Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chris_marino
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
chris_marino
14d ago
I downvoted it because I thought it was a bot response. Did not realize you were referring to cli-printing-press. The main difference is that printing press caches a local copy of data heavy sites like Discord channels, ESPN, etc. and creat
2.
▲
by
chris_marino
18d ago
My response was simplified because your question was basic. OpenClaw was one example that fit the pattern, not a claim that every deployment holds the credential in the sandbox. Injection proxies exist and I should have said so. As for sho
3.
▲
by
chris_marino
18d ago
In many cases, the agent does hold the credential. When you authorize OpenClaw to read your gMail, OpenClaw has the credential. This is absolutely a poor practice, but common, nevertheless. As for using the 'same tool', what I mea
4.
▲
by
chris_marino
18d ago
I thought I made it clear right up front. 'Why agents need their own CLI' What's not clear about that?
5.
▲
by
chris_marino
18d ago
The command structure is provider/topic/command. Taken literally from the oclif framework, with the provider simply being a topic namespace. Haven't needed to pipe anything since in our deployments, the agent makes a call to
6.
▲
by
chris_marino
18d ago
LOL.
7.
▲
by
chris_marino
18d ago
The objectives are to reduce/eliminate as much inference variability as possible. A side benefit is that inference costs collapse as well. It is used internally for what we call 'compiled workflow agents' where no inference i
8.
▲
by
chris_marino
18d ago
Yes. But any coding agent can do this in a matter of minutes. There is an example prompt and corresponding Skill.md in the repo. https://github.com/agent-cli-framework/aclif/blob/main/docs/... http
9.
▲
by
chris_marino
18d ago
We found after deploying many enterprise agents that letting the model choose tools at run time can cause problems. The agent holds the credential and sometimes chooses the wrong tool. Using the same tool every time prevents this.
10.
▲
Show HN: Aclif – Agent CLI framework: one grammar, canonical names across SaaS
(aclif.ai)
32 points
by
chris_marino
18d ago
|
16 comments
11.
▲
Never let your agent choose its own tool
(promptone.ai)
2 points
by
chris_marino
25d ago
|
2 comments
12.
▲
by
chris_marino
25d ago
Most agents that automate enterprise workflows run a defined process: on a schedule, or on every new record or update. Those agents should never choose their own tools. Unlike an ad-hoc or exploratory research agent, a workflow agent should
13.
▲
by
chris_marino
1mo ago
Don't want to split hairs here, but SOX was pre-GFC, so I'm not attributing it to only post-GFC. My first-hand experience discussing personal liability with a BoD lasted about 3 seconds. LOL.
14.
▲
by
chris_marino
1mo ago
Sure. SOX reg sec 302 and 404. Section 302 is a 100% dealbreaker for most companies, so I stand by my 'impossible' threshold. My comment was simply shorthand for all the upfront and downstream costs of going public, combined with
15.
▲
by
chris_marino
1mo ago
The article does not mention or address an important contributor to the current state of VC. The increase in regulations, post GFC, made it impractical/impossible for small companies to go public. And, until recently M&A was active
16.
▲
by
chris_marino
8mo ago
Salesforce, like every large enterprise software company, has a formal (and strict) End of Life process. It starts with an announcement like this indicating End of Sales, then once the contract obligations are met, they can end support, the
17.
▲
by
chris_marino
8mo ago
This news from Heroku does not come as any surprise to the people that were there (as I was). Lots of moving parts and second guessing (that I won't share), but one thing I will say is: Incentives matter. The seeds of this outcome were
18.
▲
by
chris_marino
9y ago
I knew that. What I didn't know was if either of these could apply network policy to these endpoints. Guessing that since they each require their own CNI, there will be probs. So, whether the CNI uses iptables, or not, not clear how ne
19.
▲
by
chris_marino
9y ago
>The ARP table might be bigger, but thats a different issue. But this is the problem that most designs are trying to solve. Large L2s are notoriously fragile. 1,000 nodes, 50-100 pods/node is a lot of ARPs. And sometimes you want
20.
▲
by
chris_marino
9y ago
It all about trade offs. We've built a CNI for k8s and have looked into all of the techniques described. It seems that Lyft's design is a direct reflection of their requirements. To the extent your requirement match theirs, this c
21.
▲
by
chris_marino
9y ago
> Just divide up whatever IP network you're using (e.g. 10/8) and make sure you allocate "enough" to each rack/whatever. Easier said than done. Most datacenters are bit more deliberate about allocating addresses
22.
▲
by
chris_marino
9y ago
Both the Lyft and AWS CNIs use ENIs, Romana's CNI does not. But more specifically, vpc-router works along with Romana's IPAM to aggregate routes so that each VPC route can forward traffic for multiple instances. So, instead of one
23.
▲
by
chris_marino
10y ago
We ran some performance benchmarks applying network policy to Kubernetes pods. Found that latency was (nearly) independent of the number of iptable rules applied. This is because once the session is set up, connection tracking lets subseque
24.
▲
Connection tracking critical for high performance network policy for Kubernetes
(blog.kubernetes.io)
4 points
by
chris_marino
10y ago
|
1 comments
25.
▲
by
chris_marino
10y ago
Another solution to this problem is Romana [1] (I am part of this effort). It avoids overlays as well as BGP because it aggregate routes. It uses its own IP address management (IPAM) to maintain the route hierarchy. The nice thing about thi
26.
▲
by
chris_marino
11y ago
Great post! The results of these benchmarks do not surprise me at all. To me, they all fall in to the category of 'less (overhead) is more (performance)'. With VXLAN encap being the obvious example of greatest overhead. I think it
27.
▲
by
chris_marino
15y ago
There is still the issue of replicating content, but that's something that can be handled in a number of different ways, depending on the requirements.
28.
▲
by
chris_marino
15y ago
Cool interface with JSON representations as well....
29.
▲
VEPA: A standard only a network hardware vendor could love
(blog.vcider.com)
1 points
by
chris_marino
16y ago
|
0 comments