Blog

Building for Autonomy

Thoughts on agent-first infrastructure, self-hosted systems, and owning the stack.

Filtering by: #open-source × Clear
#ai #crevisto #guide #machin #ai-agents #open-source #tutorial #design #devtools #agent-first #ai-engineering #cli #self-hosted #peage #agents #automaintainer #compiler #security #dogfooding #image-generation #image-tools #mfl #remotecmd #art #automation #infrastructure #memgraph #performance #roam #style
Product · September 2026

blurd — a self-hosted service that redacts faces and plates, and never keeps the original

A client needed photos pushed through a pipeline without retaining the personal data in them. blurd is the answer: one binary, async jobs, scoped keys, public blob rules, a storage cap — and the original image never touches disk.

#blurd #privacy #gdpr #self-hosted #open-source #images
Read more
Product · September 2026

A Stranger Filed a Bug. My AI Fixed It While I Slept.

On July 25, a developer I'd never met opened a GitHub issue on my open-source project. On August 8, it was closed — fixed, tested, and merged. I didn't touch it. An AI agent read the issue, diagnosed the root cause, wrote the fix, opened a PR, and got it merged. This is what happened.

#automaintainer #ai-agents #open-source #automation
Read more
AI & SWE · September 2026

Your Agent's Memory Can't Tell You When It's Wrong

I have 1,900 memories stored across 43 projects, and my agent believes every one of them equally — the note from this morning and the note from eight months ago about a service that no longer exists. So I taught memgraph to check its own claims. The first version reported 75 stale memories out of 380. Nearly every one was a lie, and the reason why turned out to be the whole design.

#ai-agents #memory #memgraph #devtools #open-source #knowledge-graph #cli
Read more
AI & SWE · September 2026

Felipe — The AI CEO That Reviews My Pull Requests

I had 20 pull requests stuck in a human-in-the-loop queue, some for 29 days. So I built Felipe — an AI CEO persona that reads each PR's diff, makes a decision, and posts it to GitHub. The existing merger picks it up and applies it. Cost: $0, using GLM-5.2's free tier. Here's how it works.

#ai-agents #automation #fleet-cli #am-fleet #devtools #glm-5.2 #open-source
Read more
Product · August 2026

Your AI Agent Is Leaking Your Secrets

I audited a secret manager that had AES-256-GCM, X25519 sealed responses, ACLs, and attestation. It leaked secrets in the simplest way possible: the exec command passed child stdout straight to the model. No interception, no scrubbing. Here's how I found it, why it matters, and how veil fixes it — mandatory output scrubbing, no raw output by default, sealed mode as the only mode.

#security #secrets #agent-first #machin #mfl #encryption #open-source
Read more
Product · August 2026

99 MB to 71 KB: rewriting MiniStats in Machin

MiniStats is a real-time metrics dashboard built with Bun — the binary is 99 MB because it bundles the entire runtime. I rewrote it in Machin/MFL, a language that compiles through C. The binary is 71 KB. That's a 1400× reduction. Same features, same dashboard, same commands.

#machin #mfl #ministats #tinystats #binary-size #compilers #websocket #open-source
Read more
Product · August 2026

I have four machines. I wanted to see them all at once. So I built MiniStats.

Prometheus + Grafana takes an afternoon and 4 GB of RAM to show me what uptime already knows. MiniStats is a 25 MB binary that does the same thing in seconds — one server, N clients, a WebSocket, no database. Here's why I built it and how it works.

#ministats #monitoring #bun #typescript #homelab #open-source
Read more
Product · August 2026

I Told My Agent What It Couldn't Do. It Found a Way Anyway.

I built a permission system for AI agents. A live model found the hole in it, on its own, twice — and the destructive-approval gate I thought was the real backstop turned out to need proving too.

#commis #ai-agents #security #dogfooding #open-source #agent-first
Read more
Product · August 2026

Stop Giving AI Agents Your SSH Keys

Your AI agent needs to run commands on your servers. The only credential most people have to give it is an SSH key: everything, forever, with no record. rcmd's answer is a token scoped to named machines, expiring by default, revocable in one command, with every action audited — now one command to mint, and an MCP server to plug into. Includes the two security bugs I found in my own audit trail while building it.

#agent-tokens #ai-agents #devops #infrastructure #mcp #open-source #remotecmd #security #ssh
Read more
Product · August 2026

How I Made remotecmd 1.7× Faster Than scp Over a 77ms Relay

remotecmd routes file transfers through a WebSocket relay — which means a single TCP stream can't fill the pipe on high-RTT links. I spent two days reading kernel source, CERN GridFTP papers, and gorilla/websocket internals. The result: parallel TCP streams that auto-tune by file size, atomic header+binary framing in the relay, and gzip writer pooling. 50MB over 77ms RTT: 1.74× faster than single stream, 1.21× faster than scp. Here's what worked, what didn't, and why.

#remotecmd #performance #tcp #websocket #parallel-streams #open-source #devtools
Read more
1 2 Next →