The agent cannot guard itself
Why coding agents need a sandbox the agent cannot reach, an audit log the agent cannot write, and signed instructions the agent cannot rewrite.
I'm terra tauri, enabling SRE at Bit Complete. I combine deep technical expertise with building high-performing teams. Previously at Grafana Labs supporting 10,000+ Kubernetes nodes. KubeCon EU speaker on eBPF observability.
Why coding agents need a sandbox the agent cannot reach, an audit log the agent cannot write, and signed instructions the agent cannot rewrite.
Trans Day of Visibility, 2026. Being myself is apparently political now.
I built a WoW-inspired raid frame on a 64x64 LED panel to monitor my AI coding agents. When an agent needs approval, it catches fire.
I enable SRE at Bit Complete, combining technical depth with building high-performing teams. Previously at Grafana Labs, I built network infrastructure supporting 10,000+ Kubernetes nodes, executed zero-downtime CNI migrations, and investigated softIRQ bottlenecks at 1M+ packets/second.
I'm also building AI-powered tooling (Claude Code Agent SDK), creating open-source projects (Nethax network testing framework), speaking at KubeCon, and experimenting with creative technical projects like this site.