2,080 karma · joined March 26, 2014
For one thing running on bare-metal @ Hetzner is insane value for money versus GCP GKE. Im a third of the running costs and get ~50x resources.
The only aspect im struggling with is full-disk encryption. Although customer data is still encrypred with envelope encryption in the database, i want to migrate to fully encrypted disks (LUKS + TPM) sooner rather than later. If anyone has any resources and/or experience with this, please let know :)
* Gatana AI MCP gateway: https://www.gatana.ai/
Works pretty well so far. Biggest issue i foresee for success is user UX for average employee, and actually useful use-cases.
Enterprise/Organization focused MCP gateway with support for sophisticated credentials management, integrates with OIDC/SAML, team and profiles support, external secret stores (AWS/GCP/Azure/Hashicrop Vault), using envelope encryption, and in-band-MCP authorization trigger for e.g. trying to use a tool which Gatana not yet has credentials for.
Ideal for Agent-2-Agent/dev teams/Github Copilot Agent (the one you assign issues)
Stack is k8s, NodeJS, React, Google KMS, hosted on GKE, with GKE Sandbox for local server isolation.
The EU ostensibly wants to improve innovation, i wonder how these new assessment regulations help with that, especially for SME and startups.
Which app store?
(shameless plug: im building an cloud based gateway where the set of servers given to an mcp client can be controlled using "profiles": https://docs.gatana.ai/profiles/)
Now, we can go into the weeds as to what constitutes solved and we might agree or disagree.
Why do you say that? It sounds like a simple solution to me.
Well, it is not taxed because it is convenient. It is taxed because of the huge negative externalities it brings with it.
Idea came from one of my clients, where they wanted to use AI agents throughout the organization but at that moment there was no centralized governance or security concepts. This pulls everything at one place and tries to solve the security concept with per-user credentials, which can be provided out-of-band through the MCP protocol (generated a one-time link end-user can use to sign in to the underlying MCP server with OAuth or provide API key)
OP simply pushed his personal opinion on how lodash (extremely popular library) should be deployed. Proceeds to get confused and upset when this is rejected.
I suggest to OP to work on his social skills.
Leaning on CloudFlare Containers seems like a good balance though. But im wondering what the limits are, some packages are very large and require more than just Javascript (e.g node gyp).
(Personally I ended up hosting a web-only VS code served as static files. Luckily i dont need to support Deno syntax so the built-in Typescript language server worked fine.)