4 ms·
Claude Code deletes developers' production setup, including database
- WalterGR 7mo agohttps://news.ycombinator.com/item?id=47275157 https://news.ycombinator.com/item?id=47275157
- rhoopr 7mo agoSloppy vibe infra management and no backups, peanut butter and chocolate.
- wpm 7mo ago"Developers let Claude Code delete their production setup, including database" Claude Code has no agency. It does what you tell it, where you let it, with a randomized temperature where it might randomly deviate.
- deleted 7mo ago[deleted]
- cyanydeez 7mo ago"Man shot by police" vs "Man involved in police shooting" Its a habituation, as much as a desire to avoid finding people at fault.
- pgwhalen 7mo agoWhile it may not have “agency” it definitely doesn’t necessarily do what you tell it. I’d put it as “it may do what you let it.”
- mrothroc 7mo agoYeah, this is what happens when there's nothing between "the agent decided to do this" and "it happened." The agent followed the state file logically. It wasn't wrong. It just wasn't checked. His post-mortem is solid but I think he's overcorrecting. If he does this as part of a CICD pipeline and he manually reviews every time, he will pretty quickly get "verification fatigue". The vast majority of cases are fine, so he'll build the habit of automatically approving it. Sure, he'll deeply review the first ones, but over time it becomes less because he'll almost always find nothing. Then he'll pay less attention. This is how humans work. He could automate the "easy" ones, though. TF plans are parseable, so maybe his time would be better spent only reviewing destructive changes. I've been running autonomous agents on production code for a while and this is the pattern that keeps working: start by reviewing everything, notice you're rubber-stamping most of it, then encode the safe cases so you only see the ones that matter.
- dmix 7mo agoOr just never run agents on anything that touches production servers. That seems extremely obvious to me. He let Claude control terminal commands which touched his live servers. That's very different than asking it for help to make a plan.
- scuff3d 7mo agoBut the CEOs are saying everyone is going to be replaced by LLMs in 6 months. Surely that means they're capable of handling production environments without oversight from a professional.
- 8note 7mo agothey're doing as well as professionals do without oversight on production environments. There's no lack of stories about people deleting their production environments with data loss too. the fix has always been to limit what can be done directly to prod, and put it through both review, and tests before a change can touch production.
- bigstrat2003 7mo ago> they're doing as well as professionals do without oversight on production environments. That's nonsense. First, most people haven't deleted the production environment by accident. They have enough sense to recognize that as a dangerous thing and will pause to think about it. Second, the ones who do make that mistake learn and won't make it again, which is not something the clanker is capable of.
- SpicyLemonZest 7mo agoThe article says that Claude did recognize the danger, and advised the developer to run a safer setup with no risk of the two websites stomping on each other's resources, but he overrode it. I've definitely seen situations in my career where a junior developer does something dangerous and destructive after a senior dev overrode guardrails meant to prevent it. (None quite this bad, but then again I've never worked on small sites.)
- Surac 7mo agono backup? well played
- dmix 7mo agono offsite backups*
- mannyv 7mo agoThis actually is easy to do with terraform and shared infrastructure; you don't need an AI in the loop. Who hasn't accidentally deleted a resource because that property triggers a resource delete/create instead of an update? It would help if it was obvious what the key fields were. But for some reason docs usually don't tell you.
- djohnston 7mo agoeven before AI - as crazy as it may sound - i've always used click-ops for the prod dbs. I've never put them in cloudformation or tf.
- jonfw 7mo agoIf you are not terrified of your production terraform, you are doing it wrong!
- eddyzh 7mo agoOriginal artikel https://open.substack.com/pub/alexeyondata/p/how-i-dropped-our-production-database https://open.substack.com/pub/alexeyondata/p/how-i-dropped-o...
- sjeiuhvdiidi 7mo agoThe computer does exactly what you tell it to do, no more, no less. Nothing new.
- nadav_tal 7mo ago[flagged]