I'm CTO at Buildkite, have been noodling on one with a view to have an environment that can run CI workloads and Agentic ones https://github.com/buildkite/cleanroom
1,755 karma · joined March 17, 2010
I'm CTO at Buildkite, have been noodling on one with a view to have an environment that can run CI workloads and Agentic ones https://github.com/buildkite/cleanroom
Enjoying writing some really fast Zig implementations of hand evaluation and CFR-based solvers.
> generally available through an API (next to GPT-4)
In the top right corner there is "Tire Service Mileage" with an estimate of when you should service your tires. There is a reset link under that, which links into the "Wheel and Tire" service tab with more maintenance options.
There are alerts for nearly all of the things you mentioned: https://www.tesla.com/ownersmanual/model3/en_us/GUID-E95DAAD...
Regarding the tire wear, the car is heavy with instant torque. I've had to replace my tires quite a few times, but it's the only thing that has needed much servicing for me in the past three years. I'd expect that from a new car though, and I don't have much confidence in it's longevity.
Username space remapping wasn’t adequate, for reasons I’m a bit blurry on. I think recent kernels have some better options on remapping permissions across file systems.
There are radically better isolation strategies now. Firecracker and/or Sysbox hardened docker containers is one I’ve recently implemented.
Well written tools and cross-functional teams that do both operations, feature work and security are still the path forward IMO, we just need to refocus on developer experience.
For the CI/CD usecase on AWS, sysbox presented the right balance of trade-offs between something like Firecracker (which would require bare metal hosts on AWS) and the docker containers that already existed. We specifically need to run privileged containers so that we could run docker-in-docker for CI workloads, so rootless docker or podman wouldn't have helped. Sysbox lets us do that with a significant improvement in security to just running privileged docker containers as most CI environments end up doing.
Just switching their docker-in-docker CI job containers to sysbox would have mitigated 4 of the compromises from the article with nearly zero other configuration changes.
This seems the obvious flaw in this hypothesis.