17 ms·
Claude Code for Infrastructure
- maxdo 8mo agoProfile and hooks + skills for cc will solve concerns . cicd with manual approve + cc will work even better . Infra is a code same as anything else .
- aspectrr 8mo agoHey HN, My name is Collin and I'm working on fluid.sh (https://fluid.sh https://fluid.sh) the Claude Code for Infrastructure. What does that mean? Fluid is a terminal agent that do work on production infrastructure like VMs/K8s cluster/etc. by making sandbox clones of the infrastructure for AI agents to work on, allowing the agents to run commands, test connections, edit files, and then generate Infra-as-code like an Ansible Playbook to be applied on production. Why not just use an LLM to generate IaC? LLMs are great at generating Terraform, OpenTofu, Ansible, etc. but bad at guessing how production systems work. By giving access to a clone of the infrastructure, agents can explore, run commands, test things before writing the IaC, giving them better context and a place to test ideas and changes before deploying. I got the idea after seeing how much Claude Code has helped me work on code, I thought "I wish there was something like that for infrastructure", and here we are. Why not just provide tools, skills, MCP server to Claude Code? Mainly safety. I didn't want CC to SSH into a prod machine from where it is running locally (real problem!). I wanted to lock down the tools it can run to be only on sandboxes while also giving it autonomy to create sandboxes and not have access to anything else. Fluid gives access to a live output of commands run (it's pretty cool) and does this by ephemeral SSH Certificates. Fluid gives tools for creating IaC and requires human approval for creating sandboxes on hosts with low memory/CPU and for accessing the internet or installing packages. I greatly appreciate any feedback or thoughts you have, and I hope you get the chance to try out Fluid!
- redrove 8mo agoSo how is this different from deploying claude code on a VM and letting it run? You can sandbox it in any of the dozen ways already available. What’s the differentiator?
- jondwillis 8mo agoOne allows middleman rent-seeking and the other does not so much.
- aspectrr 8mo agoThis allows the agent to make any changes in a production clone vs agents running on a production VM. For example, you wouldn't want claude editing crucial config on the chance it brings everything down vs letting it do in a cloned environment where it can test whatever.
- amanzi 8mo agoWhy would you not put a description like this on your actual website? Your homepage does not explain anything about what this actually does. Are you really expecting infrastructure engineers to install your app with a bash command after only providing the following information? Claude Code for infrastructure. Debug, act, and audit everything Fluid does on your infrastructure. Create sandboxes from VMs, investigate, plan, execute, generate Ansible playbooks, and audit everything.
- nkko 8mo agoThis is exciting. But I had to read and check everything twice to figure it out, as some already commented. Strong Feedback loop is an ultimate unlock for AI agents and having twins is exactly the right approach.
- aspectrr 8mo agoYOOO thanks niko! Currently reworking lots of wording to make it easier to understand!
- tayo42 8mo ago> I didn't want CC to SSH into a prod machine from where it is running locally (real problem!). I wanted to lock down the tools it can run to be only on sandboxes while also giving it autonomy to create sandboxes and not have access to anything else. This is already the modern way to run infra. If your running simple apps, why are you even spinning up vms? Container running platforms make this so easy.
- raw_anon_1111 8mo agoAnd how is this different than just pointing Terraformer at your existing infrastructure and rebuilding it in another account? That is assuming your company is standing complicated infra up by hand and if they are, your entire “DevOps” team or who ever is responsible needs to be fired
- verdverm 8mo ago> By giving access to a clone of the infrastructure, agents can explore, run commands, test things before writing the IaC, giving them better context and a place to test ideas and changes before deploying. And you thought the costs for burning tokens was high... let's amp it up by spinning up a bunch of cloud infra and let the agents fumble about. DevOps is my gig, I use agents extensively, I would never do this. This is so wasteful
- js2 8mo agoYou might want to remove that `.DS_Store` from the root of the repo and add `.DS_Store` to your global git ignore.
- JimDabell 8mo agoAn agent that runs things in remote sandboxes to set things up doesn’t really fit with Infrastructure as Code. Lately I have been setting up Pulumi stacks in ephemeral AWS accounts managed by AWS Organizations and working on a Kubernetes cluster locally with Tilt. So far, Claude is pretty good with those things. It seems to have pretty good knowledge of Pulumi, basic knowledge of Tilt, and good knowledge of Kubernetes. It’s a little out of date on some things and needs reminding to RTFM, but it can get a lot done by itself. If it were a real point of friction, a cheat sheet (sorry, “skill”) would be enough to solve the majority of issues. The example you provide seems to be more along the lines of SSHing into remote boxes and setting things up manually. That’s not really helpful when you want to work on repeatable infra. You try to distinguish yourself from generating Terraform etc., but actually that’s what’s valuable in my experience.
- deleted 8mo ago[deleted]
- lijok 8mo agoFUCK NO. Who in their right mind would let an LLM connect to prod?
- jhickok 8mo agowhy does it have to connect to prod in order to be useful?
- locusofself 8mo agoMaybe at a greenfield startup. Where I work this idea wouldn't be entertained for a millisecond.
- xyzzy123 8mo agoMany places have "dev", "test" "prod"... but IMHO you need "sandpit" as well. From an ops point of view as orgs get big enough, dev wraps around to being prod-like... in the sense that it has the property that there's going to be a lot of annoyed people whose time you're wasting if you break things. You can take the approach of having more guard rails and controls to stop people breaking things but personally I prefer the "sandpit" approach, where you have accounts / environments where anything goes. Like, if anyone is allowed to complain it's broken, it's not sandpit anymore. That makes them an ok place to let agents loose for "whole system" work. I see tools like this as a sort of alternative / workaround.
- thenewnewguy 8mo agoSandpit should be a personal (often local, if possible) dev environment. The reason people get mad about dev being broken for long periods of time is that they cannot use dev to test their changes if your code (that they depend on) is broken in dev for long periods of time.
- xyzzy123 8mo agoAgreed on all points. Local loops are faster and safer wherever possible. But particularly for devops / systems focused work, you lose too much "test fidelity" if you're not integrating against real services / cloud.
- lfx 8mo agoHey Collin! Interesting idea, few things: - The website tells less than your comment here. I want to try but have no idea how destructive it can be. - You need to add / mention how to do things in the RO mode only. - Always explain destructive actions. Few weeks ago I had to debug K8S on the GCP GDC metal, Claude Code helped me tons, but... I had to recreate whole cluster next day because agent ran too fast deleted things it should not delete or at least tell me the full impact. So some harness would be nice.
- flowardnut 8mo agoagreed, the repo readme is far more informative than the website
- aspectrr 8mo agoHey! Yes I updated the website with some more of my comments. - RO mode would be a good idea - Agreed on explaining destructive actions. The only (possibly) destructive action is creating the sanbox on the host, but that asks the user's permission if the host doesn't have enough resources. Right now it supports VMs with KVM. It will not let you create a sandbox if the host doesn't have enough ram or cpus. - The kubernetes example is exactly what this is built for, giving AI access is dangerous but there is always a chance of it messing something. Thanks for the comment!
- aspectrr 8mo agoHey ifx, I had a couple questions about your points, what's the best way to reach you?
- lfx 8mo agoPeak in my profile.
- falloutx 8mo agoAll these tools to build something, but nothing to build. I feel like I am part of a Pyramid Scheme where every product is about building something else, but nothing reaches the end user. Note: nothing against fluid.sh, I am struggling to figure out something to build.
- aabajian 8mo agoThat is the problem with software developers with expertise in software, but no deep domain knowledge outside the CS world.
- tempest_ 8mo agoIt is my belief with some exceptions it is almost always easier to teach a domain expert to code than it is to teach a software developer the domain.
- bluGill 8mo agoFor problems that can be solved with only a small amount of simple code that is true. However software can become very complex and the larger/more complex the problem is the more important software developers are. It quickly becomes easier to teach software developers enough of your domain than to teach domain experts software. In a complex project the hard parts about software are harder than the hard parts about the domain. I've seen the type of code electrical engineers write (at least as hard a domain as software). They can write code, but it isn't good.
- baalimago 8mo agoIt's pretty cool. What would be cooler is to have it as a MCP server... and then use claude code
- redfloatplane 8mo agoClever solution. I think ops (like this) and observability will be pretty hot markets for a while soon. The code is quite cheap now, but actually running it and keeping it running still requires some amount of background. I've had a number of acquaintances ask me how they can get their vibe coded app available for others to use. I really like this idea. I do a lot of kubernetes ops with workloads I'm unfamiliar with (and not directly responsible for) and often give claude read access in order to help me debug things, including with things like a grafana skill in order to access the same monitoring tools humans have. It's saved me dozens of hours in the last months - and my job is significantly less frustrating now. Your method of creating ansible playbooks makes _tons_ of sense for this kind of work. I typically create documentation (with claude) for things after I've worked through them (with claude) but playbooks is a very, very clever move. I would say something similar but as an auditable, controllable kubernetes operator would be pretty welcome.
- aspectrr 8mo agoThanks! Kubernetes is the next infrastructure primitive that I want to support but I'm glad you like. If you have any questions or ideas, lmk!
- boondongle 8mo agoThe real problem is just the volatility for the employees. Unless Board of Directors/Owners punish downtime, you risk a dark pattern of uptime just being a nice-to-have when I can just replace any expertise with the next kid out of college + Claude. So you really need customers to react. And this isn't theoretical - people have already lost their jobs and there's really, really good people in the market available right now.
- tobi_bsf 8mo agoWhats wrong with just using claude code for infrastructure? Works great tbh.
- aspectrr 8mo agoI wish, for my work it would be a safety nightmare. I left a comment on this topic. https://news.ycombinator.com/reply?id=46889704&goto=item%3Fid%3D46889703%2346889704 https://news.ycombinator.com/reply?id=46889704&goto=item%3Fi...
- ekaesmem 8mo agoPlease at least write the README.md by yourself. It's excessively lengthy.
- levkk 8mo agoSo... I already tell Claude Code to do this. Just run kubectl for me please and figure out why my helm chart is broken. Scary? A little but it's doing great. Not entirely sure why a specialized tool is needed when the general purpose CLI is working.
- redfloatplane 8mo agoYeah. The times I have let claude off the read-only leash, it's gone fine for me too (with stern warnings not to do anything stupid, and a close eye). But that's not really solving the same problem as this project, I guess. From what I can see this is using a safer and more reproducible method (and not k8s native, so it feels a little foreign to me).
- giancarlostoro 8mo agoIn Zed I just have it auto approve everything, macOS will scream if "Zed" tries to escape the folder its in anyway.
- peterldowns 8mo agoOpus 4.5 is pretty good about following instructions to not do anything destructive, but Gemini 3 Flash actively disregards my advice and just starts running commands. Definitely recommend setting up default-readonly access for stuff like this and requiring some kind of out-of-band escalation process for when you need to do writes/destroys.
- hivacruz 8mo agoI do the same. I was thinking about creating read-only kubeconfigs for him to make sure it can't do bad stuff but with a good SKILL.md, it works perfectly.
- levkk 8mo agoHim! That settles the Turing test debate.
- irl_zebra 8mo ago
- esafak 8mo agoAn infrastructure tool's primary installation method should NOT be curl | sh
- charcircuit 8mo agoIt should be. This is the least friction way to do so as server Linux operating systems still have not agreed on a common application format / package manager.
- esafak 8mo ago> It should be. This is the least friction way to do so as server Linux operating systems still have not agreed on a common application format / package manager. Nowhere in your response did you mention security.
- verdverm 8mo agoor reproducibility
- charcircuit 8mo agoUnfortunately there is not a standardized way to securely install something.
- wlonkly 8mo agoAnd after all that, the shell script only does go install github.com/aspectrr/fluid.sh/fluid/cmd/fluid@latest !
- qainsights 8mo agoCan't we just use Claude Code straight up?
- alexandercheema 8mo agoIsn't Claude Code for Infrastructure just...Claude Code?
- aspectrr 8mo agoHey, thanks for the comment. I answer this question in more depth on the website https://fluid.sh https://fluid.sh or this comment: https://news.ycombinator.com/reply?id=46889704&goto=item%3Fid%3D46889703%2346889704 https://news.ycombinator.com/reply?id=46889704&goto=item%3Fi... This lets AI work on cloned production sandboxes vs running on production instances. Yes you can sandbox Claude Code on a production box, but it cannot test changes like it would for production-breaking changes. Sandboxes give AI this flexibility allowing it to safely test changes and reproduce things via IaC like Ansible playbooks.
- stackskipton 8mo agoOps person here. I'm already using LLM to generate things and I'm not sure what this adds. The Demo isn't really doing it for me but maybe I'm wrong target for it. (What is running on that server? You don't know. Build your cattle properly!) Maybe this is better for one man band devs trying to get something running without caring beyond, it's running.
- aspectrr 8mo agoHey no problem! I'll work on the demo more. I discuss this in my comment here: https://news.ycombinator.com/reply?id=46889704&goto=item%3Fid%3D46889703%2346889704 https://news.ycombinator.com/reply?id=46889704&goto=item%3Fi... and on the website: https://fluid.sh https://fluid.sh But fluid lets AI investigate, explore, run commands, and edit files in a production-cloned sandbox. LLMs are great at writing IaC, but the LLMs won't get the right context from just generating an Ansible Playbook. They need a place to run commands safely and test changes before writing the IaC. Much like a human, hence the sandbox.
- bigcat12345678 8mo agoThis is the most plausible tool for vibe infra I can think of
- turtlebits 8mo agoMaking clones of production isn't trivial. Is your app server clone going to connect to your production database? It is going to spin up your whole stack? Seems a bit naive. A better approach is to have AI understand how prod is built and make the changes there instead of having AI inspect it and figure out how to apply one off changes. Models are already very good at writing IaaC.
- bluelightning2k 8mo agoThis sounds like a uniquely good way to accidentally spend infinity money on AWS
- Uptrenda 8mo agoAbout 90% of HN is now AI shit at any given time. I can't fucking take this shit. Can you losers talk about anything else.
- raw_anon_1111 8mo agoAs are 95% of YC funded companies https://docs.google.com/spreadsheets/d/1Uy2aWoeRZopMIaXXxY2EZqQ-p1XkybYp21llKCfLsME/edit?usp=drivesdk https://docs.google.com/spreadsheets/d/1Uy2aWoeRZopMIaXXxY2E... I don’t remember where I got this link from
- jaimex2 8mo agoHuge conflict of interest there huh
- raw_anon_1111 8mo agoIs this a real product? This is a solved problem. First I’m personally never going to create infrastructure in the console. I’m going to use IAC from the get go. That means I can reproduce my infra on another account easily. Second if I did come across an environment where this was already the case, there are tools for both Terraform and CloudFormation where you can reverse your infra to reproducible IAC. After that, let Claude go wild in my sandbox account with a reasonably scoped IAM role with temporary credentials
- JohnMakin 8mo ago> LLMs are great at generating Terraform, OpenTofu, Ansible, etc. but bad at guessing how production systems work. Sorry, that last part is absolutely not the case from my experience. IaC also uses the API to inquire about the infrastructure, and there are existing import/export tools around it, so I’m not exactly sure what you are gaining by insisting on abandoning it. IaC also has the benefit of being reusable and commitable.
- verdverm 8mo agoPeople try to write plausible copy, then come to HN to learn it's not often reality It's largely because every devops situation is a snowflake and humans love to generalize. Turns out we don't all have the same problems. I haven't seen a startup that's been successful in devops at a level above the HCL / yaml
- keyle 8mo agoIt always makes me smile when you get some random domain with a good looking CSS telling you: Don't do the same as everyone! For safety... here... Just curl this script and execute it :)
- chickensong 8mo agoSo this is a client/server thing to control KVM via libvert and provision SSH keys to allow LLM agent access to the VMs? How does the Ansible export work? Do the agents hack around inside the VM and then write a playbook from memory, or are all changes made via Ansible? If Ansible playbooks are the artifact, what does features does Fluid offer over just having agents iterate on an Ansible codebase and having Ansible drive provisioning?
- jaimex2 8mo agoThis will make some amazing memes. 'Sorry I caused a $100,000 bill. I've made the right changes this time to scale appropriately.' Next month - 'Sorry I caused a $200,000 bill...'
- latchkey 8mo agoI'm working towards this for actual infrastructure, for serving up AI compute. "install kimi 2.5 on a 4x mi300x vm and connect the endpoint to opencode, shut it down in 4 hours" We're getting close.
- verdverm 8mo agothis is not the way to do devops, we have IaC, reviews, and promotion for a reason it's clear infra level decisions are well beyond what LLMs / agents are capable of today, this is area is too high risk, devops is slow to adopt new tooling because of its role and nature
- latchkey 8mo agowow, you downvoted me. this is still devops. we use cloud-init to setup the vm. i run the underlying hardware infrastructure and we've automated the provisioning such that we have an api that can start/stop compute at will. even bare metal. the point of this is that the current $/token model is awful, especially if you're using a lot of tokens. it should be $/minute. pay for what you use.
- verdverm 8mo ago> wow, you downvoted me. 1. No, I commented, it is not even possible to downvote a reply to your own comment, seems other people must disagree with what you said or how you said it 2. It's against HN guidelines to talk about your downvotes, especially making claims about who has done it The most likely reason for your downvotes is promoting your own (incomplete) project under someone else's. What did you hope to bring to the conversation?
- verdverm 8mo agotokens are a rough proxy for usage over time, so I am paying for what I use, less than running a TPU pod myself, required for the models I use, i.e. I don't saturate the compute so it's cheaper to pay-go
- dengsauve 8mo agoI use Pulumi for work, and their AI solution (Pulumi Neo) works amazingly well in troubleshooting cloud issues. It's informed of the cloud state and recent changes right from their platform, which is pretty amazing. Compared to using Azure CoPilot for the same purposes, Pulumi Neo was faster in generating responses, and these responses were actionable and solved my issues. CoPilot was laughably useless comparably.
- zahrevsky 8mo agoI love how the landing page is straight to the point and has zero marketing BS. It achieves the opposite of AI-written text, while still being polished.
- jamesmstone 8mo agoThis general idea is exactly why I love nix. The immutability of it is powerful. It can be useful for both running your agents in a certain environment AND your agents are useful at writing your nix config. I expand on this in a blog post here https://jamesst.one/posts/agents-nix https://jamesst.one/posts/agents-nix
- wayeq 8mo ago> curl -fsSL https://fluid.sh/install.sh https://fluid.sh/install.sh | bash what could go wrong..
- snarfy 8mo agoits missing sudo
- Yash16 8mo ago[dead]
- scott-iii 8mo agothis makes sense. like giving AI a lab bench instead of just asking it to guess
- IBCNU 8mo agoThis is really cool, I don't want to think about infra tbh just want to build. Is there a wold where an on-prem version of this exists? I buy a box, install shell script, and it just works?
- aspectrr 8mo agoYo, fluid is built with on-prem in mind, specifically VMs. This is my initial use case for it. I am currently working on a remote version of fluid, where instead of CLI tool, it would be more of a codex/claude code app with a UI where you can install a server and then command hundreds of agents at once to work on infrastructure. Is this what you had in mind?
- onion2k 8mo agoA small suggestion: All those 'v run_command' blocks in the example flow could show you the command that was run.
- Zanfa 8mo agoGreat idea! A few weeks ago a non-technical client of mine decided to optimize his AWS infra bill with the help of AI. The costs went down significantly along with the application.
- cleaninglondon 8mo ago[flagged]
- gardnr 8mo agoThe reason: > Safety. I didn't want CC to SSH into a prod machine The call to action: > curl -fsSL https://fluid.sh/install.sh https://fluid.sh/install.sh | bash The reason this is ironic: https://x.com/sheeki03/status/2018382483465867444 https://x.com/sheeki03/status/2018382483465867444
- ahoka 8mo agoOne just needs to put enough poison on the internet to get the malicious URL suggested by LLMs. What a time to be alive!
- datsci_est_2015 8mo agoHonestly, I may be an accelerationist in terms of poisoning the LLM well if it gets us sooner to an industry-wide consensus that LLM output is a significant security risk.
- lovegrenoble 8mo agoEvery product needs a killer feature
- pipejosh 8mo ago[dead]