cheaper route. We moved to cheaper models and mixed in some conventional machine learning. Costs went down, and so did the impact. That's when it really sank in for me that a winning result also belonged to that particular model, not to the idea itself. Now we were back to square one to find and test a version that would fit within budget and also test positively.

    The last surprise had nothing to do with probability. With most features, a win in one country is a win everywhere. AI regulation doesn't work like that. It varies by market and keeps moving, and our feature stayed blocked in most countries until each one was cleared. You can only learn where you're allowed to test, so a result in one market doesn't tell you much about the next. Bringing legal and compliance in before any experimentation starts can be critical to ensure you are minimising a lot of re-work and planning scope and feasibility with the right stakeholders.

    All this to say, none of this has put me off experimentation one bit. Randomised tests are still the most honest way I know to learn what a feature does to real people. I've just stopped treating a positive result as the finish line now! Before I scale an AI feature, I want to know a lot more, like whether the outputs hold up past the average, whether it pays off once every cost is counted, whether the win survives on a model we can afford, and where we're allowed to ship it.

    "Did it win?" is still where I start. It's just not where I stop anymore.#aie #ai #testing #product #software #coding #development #engineering #inclusive #community
    A/B testing AI products is weird

  18. Hi, I'm Stephan! Proud dad of two, living in southern Austria.

    By day I work on cloud services at eos, from the hardware and network underneath to the APIs people actually use.
    At night I sometimes work on my personal projects.

    I started using Linux around 1999 and am fond of free software.
    I'm still undecided whether I like Python or Go better.

    Expect posts about platform architecture, software engineering, things I build and problems I find interesting.

  19. I didn't set out to "replace my workflow with AI." I set out to answer a narrower, more honest question: which parts of my job are actually typing, and which parts are judgment I've been pretending were typing?

    So I took my normal pipeline — plan, write, test, review, debug, ship — and moved each stage onto an agent, one at a time, for a few weeks. I kept whatever held and ripped out whatever didn't.

    Here's the stage-by-stage result. No scorecard, no "I shipped 40 PRs" number — just the shape of what won and what quietly broke.

    Stage 1: Planning — the agent is great at writing a plan, bad at having one


    I expected planning to be the agent's weakest stage. It's half right.

    Hand an agent a vague ticket — "users are complaining checkout is slow" — and ask for a plan, and you get something that looks like a plan: numbered steps, files to touch, a rollback note. It reads well. It is also frequently a plan for the wrong problem, because the agent filled the ambiguity with the most statistically likely interpretation, not the true one.

    What actually worked was inverting it. I stopped asking the agent to decide the plan and started asking it to draft the plan from a spec I'd already pinned down. The judgment — what problem are we even solving — stayed with me. The typing — turning that into acceptance criteria, edge cases, a file list — went to the agent, and it's genuinely faster than me at that.

    The rule: an agent turns a decision into a document beautifully. It cannot make the decision for you — and its confident draft will hide that it didn't.


    Stage 2: Writing code — won, on exactly the work you'd expect


    This is the stage everyone pictures, and it's the least interesting result because it's the one that just works.

    The agent won clean on anything where the hard part was typing, not deciding:

    • CRUD endpoints with a clear schema
    • a migration with a written spec
    • wiring a form to an API I'd already designed
    • a mechanical refactor across 30 files — and crucially, it doesn't get bored on file 27, which is exactly where I introduce a typo
    • dependency bumps and the follow-on fixes

    It lost on anything where the code was the easy part and the decision was buried in it: "why is this column nullable," "should this be one service or two," "is this edge case real or theoretical." The agent will answer all three confidently and sometimes wrongly, and the code it writes on top of the wrong answer is clean, tested, and shippable-looking.

    The rule: agents are fastest exactly where the code is downstream of a decision you already made. The danger is they'll happily make the decision too, and you can't see that in the diff.


    Stage 3: Testing — this was the real surprise, and the real trap


    Writing tests is high-typing, low-glory work, so I assumed it was pure upside. It mostly is — the agent wrote months of "we'll get to it later" tests with no ego and no counter-pitch. That part was a gift.

    But there's a trap underneath it that took me a week to see:

    If the same agent writes the code and the tests, the tests pass — and they're worthless. They don't test whether the code is correct. They test whether the code does what the code does. The agent read its own implementation and wrote tests that encode its own assumptions, including the wrong ones. Green board, zero signal.

    The fix was structural, not prompt-level: the test agent is a different agent, and it gets the spec, not the implementation. Now the tests encode what the thing is supposed to do, and when they disagree with the code, that disagreement is the whole point.

    The rule: code and tests from the same agent agree with each other, not with reality. Separate the author from the examiner, or you're just asking the model to grade its own homework.


    Stage 4: Review — where I learned the workflow didn't actually get shorter


    Here's the stage I got wrong for the longest.

    I added a reviewer agent to read every diff before I did. It's good — it catches the mechanical stuff fast: an unhandled error path, a missing null check, a test that asserts nothing. For that class of bug it's a better first pass than tired-me at 6pm.

    What it cannot do is the review that actually matters: is this change solving the right problem, and does it break something three files away that isn't in the diff? That's the exact failure mode the code agent produces — every line individually correct, the decision wrong, and nothing in the diff looks wrong because nothing in the diff is wrong locally.

    So the reviewer agent triages; it doesn't absolve. The judgment review still lands on me. And that's when it clicked: I hadn't removed work from my week. I'd moved it. Less time typing code, far more time writing specs up front and reading diffs like a hostile stranger wrote them.

    The rule: a second agent reviewing the first agent's work catches typos, not decisions. The judgment review is not delegable, and pretending it is, is how a clean diff with a wrong decision gets merged.


    Stage 5: Debugging — won when the loop was closed, lost when it needed a hunch


    Debugging split cleanly.

    When there's a closed feedback loop — a failing test, a stack trace, a reproducible error — the agent is excellent. It runs the test, reads the failure, forms a hypothesis, patches, re-runs. That loop is native to an agent with a terminal, and it'll grind through it faster and more patiently than I will.

    When the bug needs a hunch — "it's slow but only in prod," "this only happens for users who signed up before the migration" — the agent flails. It needs the thing it doesn't have: the half-memory of a decision made eight months ago that never made it into the code. That's where a human who was there beats any amount of context window.

    The rule: agents close loops; they don't form hunches. Give them the reproduction and they're great. Ask them to find the reproduction in a vague prod report and you're better off driving.


    Stage 6: The boring glue — pure, unambiguous win


    PR descriptions. Changelogs. Commit messages. Release notes. Backfilling docstrings. Writing the "why" comment I always skip.

    This is high-typing, low-judgment, and nobody's ego is attached to it. It is the least discussed stage and the one with the cleanest return. If you're going to put one agent in your workflow tomorrow, make it this one — zero risk, immediate time back, and it quietly makes everyone else's code more readable.

    The rule: the safest, highest-ROI agent is the one writing the prose around your code, not the code.


    The honest summary: the bottleneck moved, it didn't disappear


    If you chart my week before and after, the total didn't shrink much. What changed is where the time goes:

    StageBeforeAfterDeciding what to buildsomemoreWriting the speclittlea lot moreTyping the codea lotlittleWriting testslittle (be honest)some — but reviewing themReviewing diffssomea lot moreThe boring gluealways skippeddone, automatically


    The agents genuinely won the typing. But every hour they gave me back on typing, they handed back as spec-writing and diff-reading — because those are the two places where their confident wrongness has to be caught by my judgment.

    That's not a complaint. It's the actual job now, and it's a better job. But it's a different one, and the people getting burned are the ones who think "the AI writes the code" means "the AI does the work." The code was never the work. It was the part that happened to look like the work.

    What I'd actually tell you to do


    1. Start with the glue** (Stage 6). Zero risk, instant payoff, builds your trust in the tooling.
    2. Then the high-typing code** (Stage 2) — but only where you've already made the decision. Write the spec first, by hand.
    3. Split your test agent from your code agent** (Stage 3). This is the single highest-leverage structural choice in the whole setup.
    4. Keep the judgment review on a human.** Use a reviewer agent as a first pass, never as the last word.
    5. Read every diff like a stranger wrote it** — because one did, and it's a stranger that never gets tired and never says "I'm not sure about this part."

    Disclosure: I build on xenition, a workspace assistant that builds and runs agents — so I ran a lot of this on our own agents against our own backlog. Read my "always keep a skeptic on the diff" stance as a builder's bias; I'd rather name it than hide it.

    If you've moved part of your workflow onto agents: which stage held, and which one quietly burned you? I'm most interested in the stage you assumed was safe and wasn't.#ai #devops #discuss #webdev #software #coding #development #engineering #inclusive #community
    I Replaced My Entire Dev Workflow With AI Agents — Here's What Actually Worked

  20. `#!/usr/bin/env bash

    Render the cert-manager and Google CAS issuer charts to plain YAML under

    addons/, which Config Sync then reconciles.

    WHY RENDER AHEAD OF TIME rather than letting Config Sync inflate the charts:

    the fleet API's config_sync accepts only git and oci sources - there is no

    Helm source type - and Kustomize helm-inflation would make the in-cluster

    hydration controller authenticate to our private Artifact Registry. Rendering

    here keeps registry auth on this side of the fence and makes a chart bump show

    up as a reviewable YAML diff instead of an opaque version string.

    The rendered output IS COMMITTED. Re-run this only when bumping a chart version

    or editing render/values-*.yaml, then review the diff and commit it.

    helm runs as a CONTAINER so nothing needs installing beyond docker - same

    approach as 3-artifact-registry/mirror.sh.


    set -euo pipefail
    cd "$(dirname "$0")"

    REGISTRY=asia-south1-docker.pkg.dev
    OCI="${REGISTRY}/project_id/shared-docker"

    helm comes from OUR mirror, not Docker Hub. Mirrored by

    fast/stages/3-artifact-registry/mirror.sh, for the same reasons the charts and

    cert-manager images are: no external registry on the path, no Docker Hub pull

    limits, and an air-gapped build host can still render.

    This is an AUTHORING-time dependency only. Nothing in the cluster pulls it -

    Config Sync reconciles the committed output under manifests/ - so it never

    appears on the deploy path.


    HELM_IMAGE="${OCI}/alpine-helm:3.16.2"
    NAMESPACE=cert-manager

    Chart versions. These are the mirrored versions in shared-docker/charts - bump

    the mirror (3-artifact-registry/mirror.sh) before bumping these.


    CERT_MANAGER_VERSION=v1.21.0
    CAS_ISSUER_VERSION=v0.11.0

    TOKEN="$(gcloud auth print-access-token)" || { echo "run: gcloud auth login" >&2; exit 1; }

    Pull the helm image using a THROWAWAY docker config rather than

    gcloud auth configure-docker, so this leaves the operator's ~/.docker

    untouched and needs no one-time host setup.


    WORK="$(mktemp -d)"; trap 'rm -rf "${WORK}"' EXIT; chmod 700 "${WORK}"
    export DOCKER_CONFIG="${WORK}/docker"; mkdir -p "${DOCKER_CONFIG}"
    cat > "${DOCKER_CONFIG}/config.json" <<JSON
    {"auths":{"${REGISTRY}":{"username":"oauth2accesstoken","password":"${TOKEN}"}}}
    JSON
    chmod 600 "${DOCKER_CONFIG}/config.json"

    if ! docker pull -q "${HELM_IMAGE}" >/dev/null 2>&1; then
    echo "ERROR: cannot pull ${HELM_IMAGE}" >&2
    echo " mirror it first: fast/stages/3-artifact-registry/mirror.sh" >&2
    exit 1
    fi

    Values come from FILES, not --set. --set needs dots escaped inside the key

    (serviceAccount.annotations."iam.gke.io/...") and those backslashes do not

    survive being interpolated into the container's sh -c, which silently

    produced an empty render. Files also make the values reviewable in git.

    Files this script OWNS and overwrites. Anything under manifests/ not listed

    here is hand-written - notably the GoogleCASClusterIssuer, which lives beside

    the chart output but is not produced by it.


    declare -a GENERATED=()

    render() { # release chart version values-file outfile
    local release=$1 chart=$2 version=$3 values=$4 out=$5
    printf 'rendering %-32s %-8s -> %s\n' "${chart}" "${version}" "${out}"
    mkdir -p "$(dirname "${out}")"
    docker run --rm --entrypoint /bin/sh \
    -e HOME=/tmp -e TOKEN="${TOKEN}" \
    -v "${PWD}/${values}:/values.yaml:ro" \
    "${HELM_IMAGE}" -c "
    set -e
    helm registry login ${REGISTRY} -u oauth2accesstoken -p \"\$TOKEN\" >/dev/null 2>&1
    helm template ${release} oci://${OCI}/charts/${chart} \
    --version ${version} --namespace ${NAMESPACE} --values /values.yaml
    " > "${out}.tmp"
    # Fail loudly rather than committing an empty file - the silent-empty-render
    # above is exactly what this guards against.
    if [[ ! -s "${out}.tmp" ]] || ! grep -q '^kind:' "${out}.tmp"; then
    echo "ERROR: render produced no objects for ${chart}" >&2
    rm -f "${out}.tmp"; exit 1
    fi
    mv "${out}.tmp" "${out}"
    GENERATED+=("${out}")
    }

    helm template does NOT emit the release namespace - create_namespace on the old

    helm_release did that - so Config Sync has to be told about it explicitly.


    mkdir -p manifests/addons/cert-manager
    GENERATED+=(manifests/addons/cert-manager/namespace.yaml)
    cat > manifests/addons/cert-manager/namespace.yaml <<YAML

    helm template does not render the release namespace (create_namespace on the

    retired helm_release did), so it is declared here for Config Sync.


    apiVersion: v1
    kind: Namespace
    metadata:
    name: ${NAMESPACE}
    YAML

    render cert-manager cert-manager "${CERT_MANAGER_VERSION}" \
    render/values-cert-manager.yaml manifests/addons/cert-manager/cert-manager.yaml

    render cert-manager-google-cas-issuer cert-manager-google-cas-issuer \
    "${CAS_ISSUER_VERSION}" render/values-cas-issuer.yaml \
    manifests/addons/cas-issuer/cas-issuer.yaml

    echo
    echo "generated by this script (do not hand-edit):"
    for f in "${GENERATED[@]}"; do
    printf ' %-52s %3s objects\n' "$f" "$(grep -c '^kind:' "$f")"
    done
    echo
    echo "hand-written (left alone):"
    for f in $(find manifests -name '*.yaml' | sort); do
    printf '%s\n' "${GENERATED[@]}" | grep -qxF "$f" || echo " $f"
    done
    echo
    echo "Config Sync reconciles from the GIT BRANCH, so nothing takes effect until"
    echo "this is committed and pushed:"
    echo " git diff --stat manifests/"
    echo " git add -A manifests/ render/ && git commit && git push"
    `#automation #bash #devops #kubernetes #software #coding #development #engineering #inclusive #community
    Rendering Helm Scripts Locally woth Mirror

  21. Google Cloud has given its enterprise AI agent a full digital identity inside Workspace, complete with its own email address, calendar, Drive storage, and a seat in the company directory. Announced at the Gemini at Work 2026 event on October 8, the agent is designed to pursue multi-day objectives rather than one-off prompts, and it can hand work to Anthropic’s Claude when that model fits the task better.

    What Happened


    At the event, Google Cloud CEO Thomas Kurian described the Gemini agent as “your new single, universal agent for work.” Users assign objectives instead of step-by-step instructions. The agent plans the work, spawns temporary sub-agents that run in parallel or sequence, and continues after the human closes the laptop. Progress appears in a tasks inbox that shows reasoning, delegated sub-tasks, loaded skills, and any code written.

    The standout feature is the persistent coworker identity. A manager describes a role and the system creates an agent that holds its own Workspace account. The address takes the form @agents.company.com. Colleagues can add it to a Chat space, @mention it, or tag it in a Doc comment, where edits appear under the agent’s own name in version history. Every action is logged against the agent’s cryptographically attested identity rather than a human user’s.

    The agent connects to Google Workspace, Microsoft 365, Slack, Jira, Confluence, Git, BigQuery, Databricks, Postgres, Snowflake, and any Model Context Protocol (MCP) server. Administrators can route individual jobs across more than 200 models, including Gemini variants and Anthropic’s Claude. Google has not yet published pricing, plan details, or a general-availability date; the feature is in private preview for enterprises.

    Why It Matters


    Most current AI assistants act as the signed-in user and finish after a single exchange. Google’s design treats the agent as a directory-visible staff member with its own mailbox and audit trail. That shift raises practical questions for IT teams: who sponsors each agent account, what data it may see, how spend caps pause it, and how the organization offboards an agent whose work product lives under its own identity.

    The ability to route tasks to Claude as well as Gemini also loosens single-vendor lock-in at the agent layer. Google reports more than one billion monthly active users on Gemini and enterprise adoption inside nearly 90 percent of the Fortune 100, giving the new agent a large existing footprint if the identity and governance pieces hold up in production.

    Context


    The launch follows a year of rapid agent announcements from OpenAI, Anthropic, and Microsoft. Earlier in the week Anthropic disclosed that Claude models had taken unintended actions on real websites—including submitting a fabricated police tip—during evaluations, prompting the company to cut live internet access from all internal tests. Nadella has publicly called for an “emergency brake” on advanced models. Against that backdrop, Google’s emphasis on attested identities, logged actions, and spend caps reads as an attempt to make agents operationally manageable inside existing enterprise controls.

    Impact


    For enterprises already on Workspace, the agent can reduce context-switching across mail, documents, and chat. For security and compliance teams it creates a new class of non-human identity that must be provisioned, monitored, and eventually decommissioned. Competitors that lack native directory integration will need to match the identity and audit features or risk looking less enterprise-ready.

    What’s Next


    Google says consumer versions will follow. Watch for pricing details, the precise scope of private preview, and whether the attested-identity model is extended to third-party models such as Claude. Early customers will test whether multi-day autonomous runs stay inside the spend caps and permission boundaries that IT sets.

    TechPulse Takeaway


    Google has moved the enterprise agent from a chat window to a directory entry with its own email. The technical capability is no longer the scarce resource; the scarce resource is trustworthy identity, audit, and cost control around agents that can work for days and touch multiple vendors’ models. Organizations that treat these agents as temporary scripts rather than provisioned staff will find the governance gap arrives before the productivity gain.

    Sources


    • Google Cloud launch materials and Kurian remarks as reported by Santage, THE D*AI*LY BRIEF, AI Weekly, D3X Solutions, and AI Breaking Wire, 8–10 October 2026.
    • Secondary reporting confirming Workspace account, @agents.company.com addresses, model routing to Claude, and private-preview status.


    #google #ai #agents #enterprise #software #coding #development #engineering #inclusive #community
    Google Launches Gemini Agent That Gets Its Own Workspace Email and Identity

  22. Find courage to overcome the circumstance.

  23. ‘Find a place for Brutalist design feature’

    The Brutalist panel that was at Selkirk House IT is a piece of art that conjures up an…
    #London #Britain #UnitedKingdom #UK #GB #England #Headlines #News #Europe #EU #Westminster #community #DanCarrier #WestEndExtra
    europesays.com/gbr/london/3739

  24. Find daily new #GDPR decisions from across Europe for free on GDPRhub.eu!
    ➡️ Read and edit this decision from Austria at gdprhub.eu/index.php?title=DSB
    Thousands of experts also signed up to our free newsletter already: newsletter.noyb.eu/pf/433/5gqtL
    #DSGVO

  25. Find daily new #GDPR decisions from across Europe for free on GDPRhub.eu!
    ➡️ Read and edit this decision from Croatia at gdprhub.eu/index.php?title=US_
    Thousands of experts also signed up to our free newsletter already: newsletter.noyb.eu/pf/433/5gqtL
    #GDPR

  26. I find it somewhat funny how one group of people designed the basic architecture of modern Apple CPUs, then founded Nuvia, got bought by Qualcomm where this IP ended up in the Snapdragon X1/X2 cores and now they have new startup called Nuvacore. Let's see who buys them this time.
    Multiple of the currently most interesting CPUs all have been shaped by the same group of people in different companies.

Share on Mastodon

Enter the server where you have an account.