Pete Wagner

118 posts

Pete Wagner

Pete Wagner

@meofthecloud

Infra security nerd at Shopify. Previously GitHub (Dependabot+Actions), ApolloGraphQL, Fitbit. Hack the planet.

Beigetreten Kasım 2012
88 Folgt34 Follower
Pete Wagner
Pete Wagner@meofthecloud·
@ibuildthecloud Is this for AI chat? Or the Kube thing? I mentioned my DIY chat frontend before, here's a screenshot. Rendered markdown inside some rounded borders, and a pulsing spinner while the bot is generating a response. Functional garbage.
Pete Wagner tweet media
English
0
0
2
179
Darren Shepherd
Darren Shepherd@ibuildthecloud·
I finally took some time and read the docs for charm.sh. I think I can actually use this. Maybe this will be the first TUI framework I can leverage. Everything else I always get so lost in the details.
English
2
1
29
3.9K
Pete Wagner
Pete Wagner@meofthecloud·
my PR to trivy made its way to trivy-action, so now my SBOM dependency diffs include the golang stdlib for any detected binaries. neat. github.com/aquasecurity/t…
Pete Wagner tweet media
English
0
0
0
81
Pete Wagner
Pete Wagner@meofthecloud·
if you're trying the shiny new `gh attestation verify` with reusable workflows, don't get sniped into debugging the CLI like I did: github.com/cli/cli/issues…
English
0
0
1
49
Pete Wagner
Pete Wagner@meofthecloud·
@StackLokHQ I appreciate that `gh` is the only binary I'm willing to trust without seeing a signature in Rekor first. I think moving the magic from GoReleaser (the common thread in the "good" projects I mentioned) to the GitHub platform will let me verify more and configure less.
English
1
0
2
29
Pete Wagner
Pete Wagner@meofthecloud·
@StackLokHQ My interest is from my verifying Debian proxy. Projects like Trivy, SOPS, and GoReleaser provide attestations via cosign sign-blob, so I have a service that let's me "apt-get" updates as long as I trust their signer. The config file explains it best: gist.github.com/thepwagner/52d…
English
1
0
1
48
Pete Wagner
Pete Wagner@meofthecloud·
@ibuildthecloud Rolling your own with charm libs isn't too bad - mine is a Bubbles Viewport+TextInput. Add Glamour to style the markdown, a few borders, ship it. It's still as un-fun as writing UI code, but at least it's Golang.
English
0
0
0
73
Darren Shepherd
Darren Shepherd@ibuildthecloud·
What's a good terminal based chat program that talks to openai chat completion? Something slick. I really like charm.sh mods but it doesn't really chat it's for scripting.
English
2
0
1
2.3K
Pete Wagner
Pete Wagner@meofthecloud·
@gudmundur Do you see value in an LLM for this, or is there too much domain knowledge? I've been fiddling with markdown timelines in an LLM as a rubber duck on steroids, I'd say it's only 25% gibberish .
English
0
0
0
18
Guðmundur Bjarni
Guðmundur Bjarni@gudmundur·
Very important corollary to this, pair with someone while doing the work. Talk through every step, what the thinking is, agree on what is about to be done.
English
1
0
1
121
Guðmundur Bjarni
Guðmundur Bjarni@gudmundur·
When going through operations of systems, whether during incidents or doing one-off things, I’ve found that it’s critical to maintain a timeline of what’s about to be done, how it went, and what steps are taken to deal with or mitigate the results.
English
4
0
3
490
Dan Lorenc
Dan Lorenc@lorenc_dan·
Sick of managing GitHub PATs? Check out octo-sts! chainguard.dev/unchained/the-… "In short: GitHub didn’t expose an STS, so we went ahead and built one."
English
4
18
71
10.1K
Pete Wagner
Pete Wagner@meofthecloud·
@ibuildthecloud I did a thing that drops an LLM agent into a simulated world (a 10x10 grid with randomly distributed "food") and let it issue commands to survive. Local models could barely speak JSON and I had to hand-feed them tokens (e.g. to "move_west", prompt: "there is food to the west")
English
0
0
0
73
Darren Shepherd
Darren Shepherd@ibuildthecloud·
OpenAI is pretty smart, the others models are just doing cosplay.
English
1
0
2
1.6K
Pete Wagner
Pete Wagner@meofthecloud·
How can a ski hill be open with a small amount of natural snow? Snowmakers go BRRRRR.
English
0
0
0
49
Pete Wagner
Pete Wagner@meofthecloud·
I wanted this enough to build it again: a service to generate Debian repositories in-memory from a bunch of debs. It can source packages directly from GitHub release assets and verify Rekor records produced by cosign sign-blob.
Pete Wagner tweet media
English
0
0
0
91
Pete Wagner
Pete Wagner@meofthecloud·
Until you pin your dependencies George, Festivus is not over
English
0
0
1
33
Pete Wagner
Pete Wagner@meofthecloud·
i spilled making a pourover and knew i had exactly 23.5g of coffee to clean up off the counter. ever catch yourself napkin mathing literal napkin math.
English
0
0
1
45
Marc Campbell
Marc Campbell@marccampbell·
How are you managing proactively rotating GitHub tokens in CI pipelines? We have a lot of narrowly scoped tokens, and the expiration & rotation process feels too manual still. Any recommendations?
English
3
0
4
1.6K
Pete Wagner
Pete Wagner@meofthecloud·
more tech clutter tips: "does this SPARC? joy"
English
0
0
0
48
Pete Wagner
Pete Wagner@meofthecloud·
the SSD rule of thumb is literal: once you have several thumbdrives larger than a 2.5" SSD, that SSD is probably waste.
English
1
0
0
56
Pete Wagner
Pete Wagner@meofthecloud·
@jessfraz I’m convinced this will be the new typo-squatting. Nobody fat fingers what they copy/paste from GPT, so squat packages that bots will assume exist.
English
0
0
0
317
Jessie Frazelle
Jessie Frazelle@jessfraz·
I asked ChatGPT how I would do something in Rust and it hallucinated an entire crate existing that basically handled the entire thing. Queue song: "Wouldn't it be nice".
English
8
5
129
21.8K
Pete Wagner
Pete Wagner@meofthecloud·
"this is man chmod(1), i wanted man chmod(2)" - statement dreamed up by the utterly Deranged
English
1
0
3
64