<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: kalib_tweli</title><link>https://news.ycombinator.com/user?id=kalib_tweli</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 11 Oct 2026 10:17:41 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=kalib_tweli" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by kalib_tweli in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>Good points across the board. I ran into a lot of problems auditing the security of my approach and it was just too easy to circumvent.<p>First lesson was that the architecture had to be secure in structure, not configuration. Otherwise, a novice will run claude code on the host machine and just bork the entire setup.<p>So now I've replaced tightbeam runtime with a small runtime on the workspace container. Tightbeam and Airlock have been moved to separate pods. So you don't need network egress on the workspace pod at all.<p>Secondly, I'm isolating credentials on Tightbeam and Airlock with k8s jobs. Rather than airlock full CLI commands, you just create "airlock tools" with k8s secrets. Airlock controller never sees the secret. The tool could be like "git-create-branch" and "gh-create-pr".<p>Tightbeam is pretty much symmetrical. LLM credentials are tied to jobs.<p>I'm tying them together into a unified architecture now. Please do let me know if you have additional thoughts!</p>
]]></description><pubDate>Sun, 29 Mar 2026 08:00:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=47561223</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=47561223</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47561223</guid></item><item><title><![CDATA[New comment by kalib_tweli in "LiteLLM Python package compromised by supply-chain attack"]]></title><description><![CDATA[
<p>Would value your opinion on my project to isolate creds from the container:<p><a href="https://github.com/calebfaruki/tightbeam" rel="nofollow">https://github.com/calebfaruki/tightbeam</a>
<a href="https://github.com/calebfaruki/airlock" rel="nofollow">https://github.com/calebfaruki/airlock</a><p>This is literally the thing I'm trying to protect against.</p>
]]></description><pubDate>Tue, 24 Mar 2026 14:08:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47502853</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=47502853</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47502853</guid></item><item><title><![CDATA[New comment by kalib_tweli in "LLM Proxy for Agent Containers"]]></title><description><![CDATA[
<p>LLM proxy for containerized AI agents. The daemon proxies LLM API calls and remote MCP tool calls through a unix socket. The runtime drives the agent loop inside the container. Credentials never cross the socket boundary.</p>
]]></description><pubDate>Mon, 23 Mar 2026 19:38:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=47494138</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=47494138</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47494138</guid></item><item><title><![CDATA[LLM Proxy for Agent Containers]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/calebfaruki/tightbeam">https://github.com/calebfaruki/tightbeam</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47494137">https://news.ycombinator.com/item?id=47494137</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 23 Mar 2026 19:38:37 +0000</pubDate><link>https://github.com/calebfaruki/tightbeam</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=47494137</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47494137</guid></item><item><title><![CDATA[Show HN: Airlock – container agents should never hold credentials]]></title><description><![CDATA[
<p>I built Airlock to move policy enforcement for credentialed CLI access out of agent containers and onto the host.<p>In Dockerized agent setups, prompt files, skills, and other in-container controls are not a real boundary. The agent can ignore or rewrite them.<p>Airlock replaces sensitive CLIs in the container with shims that send requests to a host daemon over a Unix socket. The host validates the request against policy and, if allowed, executes the real command there.<p>The goal is to let a containerized agent use tools like git, ssh, aws, terraform, or docker without the container holding the real credentials.<p>It’s not a general sandbox or a complete agent security solution. It solves a narrower problem: host-side enforcement for credentialed CLI access.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47424437">https://news.ycombinator.com/item?id=47424437</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 18 Mar 2026 11:42:20 +0000</pubDate><link>https://github.com/calebfaruki/airlock</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=47424437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47424437</guid></item><item><title><![CDATA[New comment by kalib_tweli in "What should I expect from moving tech jobs from USA to Europe?"]]></title><description><![CDATA[
<p>TLDR; visit this link: <a href="https://immigration-portal.ec.europa.eu/index_en" rel="nofollow">https://immigration-portal.ec.europa.eu/index_en</a><p>American living in France for 5 years. Previously worked in NYC startups earning a similar salary to you. Made lots of mistakes that, if I had known better, I could've saved myself some time and money. That being said, I am doing far better financially even if I make less on paper and I just bought my first place (unthinkable in NYC). I work as a software contractor technically, though I work full time for an American company.<p>Your first question is what your longterm goal? Permanent relocation or experiment for a few years? In other words, where are you planning to retire? You want to make your social security payments to the correct country. Your tax paperwork will stress you out for the first few years if you don't figure that out.<p>In either case, I'd suggest you try to keep your American job and go fully remote. You don't need a work visa if you don't work for a European company. But if you move permanently, you should do the paperwork to replace your American employment contract with a European contracting company like I did. It's more paperwork but earning an American salary in Europe gives you a significant purchasing power advantage even if you pay more in taxes. The real killer is the paperwork. European bureaucracy sucks.<p>If you don't keep your American job, you should apply for jobs before moving ideally. Most EU countries have reasonably low bars for skilled worker visas. Spain and France I know are very simple. The Netherlands are a bit more confusing. Regardless, you roughly need an offer of 50 000 € and a college degree to get one.<p>EDIT: saw discussion about housing shortages. France has tons of housing (<a href="https://pap.fr" rel="nofollow">https://pap.fr</a>). I had a two-bedroom apartment with a balcony in Paris proper for 1 900 €.</p>
]]></description><pubDate>Thu, 20 Feb 2025 10:04:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=43112977</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=43112977</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43112977</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Using Cloudflare on your website could be blocking RSS users"]]></title><description><![CDATA[
<p>It wouldn't. It's the role of the HTTP server to set the correct content type header.</p>
]]></description><pubDate>Thu, 17 Oct 2024 12:36:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=41869066</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=41869066</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41869066</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Using Cloudflare on your website could be blocking RSS users"]]></title><description><![CDATA[
<p>I confirmed that if you explicitly set the Content-Type response header to application/rss+xml it seems to work with Cloudflare Proxy enabled.<p>The issue here is that Cloudflare's content type check is naive. And the fact that CF is checking the content-type header directly needs to be made more explicit OR they need to do a file type check.</p>
]]></description><pubDate>Thu, 17 Oct 2024 10:14:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=41868120</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=41868120</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41868120</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Using Cloudflare on your website could be blocking RSS users"]]></title><description><![CDATA[
<p>There are email obfuscation and managed challenge script tags being injected into the RSS feed.<p>You simply shouldn't have any challenges whatsoever on an RSS feed. They're literally meant to be read by a machine.</p>
]]></description><pubDate>Thu, 17 Oct 2024 09:24:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=41867836</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=41867836</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41867836</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Ask HN: Should we bring software dev in-house?"]]></title><description><![CDATA[
<p>This is exactly the situation my company ran into. Don't hire a contractor, their incentive won't be aligned with your company and you'll overspend.<p>My company hired me to replace their terrible software vendor and by their own account it's been a clear success. I visit the factories and stores and work with the employees to tailor make the software for their needs.<p>We're finally about to hire our second developer next year using the money we've saved by ending out contract with our old software vendor.<p>We're even at the point now where we can sort of brag about it. Here's the customer story we did with Heroku: <a href="https://www.heroku.com/customers/leatherspa" rel="nofollow">https://www.heroku.com/customers/leatherspa</a></p>
]]></description><pubDate>Sat, 10 Aug 2024 09:32:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=41208350</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=41208350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41208350</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Ask HN: Best Tools for Monorepo?"]]></title><description><![CDATA[
<p>Makefile and docopt. No muss, no fuss. No "works on my machine" issues.<p>I'm running a hand-rolled monorepo with ansible, terraform, and several language projects (JS/TS, Swift, Ruby) that each have a makefile to standardize entrypoints for CI/CD. Docopt is nice because it's self documenting so you can better understand how all your apps are deployed.</p>
]]></description><pubDate>Wed, 31 Jul 2024 21:55:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=41123896</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=41123896</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41123896</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Ask HN: People who make $10k+/month working on AI tools, what do you do?"]]></title><description><![CDATA[
<p>I made training data.</p>
]]></description><pubDate>Wed, 05 Jun 2024 17:04:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=40587490</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=40587490</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40587490</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Ask HN: Please recommend how to manage personal serverss"]]></title><description><![CDATA[
<p>The hard part here is idempotency. Ansible is great for a programmer because it's learning for fun. And you just have to spar with your machine to get good.<p>But for a non-programmer, it's understandable you don't want to be bother with the inner workings of your OS and how to maintain Ansible script idempotency.<p>And for every piece of software you want to run on your server, the idempotency task grows more difficult.<p>My honest opinion? Tolerate the learning curve for docker-compose. Each application you need can be managed and tweaked in isolation. Troubleshooting "works on my machine" problems will cost you more time in the long-run. You can't anticipate all the weird interactions between your programs and the os. Being able to nuke the setup and rebuild from scratch is your most valuable tool.<p>- thin base os (install just enough to run docker-compose)<p>- maintain images for each of your apps you need.<p>- mount the essential volumes of each image to well known location on your hard drive to make manual backups easy.</p>
]]></description><pubDate>Sun, 21 Apr 2024 07:46:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=40103897</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=40103897</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40103897</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Passage Du Gois"]]></title><description><![CDATA[
<p>Funny enough I'm on my way to Noirmoutier right now. My wife's family has a house there on the northeast side of the island near where a lot of the oldest houses are. The Passage du Gois is very convenient when driving from Paris because it saves you about 40 minutes. Otherwise you need to take the bridge. The problem is that it's only for about an hour during low tide. It's peppered with towers for those unwise enough to overstay their welcome too. Happens every once in a while. You'll often find people parked all along the Passage hunting for mussels.<p>The town definitely has rules about how your home must look (if it's a new construction). Old houses don't though.<p>The town definitely empties out during the colder months but my wife and I still enjoy going there because it beats city living. Also they installed fiber optic internet not too long ago. Since we WFH, we try to go there as often as possible.<p>The chimneys are likely real but sealed because of climate change related rules.<p>There's also a castle that dates back to the 12th century built to protect monks from vikings. They've recently finished some restoration work there too.</p>
]]></description><pubDate>Mon, 08 Apr 2024 06:21:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=39966757</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=39966757</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39966757</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Ask HN: What non-AI products are you working on?"]]></title><description><![CDATA[
<p>Thanks! I'm using this as an experience to teach myself mainly. I'm not an expert cyclist but I prefer to DIY when I can.<p>For example, I looked at tires and wheels as a good litmus test. What were the minimum pieces of information that you need to know to pick the right tire or wheel and make those the only filters on the site.<p>In terms of expertise, I've mainly farmed out to the cyclist community on Mastodon and served requests on a first-come-first-serve basis. For example, one person pointed me to sheldonbrown.com for their article on tires and it was really illuminating.</p>
]]></description><pubDate>Wed, 27 Mar 2024 12:37:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=39838248</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=39838248</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39838248</guid></item><item><title><![CDATA[New comment by kalib_tweli in "Ask HN: What non-AI products are you working on?"]]></title><description><![CDATA[
<p>I'm working on a bike part compatibility database for cyclists and anyone else who may work on bicycles.<p><a href="https://builder.bike" rel="nofollow">https://builder.bike</a></p>
]]></description><pubDate>Tue, 26 Mar 2024 23:25:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=39834014</link><dc:creator>kalib_tweli</dc:creator><comments>https://news.ycombinator.com/item?id=39834014</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39834014</guid></item></channel></rss>