200 karma · joined June 11, 2015
celld is the full distributed system (albeit single tenant). It distributes DOs (cells) across any number of VMs. The databases for each DO are in object storage with RPO=0 guarantee.
Plus a lot of these services are reached by tunneling through something else. We tunnel into k8s where it has dangerous credentials.
We also don't want to define MCPs for everything. The principle is that the agent doesn't need code changes, including skills/MCPs - it just accesses systems.
Claw Patrol lets us give agents more access because it's watching everything at the wire. `kubectl delete pod foo` waits for slack approval, SELECT on env_vars runs through an LLM judge to check if it actually returns secret data. For our setup this is security policy that is a single file, checked into git, that gates access across 14 k8s clusters, clickhouse, postgres, a dozen other HTTP APIs.
Regarding reinventing permissions - scoped credentials solve this to some extent, but it's really nice to have a single place where we can define rules for all services (eg "DROP TABLE" never can occur), or you can SELECT unless it includes the env_vars.secrets column.
Claw Patrol holds credentials - so probably doesn't make sense to layer with AV - but it's true that AV has more sophisticated storage of creds (eg using 1p)
We have a big and detailed config file for our own internal use - but reluctant to release that exactly because it has information about our systems.
There's an example config file here that might be helpful https://github.com/denoland/clawpatrol/blob/main/examples/ga... - we use agents to write the config by pointing it at https://clawpatrol.dev/llms-full.txt
> We are targeting Summer 2026 for a first Alpha version on Linux and macOS. This will be aimed at developers and early adopters.
this is frighteningly far out for a prototype...
https://github.com/denoland/deno/blob/75efc74931c1021fdc41c9...
https://github.com/denoland/deno/blob/75efc74931c1021fdc41c9...
Deno makes certain tradeoffs that make it feel seamless
and use `deno compile` to ship it as a self contained binary
https://github.com/denoland/deno/issues/21389 https://github.com/denoland/vscode_deno/issues/895
other fixes are being discussed.
We cannot simply stop driving anymore than we can stop using an increasing amount energy. There are huge portions of humanity that live in places that depend on cars. It’s a non-solution to say people should just stop driving - billions cannot.
People should read “Beginning of Infinity” for a strong counter argument.
Deno makes it easy to use JavaScript outside of the browser to build all types of software. Our open source runtime is one of the most popular projects on Github. Our business is hosting JavaScript servers at the edge with the Deno Deploy serverless runtime. Our infrastructure is built in Rust.
For ahead of time static sites in Deno, check out Packup https://packup.deno.dev/
Just use --unstable to enable it.
You can use Deno modules in Node using https://github.com/denoland/dnt