Agentic DevOps : AI Engineering for Infrastructure

Agentic DevOps : AI Engineering for Infrastructure

Download on the App Store

Agentic DevOps : AI Engineering for Infrastructure episodes

  • Rogue AI or Just Sloppy Ops?

    The OpenAI Hugging Face hack. The Anthropic testing failures. Listen to the security and ops experts, not lab researchers. I walk you through the production failures that allowed OpenAI’s models to access the internet, and what we can learn from the last few months on how to protect our systems and data. Let’s stop debating imaginary outcomes and start working through that security backlog in our infrastructure.

    I agree with the labs needing to slow down, but not because I believe AI will do uncontrollable harm on humans, but because the labs clearly need better production security and ops teams and more advanced lab infrastructure that’s been properly hardened. They also need to become a production ops security innovator and share that knowledge far and wide.

    Watch the video of this episode.


    Thanks to SpeechifyAI for sponsoring this podcast. Get started for free.

    Check the benchmarks for Best Provider Text-to-Speech.


    😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



    ★Articles★

    • The Hugging Face Incident Is Not an AI Story - Marius Horatau
    • From Frenzy to Freakout - Ciaran Martin & Professor Alan Woodward
    • Stop Freaking Out and Start Fixing Things - SANS Institute
    • Fragments: September 8th - Martin Fowler
    • When AI can do more than we can check - Christian Catalini
    • I'm sorry, you're not going to die from an AI-engineered supervirus - Claus Wilke
    • This Week in Security - Zack Whittaker

    ★Other stuff★

    • 'Big Short' investor Steve Eisman on AI: The companies are trying to manufacture a crisis - CNBC
    • xkcd: Dependency - so much of our systems are this.
    • xkcd: Python Environment - and also this.
    • Defense Factory - OpenAI
    • Investigating three real-world incidents in our cybersecurity evaluations - Anthropic
    • Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident - Hugging Face
    • My recommended podspec, with seccomp enabled - Bret Fisher


    Creators & Guests

    • Bret Fisher - Host
    • Beth Fisher - Producer
    • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

      Grab the best coupons for my Docker and Kubernetes courses on Udemy.
      Join my cloud native DevOps community on Discord.
      Grab some merch at Bret's Loot Box
      Homepage bretfisher.com

      • (00:00) - Start
    • (01:51) - Speechify AI
    • (03:04) - The Hugging Face Incident: Facts
    • (07:07) - Attack Timeline & Escalation
    • (15:33) - Root Cause: Infrastructure Failure
    • (21:15) - Expert Analysis: From Frenzy to Freak Out
    • (23:41) - Martin's Key Points
    • (28:13) - Expert Analysis: Alan Woodward
    • (34:47) - SANS Institute Takeaways
    • (37:47) - Other Good Resources
    • ★ Support this podcast on Patreon ★
      43 min
    • AI Agent Sandboxing with Nono

      Luke Hinds, co-founder of nolabs Inc. and the nono project, joins me to dig into AI agent sandboxing with the nono CLI. It's been my go-to sandboxing tool for local agent use, but I know there are more features I should be using, like secure secrets injection and egress URL path control.

      Watch the video of this episode.


      Thanks to SpeechifyAI for sponsoring this podcast. Get started for free.

      Check the benchmarks for Best Provider Text-to-Speech.


      😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



      ★Show Links★

      • nono website
      • nono repo on GitHub
      • nolabs website
      • OpenSSF SLSA


      Creators & Guests

      • Bret Fisher - Host
      • Beth Fisher - Producer
      • Cristi Cotovan - Editor
      • Luke Hinds - Guest
      • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

        Grab the best coupons for my Docker and Kubernetes courses on Udemy.
        Join my cloud native DevOps community on Discord.
        Grab some merch at Bret's Loot Box
        Homepage bretfisher.com

        • (00:00) - Introduction
      • (04:40) - SLSA
      • (07:38) - Nono Origin and Quickstart
      • (12:19) - Nono Elevator Pitch
      • (22:22) - How Nono Works in Practice
      • (46:42) - DEMO
      • (50:35) - What's Next for Nono?
      • ★ Support this podcast on Patreon ★
        1 hr 5 min
      • AI-Native Engineering Culture from a CTO

        My friend Mike Rollins joins me for a chat about what it’s like leading a software engineering team that doesn’t read code anymore.

        Click here to watch a video of this episode.


        Thanks to SpeechifyAI for sponsoring this podcast. Get started for free.

        Check the benchmarks for Best Provider Text-to-Speech

        😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



        ★Show Links★

        • https://github.com/rollinsio/delta-v-dev-container-boilerplate
        • https://github.com/rollinsio/beyond-test-coverage (expand your testing strength)
        • https://rollins.io/
        • https://www.instagram.com/rollins.io


        Creators & Guests

        • Bret Fisher - Host
        • Beth Fisher - Producer
        • Cristi Cotovan - Editor
        • Mike Rollins - Guest
        • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

          Grab the best coupons for my Docker and Kubernetes courses on Udemy.
          Join my cloud native DevOps community on Discord.
          Grab some merch at Bret's Loot Box
          Homepage bretfisher.com

          • (00:00) - MAIN - Video Podcast
        • (02:14) - Welcome Mike
        • (02:23) - Mike Rollins AI First Journey
        • (06:55) - Speechify.AI
        • (07:57) - Agentic Delivery and Safety Nets
        • (17:50) - PR to Production
        • (35:10) - Testing and PR Chaos
        • (47:49) - Harness Safety and Cost
        • (54:25) - Maturity Milestones and Wrap
        • ★ Support this podcast on Patreon ★
          1 hr 5 min
        • Safer Agent Automation with GitHub Agentic Workflows

          A deep dive into GitHub’s Agentic Workflows feature, with Don Syme of GitHub Next & Peli de Halleux of Microsoft Research. 

          Check out the video podcast version here: https://youtu.be/zmM8VISTOwo

          😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



          ★Show Links★
          https://githubnext.com/projects/agentic-workflows/
          https://github.github.com/gh-aw/
          https://githubnext.com/projects/continuous-ai/
          https://github.com/githubnext/repo-assist-impact/blob/main/report.md
          https://github.com/microsoft/apm


          Creators & Guests

          • Bret Fisher - Host
          • Beth Fisher - Producer
          • Cristi Cotovan - Editor
          • Don Syme - Guest
          • Peli de Halleux - Guest
          • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

            Grab the best coupons for my Docker and Kubernetes courses on Udemy.
            Join my cloud native DevOps community on Discord.
            Grab some merch at Bret's Loot Box
            Homepage bretfisher.com

            • (00:00) - MAIN - Video Podcast
          • (10:42) - Agentic Workflows Explained
          • (17:43) - Toil, Repo Assist, and Guardrails
          • (36:44) - Why Agents Need Guardrails
          • (38:45) - Deterministic Security Box
          • (57:16) - Repo Assist in Action
          • (01:04:51) - Async Agent Workflow
          • (01:10:16) - Workflow Optimization Tricks
          • (01:12:03) - Agentic Enterprise Future
          • ★ Support this podcast on Patreon ★
            1 hr 31 min
          • AI SREs, Chat With Your Infrastructure with Anyshift

            Bret’s joined by the Anyshift.io co-founders, Roxane Fischer and Stephane Jourdan to discuss how an always-on SRE agent can help you proactively find risks and avoid incidents.

            😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



            This edited version is from my live stream show Apr 9, 2026: https://www.youtube.com/live/-DHZwxXigYI?si=9JnQYp8UZG27Bp2X&t=232 

            ★Show Links★

            • Anyshift website
            • Annie CLI
            • Blog post: Agentic Context Engineering in Production: How AI Agents Build Institutional Expertise


            Creators & Guests

            • Bret Fisher - Host
            • Beth Fisher - Producer
            • Cristi Cotovan - Editor
            • Roxane Fischer - Guest
            • Stephane Jourdan - Guest
            • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

              Grab the best coupons for my Docker and Kubernetes courses on Udemy.
              Join my cloud native DevOps community on Discord.
              Grab some merch at Bret's Loot Box
              Homepage bretfisher.com

              • (00:00) - Introduction
            • (03:09) - Meet Anyshift and the big idea
            • (03:29) - When Was Anyshift Created?
            • (07:13) - Context graphs and agent workflows
            • (24:31) - Permissions and Auditing
            • (28:16) - Memory and Context Graph
            • (47:07) - Roadmap and Wrap Up
            • ★ Support this podcast on Patreon ★
              53 min
            • Can AI Agents Safely Become DevOps Engineers?

              Sam Alba, co-founder of Mendral, joins the show to discuss their new AI agents that act as “junior devops engineers” against GitHub Actions, security, failed tests, and more.

              Check out the video podcast version here: https://youtu.be/zHmE6VpWD7o

              😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



              ★Show Links★

              • Mendral website

              Creators & Guests

              • Bret Fisher - Host
              • Beth Fisher - Producer
              • Cristi Cotovan - Editor
              • Sam Alba - Guest
              • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

                Grab the best coupons for my Docker and Kubernetes courses on Udemy.
                Join my cloud native DevOps community on Discord.
                Grab some merch at Bret's Loot Box
                Homepage bretfisher.com

                • (00:00) - Introduction
              • (05:16) - Why CI Needs Agents
              • (18:01) - How Mendral Learns and Automates
              • (42:04) - Trusting Auto Merge
              • (49:35) - Guardrails And Delivery
              • (58:00) - Harnesses And CLI Future
              • (01:09:10) - Future of Mendral
              • ★ Support this podcast on Patreon ★
                1 hr 20 min
              • Our Favorite Agent Setups

                My friend Brian Christner (Docker Captain alum) and I go through our AI harnesses, agents, models, and what we’re playing with right now. OpenClaw, OpenCode, Claude Code, Copilot, and all of it.

                Check out the video podcast version here: https://youtu.be/8AFE0kxaY2k

                😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



                ★Show Links★

                Brian’s Newsletter

                Agents & Claude Code Setup

                • Awesome Claude Code Subagents
                • Agency Agents
                • Claude Code Course
                • OpenClaw alternative

                Brian’s OpenClaw Projects

                • OpenClaw Security Checklist
                • Garmin Connect Skill
                • OpenClaw Security Dashboard Skill


                Creators & Guests

                • Bret Fisher - Host
                • Beth Fisher - Producer
                • Cristi Cotovan - Editor
                • Brian Christner - Guest
                • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

                  Grab the best coupons for my Docker and Kubernetes courses on Udemy.
                  Join my cloud native DevOps community on Discord.
                  Grab some merch at Bret's Loot Box
                  Homepage bretfisher.com

                  • (00:00) - Introduction
                • (03:01) - AI Tools and Skills Deep Dive
                • (30:52) - Securing OpenClaw Servers
                • (36:58) - Safe Use Cases and Token Control
                • (47:43) - OpenClaw DOs and DON'Ts
                • (53:11) - NanoClaw and Container Future
                • ★ Support this podcast on Patreon ★
                  1 hr 4 min
                • Four Months Felt Like Four Years

                  It’s been 6 months since the last episode, and it feels like everything has changed. Bret and Nirmal catch you up on the increasing pace of AI change, how it will likely affect DevOps engineers and platform builders, and what’s coming on the podcast.

                  Check out the video podcast version here: https://youtu.be/NkqAMAIW5ks

                  😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.



                  ★Show Links★

                  • Agent Harness Skills https://agentskills.io
                  • Video of Gradel CEO "You can write code faster, can you deliver it faster?" https://www.youtube.com/watch?v=VOXNJ9_sHuM
                  • Is your team still hand-chiseling code? https://www.geocod.io/code-and-coordinates/2026-01-21-hand-chiseling-code/

                  Creators & Guests

                  • Bret Fisher - Host
                  • Beth Fisher - Producer
                  • Cristi Cotovan - Editor
                  • Nirmal Mehta - Host
                  • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

                    Grab the best coupons for my Docker and Kubernetes courses on Udemy.
                    Join my cloud native DevOps community on Discord.
                    Grab some merch at Bret's Loot Box
                    Homepage bretfisher.com

                    • (00:00) - ADOP - Feb 26, 2026
                  • (02:23) - Introduction
                  • (03:00) - Season Two Kickoff
                  • (04:34) - Productivity Debate and Two AI Camps
                  • (06:48) - Ops View from Dev Retreats
                  • (10:05) - Automation Debt and App Tsunami
                  • (14:12) - Frontier Models Changed Everything
                  • (20:12) - Red Pill vs Blue Pill Skepticism
                  • (23:14) - Three Focus Areas for DevOps
                  • (25:34) - GitHub Copilot and Agentic Workflows
                  • (29:00) - Harnesses That Run Longer
                  • (29:34) - Skills As SOPs
                  • (32:13) - Guardrails For App Tsunami
                  • (34:13) - Agent Orchestration a nd Kubernetes
                  • (35:33) - Shadow IT Goes AI
                  • (36:13) - Inner Loop Diagram Breakdown
                  • (38:37) - AI Code Review Councils
                  • (40:52) - Context Layer And Docs Debt
                  • (47:06) - Career Waves to Agent Ops
                  • (55:12) - Future Guests and Episodes
                  • (58:28) -
                  • ★ Support this podcast on Patreon ★
                    59 min
                  • AI Hype vs. Reality. Real Stats from Laura Tacho, CTO of DX

                    Bret and Nirmal are joined by Laura Tacho, CTO at DX and long-time friend of the show, to discuss AI usage and success in teams adopting AI and Agents to generate code and perform tasks.

                    😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.


                    We finally have some real data on this topic, and Laura Tacho in her role at DX, the developer experience company, has been studying AI successes and failures in the industry and has released a framework to measure AI impact in an orgs software lifecycle.

                    Check out the video podcast version here: https://www.youtube.com/watch?v=0G_TWLHkj7U

                    ★Show Links★
                    AI Measurement Framework
                    DX Core 4 Framework
                    Applying the Core 4 Framework


                    Creators & Guests

                    • Bret Fisher - Host
                    • Beth Fisher - Producer
                    • Cristi Cotovan - Editor
                    • Nirmal Mehta - Host
                    • Laura Tacho - Guest
                      • (00:00) - Teaser
                    • (03:05) - Welcome
                    • (04:58) - AI Measurement Framework
                    • (07:40) - Distilling Fact from Fiction with AI
                    • (23:42) - Skepticism and Adoption of AI Tools
                    • (26:20) - Measuring AI Impact on Developer Work
                    • (47:30) - Assisted vs Agentic
                    • (54:22) - More Gains from Training Humans on AI
                    • (01:02:59) - Measuring AI's Impact
                    • (01:08:38) - Context Switching
                    • (01:12:03) - Navigating AI Hype and Reality

                    • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

                      Grab the best coupons for my Docker and Kubernetes courses on Udemy.
                      Join my cloud native DevOps community on Discord.
                      Grab some merch at Bret's Loot Box
                      Homepage bretfisher.com

                      ★ Support this podcast on Patreon ★
                      1 hr 18 min
                    • My Favorite AI Terminal, Prompt Injection, and More

                      In this episode, I walk though some of my favorite new AI tools and content.

                      😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.

                      Resources and Topics mentioned in this episode:

                      • My AI Skeptic Friends are All Nuts, blog post from fly.io by Thomas Ptacek
                      • From Toil to Triumph: Harnessing Agentic AI to Streamline Infrastructure as Code, KubeCon video by Jody Varney
                      • The Dark Side of Just Hooking Up AI Agents to GitHub, blog post by Simon Maple from AI Native Dev
                      • Warp 2.0
                      • Warp 2.0 walkthrough
                      • Container Use project
                      • Devstral release in May
                      • The latest Devstral release
                      • SWE Bench 


                      Creators & Guests

                      • Bret Fisher - Host
                      • Beth Fisher - Producer
                      • Cristi Cotovan - Editor
                        • (00:00) - Intro
                      • (01:51) - High Fives Meetup
                      • (03:18) - Warp 2.0 Terminal
                      • (09:10) - Container Use and AI Agents
                      • (10:24) - Dagger's Container Use
                      • (12:53) - Comparing Free and Foundational AI Models on SWE Bench
                      • (19:52) - Insights from Videos and Blog Posts
                      • (22:54) - Security Concerns with AI Agents

                      • You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!

                        Grab the best coupons for my Docker and Kubernetes courses on Udemy.
                        Join my cloud native DevOps community on Discord.
                        Grab some merch at Bret's Loot Box
                        Homepage bretfisher.com

                        ★ Support this podcast on Patreon ★
                        28 min

                      About Agentic DevOps : AI Engineering for Infrastructure

                      From the publisher's feed

                      Where LLMs, AI Agents, and MCP tools meet DevOps and platform engineering. How can we humans use non-deterministic, often hallucinating LLMs to automate our infrastructure and help us with the job of…

                      More shows like Agentic DevOps : AI Engineering for Infrastructure

                      DevOps and Docker Talk: Cloud Native Interviews and Tooling by Bret Fisher

                      DevOps and Docker Talk: Cloud Native Interviews and Tooling

                      55 Listeners