Dev trusts coding agents with production secrets, given isolation and least privilege
rseroter · x · 2026-09-10
AI infra engineer Jake Gold explains why he now hands his coding agents production secrets—Tailscale keys, SSH private keys, Anthropic/Codex OAuth tokens—stored in a vault so agents use them without seeing values. His setup hits Simon Willison's 'lethal trifecta', but he argues security is a productivity-risk tradeoff: with production access, agents can investigate outages, deploy fixes, and verify them autonomously. He compares it to onboarding new teammates and says frontier models' improved injection resistance makes this viable—something he wouldn't do with older models. Preconditions: isolate agents and apply least privilege.
More from coding & agent
- Long Lake Has Acquired 40+ Services Businesses to Deploy Agents in Real Workflows — varunshenoy_ · 2026-09-10
- Anthropic: sandbox accidentally connected to internet, Claude agents attacked real systems — offgramercy · 2026-09-10
- Freebots adds real-money wallets, then prices out bots building oversized towers — Daniel_Farinax · 2026-09-10
- Karpathy says coding agents finally work as of December; OpenAI's Kuprel says humans need not code — Kuprel · 2026-09-10
- App Store Connect CLI Skills lets AI agents manage your App Store workflows — rudrank · 2026-09-10
- Sonnet scores 97% at $12.71/run vs Astra 93% at $67.33/run in JDK migration agent test — WirelessLife · 2026-09-10