WEBVTT

00:00:02.399 --> 00:00:06.400
Wow, I can see everything clearly now.

00:00:06.400 --> 00:00:06.960
Are

00:00:06.960 --> 00:00:09.120
>> are you do you have uh what do you call

00:00:09.120 --> 00:00:11.200
it? By focal

00:00:11.200 --> 00:00:12.160
now because you're

00:00:12.160 --> 00:00:15.679
>> I have no idea. I have I I don't I need

00:00:15.679 --> 00:00:19.840
to wear these for um for at the desk.

00:00:19.840 --> 00:00:22.960
It's different from far sight. Like I I

00:00:22.960 --> 00:00:25.039
don't need them outside. I can perfectly

00:00:25.039 --> 00:00:27.039
see clear in the distance, but not not

00:00:27.039 --> 00:00:29.920
like 70 cm.

00:00:29.920 --> 00:00:30.960
Um,

00:00:30.960 --> 00:00:32.880
>> yeah, I actually need glasses for a

00:00:32.880 --> 00:00:35.520
while. But now, you know, when I put

00:00:35.520 --> 00:00:37.360
them on and I see the screen, then I

00:00:37.360 --> 00:00:40.879
realize how bad it was, like how blurry

00:00:40.879 --> 00:00:43.600
actually my I was looking at.

00:00:43.600 --> 00:00:45.360
>> There's a a way around that, like just

00:00:45.360 --> 00:00:47.200
having a bigger screen and bigger fonts

00:00:47.200 --> 00:00:47.840
and

00:00:47.840 --> 00:00:50.399
>> Yeah. Yeah. Yeah. I definitely had like

00:00:50.399 --> 00:00:52.239
situations where I woke up and I just

00:00:52.239 --> 00:00:53.920
was like, I can't be bothered with this

00:00:53.920 --> 00:00:56.399
right now. Just up the up the font size.

00:00:56.399 --> 00:00:58.079
And then later on during the day didn't

00:00:58.079 --> 00:00:59.760
even realize that I've been, you know,

00:00:59.760 --> 00:01:03.039
working with the font size like this

00:01:03.039 --> 00:01:06.080
big.

00:01:06.080 --> 00:01:09.360
>> Cool, man. So, uh, yeah. How so now

00:01:09.360 --> 00:01:11.360
you're you can see better, you can feel

00:01:11.360 --> 00:01:14.560
better, you can work better.

00:01:14.560 --> 00:01:16.240
>> It's like I'm wearing binoculars, dude.

00:01:16.240 --> 00:01:18.320
It's like like like the screen is like

00:01:18.320 --> 00:01:21.360
suddenly right in front of my face.

00:01:21.360 --> 00:01:23.200
>> What? I think I have the opposite

00:01:23.200 --> 00:01:26.400
problem. I I I see better near without

00:01:26.400 --> 00:01:29.759
my glasses.

00:01:29.759 --> 00:01:34.159
>> Yeah. H So I was just trying to add to

00:01:34.159 --> 00:01:37.600
the to the AI infrastructure podcast

00:01:37.600 --> 00:01:40.400
notes about what to talk about. I wish I

00:01:40.400 --> 00:01:42.400
did this a bit earlier.

00:01:42.400 --> 00:01:43.680
>> I haven't really been adding anything

00:01:43.680 --> 00:01:45.200
there for a while.

00:01:45.200 --> 00:01:45.920
>> There's been a lot

00:01:45.920 --> 00:01:47.439
>> quite a lot of announcements, right?

00:01:47.439 --> 00:01:48.640
Yeah,

00:01:48.640 --> 00:01:52.399
>> there's been a lot. Um, I guess you're

00:01:52.399 --> 00:01:54.640
>> I don't have a lot of time, though.

00:01:54.640 --> 00:01:56.720
>> Oh, you're you're all in on Claude, so I

00:01:56.720 --> 00:01:58.399
guess you haven't even bothered with uh

00:01:58.399 --> 00:02:00.320
Open AI stuff.

00:02:00.320 --> 00:02:02.960
>> They gave me cuz I was one of those

00:02:02.960 --> 00:02:05.759
people that unsubscribed after the whole

00:02:05.759 --> 00:02:09.759
um Department of War situation.

00:02:09.759 --> 00:02:10.800
>> Oh,

00:02:10.800 --> 00:02:13.680
>> I I went to Chat GPT and cancelled, but

00:02:13.680 --> 00:02:14.959
then they said, "We'll give you a month

00:02:14.959 --> 00:02:16.560
for free, so I still have access for a

00:02:16.560 --> 00:02:18.879
month." And now people are all raving

00:02:18.879 --> 00:02:22.319
about uh for 5.4 being um you know

00:02:22.319 --> 00:02:24.720
fine-tuned for coding and being so much

00:02:24.720 --> 00:02:25.440
better.

00:02:25.440 --> 00:02:27.920
>> Well well I don't think they've released

00:02:27.920 --> 00:02:31.840
GBT 5.4 for Codex. Codex is the one

00:02:31.840 --> 00:02:32.640
that's optimized,

00:02:32.640 --> 00:02:34.720
>> but they believe they believe it won't

00:02:34.720 --> 00:02:36.480
because they basically integrated the

00:02:36.480 --> 00:02:39.440
fine tuning from Codex into it and kind

00:02:39.440 --> 00:02:42.560
of reduce reduce the confusion

00:02:42.560 --> 00:02:45.200
>> of of the all of the Yeah, that's at

00:02:45.200 --> 00:02:48.080
least that's Tio's theory, right? I did

00:02:48.080 --> 00:02:50.160
watch The first 10 minutes.

00:02:50.160 --> 00:02:55.200
>> This is where you get the news.

00:02:55.200 --> 00:02:56.160
>> Yeah. Well, that's

00:02:56.160 --> 00:02:58.000
>> it. To me it makes sense

00:02:58.000 --> 00:03:00.080
>> because like all of this additional

00:03:00.080 --> 00:03:01.680
terminology people were getting super

00:03:01.680 --> 00:03:03.840
confused if you were open opening your

00:03:03.840 --> 00:03:07.440
your LLM model selection it was like 20

00:03:07.440 --> 00:03:09.519
GPT options

00:03:09.519 --> 00:03:14.239
>> GPT 5.2 two 5.3 5.3 thinking 5.3 codex

00:03:14.239 --> 00:03:17.120
5.3 codex ultra think

00:03:17.120 --> 00:03:19.519
>> it's like what are you what are you

00:03:19.519 --> 00:03:20.879
doing

00:03:20.879 --> 00:03:25.440
>> so on different models so so I wanted to

00:03:25.440 --> 00:03:28.560
ask you about do you use one model

00:03:28.560 --> 00:03:31.680
against another in your workflow I mean

00:03:31.680 --> 00:03:33.519
you showed me like months ago that you

00:03:33.519 --> 00:03:35.360
were doing something like that like

00:03:35.360 --> 00:03:38.720
>> yeah I was because I was getting

00:03:38.720 --> 00:03:39.920
>> uh sorry

00:03:39.920 --> 00:03:41.760
>> I was Because the problem was I was I

00:03:41.760 --> 00:03:43.280
was never I was always running out of

00:03:43.280 --> 00:03:44.959
credits on cloud, right?

00:03:44.959 --> 00:03:46.959
>> Oh, yeah. That's true. You're doing it

00:03:46.959 --> 00:03:48.959
as a means of necessity.

00:03:48.959 --> 00:03:52.239
>> Yeah. But now now I I I haven't even

00:03:52.239 --> 00:03:55.280
been able to, you know, hit my budget

00:03:55.280 --> 00:03:56.640
limits on cloud.

00:03:56.640 --> 00:03:59.200
>> Yeah. So that's interesting. So you were

00:03:59.200 --> 00:04:01.280
doing it you were using multi- aents

00:04:01.280 --> 00:04:03.840
because you're running out of credits

00:04:03.840 --> 00:04:05.599
though. So, I'm I'm thinking using

00:04:05.599 --> 00:04:07.120
multiple

00:04:07.120 --> 00:04:09.920
multiple different models might be

00:04:09.920 --> 00:04:11.760
>> constraint.

00:04:11.760 --> 00:04:13.599
>> Yeah, it might be a quality game because

00:04:13.599 --> 00:04:15.280
I'm I was actually a little bit shocked.

00:04:15.280 --> 00:04:19.440
I had this experience last week where I

00:04:19.440 --> 00:04:24.080
I uh I created a a PR. Of course, other

00:04:24.080 --> 00:04:27.120
people approved it without asking too

00:04:27.120 --> 00:04:29.120
many questions or I mean, it's human

00:04:29.120 --> 00:04:31.840
approval. What do you expect?

00:04:31.840 --> 00:04:33.360
your track record

00:04:33.360 --> 00:04:36.639
>> and and then I noticed that um like if I

00:04:36.639 --> 00:04:38.960
was if I was actually less trustful of

00:04:38.960 --> 00:04:41.759
AI and I honestly looked at this patch

00:04:41.759 --> 00:04:43.440
that I was contributing I would have

00:04:43.440 --> 00:04:45.440
realized it was a terrible mistake it

00:04:45.440 --> 00:04:47.360
was such an obvious mistake really like

00:04:47.360 --> 00:04:50.000
I I used env instead of environment for

00:04:50.000 --> 00:04:52.720
GitHub workflow and of course I didn't

00:04:52.720 --> 00:04:55.360
really test it because it was a kind of

00:04:55.360 --> 00:04:58.000
a trivial change but anyway long story

00:04:58.000 --> 00:05:02.080
short this this PR that I pushed that

00:05:02.080 --> 00:05:06.240
was AI generated was wrong and now

00:05:06.240 --> 00:05:08.639
that's just making me very it's just

00:05:08.639 --> 00:05:10.639
sort of like wrapped ripped my

00:05:10.639 --> 00:05:12.960
confidence apart

00:05:12.960 --> 00:05:14.960
and uh I'm just thinking like what can I

00:05:14.960 --> 00:05:16.960
what like what practical steps can I do

00:05:16.960 --> 00:05:19.600
to make sure I don't

00:05:19.600 --> 00:05:22.720
commit junk

00:05:22.720 --> 00:05:25.600
this has always been the job of uh CI/CD

00:05:25.600 --> 00:05:27.520
DevOps people like my job pretty much

00:05:27.520 --> 00:05:29.199
all the time is to set up llinters

00:05:29.199 --> 00:05:31.520
pre-commit and all this type of stuff.

00:05:31.520 --> 00:05:33.039
Whatever I can deterministically

00:05:33.039 --> 00:05:33.840
validate.

00:05:33.840 --> 00:05:36.639
>> Yeah, that that's that's the trick.

00:05:36.639 --> 00:05:39.919
Making AI deterministic or making what

00:05:39.919 --> 00:05:42.320
AI does deterministic though. The

00:05:42.320 --> 00:05:45.680
trouble is is that maybe I'm just

00:05:45.680 --> 00:05:48.639
casting shade on GitHub, but like GitHub

00:05:48.639 --> 00:05:52.320
actions is such a pain.

00:05:52.320 --> 00:05:55.280
The difficulty now there's action lint,

00:05:55.280 --> 00:05:57.199
but it doesn't capture like half the

00:05:57.199 --> 00:06:00.639
problems. it doesn't support like

00:06:00.639 --> 00:06:02.800
actions and

00:06:02.800 --> 00:06:06.000
>> I had the similar situation on Friday

00:06:06.000 --> 00:06:12.720
where I was like I was working on

00:06:12.720 --> 00:06:17.280
something related to a docker image and

00:06:17.280 --> 00:06:19.520
yes I remember uh we need to do

00:06:19.520 --> 00:06:24.319
immutable digest pins on the um docker

00:06:24.319 --> 00:06:26.720
base images so when we build using a

00:06:26.720 --> 00:06:29.919
>> file you're in a environment are what?

00:06:29.919 --> 00:06:33.120
>> Yeah. So, so we we we have like the .NET

00:06:33.120 --> 00:06:36.880
4 8.0 tag which is immutable because

00:06:36.880 --> 00:06:38.560
security patches and so on, right? When

00:06:38.560 --> 00:06:40.080
Microsoft builds a new version, they

00:06:40.080 --> 00:06:42.720
just push it under that 8.0 tag even

00:06:42.720 --> 00:06:43.600
though

00:06:43.600 --> 00:06:45.840
>> it's a different image. So, they don't

00:06:45.840 --> 00:06:47.680
accept that. So, they were like, you

00:06:47.680 --> 00:06:50.240
need to use an immutable digest.

00:06:50.240 --> 00:06:51.759
>> And then I was like, yeah, that's a pain

00:06:51.759 --> 00:06:53.360
because now we have to do a schedule to

00:06:53.360 --> 00:06:55.120
always check if there's a new digest and

00:06:55.120 --> 00:06:57.440
bump our base images, right? It's kind

00:06:57.440 --> 00:06:59.599
of like security like check checklist

00:06:59.599 --> 00:07:01.840
security like do we're consuming from

00:07:01.840 --> 00:07:04.800
Microsoft. Uh

00:07:04.800 --> 00:07:06.560
>> yeah sure there's supply chain attacks

00:07:06.560 --> 00:07:08.400
that can you know

00:07:08.400 --> 00:07:09.680
>> I'm not a I'm not a fan of these

00:07:09.680 --> 00:07:11.280
immutusable

00:07:11.280 --> 00:07:14.880
hashes on on docker things

00:07:14.880 --> 00:07:16.880
>> but like if Microsoft's been compromised

00:07:16.880 --> 00:07:19.520
and their and their 8.0.NET net image is

00:07:19.520 --> 00:07:21.919
is insecure and therefore you're saying

00:07:21.919 --> 00:07:23.759
we cannot have I think this is the type

00:07:23.759 --> 00:07:26.400
of nonsense um you know

00:07:26.400 --> 00:07:28.080
>> type of security because you're actually

00:07:28.080 --> 00:07:30.000
aggravating the issue because now you

00:07:30.000 --> 00:07:33.759
expect the client to adequately keep up

00:07:33.759 --> 00:07:34.400
up to

00:07:34.400 --> 00:07:38.000
>> yeah anyway the point was that um with

00:07:38.000 --> 00:07:40.240
Sun we had built a beautiful GitHub

00:07:40.240 --> 00:07:43.520
workflow that was tested against uh brew

00:07:43.520 --> 00:07:47.440
installed uh docker buildex image tools

00:07:47.440 --> 00:07:49.599
to inspect the digest for the remote

00:07:49.599 --> 00:07:51.440
image to figure out if we were using the

00:07:51.440 --> 00:07:54.400
if there was a new digest. And before I

00:07:54.400 --> 00:07:57.680
actually, you know, remove moved the PR

00:07:57.680 --> 00:08:00.639
from draft to review ready, I asked um

00:08:00.639 --> 00:08:03.520
Sun, hey, you know, we can test this. We

00:08:03.520 --> 00:08:06.639
can run the Docker Ubuntu image here and

00:08:06.639 --> 00:08:08.479
we can run the the commands that you

00:08:08.479 --> 00:08:10.319
have in the in the in the GitHub actions

00:08:10.319 --> 00:08:11.919
workflow. You can we can run it inside

00:08:11.919 --> 00:08:12.960
the local Docker image.

00:08:12.960 --> 00:08:13.280
>> Yeah.

00:08:13.280 --> 00:08:15.120
>> Ubuntu. and it did that and it

00:08:15.120 --> 00:08:17.120
immediately broke and there were all

00:08:17.120 --> 00:08:19.680
kinds of problems with it because um it

00:08:19.680 --> 00:08:23.199
was a multiarchc um digest and it wasn't

00:08:23.199 --> 00:08:24.879
detecting the digest properly. it was

00:08:24.879 --> 00:08:27.680
using uh a template string that didn't

00:08:27.680 --> 00:08:29.120
work or something or

00:08:29.120 --> 00:08:30.800
>> Yeah. And then also it was using the

00:08:30.800 --> 00:08:33.599
docker build 0.19 whereas in in the

00:08:33.599 --> 00:08:36.000
docker um that was on my local then it

00:08:36.000 --> 00:08:38.240
it says oh it fails I I should do an a

00:08:38.240 --> 00:08:39.760
instead of trying to use a temp because

00:08:39.760 --> 00:08:41.519
you know when you do golang like docker

00:08:41.519 --> 00:08:43.360
you can do these template strings to

00:08:43.360 --> 00:08:46.000
extract certain fields. So you can you

00:08:46.000 --> 00:08:48.000
can do docker inspect and then you can

00:08:48.000 --> 00:08:49.519
pass in a template string and it will

00:08:49.519 --> 00:08:52.240
expect it. Uh but the thing was it

00:08:52.240 --> 00:08:53.519
didn't work and then I assumed it was

00:08:53.519 --> 00:08:54.640
because it was using the wrong version

00:08:54.640 --> 00:08:56.640
and I said you're using 0.19 the latest

00:08:56.640 --> 00:08:58.720
is 0.26 and the GitHub action is using

00:08:58.720 --> 00:09:00.720
026 and they tried that it didn't work.

00:09:00.720 --> 00:09:02.720
Anyway the point is yeah I got so much

00:09:02.720 --> 00:09:05.279
things wrong and even even today when I

00:09:05.279 --> 00:09:07.600
was like um let's you use a make target.

00:09:07.600 --> 00:09:09.360
So this is another very stupid security

00:09:09.360 --> 00:09:11.920
problem where we have sonar cube that

00:09:11.920 --> 00:09:16.720
lints bashcript and I'm vendoring a v a

00:09:16.720 --> 00:09:18.399
third party supplier

00:09:18.399 --> 00:09:20.240
>> vendoring okay vendor

00:09:20.240 --> 00:09:22.000
>> vendoring meaning I'm inlining it into

00:09:22.000 --> 00:09:23.839
my git because I don't want to do a curl

00:09:23.839 --> 00:09:26.880
during my build I want to use an install

00:09:26.880 --> 00:09:29.279
script and when in my pull request it

00:09:29.279 --> 00:09:32.800
was flagged with 32 um sonar cube issues

00:09:32.800 --> 00:09:33.680
and

00:09:33.680 --> 00:09:35.760
>> if I fix them then the next time I pull

00:09:35.760 --> 00:09:37.920
the vendor next time I update from the

00:09:37.920 --> 00:09:39.040
vendor script, I'm going to have the

00:09:39.040 --> 00:09:41.040
same problem. Right? So, I want to like

00:09:41.040 --> 00:09:42.880
allow list it. I can't say whitelist,

00:09:42.880 --> 00:09:45.920
right? I have to say allow listed.

00:09:45.920 --> 00:09:46.880
>> Thank you.

00:09:46.880 --> 00:09:47.600
>> I'm very

00:09:47.600 --> 00:09:49.600
>> The audience appreciates this.

00:09:49.600 --> 00:09:52.240
>> Yeah. Um, so so I have to I have I I

00:09:52.240 --> 00:09:53.760
have to the I mean to me the right way

00:09:53.760 --> 00:09:56.560
is to vendor it and get track it allow

00:09:56.560 --> 00:09:59.279
list it. Um, but that's going to take

00:09:59.279 --> 00:10:01.279
time because I'm in this organization

00:10:01.279 --> 00:10:03.839
not an admin. So I I have to wait for

00:10:03.839 --> 00:10:05.440
someone else to whitelist it. So anyway,

00:10:05.440 --> 00:10:09.200
I says let's let's use a make target and

00:10:09.200 --> 00:10:11.279
um you know let's make sure that we

00:10:11.279 --> 00:10:12.880
actually do the insecure thing which is

00:10:12.880 --> 00:10:16.480
we we um we curl it and with make

00:10:16.480 --> 00:10:18.640
targets you can specify a file on disk

00:10:18.640 --> 00:10:20.320
and if it doesn't exist

00:10:20.320 --> 00:10:22.399
>> it will basically run the commands right

00:10:22.399 --> 00:10:24.480
I mean they it will keep it even like

00:10:24.480 --> 00:10:26.399
>> I'm the number one make file fan here

00:10:26.399 --> 00:10:28.240
>> yeah so but the thing is when I asked

00:10:28.240 --> 00:10:31.040
son or opus I think it was opus 4.6 six

00:10:31.040 --> 00:10:32.560
and I said, "Let's use a make target."

00:10:32.560 --> 00:10:35.360
It came up with all these phony make

00:10:35.360 --> 00:10:37.760
targets to do a unsure local or

00:10:37.760 --> 00:10:40.240
whatever. And I was like, you don't need

00:10:40.240 --> 00:10:41.680
to do that. That's not how make file

00:10:41.680 --> 00:10:44.000
works. You can point it to a file

00:10:44.000 --> 00:10:44.800
target.

00:10:44.800 --> 00:10:45.920
>> And then it was like, oh, you're

00:10:45.920 --> 00:10:47.680
absolutely right. But you see, like

00:10:47.680 --> 00:10:49.680
because I know make file, I know what to

00:10:49.680 --> 00:10:51.440
tell it. Like I know this this makes no

00:10:51.440 --> 00:10:52.160
sense.

00:10:52.160 --> 00:10:54.000
>> It's funny how make files trip up a lot

00:10:54.000 --> 00:10:57.120
of people and and AI in some ways. But

00:10:57.120 --> 00:10:59.120
>> so I was I was I was all mighty. I was

00:10:59.120 --> 00:11:01.040
like, "Haha, look at AI. You can't be

00:11:01.040 --> 00:11:02.640
just a stupid wipe coder. You have to

00:11:02.640 --> 00:11:04.320
know how make files work." At the same

00:11:04.320 --> 00:11:06.160
time, I was wondering the issue really

00:11:06.160 --> 00:11:08.240
is the make file, though. Like, if make

00:11:08.240 --> 00:11:10.320
file wasn't this so cryptic.

00:11:10.320 --> 00:11:12.240
>> Oh, have you heard of redo? By the way,

00:11:12.240 --> 00:11:15.279
I sometimes use redo in my projects.

00:11:15.279 --> 00:11:17.120
>> I you were just talking about you you

00:11:17.120 --> 00:11:19.040
did your all your skills with just or

00:11:19.040 --> 00:11:20.320
something like that, right?

00:11:20.320 --> 00:11:23.920
>> No, not just. I used redo. It's a DGP.

00:11:23.920 --> 00:11:28.240
Anyway, so going back to the the quality

00:11:28.240 --> 00:11:30.560
thing. Okay, I I'm with you a thousand%

00:11:30.560 --> 00:11:32.880
that we should we should do less things

00:11:32.880 --> 00:11:35.519
in GitHub actions, do more make files.

00:11:35.519 --> 00:11:37.120
That's what I'm that's my mantra.

00:11:37.120 --> 00:11:38.959
>> That's not what I said, though. I just

00:11:38.959 --> 00:11:41.519
said that that we can validate some of

00:11:41.519 --> 00:11:45.600
it. Um, for example,

00:11:45.600 --> 00:11:47.680
>> we can validate, we can we we can ask

00:11:47.680 --> 00:11:50.240
the AI to do a little extra and say

00:11:50.240 --> 00:11:52.320
like, you know, it all looks good and we

00:11:52.320 --> 00:11:54.480
can push it and see it pass. But even

00:11:54.480 --> 00:11:56.880
then, we're not 100% sure. We can still

00:11:56.880 --> 00:11:59.760
use local Docker VMs with with Linux and

00:11:59.760 --> 00:12:02.399
and and try to use that to reproduce in

00:12:02.399 --> 00:12:04.480
Ubuntu. Oh, by the way, I wanted to say

00:12:04.480 --> 00:12:06.480
on the subject of pinning, the one good

00:12:06.480 --> 00:12:08.480
thing about pinning in a Docker image is

00:12:08.480 --> 00:12:10.639
that is that you're likely to speed up

00:12:10.639 --> 00:12:12.720
your Docker builds because

00:12:12.720 --> 00:12:14.320
>> uh using caches and and things.

00:12:14.320 --> 00:12:18.240
>> Yeah, you're more that's one sort of

00:12:18.240 --> 00:12:20.880
>> Yeah. of the churn.

00:12:20.880 --> 00:12:22.800
>> But you were basically you started

00:12:22.800 --> 00:12:25.519
saying that um it's hard to trust the AI

00:12:25.519 --> 00:12:27.920
outputs because it can we can still miss

00:12:27.920 --> 00:12:29.920
things and how do we validate it? Um

00:12:29.920 --> 00:12:31.120
>> yeah. So,

00:12:31.120 --> 00:12:33.680
>> but you have you seen Adam Jacob's

00:12:33.680 --> 00:12:39.040
latest LinkedIn posts about that?

00:12:39.040 --> 00:12:40.399
I think he's been saying the same thing

00:12:40.399 --> 00:12:42.639
like quite a few times which is like

00:12:42.639 --> 00:12:45.600
it's it's difficult to be in this like

00:12:45.600 --> 00:12:50.800
what's it called the the twilight zone

00:12:50.800 --> 00:12:53.360
the where you are still validating like

00:12:53.360 --> 00:12:55.120
you have a lot of manual code and you

00:12:55.120 --> 00:12:57.360
still want to control what the AI output

00:12:57.360 --> 00:13:00.000
is um and you're actually validating the

00:13:00.000 --> 00:13:01.920
code versus you're not validating the

00:13:01.920 --> 00:13:04.320
output you're not validating the result

00:13:04.320 --> 00:13:06.480
and and he had quite a few posts where

00:13:06.480 --> 00:13:08.639
he was going on about how people have a

00:13:08.639 --> 00:13:11.360
difficulty letting go of the code and I

00:13:11.360 --> 00:13:12.959
mean something we've been discussing a

00:13:12.959 --> 00:13:14.639
lot as well and I kept telling you like

00:13:14.639 --> 00:13:16.480
you know as long as we put the

00:13:16.480 --> 00:13:18.240
deterministic checks around it then we

00:13:18.240 --> 00:13:20.000
can uh do a lot more

00:13:20.000 --> 00:13:22.720
>> I don't understand the oh I think this

00:13:22.720 --> 00:13:24.560
is how you do it

00:13:24.560 --> 00:13:27.680
>> I don't understand LinkedIn

00:13:27.680 --> 00:13:28.800
>> there was a

00:13:28.800 --> 00:13:30.720
>> yeah I mean there's definitely like

00:13:30.720 --> 00:13:34.160
people who are into AI and cranking it

00:13:34.160 --> 00:13:34.880
out

00:13:34.880 --> 00:13:36.959
>> this one about Nick's like I've been

00:13:36.959 --> 00:13:38.399
programming for literally my entire

00:13:38.399 --> 00:13:41.440
life. There's um that one I think he's

00:13:41.440 --> 00:13:44.079
talking about the fact that it's really

00:13:44.079 --> 00:13:47.760
a big mind shift. Uh it wasn't that Adam

00:13:47.760 --> 00:13:49.680
actually a couple of reflections that

00:13:49.680 --> 00:13:52.720
one couple of reflections the third one

00:13:52.720 --> 00:13:55.600
below from Adam that one. Yeah. Yeah.

00:13:55.600 --> 00:13:57.519
that that's where he goes on and says

00:13:57.519 --> 00:13:59.920
like it's hard to if you have an

00:13:59.920 --> 00:14:02.720
existing large code base um it's hard to

00:14:02.720 --> 00:14:05.839
let AI go wild on that code base

00:14:05.839 --> 00:14:07.680
>> and it's more easy to just start from

00:14:07.680 --> 00:14:09.839
scratch and let AI build everything and

00:14:09.839 --> 00:14:11.440
just build all the loops around it and

00:14:11.440 --> 00:14:12.880
that make me think I think the first

00:14:12.880 --> 00:14:14.480
thing we need to do when we are adopting

00:14:14.480 --> 00:14:17.600
AI into a codebase is to ask AI to

00:14:17.600 --> 00:14:19.519
validate all of the user stories and

00:14:19.519 --> 00:14:21.760
build a very strong build hardness don't

00:14:21.760 --> 00:14:24.880
let AI build like modify the code let AI

00:14:24.880 --> 00:14:27.199
build all of the validation and make

00:14:27.199 --> 00:14:28.959
sure that the validation is correct

00:14:28.959 --> 00:14:31.279
before you let AI loose on the code.

00:14:31.279 --> 00:14:32.959
>> I think that a way to

00:14:32.959 --> 00:14:36.320
>> my my colleague um was using AI with

00:14:36.320 --> 00:14:39.519
some database flows and what I and he's

00:14:39.519 --> 00:14:42.880
a very seasoned colleague um he's been

00:14:42.880 --> 00:14:44.480
around the block. He's been he's been

00:14:44.480 --> 00:14:48.000
hacking since the 80s sort of thing. And

00:14:48.000 --> 00:14:49.519
I don't know, maybe he's listening to

00:14:49.519 --> 00:14:51.199
different podcasts and getting his

00:14:51.199 --> 00:14:53.440
information from different sources, but

00:14:53.440 --> 00:14:56.000
I was really impressed that he like what

00:14:56.000 --> 00:14:59.199
what do you what he did was that he he

00:14:59.199 --> 00:15:03.120
set up like a flow where he was he was

00:15:03.120 --> 00:15:05.440
using different personas like he was

00:15:05.440 --> 00:15:07.760
saying like you know I am a business

00:15:07.760 --> 00:15:10.639
analyst and I want this thing and then I

00:15:10.639 --> 00:15:13.680
am um a database designer and I want

00:15:13.680 --> 00:15:16.320
this thing. I am a QA engineer and I

00:15:16.320 --> 00:15:18.240
want this thing. And then he basically

00:15:18.240 --> 00:15:21.519
ran the problem through these three

00:15:21.519 --> 00:15:24.959
agents profiles to do his work. And I

00:15:24.959 --> 00:15:26.399
thought it was very impressive the way

00:15:26.399 --> 00:15:28.880
he he did that. I mean, have you have

00:15:28.880 --> 00:15:31.760
you done have you thought about personas

00:15:31.760 --> 00:15:34.079
and in your spec ledger and things like

00:15:34.079 --> 00:15:34.959
that? Do you

00:15:34.959 --> 00:15:36.880
>> No, but there is quite a few.

00:15:36.880 --> 00:15:38.720
>> I am a quality assurance engineer.

00:15:38.720 --> 00:15:40.800
>> Yeah. I mean, a lot of people don't like

00:15:40.800 --> 00:15:42.399
it. They say it's like it's like

00:15:42.399 --> 00:15:44.160
theatrics. It's like you're going to a

00:15:44.160 --> 00:15:45.920
play and it's like, you know, I'm

00:15:45.920 --> 00:15:47.680
playing house and balls with my like

00:15:47.680 --> 00:15:48.320
daughter.

00:15:48.320 --> 00:15:49.839
>> Yeah. Yeah.

00:15:49.839 --> 00:15:50.240
>> But

00:15:50.240 --> 00:15:53.440
>> though I do I I think the the probably

00:15:53.440 --> 00:15:55.519
the benefit really is that you have like

00:15:55.519 --> 00:15:57.279
a fresh

00:15:57.279 --> 00:16:00.399
context in two or three different agents

00:16:00.399 --> 00:16:01.920
just to cover.

00:16:01.920 --> 00:16:04.320
>> Oh yeah, for sure. I think I think it I

00:16:04.320 --> 00:16:06.079
think people underestimate how effective

00:16:06.079 --> 00:16:08.160
it is. I think because of these things

00:16:08.160 --> 00:16:12.160
are language models the context and you

00:16:12.160 --> 00:16:14.079
know that you create around them and

00:16:14.079 --> 00:16:17.199
clearing the context and having it with

00:16:17.199 --> 00:16:19.440
different perspective like you know

00:16:19.440 --> 00:16:22.000
creating these personas I think it makes

00:16:22.000 --> 00:16:23.759
sense I don't think we understand

00:16:23.759 --> 00:16:25.759
>> you've not you've not uh implemented

00:16:25.759 --> 00:16:28.160
>> I don't do that no I' also many people

00:16:28.160 --> 00:16:29.680
are yeah like I just said people don't

00:16:29.680 --> 00:16:32.160
really like that but I think it makes

00:16:32.160 --> 00:16:33.680
sense that I'm not going to do that at

00:16:33.680 --> 00:16:36.240
the moment for me right now the because

00:16:36.240 --> 00:16:37.680
There's quite a few announcements lately

00:16:37.680 --> 00:16:40.000
that really affect uh Spec Ledger's

00:16:40.000 --> 00:16:42.959
position a lot. One is uh Antropic

00:16:42.959 --> 00:16:45.759
announcing announcing like a um config

00:16:45.759 --> 00:16:47.839
management as a service so that you can

00:16:47.839 --> 00:16:50.959
share configurations uh for Claude Code.

00:16:50.959 --> 00:16:52.639
That's something that they launched.

00:16:52.639 --> 00:16:55.600
They added the scheduling. So people are

00:16:55.600 --> 00:16:58.240
saying ohropic just launched openclaw

00:16:58.240 --> 00:17:00.560
clone by making Claude Code run

00:17:00.560 --> 00:17:02.800
independently and can run schedule task

00:17:02.800 --> 00:17:04.640
which is a bit like one of the aspects

00:17:04.640 --> 00:17:06.400
of open claw.

00:17:06.400 --> 00:17:08.160
I'm actually surprised how long that

00:17:08.160 --> 00:17:10.720
it's it's taken like I still think

00:17:10.720 --> 00:17:12.720
>> Claude and Codex doesn't make it super

00:17:12.720 --> 00:17:15.760
easy to share things in an organization.

00:17:15.760 --> 00:17:18.160
>> Yeah. So so that's what Speckled Ledger

00:17:18.160 --> 00:17:20.079
does, right? I mean we have a superbase

00:17:20.079 --> 00:17:23.039
metadata where we are um allowing

00:17:23.039 --> 00:17:25.360
organizations to

00:17:25.360 --> 00:17:27.439
create skill bundles. I think Tessle

00:17:27.439 --> 00:17:28.799
apparently does that as well. I didn't

00:17:28.799 --> 00:17:30.320
know but like tessel they are not like

00:17:30.320 --> 00:17:32.799
we are the scale bundle

00:17:32.799 --> 00:17:35.120
>> uh solution to belittle anything but I

00:17:35.120 --> 00:17:36.480
don't think it's like a huge problem to

00:17:36.480 --> 00:17:38.960
share the prompts but like it it

00:17:38.960 --> 00:17:40.640
absolutely it's become an industry in

00:17:40.640 --> 00:17:40.880
itself

00:17:40.880 --> 00:17:42.640
>> it's just it's just one of those little

00:17:42.640 --> 00:17:44.400
things you know it's just one of those

00:17:44.400 --> 00:17:46.240
things you easily tack tack on if you're

00:17:46.240 --> 00:17:48.640
if you're going to provide a spec ledger

00:17:48.640 --> 00:17:50.559
flow and you're going to create a UI

00:17:50.559 --> 00:17:53.440
that that allows you to to visualize the

00:17:53.440 --> 00:17:55.919
process might as well includes you know

00:17:55.919 --> 00:17:58.240
skill bundles might as well include you

00:17:58.240 --> 00:17:59.679
part of the bootstrap of the of the

00:17:59.679 --> 00:18:01.840
repo. That's part of like

00:18:01.840 --> 00:18:03.840
>> some organizations they call it a AI

00:18:03.840 --> 00:18:06.240
readiness of a repository. Um across

00:18:06.240 --> 00:18:08.799
teams you need to set set up your repos

00:18:08.799 --> 00:18:10.559
so that they are ready for AI

00:18:10.559 --> 00:18:12.320
contribution so that anyone who starts

00:18:12.320 --> 00:18:14.480
working into it gets the best practices

00:18:14.480 --> 00:18:17.360
gets the the skills to to set up the you

00:18:17.360 --> 00:18:19.760
know everything. about talking about

00:18:19.760 --> 00:18:21.679
that and best practices and

00:18:21.679 --> 00:18:24.480
documentation. The one good thing at

00:18:24.480 --> 00:18:26.480
work is that it just took some

00:18:26.480 --> 00:18:31.200
convincing I feel took some took some um

00:18:31.200 --> 00:18:33.840
posturing but I I think I have the

00:18:33.840 --> 00:18:35.440
mandate to move everything from

00:18:35.440 --> 00:18:40.080
confluence or p confluence to markdown.

00:18:40.080 --> 00:18:41.440
I don't know if I've shown you this

00:18:41.440 --> 00:18:44.400
before but like yeah basically I feel

00:18:44.400 --> 00:18:45.760
this is going to make my life a lot

00:18:45.760 --> 00:18:47.039
easier.

00:18:47.039 --> 00:18:49.760
I hope you agree

00:18:49.760 --> 00:18:52.080
>> moving away from Atlassian is uh the

00:18:52.080 --> 00:18:55.200
sweetest uh AI move you can make really.

00:18:55.200 --> 00:18:56.880
>> I say that but then I spend the whole

00:18:56.880 --> 00:18:59.919
morning um create like playing with the

00:18:59.919 --> 00:19:03.200
J CLI Golang and writing a skill for but

00:19:03.200 --> 00:19:04.720
I'm right I wrote a skill very

00:19:04.720 --> 00:19:06.799
explicitly customized for all the custom

00:19:06.799 --> 00:19:08.400
fields and all the custom workflows for

00:19:08.400 --> 00:19:10.720
one board and one team that I'm in.

00:19:10.720 --> 00:19:14.640
>> You use the Atlassian um MCP. I know you

00:19:14.640 --> 00:19:17.120
don't like MCP. I don't like MCPS.

00:19:17.120 --> 00:19:18.240
>> It does work really well. This

00:19:18.240 --> 00:19:21.360
particular one, this super set.

00:19:21.360 --> 00:19:22.320
>> Okay.

00:19:22.320 --> 00:19:24.320
>> Though it's got some blind size like it

00:19:24.320 --> 00:19:26.480
doesn't work with

00:19:26.480 --> 00:19:29.120
uh what do you call these these these

00:19:29.120 --> 00:19:31.919
boards? White spaces. Not too sure what

00:19:31.919 --> 00:19:32.240
they call.

00:19:32.240 --> 00:19:33.520
>> Yeah. So, I guess it wouldn't work for

00:19:33.520 --> 00:19:34.960
me because that's exactly what I just

00:19:34.960 --> 00:19:37.200
did. I just took the Golang CLI that's

00:19:37.200 --> 00:19:40.080
like the most popular one and apparently

00:19:40.080 --> 00:19:42.640
hasn't received PR merge. So, I I forked

00:19:42.640 --> 00:19:44.240
it. I added the PR.

00:19:44.240 --> 00:19:46.400
Is it able to understand um a

00:19:46.400 --> 00:19:47.600
blackboard? I don't know what it's

00:19:47.600 --> 00:19:49.520
called in Atlas. Yeah.

00:19:49.520 --> 00:19:50.160
>> A white board.

00:19:50.160 --> 00:19:51.360
>> Maybe we're talking about a different

00:19:51.360 --> 00:19:52.960
thing like a conbon board is not the

00:19:52.960 --> 00:19:53.919
same as a whiteboard.

00:19:53.919 --> 00:19:55.120
>> Oh, no, no, no, no, no,

00:19:55.120 --> 00:19:56.080
>> no.

00:19:56.080 --> 00:19:57.440
>> This supports everything except a

00:19:57.440 --> 00:19:59.840
whiteboard and it it's really good and

00:19:59.840 --> 00:20:01.679
but I do notice that sometimes it

00:20:01.679 --> 00:20:04.080
struggles to do the markdown inside Jira

00:20:04.080 --> 00:20:06.799
because Jirro markdown has always been

00:20:06.799 --> 00:20:09.120
>> insane. I'm I I was very surprised

00:20:09.120 --> 00:20:10.559
because I always struggle with Jira

00:20:10.559 --> 00:20:12.640
markdown and then I see Cloud Sonnet or

00:20:12.640 --> 00:20:14.960
Opus create Jira tickets and with all

00:20:14.960 --> 00:20:16.960
theseh4 and all M's like what the hell

00:20:16.960 --> 00:20:18.880
is that and and then it just creates the

00:20:18.880 --> 00:20:22.080
tickets and I go oh that looks good.

00:20:22.080 --> 00:20:23.520
>> Okay.

00:20:23.520 --> 00:20:25.200
>> Okay. You need to share this skill with

00:20:25.200 --> 00:20:27.600
me but I'm pretty happy. I

00:20:27.600 --> 00:20:30.000
>> I asked a I asked Opus to highlight any

00:20:30.000 --> 00:20:32.320
sensitive info and it was like um

00:20:32.320 --> 00:20:34.320
enumeration of projects, enumeration of

00:20:34.320 --> 00:20:36.240
of statuses, enumeration like don't

00:20:36.240 --> 00:20:37.679
share this. I was like, "Okay, I won't

00:20:37.679 --> 00:20:39.760
share it."

00:20:39.760 --> 00:20:41.440
I was like, "Ai, can I open source

00:20:41.440 --> 00:20:43.360
this?" And and and it was like, "No." I

00:20:43.360 --> 00:20:45.120
was like, "Okay.

00:20:45.120 --> 00:20:47.280
>> I don't even ask myself anymore."

00:20:47.280 --> 00:20:49.919
>> Well, I I'm not too sure I've shared

00:20:49.919 --> 00:20:51.280
this with you before, but I'm looking

00:20:51.280 --> 00:20:53.360
forward to rewriting a lot of well, not

00:20:53.360 --> 00:20:56.799
rewriting, just dumping Confluence to to

00:20:56.799 --> 00:20:57.520
markdown.

00:20:57.520 --> 00:21:01.919
>> Nice. And then I suppose just to make it

00:21:01.919 --> 00:21:04.159
agent friendly

00:21:04.159 --> 00:21:07.280
uh to to make it like goal orientated so

00:21:07.280 --> 00:21:09.440
that uh

00:21:09.440 --> 00:21:12.240
>> yeah so that the agents will know what

00:21:12.240 --> 00:21:15.760
to do considering this this uh platform

00:21:15.760 --> 00:21:17.520
that I'm working on is compated.

00:21:17.520 --> 00:21:18.799
>> That's a big improvement.

00:21:18.799 --> 00:21:20.880
>> It's going to be a massive improvement I

00:21:20.880 --> 00:21:23.520
feel. um trying not to big it up too

00:21:23.520 --> 00:21:26.240
much, but it's just it's just so nice to

00:21:26.240 --> 00:21:28.400
work in a in a sensible way like with

00:21:28.400 --> 00:21:31.520
markdown and uh being able to easily

00:21:31.520 --> 00:21:33.200
edit things because just just the act of

00:21:33.200 --> 00:21:34.720
edit updating documentation and

00:21:34.720 --> 00:21:37.039
confluence is such a nightmare. I'm just

00:21:37.039 --> 00:21:41.919
sick of it for me. Um right now my focus

00:21:41.919 --> 00:21:44.960
is to maximize my output but also stay

00:21:44.960 --> 00:21:47.360
reasonable healthy. So, I'm more of like

00:21:47.360 --> 00:21:50.000
in the AI of Empire chart. I'm close to

00:21:50.000 --> 00:21:52.080
the first group of I'm not I'm not

00:21:52.080 --> 00:21:54.400
trying to burn out, but I'm trying to

00:21:54.400 --> 00:21:56.880
achieve slightly more than what I would

00:21:56.880 --> 00:21:59.840
be able to do if I was working full-time

00:21:59.840 --> 00:22:02.000
uh myself. So, I'm trying to use AI to

00:22:02.000 --> 00:22:04.880
to just hit more than what I my my

00:22:04.880 --> 00:22:06.720
regular output, but not insane. Not like

00:22:06.720 --> 00:22:09.840
10x um for for different

00:22:09.840 --> 00:22:12.159
>> Yeah, I guess. And then I try to I try

00:22:12.159 --> 00:22:14.559
to do this for the next few months

00:22:14.559 --> 00:22:17.039
before I don't know organizations

00:22:17.039 --> 00:22:18.799
>> every I'm feeling pretty ragged really

00:22:18.799 --> 00:22:21.039
in uh

00:22:21.039 --> 00:22:23.360
>> um though

00:22:23.360 --> 00:22:25.840
I I'm I am sort of trying to take a step

00:22:25.840 --> 00:22:27.760
back. I'm trying to be that uh force

00:22:27.760 --> 00:22:30.400
multiplier where I I on board my

00:22:30.400 --> 00:22:33.440
colleagues and and and with my learnings

00:22:33.440 --> 00:22:36.080
of AI, you know, just simple stuff like

00:22:36.080 --> 00:22:38.320
if we just put our documentation AI and

00:22:38.320 --> 00:22:40.799
then reference that a that documentation

00:22:40.799 --> 00:22:44.000
when we want something to be done, then

00:22:44.000 --> 00:22:45.760
we'll get there in a more reliable

00:22:45.760 --> 00:22:48.960
fashion. As for like building things,

00:22:48.960 --> 00:22:51.520
I'm definitely not on your uh wavelength

00:22:51.520 --> 00:22:54.080
at the moment just because

00:22:54.080 --> 00:22:54.400
well,

00:22:54.400 --> 00:22:56.159
>> I've taken a step back, I think, for the

00:22:56.159 --> 00:22:56.960
last uh

00:22:56.960 --> 00:22:58.400
>> Oh, that reminds me. I need to do that

00:22:58.400 --> 00:23:00.960
blog.

00:23:00.960 --> 00:23:02.640
>> I'll I'll do that. I'll do that blog

00:23:02.640 --> 00:23:03.280
this morning.

00:23:03.280 --> 00:23:06.159
>> SEO uh strategy.

00:23:06.159 --> 00:23:06.799
>> So funny.

00:23:06.799 --> 00:23:08.960
>> You should focus on CDKTF because I

00:23:08.960 --> 00:23:11.280
think it's there is a need for it.

00:23:11.280 --> 00:23:13.360
Actually, there is a need. Um

00:23:13.360 --> 00:23:17.360
>> yeah, I I just spent a weekend Oh yeah,

00:23:17.360 --> 00:23:17.840
doing well

00:23:17.840 --> 00:23:22.240
>> brainstorming on how to incorporate

00:23:22.240 --> 00:23:24.880
the L2 library. So I have Terra

00:23:24.880 --> 00:23:27.039
constructs right but I feel the name is

00:23:27.039 --> 00:23:29.600
too close to Terraform and and I feel

00:23:29.600 --> 00:23:33.120
the CDK terrain should have its own L2

00:23:33.120 --> 00:23:35.440
library. I I intend so terra constructs

00:23:35.440 --> 00:23:38.320
is more like a it's more like a proof of

00:23:38.320 --> 00:23:40.159
concept. It it shows that if you build

00:23:40.159 --> 00:23:41.919
those L2 constructs and you can port

00:23:41.919 --> 00:23:44.400
them from AW CDK it works really well.

00:23:44.400 --> 00:23:46.559
And now I want to port that effort and

00:23:46.559 --> 00:23:48.480
maybe start again but under a new name

00:23:48.480 --> 00:23:50.640
which is aligned with with with CDK

00:23:50.640 --> 00:23:52.559
terrain. So I was like brainstorming

00:23:52.559 --> 00:23:55.039
names like what is the L2 concept? Is it

00:23:55.039 --> 00:23:55.840
stratum?

00:23:55.840 --> 00:23:57.600
>> You must have had some level twos in

00:23:57.600 --> 00:23:59.200
there already somewhere. I just haven't

00:23:59.200 --> 00:23:59.760
looked

00:23:59.760 --> 00:24:01.280
>> in terrain.

00:24:01.280 --> 00:24:02.720
>> Yeah.

00:24:02.720 --> 00:24:05.440
>> Syndicate terrain

00:24:05.440 --> 00:24:07.360
doesn't really do level twos, right? It

00:24:07.360 --> 00:24:09.520
just does the init sorry it just does

00:24:09.520 --> 00:24:12.320
the initial L1 bindings and then Terra

00:24:12.320 --> 00:24:14.159
Construct is the full L2 library. And I

00:24:14.159 --> 00:24:15.919
always wanted to keep them separate

00:24:15.919 --> 00:24:17.840
>> cuz everyone has built their own.

00:24:17.840 --> 00:24:19.360
>> Yeah, when I think about it, you're

00:24:19.360 --> 00:24:20.400
right.

00:24:20.400 --> 00:24:22.080
>> There's a few like there's there's the

00:24:22.080 --> 00:24:24.799
concept of an archive. Um Oh, but you

00:24:24.799 --> 00:24:26.480
asked me a question. You asked me about

00:24:26.480 --> 00:24:27.919
like what is the difference between

00:24:27.919 --> 00:24:30.960
CDKTF CLI and why would you run the CLI

00:24:30.960 --> 00:24:33.679
versus running the same directly?

00:24:33.679 --> 00:24:35.360
>> And I was going on about it's the asset

00:24:35.360 --> 00:24:37.440
pipeline. It's the asset pipeline.

00:24:37.440 --> 00:24:39.200
>> Yeah. And you were going to you're going

00:24:39.200 --> 00:24:44.400
to show me how dumb I am about this.

00:24:44.400 --> 00:24:47.039
You caught me in a bad time.

00:24:47.039 --> 00:24:51.600
>> Well, okay. C can I just explain my my

00:24:51.600 --> 00:24:54.240
problem just so that you just let me

00:24:54.240 --> 00:24:56.400
just explain what I'm trying to do. We

00:24:56.400 --> 00:24:59.120
have a whole bunch of CDK and I want to

00:24:59.120 --> 00:25:01.279
refactor it so that

00:25:01.279 --> 00:25:03.360
>> is it CDK AWS CDK.

00:25:03.360 --> 00:25:06.320
>> Yeah, it's a CDK but I feel this is

00:25:06.320 --> 00:25:09.200
>> a CDK a problem that h would probably

00:25:09.200 --> 00:25:12.720
happen in CDKF whatever. So we we have

00:25:12.720 --> 00:25:14.799
we have many business divisions. They

00:25:14.799 --> 00:25:16.960
say there's 10 like it could be I don't

00:25:16.960 --> 00:25:18.880
know HR,

00:25:18.880 --> 00:25:23.120
commercial, whatever. Um, and each of

00:25:23.120 --> 00:25:26.799
them has their own dev staging prod

00:25:26.799 --> 00:25:28.320
and and with all these different

00:25:28.320 --> 00:25:31.120
domains, there's lots of shared uh CDK

00:25:31.120 --> 00:25:34.320
stacks and and and while we've been

00:25:34.320 --> 00:25:35.679
bootstrapping them, we've been just

00:25:35.679 --> 00:25:38.880
copying files across because SIM links

00:25:38.880 --> 00:25:42.640
are unfortunately a dark art. Um, and

00:25:42.640 --> 00:25:44.640
people don't want to use SIM links. So

00:25:44.640 --> 00:25:46.320
we've been copying files and then over

00:25:46.320 --> 00:25:48.799
time each file has been slightly changed

00:25:48.799 --> 00:25:50.799
or got some wide space or what have you.

00:25:50.799 --> 00:25:54.640
So we have like 10 sort of duplicated

00:25:54.640 --> 00:25:56.320
CDK

00:25:56.320 --> 00:25:59.520
uh apps I think is the correct term and

00:25:59.520 --> 00:26:03.600
we want to dduplicate it. So but already

00:26:03.600 --> 00:26:05.679
each each domain is quite complicated. I

00:26:05.679 --> 00:26:07.840
wanted to create like a like a shared

00:26:07.840 --> 00:26:10.400
library and then when I refactor some

00:26:10.400 --> 00:26:12.640
stuff into a shared library that when I

00:26:12.640 --> 00:26:16.640
do a CDK synth that I know it's the same

00:26:16.640 --> 00:26:18.799
in a sense because one thing that bit me

00:26:18.799 --> 00:26:21.440
with CDK refactoring is that I didn't

00:26:21.440 --> 00:26:23.760
realize that at least in Python that if

00:26:23.760 --> 00:26:26.320
you like put it in a different class

00:26:26.320 --> 00:26:28.480
then the name changes because

00:26:28.480 --> 00:26:28.880
>> Yeah.

00:26:28.880 --> 00:26:31.279
>> I mean that caught me out. So basically

00:26:31.279 --> 00:26:34.000
I'm having to rejig it again.

00:26:34.000 --> 00:26:36.000
>> Yeah. But what I I I don't want I mean I

00:26:36.000 --> 00:26:36.240
think

00:26:36.240 --> 00:26:37.679
>> I think that will be

00:26:37.679 --> 00:26:40.960
>> very difficult with with AWS CDK.

00:26:40.960 --> 00:26:43.440
>> What I'm trying to do is not have all

00:26:43.440 --> 00:26:45.760
these updates and deletes because I I

00:26:45.760 --> 00:26:48.080
just hate hate doing that. So

00:26:48.080 --> 00:26:49.679
>> So

00:26:49.679 --> 00:26:52.080
basically I'm doing a CDK sent and I'm

00:26:52.080 --> 00:26:53.679
like comparing it before and after to

00:26:53.679 --> 00:26:56.400
make sure that my refactor is is is a

00:26:56.400 --> 00:26:56.799
good idea.

00:26:56.799 --> 00:26:58.720
>> Exactly. So yeah I see refactoring which

00:26:58.720 --> 00:27:00.799
in terraform is a non-issue, right?

00:27:00.799 --> 00:27:02.320
because you change it and then you just

00:27:02.320 --> 00:27:04.400
put in a refactoring configuration and

00:27:04.400 --> 00:27:06.960
it takes care of the logical ID changes.

00:27:06.960 --> 00:27:08.559
What you just described is your logical

00:27:08.559 --> 00:27:10.320
ID of the resources change but

00:27:10.320 --> 00:27:12.000
physically the resources shouldn't

00:27:12.000 --> 00:27:13.840
change. They shouldn't be deleted and

00:27:13.840 --> 00:27:15.120
red recreated. Right?

00:27:15.120 --> 00:27:18.400
>> Yeah. Yeah. What in terform I've seen

00:27:18.400 --> 00:27:18.880
some people

00:27:18.880 --> 00:27:21.039
>> because Terraform state is accessible

00:27:21.039 --> 00:27:23.440
you can modify it. Cloud form is not.

00:27:23.440 --> 00:27:24.400
They added a lot of

00:27:24.400 --> 00:27:25.520
>> What do you mean like modify with an

00:27:25.520 --> 00:27:26.720
import or something like that? What do

00:27:26.720 --> 00:27:27.039
you

00:27:27.039 --> 00:27:28.720
>> Yeah, you can like basically for me,

00:27:28.720 --> 00:27:31.440
right, when I change my CDKTF

00:27:31.440 --> 00:27:33.360
drastically and I get the problem that

00:27:33.360 --> 00:27:35.279
you have, which is it's going to like

00:27:35.279 --> 00:27:37.360
change all the logical identities. Yeah.

00:27:37.360 --> 00:27:40.400
>> Um I I can I actually have a script that

00:27:40.400 --> 00:27:43.440
reads um I have two.

00:27:43.440 --> 00:27:45.200
>> I have one that reads the terapform plan

00:27:45.200 --> 00:27:46.799
diff and sees what it's going to create

00:27:46.799 --> 00:27:48.480
and what it's going to delete. It parses

00:27:48.480 --> 00:27:50.799
out the resource type and the logic ID

00:27:50.799 --> 00:27:52.480
and it tries to map them. If you have

00:27:52.480 --> 00:27:54.159
one resource type, exactly one create,

00:27:54.159 --> 00:27:56.080
one delete, it will map it one to one,

00:27:56.080 --> 00:27:57.600
right? So say that's one that's that's

00:27:57.600 --> 00:27:58.880
exactly the same one that you deleted

00:27:58.880 --> 00:28:00.640
and created and it's going to generate a

00:28:00.640 --> 00:28:02.640
move block for you. It's going to go if

00:28:02.640 --> 00:28:04.320
you have three deletes and three

00:28:04.320 --> 00:28:05.520
creates, it's going to sort them

00:28:05.520 --> 00:28:07.200
alphabetically and try to map them and

00:28:07.200 --> 00:28:08.960
say like those three they match. Most

00:28:08.960 --> 00:28:10.159
likely these are the way that they

00:28:10.159 --> 00:28:12.080
match. But maybe that's wrong. It's put

00:28:12.080 --> 00:28:14.000
a big fat comment in the top says review

00:28:14.000 --> 00:28:16.399
this because I could get this wrong. And

00:28:16.399 --> 00:28:18.320
then the the one if it's asynchronous

00:28:18.320 --> 00:28:19.919
like there's two deletes and there's uh

00:28:19.919 --> 00:28:21.760
one create then one of them is deleted

00:28:21.760 --> 00:28:23.279
one is kept. So which one do you want to

00:28:23.279 --> 00:28:25.120
create? You have to valid validate that.

00:28:25.120 --> 00:28:26.880
So that's what my Python script does

00:28:26.880 --> 00:28:28.880
that I created with Opus like three

00:28:28.880 --> 00:28:30.399
years ago. And you can do that very

00:28:30.399 --> 00:28:32.399
easily with Terraform. Um you can parse

00:28:32.399 --> 00:28:34.159
the plans you can generate those those

00:28:34.159 --> 00:28:36.399
refactor blocks. If you do that with AWS

00:28:36.399 --> 00:28:39.360
CDK it was three years ago very very

00:28:39.360 --> 00:28:41.279
hard. I literally people usually just

00:28:41.279 --> 00:28:43.200
delete the stacks and recreate them

00:28:43.200 --> 00:28:46.080
because modifying a ter cloud for stack

00:28:46.080 --> 00:28:50.399
is extremely hard but they did create a

00:28:50.399 --> 00:28:52.399
whole bunch of refactoring tools around

00:28:52.399 --> 00:28:55.200
cloud for that I never used in the last

00:28:55.200 --> 00:28:56.080
oh this is interesting

00:28:56.080 --> 00:28:57.919
>> I have no idea but yes there there's a

00:28:57.919 --> 00:29:00.159
bunch of announcements around that um so

00:29:00.159 --> 00:29:02.000
so this is where I would be looking if I

00:29:02.000 --> 00:29:04.159
was you um if you need to do these

00:29:04.159 --> 00:29:06.080
massive code refactoring and you can

00:29:06.080 --> 00:29:08.559
also Google for people facing issues

00:29:08.559 --> 00:29:10.960
with AWS cloud automation around uh and

00:29:10.960 --> 00:29:14.080
CDK specifically about logical ids

00:29:14.080 --> 00:29:16.159
because the moment you change things the

00:29:16.159 --> 00:29:18.480
logic ID changes and then cloudformation

00:29:18.480 --> 00:29:20.159
loses track of it and it says that

00:29:20.159 --> 00:29:21.840
doesn't exist anymore.

00:29:21.840 --> 00:29:23.679
>> I feel like an idiot. I I mean I've had

00:29:23.679 --> 00:29:24.960
this problem for a while and I didn't

00:29:24.960 --> 00:29:29.440
actually care to to do a basic AWS CDK

00:29:29.440 --> 00:29:30.080
>> refactor

00:29:30.080 --> 00:29:31.360
>> refactor search.

00:29:31.360 --> 00:29:32.720
>> I said three years but it's from

00:29:32.720 --> 00:29:34.720
September so it's not it's not just 10

00:29:34.720 --> 00:29:36.799
months.

00:29:36.799 --> 00:29:38.720
So this is the thing about cloud for

00:29:38.720 --> 00:29:41.200
>> three years and AI.

00:29:41.200 --> 00:29:43.440
>> Yeah. This is the problem with with with

00:29:43.440 --> 00:29:44.799
cloud form playing catch up with

00:29:44.799 --> 00:29:46.480
Terraform, right? I mean that's why I

00:29:46.480 --> 00:29:48.960
convince people that I think CDKTF is

00:29:48.960 --> 00:29:51.200
better than AWS CDK because these things

00:29:51.200 --> 00:29:54.080
only come into AWS like in cloud form

00:29:54.080 --> 00:29:55.919
now where Terraform started out with

00:29:55.919 --> 00:29:57.760
these things. Well, not really. The

00:29:57.760 --> 00:29:59.679
refactoring has only been there maybe

00:29:59.679 --> 00:30:00.399
for four years.

00:30:00.399 --> 00:30:02.720
>> Holy moly. Why didn't Why didn't I

00:30:02.720 --> 00:30:06.399
bloody Google? Yeah, but but come back

00:30:06.399 --> 00:30:08.240
to the reason why I was being so

00:30:08.240 --> 00:30:11.760
annoying to you about the pipeline.

00:30:11.760 --> 00:30:13.200
Um I can show you.

00:30:13.200 --> 00:30:15.440
>> I don't get it. Just don't get it.

00:30:15.440 --> 00:30:17.440
>> Yeah, I I'll show you what I think.

00:30:17.440 --> 00:30:18.799
Maybe we'll explain it, but then I have

00:30:18.799 --> 00:30:20.799
to go because I have another call. Um so

00:30:20.799 --> 00:30:23.840
I'll just share this real quick. So um

00:30:23.840 --> 00:30:25.279
can you see this like

00:30:25.279 --> 00:30:27.840
>> Oh yeah. So what I'm doing here is a

00:30:27.840 --> 00:30:30.799
comparison between CDKTF and AWS CDK

00:30:30.799 --> 00:30:31.840
because a lot of people don't really

00:30:31.840 --> 00:30:33.120
understand what's the difference between

00:30:33.120 --> 00:30:36.720
them. Right? So AWS CDK and CDKTF they

00:30:36.720 --> 00:30:39.039
both are a comment line interface and

00:30:39.039 --> 00:30:42.000
one orchestrates terraform execution a

00:30:42.000 --> 00:30:43.279
little bit and the other one

00:30:43.279 --> 00:30:45.840
orchestrates cloud form right you will

00:30:45.840 --> 00:30:50.000
agree to that right

00:30:50.000 --> 00:30:52.320
>> both of them have L1 constructs so when

00:30:52.320 --> 00:30:54.799
you use AWS CDK inside there's a whole

00:30:54.799 --> 00:30:56.720
library of the L1 resources that are

00:30:56.720 --> 00:30:59.200
directly the cloud for resources for

00:30:59.200 --> 00:31:01.520
CDKTF you have the same thing you can

00:31:01.520 --> 00:31:04.399
build the um L1 construct which are

00:31:04.399 --> 00:31:06.640
basically one to one. So if you have

00:31:06.640 --> 00:31:08.480
Terraform provider AWS, it has a

00:31:08.480 --> 00:31:10.640
resource called AWS instance. There will

00:31:10.640 --> 00:31:13.039
be an L1 construct called AWS inst or

00:31:13.039 --> 00:31:15.200
just instance and you can use that to

00:31:15.200 --> 00:31:18.240
create an AWS instance um configuration

00:31:18.240 --> 00:31:20.399
block in terapform right the same thing

00:31:20.399 --> 00:31:23.360
CFN resources they also have an L1. So

00:31:23.360 --> 00:31:25.760
that's actually nothing special. Now the

00:31:25.760 --> 00:31:28.559
big difference is that AWS CDK has an

00:31:28.559 --> 00:31:30.799
advanced asset pipeline which includes

00:31:30.799 --> 00:31:34.240
bundling. what the asset pipeline which

00:31:34.240 --> 00:31:36.399
which sometimes I feel shouldn't be

00:31:36.399 --> 00:31:38.720
there because it creates really annoying

00:31:38.720 --> 00:31:40.320
divs but carry on

00:31:40.320 --> 00:31:42.399
>> the asset pipeline does things like if

00:31:42.399 --> 00:31:45.200
you have a lambda function and it needs

00:31:45.200 --> 00:31:46.000
u python

00:31:46.000 --> 00:31:47.360
>> it builds a layer and everything yeah

00:31:47.360 --> 00:31:47.919
it's nice

00:31:47.919 --> 00:31:50.240
>> it can do the layering it can package up

00:31:50.240 --> 00:31:52.960
like if you have JavaScript or NodeJS

00:31:52.960 --> 00:31:55.360
package JSON with dependencies it can

00:31:55.360 --> 00:31:56.960
identify automatically that you're

00:31:56.960 --> 00:31:59.440
deploying into a lambda layer or into a

00:31:59.440 --> 00:32:01.760
lambda function runtime that supports

00:32:01.760 --> 00:32:05.039
AWS SDK version 3 and it will make those

00:32:05.039 --> 00:32:06.799
external. So when you bundle things up,

00:32:06.799 --> 00:32:08.640
it's going to automatically make sure

00:32:08.640 --> 00:32:10.960
that it doesn't bundle in the AWS SDK

00:32:10.960 --> 00:32:12.480
for you. It does a lot of amazing

00:32:12.480 --> 00:32:14.080
things. You get none of that in

00:32:14.080 --> 00:32:15.679
Terraform world, right? Unless you build

00:32:15.679 --> 00:32:16.159
it.

00:32:16.159 --> 00:32:18.960
>> It could be more amazing. I feel like we

00:32:18.960 --> 00:32:21.840
at work it we have a few stacks that

00:32:21.840 --> 00:32:23.840
build a lot of lambda layers and and I

00:32:23.840 --> 00:32:25.600
like I I don't maybe there's a trick,

00:32:25.600 --> 00:32:27.279
but I would like to say like these

00:32:27.279 --> 00:32:29.120
lambda layers are all effectively the

00:32:29.120 --> 00:32:30.720
same. Can you just make them share

00:32:30.720 --> 00:32:31.200
ahead?

00:32:31.200 --> 00:32:33.039
>> Yeah. And if you look at to rebuild

00:32:33.039 --> 00:32:34.320
everyone.

00:32:34.320 --> 00:32:36.399
>> So, so there's an amazing open source

00:32:36.399 --> 00:32:38.640
project from the AWS CDK team, uh, an

00:32:38.640 --> 00:32:41.120
internal team at AWS that built the

00:32:41.120 --> 00:32:42.799
construct hub. So, if you go to

00:32:42.799 --> 00:32:45.279
constructs.dev or construct.dev, you can

00:32:45.279 --> 00:32:47.440
see every single package on npmgs that

00:32:47.440 --> 00:32:48.880
have constructs. If they are tacked and

00:32:48.880 --> 00:32:50.320
licensed properly, they get

00:32:50.320 --> 00:32:51.840
automatically indexed and they have a

00:32:51.840 --> 00:32:53.679
nice documentation page made available.

00:32:53.679 --> 00:32:56.000
So, this this hub thing, right, it runs

00:32:56.000 --> 00:32:58.559
an a data ETL pipeline. And I think I

00:32:58.559 --> 00:33:00.799
really have to go uh but that thing runs

00:33:00.799 --> 00:33:03.600
a pipeline and it runs off bunch of step

00:33:03.600 --> 00:33:05.760
functions and lambdas. And inside that

00:33:05.760 --> 00:33:08.320
repo the if you go to the source code

00:33:08.320 --> 00:33:09.600
you can actually see that they use

00:33:09.600 --> 00:33:11.840
progen to generate a special lambda

00:33:11.840 --> 00:33:14.000
function generator that then bundles the

00:33:14.000 --> 00:33:16.240
code appropriately. So exactly what you

00:33:16.240 --> 00:33:18.799
just said they build it in there.

00:33:18.799 --> 00:33:21.120
>> Yeah. Progen is is a tool that that that

00:33:21.120 --> 00:33:23.519
manages a it's like CDK for file

00:33:23.519 --> 00:33:25.840
systems. So you can define a file

00:33:25.840 --> 00:33:27.840
construct and you can define um

00:33:27.840 --> 00:33:29.039
>> okay I'll have to have a look at well

00:33:29.039 --> 00:33:31.039
thank well okay you have to go you have

00:33:31.039 --> 00:33:33.440
to go so

00:33:33.440 --> 00:33:35.679
>> so that that's the main difference AWS

00:33:35.679 --> 00:33:39.519
CDK does CDK does so much more and CDKTF

00:33:39.519 --> 00:33:41.840
does only the very basic it the asset

00:33:41.840 --> 00:33:43.760
pipeline is actually it has the concept

00:33:43.760 --> 00:33:46.399
of an archive but that's not bound to

00:33:46.399 --> 00:33:48.559
like any provider because Terapform is

00:33:48.559 --> 00:33:50.799
decoupled from AWS right so if you do

00:33:50.799 --> 00:33:53.279
AWS CDK if you say an asset it will use

00:33:53.279 --> 00:33:55.600
ECR S3 for you behind the behind the

00:33:55.600 --> 00:33:55.840
scenes.

00:33:55.840 --> 00:33:57.120
>> Yeah, I mean that could be that could be

00:33:57.120 --> 00:33:59.200
a benefit because I do I do prefer basic

00:33:59.200 --> 00:34:01.600
in a way. I do prefer zip files than

00:34:01.600 --> 00:34:02.640
docker images.

00:34:02.640 --> 00:34:04.880
>> You do until you don't you do until it's

00:34:04.880 --> 00:34:06.240
done for you and then you say, "Oh my

00:34:06.240 --> 00:34:07.519
god, I wish I had this sooner."

00:34:07.519 --> 00:34:08.079
>> Yeah.

00:34:08.079 --> 00:34:09.679
>> The trouble with zip files is that is

00:34:09.679 --> 00:34:11.679
that Snick doesn't seem to like them or

00:34:11.679 --> 00:34:13.839
whatever security bloody thing people

00:34:13.839 --> 00:34:14.159
use.

00:34:14.159 --> 00:34:16.560
>> Oh, then you just base 64, save them,

00:34:16.560 --> 00:34:19.200
zip them again, 64 them, zip them again.

00:34:19.200 --> 00:34:21.919
Then no security scanner will detect it.

00:34:21.919 --> 00:34:24.480
Okay. All right. I I have to drop.

00:34:24.480 --> 00:34:26.800
>> Okay. Thanks, Vincent. See you, man.

00:34:26.800 --> 00:34:29.520
>> See you. Bye.

00:34:29.520 --> 00:34:34.639
>> Uh well, it's just me and

00:34:34.639 --> 00:34:37.040
I will publish as as a podcast. And if

00:34:37.040 --> 00:34:38.480
you're listening to this podcast, thank

00:34:38.480 --> 00:34:44.159
you and comment and like.

00:34:44.159 --> 00:34:46.720
I wanted to remind you that if you got

00:34:46.720 --> 00:34:48.960
this far, well, well done. though we

00:34:48.960 --> 00:34:50.960
also do have summaries on debates.com

00:34:50.960 --> 00:34:53.040
podcast

00:34:53.040 --> 00:34:55.599
and uh yeah please comment please get in

00:34:55.599 --> 00:34:57.520
touch if you like the podcast so we I

00:34:57.520 --> 00:35:00.079
can keep on uh being motivated to get up

00:35:00.079 --> 00:35:04.320
really early and and do it though at the

00:35:04.320 --> 00:35:07.520
same time it's just great to chat with

00:35:07.520 --> 00:35:10.240
Vincent and have an excuse to do that

00:35:10.240 --> 00:35:12.000
because I'm always learning. I hope you

00:35:12.000 --> 00:35:13.680
agree

00:35:13.680 --> 00:35:15.599
um well that I'm learning and I hope

00:35:15.599 --> 00:35:18.640
that you picked up something yourself.

00:35:18.640 --> 00:35:21.040
Cool beans, have a great day. Have a

00:35:21.040 --> 00:35:23.280
great week.

00:35:23.280 --> 00:35:26.560
Get in touch.

