1
00:00:04,423 --> 00:00:07,873
Welcome to DevOps and Docker Talk,
and I am your host, Bret Fisher.

2
00:00:08,443 --> 00:00:13,513
In this episode, I've got Michael
Irwin from Docker back on the podcast

3
00:00:13,513 --> 00:00:18,073
to talk about everything that Docker
has been releasing and updating

4
00:00:18,343 --> 00:00:20,173
for about the last eight months.

5
00:00:20,728 --> 00:00:23,608
Now this show is called
DevOps and Docker Talk.

6
00:00:24,118 --> 00:00:27,538
We should be talking more about
Docker, but I unfortunately, probably

7
00:00:27,538 --> 00:00:31,738
like a lot of us have been heads
down learning AI tooling for the

8
00:00:31,738 --> 00:00:33,658
last four or five, six months.

9
00:00:33,928 --> 00:00:37,258
As the models have gotten better, the
harnesses have gotten better, we've

10
00:00:37,258 --> 00:00:43,119
gotten fancier with our agents and
Subagents, and TUI and GUIs and WUIs.

11
00:00:43,189 --> 00:00:44,579
That's my new name for Web UI.

12
00:00:45,149 --> 00:00:45,459
TUI, GUI, WUI.

13
00:00:46,586 --> 00:00:49,106
I've been playing with OpenCode
and I've been very busy on that all

14
00:00:49,106 --> 00:00:52,646
year, and everyone else is focused on
Claude Code, which is also awesome.

15
00:00:53,246 --> 00:00:56,006
But I haven't been talking a lot about
Docker, and I haven't quite frankly

16
00:00:56,006 --> 00:00:57,296
been playing a lot with Docker.

17
00:00:57,776 --> 00:01:00,416
And that is not because
Docker isn't shipping.

18
00:01:00,716 --> 00:01:05,161
Docker has been on a steady release
cycle of shipping not just updates

19
00:01:05,161 --> 00:01:09,181
to their existing tools and adding AI
functionality and improvements for those

20
00:01:09,181 --> 00:01:13,912
tools, working with AI, but also entirely
new product lines and product tools.

21
00:01:14,032 --> 00:01:17,572
Just products like lots of
products, and we go through that.

22
00:01:17,602 --> 00:01:22,222
That's why this episode's going to be
a little long one, but hopefully this

23
00:01:22,222 --> 00:01:27,562
will catch you up on everything you've
missed since almost this time last year.

24
00:01:27,742 --> 00:01:31,852
About this time last year, I had a
couple of podcast episodes around

25
00:01:31,852 --> 00:01:36,837
Docker's  Docker Model Runner,
DMR, and some other updates.

26
00:01:36,837 --> 00:01:39,177
They were releasing
Gordon AI and some stuff.

27
00:01:39,177 --> 00:01:42,657
But since then, a lot of those tools
have received improvements and they've

28
00:01:42,657 --> 00:01:44,307
got all sorts of new things out.

29
00:01:44,577 --> 00:01:49,522
So on this episode, we cover the updates
to Gordon, which is the AI built in

30
00:01:49,522 --> 00:01:53,882
the Docker Desktop, and it's gotten
quite better, and I think it's probably

31
00:01:53,882 --> 00:01:57,272
the thing I should be using anytime
I'm playing around with containers

32
00:01:57,272 --> 00:02:01,532
and I need to either troubleshoot them
or I need to improve the Dockerfile.

33
00:02:01,802 --> 00:02:06,512
I think this AI, because it's backed by
so much of the current and up-to-date

34
00:02:06,512 --> 00:02:10,022
data and it can see into your running
containers and see what's going on while

35
00:02:10,022 --> 00:02:14,957
you're in the middle of Docker Desktop, I
think that's the best way to go for asking

36
00:02:15,257 --> 00:02:16,637
what's going on in my container right now.

37
00:02:16,637 --> 00:02:20,927
Like, that's better than maybe using
Claude locally, which can't maybe see

38
00:02:20,927 --> 00:02:22,847
as much as what Docker Desktop can see.

39
00:02:23,237 --> 00:02:24,107
So that's pretty cool.

40
00:02:24,107 --> 00:02:28,257
Docker hardened images came out almost
a year ago, which is one of the new

41
00:02:28,257 --> 00:02:32,127
product category in the last five years
of not just minimal images, but actually

42
00:02:32,127 --> 00:02:37,122
hardened images that are going after
locking down things, making new OSes or

43
00:02:37,272 --> 00:02:41,562
slimming, even existing OSes down into
something that's not just minimal, but

44
00:02:41,562 --> 00:02:46,122
also designed with CVE count in mind.

45
00:02:46,242 --> 00:02:51,522
And I have been shouting for the rooftops
for probably a decade now about CVEs and

46
00:02:51,522 --> 00:02:55,782
images and the techniques and the tactics
for how we shrink those things down.

47
00:02:56,022 --> 00:02:59,532
And I feel now that we have
a hardened image ecosystem

48
00:02:59,892 --> 00:03:01,262
basically started by Chainguard.

49
00:03:01,872 --> 00:03:05,532
Lots of players in there now,
and Docker and Chainguard are the

50
00:03:05,532 --> 00:03:06,672
two that I'm paying attention to.

51
00:03:07,212 --> 00:03:11,232
So Docker has announced now that a
significant portion of that catalog

52
00:03:11,232 --> 00:03:14,832
is free, and we talk through the
details of what's free, what's not

53
00:03:14,832 --> 00:03:18,162
free, how to customize these things,
what you get on the paid plan.

54
00:03:18,492 --> 00:03:22,752
And I think every team should be
considering hardened images in some

55
00:03:22,752 --> 00:03:25,422
fashion for their workloads in production.

56
00:03:26,052 --> 00:03:26,592
Next.

57
00:03:27,154 --> 00:03:28,174
Docker sandboxes.

58
00:03:28,774 --> 00:03:33,964
Arguably a new category for Docker
because It's not just images in

59
00:03:33,964 --> 00:03:36,484
sandboxes that help you run AI securely.

60
00:03:36,724 --> 00:03:43,266
it's now VMs  per project with a
container in them running your agents

61
00:03:43,266 --> 00:03:45,396
and your harnesses for more security.

62
00:03:45,396 --> 00:03:50,856
So Docker is taking it to the next level
by creating VMs or micro VMs locally

63
00:03:50,856 --> 00:03:55,461
for your sandboxes, and they provide
a command line tool that essentially

64
00:03:55,461 --> 00:04:01,011
allows you to spin up a VM with a
container in it in the current directory

65
00:04:01,011 --> 00:04:06,007
you're in to run your Claude Code, to
run your OpenCode and your other  agent

66
00:04:06,007 --> 00:04:11,932
harnesses, and they bundle those all
into customizable VMs with containers.

67
00:04:12,382 --> 00:04:15,732
And you can run those locally, you
can, I think eventually they're

68
00:04:15,732 --> 00:04:17,912
going to probably figure out a
way to run that remotely maybe.

69
00:04:17,912 --> 00:04:21,902
But today it's really just about local
and it's called Docker Sandboxes.

70
00:04:22,202 --> 00:04:25,532
So I am definitely interested in
that because as, especially as a

71
00:04:25,532 --> 00:04:30,182
DevOps and operations person, I tend
to have a lot of credentials on my

72
00:04:30,182 --> 00:04:34,547
machine as much as I try to work least
privilege, I've got a lot of keys.

73
00:04:34,697 --> 00:04:37,997
I've got a lot of CLI tools that
are logged into systems that

74
00:04:37,997 --> 00:04:39,197
I don't want my agent to have.

75
00:04:39,467 --> 00:04:43,037
And when I'm working in Claude Code,
as good as the latest state-of-the-art

76
00:04:43,037 --> 00:04:47,057
models are, they don't hallucinate
that much lately, and they pretty

77
00:04:47,057 --> 00:04:48,587
much stay on task all the time.

78
00:04:48,857 --> 00:04:51,887
But it still means if I'm running
them locally that they have access

79
00:04:51,887 --> 00:04:55,467
to command line tools that I don't
want them to just run accidentally

80
00:04:56,832 --> 00:04:59,442
With a prompt injection or something
else that might happen, right?

81
00:04:59,712 --> 00:05:02,652
So I really want to figure out
a way to get these things locked

82
00:05:02,652 --> 00:05:06,252
down, to run them isolation, to give
them temporary keys or their own

83
00:05:06,252 --> 00:05:08,142
keys or their own pats or whatever.

84
00:05:08,592 --> 00:05:11,772
And I think sandboxing is going
to be in a lot of our futures.

85
00:05:12,712 --> 00:05:18,262
Once we get past this crazy town time
of just rapidly iterating on agents and

86
00:05:18,262 --> 00:05:21,952
what harnesses look like with a bunch
of agents running inside them and agent

87
00:05:21,952 --> 00:05:25,012
orchestration, I think we're going
to start caring about security again.

88
00:05:25,402 --> 00:05:27,922
And we all are going to need
some sandbox tooling to do that.

89
00:05:27,952 --> 00:05:28,642
And why?

90
00:05:28,882 --> 00:05:32,152
Why adopt a whole new tool when
you can always use the tools

91
00:05:32,152 --> 00:05:33,922
that you love like Docker?

92
00:05:34,102 --> 00:05:34,972
So that makes sense.

93
00:05:35,272 --> 00:05:39,132
They've also announced that they can
now support NanoClaw, which is not

94
00:05:39,132 --> 00:05:42,132
really an offshoot of OpenClaw as I
understand it, but a basically a whole

95
00:05:42,132 --> 00:05:47,392
new project that's trying to build a
safer, more secure version of OpenClaw.

96
00:05:48,102 --> 00:05:51,182
Maybe I would almost call it maybe
the business version of OpenClaw.

97
00:05:51,552 --> 00:05:52,642
It's called NanoClaw.

98
00:05:52,962 --> 00:05:55,902
I haven't used it yet, but
you can now run it in a safe

99
00:05:55,902 --> 00:05:57,282
sandbox with Docker sandboxing.

100
00:05:58,152 --> 00:06:00,432
Next up, let's do some
Model Runner updates.

101
00:06:00,432 --> 00:06:01,872
We are going to talk through.

102
00:06:02,232 --> 00:06:04,932
Some of the updates to the Docker
Model Runner, and that's about

103
00:06:04,932 --> 00:06:08,752
running LLM models locally on
your machine, kinda like Ollama.

104
00:06:09,672 --> 00:06:12,852
And they've had multiple
iterations and improvements

105
00:06:12,852 --> 00:06:14,022
over the last couple of years.

106
00:06:14,232 --> 00:06:15,702
I've also made videos about them.

107
00:06:15,702 --> 00:06:17,952
I've also had podcasts
about Docker Model Runner.

108
00:06:18,342 --> 00:06:22,692
But they now have some additions, like
finally on Mac, we get MLX support,

109
00:06:22,692 --> 00:06:28,332
which is a native Apple, Silicon focused
model runner that will allow us through

110
00:06:28,332 --> 00:06:33,522
something called VLLM to probably
get around 20%, maybe 30% performance

111
00:06:33,522 --> 00:06:35,622
improvement on our token output.

112
00:06:35,982 --> 00:06:37,722
And that's on the same hardware.

113
00:06:37,752 --> 00:06:38,502
So that's great.

114
00:06:38,532 --> 00:06:40,482
If you haven't tried DMR, give it a shot.

115
00:06:40,482 --> 00:06:43,392
If you've tried it before,
tried again, it might be better.

116
00:06:44,230 --> 00:06:48,460
They've also improved DMR to
support Open Web UI outta the box.

117
00:06:48,710 --> 00:06:53,090
About a year ago I made a video and
provided some examples on GitHub

118
00:06:53,465 --> 00:06:57,815
for how you could use Docker Model
Runner locally with Open Web UI,

119
00:06:58,115 --> 00:07:00,755
which is essentially a ChatGPT clone.

120
00:07:00,985 --> 00:07:02,465
It looks and acts like ChatGPT.

121
00:07:02,485 --> 00:07:05,035
It's pretty great and that
you could run that locally.

122
00:07:05,035 --> 00:07:07,345
And then using something like
Tailscale, you could essentially

123
00:07:07,345 --> 00:07:11,005
have your own private AI chat bot
that you could access from anywhere.

124
00:07:11,055 --> 00:07:16,665
And so that, plus a couple other
things, including the MCP Toolkit,

125
00:07:16,695 --> 00:07:19,815
which is something you would probably
run with Docker Model runner.

126
00:07:19,815 --> 00:07:24,015
But you can also run MCP tools
in Docker now, and it's, they've

127
00:07:24,015 --> 00:07:25,305
had this toolkit for years.

128
00:07:25,575 --> 00:07:26,205
It's pretty great.

129
00:07:27,341 --> 00:07:31,361
And it's to me, really the way
that I want to run MCP tools.

130
00:07:31,731 --> 00:07:34,491
I just don't run a lot of 'em right
now 'cause we're all kind of figuring

131
00:07:34,491 --> 00:07:38,691
out how the agents can just run
CLI tooling more efficiently than

132
00:07:38,691 --> 00:07:40,161
they can actually run MCP tools.

133
00:07:40,701 --> 00:07:45,201
But think that's a revolving door, and
I think MCP tools still have a place

134
00:07:45,201 --> 00:07:49,341
in our toolbox, and Docker is adding
more functionality to it, including not

135
00:07:49,341 --> 00:07:52,611
just catalog improvements to everything
that they have there, which there's

136
00:07:52,611 --> 00:07:54,651
tons of stuff in their MCP toolkit.

137
00:07:55,221 --> 00:07:58,521
But they're also adding something called
dynamic discovery, which will allow

138
00:07:58,521 --> 00:08:02,541
your local chatbots if they're going
through Docker to get their MCP tools.

139
00:08:02,931 --> 00:08:06,681
It gives you basically this short
list of MCP tools for finding

140
00:08:06,681 --> 00:08:09,261
other MCP tools in their toolbox.

141
00:08:09,591 --> 00:08:12,441
So you don't have to front
load a bunch of tools.

142
00:08:12,711 --> 00:08:17,001
You can now load them in dynamic and
discover the tool you need through

143
00:08:17,001 --> 00:08:19,191
your AI agent and your harness.

144
00:08:19,461 --> 00:08:23,781
And then you load those up into your
project dynamically during your work,

145
00:08:23,931 --> 00:08:27,801
which is really where we're needing to
be anyway, because we're finding that

146
00:08:28,041 --> 00:08:32,631
too many MCP tools are bad for your
context window and bad for hallucinations.

147
00:08:32,901 --> 00:08:34,461
So you want to keep that very small.

148
00:08:34,761 --> 00:08:38,151
And so you want to be able to dynamically
load and unload MCP tools as you go.

149
00:08:38,421 --> 00:08:39,021
So that's cool.

150
00:08:39,631 --> 00:08:43,111
Lastly, we talked about
cagent, which is not new.

151
00:08:43,111 --> 00:08:45,181
That came out sometime last year.

152
00:08:45,181 --> 00:08:46,411
It's an open source project.

153
00:08:47,506 --> 00:08:52,936
Presumably stands for Container Agent, but
it's Docker agent for automating things,

154
00:08:52,936 --> 00:08:55,396
and they now have a GitHub action for it.

155
00:08:55,396 --> 00:08:57,466
And then we talked through
some examples of PR review.

156
00:08:58,936 --> 00:09:04,096
As well as like a nightly docs check
that has their cagent, their Docker

157
00:09:04,096 --> 00:09:08,566
agent, which runs in Docker, running
inside of GitHub action to go and

158
00:09:08,566 --> 00:09:12,256
check the documentation sites for
Docker docs and to make sure that

159
00:09:12,256 --> 00:09:16,216
if anything's outdated, that new
PRs show up to suggest improvements

160
00:09:16,216 --> 00:09:18,046
or to suggest fixes for things.

161
00:09:18,136 --> 00:09:20,711
And it does this every day on
a cron job in GitHub Actions.

162
00:09:21,541 --> 00:09:23,551
So I thought that was a pretty
cool demo that we walked through.

163
00:09:23,941 --> 00:09:25,531
I think they're changing the
name of that, by the way.

164
00:09:25,531 --> 00:09:28,471
I think they're changing it to Docker
Agent, so we're just going to have

165
00:09:28,471 --> 00:09:32,401
to start calling it the Docker Agent,
which is not confusing at all because

166
00:09:32,401 --> 00:09:34,351
we've used the word agent in everything.

167
00:09:34,351 --> 00:09:36,091
So it's completely
overloaded at this point.

168
00:09:36,541 --> 00:09:38,761
But I'm going to definitely be
checking that out because, hey,

169
00:09:38,881 --> 00:09:40,351
I'm making GitHub Actions courses.

170
00:09:40,878 --> 00:09:45,618
So this is a jam packed episode
with Michael Irwin of Docker, and

171
00:09:45,618 --> 00:09:48,138
I'm so glad he is back and I'm
going to learn stuff with him too.

172
00:09:48,138 --> 00:09:49,308
So let's get into it.

173
00:09:51,356 --> 00:09:52,226
Michael Irwin.

174
00:09:52,601 --> 00:09:53,981
Tell the people who you
are and what you do.

175
00:09:54,481 --> 00:09:55,291
hello, everyone.

176
00:09:55,451 --> 00:09:56,691
I'm glad to be back here.

177
00:09:57,031 --> 00:09:58,361
So my name is Michael Irwin.

178
00:09:58,381 --> 00:10:02,791
I'm a longtime friend of Bret's and
actually a high fiver as well, too.

179
00:10:02,791 --> 00:10:05,521
So join the High Fiver's Club
if you're not as well, too.

180
00:10:06,021 --> 00:10:06,491
Hurrah!

181
00:10:07,561 --> 00:10:09,421
And yeah, I work at Docker.

182
00:10:09,691 --> 00:10:13,171
But even before working at
Docker, I was a captain, right?

183
00:10:13,631 --> 00:10:17,231
There with Bret and, we're both
in Virginia and, we traveled the

184
00:10:17,231 --> 00:10:20,351
world speaking at conferences
and having all kinds of fun.

185
00:10:20,851 --> 00:10:21,601
I'm excited to get in.

186
00:10:21,641 --> 00:10:24,411
we're going to have to jump in quickly
because I feel like this is actually

187
00:10:24,411 --> 00:10:27,071
like three hours of content that we're
going to try to cram into an hour.

188
00:10:27,567 --> 00:10:28,817
Michael's going to do all the work here.

189
00:10:29,317 --> 00:10:33,347
So, first on this list since we've really
had, like, if you didn't know the history,

190
00:10:33,347 --> 00:10:37,047
by the way, Michael and I, we've started
to do this yearly, everything in Docker.

191
00:10:37,048 --> 00:10:40,690
Because could be like a dedicated
Docker podcast with as much stuff as

192
00:10:40,690 --> 00:10:42,220
you guys have produced in the last year.

193
00:10:42,340 --> 00:10:43,650
We could just do nothing but Docker.

194
00:10:44,150 --> 00:10:47,060
And obviously we do more
than that on my channel.

195
00:10:47,070 --> 00:10:49,230
So the challenge is, how do we catch up?

196
00:10:49,230 --> 00:10:53,515
How do we get people To realize
all the releases, all the

197
00:10:53,525 --> 00:10:54,625
updates, all the features.

198
00:10:54,645 --> 00:10:57,935
we're only going to cover
the major bits, I feel like.

199
00:10:58,325 --> 00:11:01,315
kind of like that old commercial, if
you're old enough in the nineties, there

200
00:11:01,315 --> 00:11:04,495
was this guy that would talk really fast
on TV commercials about he sounded like

201
00:11:04,495 --> 00:11:07,575
a car salesman and he was selling little
toys and he was, oh, micromachines.

202
00:11:07,585 --> 00:11:08,325
That's what they were called.

203
00:11:08,325 --> 00:11:09,045
Micromachines.

204
00:11:09,595 --> 00:11:12,515
And I feel like we're going to have
to talk that fast, but people can

205
00:11:12,515 --> 00:11:14,605
always slow it down in their podcast

206
00:11:14,655 --> 00:11:15,155
that's right.

207
00:11:15,685 --> 00:11:18,905
But the first thing up that
you gave me on your list, was

208
00:11:19,405 --> 00:11:20,745
talking about hardened images.

209
00:11:20,755 --> 00:11:24,985
So can you give me, assuming someone
hasn't tried Hard images yet.

210
00:11:24,995 --> 00:11:28,335
What is the difference between all
the Docker images we know about and

211
00:11:28,335 --> 00:11:32,255
then the hardened images that we now,
like now the industry has sort of

212
00:11:32,255 --> 00:11:36,835
established what this is as an industry
thing and Docker is one of the leaders.

213
00:11:37,335 --> 00:11:43,245
Yeah, so hardened images is a, I would
say, a collection, it's a category of

214
00:11:43,275 --> 00:11:50,014
container images are really designed
for secure, for folks that are

215
00:11:50,014 --> 00:11:54,124
interested in making sure that their
supply chain is tight and is secure.

216
00:11:54,486 --> 00:11:58,016
Even in the blog post here, the
second paragraph there, why supply

217
00:11:58,016 --> 00:11:59,256
chain attacks are exploding.

218
00:11:59,626 --> 00:12:03,016
and we see, okay, 60 billion
in damage, tripling from 2021.

219
00:12:03,016 --> 00:12:03,826
No one is safe.

220
00:12:03,826 --> 00:12:06,626
obviously, that's a little bit
of hype around that as well, too.

221
00:12:07,126 --> 00:12:09,666
But the idea around a hardened
image is that when you use this

222
00:12:09,666 --> 00:12:13,166
hardened image, it's going to have
much less in it to start with.

223
00:12:13,216 --> 00:12:15,056
only the things that are
needed to run your application.

224
00:12:15,486 --> 00:12:19,356
so for example, if I'm running a node
based application, I can use the hardened

225
00:12:19,366 --> 00:12:23,206
image that doesn't even have npm and
yarn and the package managers installed.

226
00:12:23,376 --> 00:12:24,586
It just has the node runtime.

227
00:12:24,961 --> 00:12:27,351
Which does change a little
bit of how I build the image.

228
00:12:27,351 --> 00:12:29,611
I have to actually install
those dependencies, maybe in

229
00:12:29,611 --> 00:12:31,311
another stage in my Dockerfile.

230
00:12:31,701 --> 00:12:34,441
But then my final image is much
more locked down and secure.

231
00:12:34,841 --> 00:12:36,611
In fact, it may not
even have a shell in it.

232
00:12:36,661 --> 00:12:41,571
and so if that container were to
be compromised, the blast radius,

233
00:12:41,611 --> 00:12:45,221
the number of things that can be
done with that container are quite

234
00:12:45,221 --> 00:12:48,931
limited because it doesn't have any
ability to install new stuff there.

235
00:12:48,931 --> 00:12:50,711
So again, it's this idea of.

236
00:12:51,211 --> 00:12:56,811
Trading off a little bit of flexibility
and ease of use, but to make it

237
00:12:57,211 --> 00:13:00,771
more hardened and more secure,
ready for production workloads.

238
00:13:01,271 --> 00:13:07,131
Right now, these images can still be
used locally, but there is a little

239
00:13:07,131 --> 00:13:12,151
bit of onboarding and understanding
around what you can do in them and what

240
00:13:12,151 --> 00:13:13,741
you can't, especially for development.

241
00:13:14,001 --> 00:13:18,411
Is this of the kind where there's like a
dev image or an alternative option that

242
00:13:18,411 --> 00:13:21,481
has a little bit more in it, like maybe
a shell in it that I can use locally?

243
00:13:21,981 --> 00:13:25,521
Yeah, so going back to that Node
example, I could use a dev variant

244
00:13:25,561 --> 00:13:30,597
that then has a shell, has the npm
package manager, etc. So many of our

245
00:13:30,607 --> 00:13:35,528
images have a dev variant that have
these additional things baked into it.

246
00:13:35,963 --> 00:13:38,763
And then I can either use that in
development or I can use that to help.

247
00:13:39,228 --> 00:13:42,328
Install the things that would
eventually need to be, available in

248
00:13:42,378 --> 00:13:43,828
my final production image as well.

249
00:13:43,828 --> 00:13:47,668
So, not every image has a dev variant,
but especially those that I'm going to be

250
00:13:47,678 --> 00:13:51,458
building, you know, the node, the pythons,
are going to have these dev variants.

251
00:13:52,252 --> 00:13:56,982
Alright, so you announced after that,
you announced that they were going free.

252
00:13:57,667 --> 00:14:02,957
The headline was free hardened images,
which Up until then, in my experience,

253
00:14:03,307 --> 00:14:09,507
the challenge with other free hardened
images was either they weren't really that

254
00:14:09,517 --> 00:14:15,407
usable in production unless I paid for
them, or, like Google had this distro less

255
00:14:15,417 --> 00:14:16,757
thing, which they were really early on.

256
00:14:16,777 --> 00:14:17,787
That was an early concept.

257
00:14:17,787 --> 00:14:19,607
we were at the time we
were calling it distro.

258
00:14:19,607 --> 00:14:21,707
I think now we have the
definition of difference between

259
00:14:22,037 --> 00:14:23,907
distro less and hardened.

260
00:14:23,917 --> 00:14:26,507
Hardened to me is like an
improvement on distro less.

261
00:14:26,507 --> 00:14:29,677
Distro less was a smaller
image, but also harder to use.

262
00:14:30,022 --> 00:14:33,232
And one of the challenges with
distro lists it was harder to get

263
00:14:33,232 --> 00:14:36,912
to use them and they were only so
many of them that were provided.

264
00:14:36,912 --> 00:14:38,832
It wasn't like it was the entire catalog.

265
00:14:39,172 --> 00:14:42,542
So can you talk to me a little bit
about What's actually free for those

266
00:14:42,542 --> 00:14:43,972
engineers that are wanting to adopt it?

267
00:14:43,972 --> 00:14:46,832
And then what's the paid tier and
where does that line get drawn?

268
00:14:47,037 --> 00:14:47,407
Yeah.

269
00:14:47,567 --> 00:14:47,887
Yeah.

270
00:14:47,887 --> 00:14:50,737
so our free tier is available.

271
00:14:50,817 --> 00:14:52,587
Anybody can just go to dhi.

272
00:14:52,627 --> 00:14:53,087
io.

273
00:14:53,347 --> 00:14:55,287
and then that'll redirect to the catalog.

274
00:14:55,597 --> 00:14:58,927
and there's several hundred images that
are available there, on the free tier.

275
00:14:59,267 --> 00:15:02,387
You're going to, you're going to get all
these images and anybody can use them.

276
00:15:02,747 --> 00:15:05,777
Now the difference between this and
the paid for tier, the enterprise tier,

277
00:15:06,132 --> 00:15:10,432
is that the enterprise tier is going
to give you SLAs around those images.

278
00:15:10,822 --> 00:15:13,375
So when new vulnerabilities
come out, you know, they'll get

279
00:15:13,375 --> 00:15:14,965
patched, they'll get released, etc.

280
00:15:14,965 --> 00:15:18,125
But then there's also guarantees, which
a lot of organizations need for audit

281
00:15:18,125 --> 00:15:20,455
compliance, That there's SLAs around that.

282
00:15:20,888 --> 00:15:26,198
Additionally, the paid for tier has
this really cool customization pipeline.

283
00:15:26,848 --> 00:15:31,198
So for example, a lot of
organizations may use HTTPS proxy

284
00:15:31,198 --> 00:15:33,038
certs at their network boundary.

285
00:15:33,408 --> 00:15:36,208
And they want to see everything that's
going in and out of their network.

286
00:15:36,892 --> 00:15:42,222
With this customization pipeline,
organizations can actually customize the

287
00:15:42,232 --> 00:15:46,282
image that they get from Docker hardened
image, to bake in these proxy certs

288
00:15:46,282 --> 00:15:47,862
as part of the actual build pipeline.

289
00:15:48,182 --> 00:15:51,452
So by the time the image ends up in
their organization, it's mirrored

290
00:15:51,452 --> 00:15:57,072
into their org, it's starting from
this DHI base, and then has these

291
00:15:57,072 --> 00:15:59,122
other customizations applied to it.

292
00:15:59,492 --> 00:16:02,766
all these images are built
with Salsa level three build

293
00:16:02,766 --> 00:16:04,056
pipelines and everything.

294
00:16:04,266 --> 00:16:08,086
You can validate attestations and
how things are built and whatnot.

295
00:16:08,096 --> 00:16:09,526
there's a lot of really
cool aspects to it.

296
00:16:09,576 --> 00:16:13,246
But again, at Docker, we decided
access to these hardened images

297
00:16:13,246 --> 00:16:14,556
should be available to everybody.

298
00:16:14,616 --> 00:16:18,866
And it's been neat to see the open source
space really start to take up on it.

299
00:16:19,216 --> 00:16:22,836
and Aden has adopted it for their
base images and others as well too.

300
00:16:22,836 --> 00:16:26,716
So, By making these available,
it's helping, slowly anyways,

301
00:16:27,166 --> 00:16:29,596
the entire ecosystem just
become a little bit more secure.

302
00:16:29,596 --> 00:16:33,566
And we also think about supply chain a
little bit more than we have in the past.

303
00:16:33,616 --> 00:16:33,826
Yeah.

304
00:16:33,826 --> 00:16:38,171
challenge before this was always that
the, the difference between using, you

305
00:16:38,171 --> 00:16:43,631
know, like slim images or Alpine images
from Docker official, and then the, Self

306
00:16:43,631 --> 00:16:48,471
created, hardened image was a I always
felt like a huge leap and it required.

307
00:16:48,841 --> 00:16:54,681
I almost felt like at times it required a
10x level of knowledge and understanding.

308
00:16:55,151 --> 00:16:57,531
AI has probably made that a lot easier
for us when we can understand things and

309
00:16:57,531 --> 00:16:58,481
troubleshoot a little bit better with AI.

310
00:16:59,236 --> 00:17:03,596
But the knowledge that even I had,
someone who was deeply invested in

311
00:17:03,596 --> 00:17:07,546
the Docker ecosystem and obsessed with
Dockerfiles and minification of things

312
00:17:07,546 --> 00:17:11,216
and, multi stage, I mean, I'm the guy
that's writing the 200 line Dockerfiles

313
00:17:11,226 --> 00:17:16,166
when you probably could get away with
80 lines of Dockerfile, but I would take

314
00:17:16,166 --> 00:17:19,086
it to the next level and I would be the
one on the team that was the only one

315
00:17:19,086 --> 00:17:22,086
that understood it, which is part of,
that's not a great thing because there

316
00:17:22,086 --> 00:17:23,596
was, I was using every trick in my.

317
00:17:23,831 --> 00:17:25,691
Toolbag to make this thing slim.

318
00:17:26,171 --> 00:17:29,261
And then that the problem was always that
the team would have to maintain that.

319
00:17:29,521 --> 00:17:32,431
And I would leave as the consultant,
knowing that I've created them this

320
00:17:32,431 --> 00:17:36,791
really sophisticated minified image
that's good or better for production,

321
00:17:36,801 --> 00:17:42,611
less CVEs, but if they have one stumbling
block or one dependency gets fails and

322
00:17:42,611 --> 00:17:44,041
they need to change a dependency lock.

323
00:17:44,541 --> 00:17:47,651
It might be a little tricky for them
to figure out how to fix that or,

324
00:17:47,651 --> 00:17:50,881
there might be a CVEs that they don't
really know how to deal with because

325
00:17:50,881 --> 00:17:54,941
of ways that I was copying in certain
packages versus installing them and

326
00:17:54,941 --> 00:17:58,781
like doing sideloading of stuff from
other images into the same image.

327
00:17:58,981 --> 00:18:01,071
there was all these little tricks
you can do if you get really deep

328
00:18:01,071 --> 00:18:02,401
into Docker, Dockerfile stuff.

329
00:18:02,751 --> 00:18:05,921
But I feel like these hardened
images are such an easy button now

330
00:18:05,921 --> 00:18:07,801
that if I was to start a company.

331
00:18:08,301 --> 00:18:11,881
Or if I was to walk into a company
today and they pretty much all

332
00:18:11,881 --> 00:18:14,021
should have requirements for
hardened images at this point.

333
00:18:14,251 --> 00:18:19,401
But if they didn't, I would absolutely
be pushing for them to lean into a

334
00:18:19,401 --> 00:18:24,661
hardened image platform because it to
me solves a major supply chain risk

335
00:18:24,691 --> 00:18:29,341
area with a problem that someone else
has already solved, like a fix that

336
00:18:29,341 --> 00:18:30,471
someone else has already done for you.

337
00:18:30,481 --> 00:18:32,941
And it is not easy to fix yourself.

338
00:18:32,941 --> 00:18:37,901
I think even with AI, to pre build your
own image with everything on top of like

339
00:18:37,901 --> 00:18:42,211
an Ubuntu or something and have everything
thoroughly checked and thoroughly

340
00:18:42,221 --> 00:18:45,651
scanned and I think that's still a
really rough area to do because there's

341
00:18:45,651 --> 00:18:47,281
still a lot in the regular Ubuntu image.

342
00:18:47,281 --> 00:18:49,221
there's still a lot of
stuff going on in there.

343
00:18:49,231 --> 00:18:52,581
So I'm a huge fan of these in
case you couldn't notice it on

344
00:18:52,581 --> 00:18:53,861
the, for you podcast listeners.

345
00:18:53,911 --> 00:18:57,981
I've been shouting from the
rooftops for at least eight years.

346
00:18:58,001 --> 00:19:01,561
I can actually go back to
DockerCon, I think 2019 where

347
00:19:01,561 --> 00:19:03,231
I did a whole talk on Node.

348
00:19:03,241 --> 00:19:08,061
js, and part of that talk was really
about locking down the images, never using

349
00:19:08,061 --> 00:19:12,181
the default image, always using at least
slim, you know, the risks of Alpine and

350
00:19:12,181 --> 00:19:16,281
Musel, or maybe a little, not so much
as a risk anymore, but they were back in

351
00:19:16,281 --> 00:19:18,101
2019, they were a little dicey at times.

352
00:19:18,461 --> 00:19:21,531
And so I felt like I was shouting
from the rooftops, but the solution

353
00:19:21,531 --> 00:19:25,311
to that was to expect teams to like
three X their knowledge and just how a

354
00:19:25,311 --> 00:19:29,151
Dockerfile works so that they could even
attempt this level of sophistication.

355
00:19:29,651 --> 00:19:32,551
So that's my long way of
saying, this is all good stuff.

356
00:19:32,551 --> 00:19:35,701
Like people should be looking at these
to see if they can fit even the free

357
00:19:35,701 --> 00:19:38,881
ones before, even if they can't get
budget to figure out if they can use

358
00:19:38,881 --> 00:19:41,971
some of the free ones, even if you
can't use them all, or you can just find

359
00:19:41,971 --> 00:19:44,656
a few of the images to migrate over.

360
00:19:44,686 --> 00:19:48,346
Like this is one of those things where
it's probably a six month project.

361
00:19:48,396 --> 00:19:50,646
you probably have dozens of images, like
if you're watching this show, you're

362
00:19:50,646 --> 00:19:54,696
probably someone who has dozens of images
in production And so you are going to

363
00:19:54,706 --> 00:19:59,346
have to go one by one, and you should
probably, in my experience, probably start

364
00:19:59,346 --> 00:20:02,716
with like your programming images, because
if you can get like a Python or a Node.

365
00:20:02,726 --> 00:20:07,736
js image to actually start working on
Hardened, and you're a Python shop or a

366
00:20:07,736 --> 00:20:11,746
Node shop or a Ruby shop, like if you can
get that one image that you use for your

367
00:20:11,746 --> 00:20:16,186
programming, then you've probably won a
lot, because you've probably got a bunch

368
00:20:16,186 --> 00:20:20,931
of apps in production that will suddenly
Drop from possibly hundreds or thousands

369
00:20:20,931 --> 00:20:25,841
of CVEs down to very few, like maybe
even if you're lucky, maybe on a couple

370
00:20:25,841 --> 00:20:27,511
of hands between all your dependencies.

371
00:20:27,511 --> 00:20:30,469
If you're super lucky, maybe you can
get close to zero, but just because the

372
00:20:30,469 --> 00:20:34,169
base image is close to zero or at zero
doesn't mean that your app will be.

373
00:20:34,209 --> 00:20:37,929
But, uh, so yeah, it's like once
you install your dependencies.

374
00:20:38,004 --> 00:20:40,704
we can all hope and dream that someday
we will all be zero everywhere.

375
00:20:40,724 --> 00:20:44,674
But, I feel like that's the strategy if I
was to step into a shop today, it's like,

376
00:20:44,674 --> 00:20:47,954
okay, let's go see what we can do with
your very, what's your most popular image?

377
00:20:48,264 --> 00:20:49,454
what's the one you're using everywhere?

378
00:20:49,454 --> 00:20:50,754
Let's go see if we can attempt that.

379
00:20:51,114 --> 00:20:52,594
And then you gotta get
the developers on board.

380
00:20:52,594 --> 00:20:55,124
And then you're going to have this
whole process where the developers

381
00:20:55,319 --> 00:20:57,849
All of these are going to like, it's
not going to work locally, so you're

382
00:20:57,849 --> 00:20:59,879
going to have to swap out for the dev
images and you're going to have to

383
00:20:59,879 --> 00:21:02,929
train people and educate people on how
these images work a little differently.

384
00:21:03,399 --> 00:21:06,469
And then maybe you can get management
buy in when you finally get it to work

385
00:21:06,469 --> 00:21:07,959
and they're like, I see the benefits.

386
00:21:08,299 --> 00:21:09,489
Our security team loves it.

387
00:21:09,489 --> 00:21:12,229
let's go for paid and let's
get a, purchase order together.

388
00:21:12,229 --> 00:21:16,249
And then finally you can start rolling
out some more of these customized images.

389
00:21:16,249 --> 00:21:19,319
I love that you can build them
customized on the platform.

390
00:21:19,319 --> 00:21:20,109
That's a pretty cool.

391
00:21:20,464 --> 00:21:24,354
feature because we're all
like, this is all one on one

392
00:21:24,354 --> 00:21:25,394
stuff that we're talking about.

393
00:21:25,394 --> 00:21:28,174
But the day you hit the ground running
with a new image and you realize that

394
00:21:28,634 --> 00:21:32,584
the customization you have to apply
to an image is usually significant.

395
00:21:32,889 --> 00:21:36,939
Well, and also well, the nice thing about
the customization pipeline then is that

396
00:21:37,439 --> 00:21:42,499
Every time the base image, okay, if we
have a new version of, we'll just use

397
00:21:42,509 --> 00:21:46,209
Node again, the next version of Node
gets pushed out, that customization

398
00:21:46,209 --> 00:21:47,469
is automatically going to be applied.

399
00:21:47,469 --> 00:21:49,399
You don't have to figure out,
wait, how are we going to

400
00:21:49,409 --> 00:21:51,589
respond to updated base images?

401
00:21:51,599 --> 00:21:54,029
Now we need to build our own
images and now roll it out

402
00:21:54,039 --> 00:21:54,729
and all that kind of stuff.

403
00:21:54,739 --> 00:21:55,709
it's just part of the service.

404
00:21:55,709 --> 00:21:55,939
So,

405
00:21:56,329 --> 00:21:58,649
It's good to hear from people out
there in the wild actually using it.

406
00:21:58,659 --> 00:22:01,609
Cause I kind of fired all my
consulting clients a couple years ago.

407
00:22:02,109 --> 00:22:04,829
back and looking for some new ones that
want to do some AI stuff in DevOps.

408
00:22:04,849 --> 00:22:09,709
But, I took a break from consulting
to just do content and make courses.

409
00:22:10,109 --> 00:22:14,454
And what I noticed was that was around
the time that chain got really big and

410
00:22:14,454 --> 00:22:17,764
then eventually Docker came out with
hardened images and I don't yet have

411
00:22:17,784 --> 00:22:22,064
production experience with a lot of these
hardened images and I am very curious

412
00:22:22,064 --> 00:22:27,374
about the challenges to adoption, the edge
cases that maybe they don't cover yet.

413
00:22:27,464 --> 00:22:30,434
are there situations where
you can't use hardened images?

414
00:22:30,494 --> 00:22:35,824
is that a thing or are there scenarios
where Hardened images are a utopia.

415
00:22:35,844 --> 00:22:38,104
And every single thing you use
in your company is hardened.

416
00:22:38,104 --> 00:22:42,364
And you make a unilateral decision that
only hardened images will ever be used.

417
00:22:42,634 --> 00:22:44,294
I haven't heard a lot
of the stories I hear.

418
00:22:44,524 --> 00:22:48,284
There's a ton of stuff on the internet
about people like day one with hardened

419
00:22:48,284 --> 00:22:50,624
images, but I'd love to hear some
of the battles from the trenches.

420
00:22:50,674 --> 00:22:53,004
So, anyway, Anything
else on hardened images?

421
00:22:53,004 --> 00:22:53,934
We could talk about this all week.

422
00:22:54,094 --> 00:22:55,774
We could make this a hardened
image episode, but we have

423
00:22:55,774 --> 00:22:56,664
so much more to talk about.

424
00:22:56,834 --> 00:22:59,694
yeah, I think that's good and
actually kind of serves as a good

425
00:22:59,694 --> 00:23:01,544
segue into what we get next here.

426
00:23:01,544 --> 00:23:01,794
So

427
00:23:02,344 --> 00:23:02,644
All right.

428
00:23:02,914 --> 00:23:05,974
Gordon AI agents just got an update.

429
00:23:06,024 --> 00:23:06,454
Okay.

430
00:23:06,644 --> 00:23:08,514
So, I can speak to a little bit.

431
00:23:08,784 --> 00:23:12,374
Gordon AI is uniquely in
Docker desktop, right?

432
00:23:12,874 --> 00:23:13,364
Yes.

433
00:23:13,744 --> 00:23:14,004
Okay.

434
00:23:14,264 --> 00:23:15,644
So yeah, this is not a web service.

435
00:23:15,644 --> 00:23:16,524
This isn't a website.

436
00:23:16,524 --> 00:23:18,254
this is a feature in Docker desktop.

437
00:23:18,524 --> 00:23:20,114
It is a free feature, correct?

438
00:23:20,614 --> 00:23:20,984
Correct.

439
00:23:21,404 --> 00:23:24,614
and when it first came out,
it was actually pretty early.

440
00:23:24,634 --> 00:23:26,304
this was at least a couple
of years ago, I feel like.

441
00:23:26,734 --> 00:23:32,784
and it was originally designed around
helping answer my Docker specific

442
00:23:32,784 --> 00:23:36,804
questions in case I didn't have
ChatGPT for subscription at the time

443
00:23:36,804 --> 00:23:41,214
or whatever, and so we were using it
to understand maybe what was going

444
00:23:41,214 --> 00:23:43,374
on in a Dockerfile, like you could
give it a Compose file and ask it to

445
00:23:43,374 --> 00:23:44,764
describe what's in that Compose file.

446
00:23:45,094 --> 00:23:48,094
And I remember very specifically one of
the early things that we were focused

447
00:23:48,094 --> 00:23:52,784
on with the Docker team as captains was
improving that AI so that it was actually

448
00:23:52,784 --> 00:23:58,484
smarter about Docker specific stuff than
the general ChatGPTs of the world, right?

449
00:23:58,484 --> 00:24:01,064
Because they just go on world
knowledge, and there's obviously a

450
00:24:01,064 --> 00:24:03,974
lot that's happened in Docker, and
there's a lot of updated documentation,

451
00:24:03,974 --> 00:24:05,204
and things change constantly.

452
00:24:05,614 --> 00:24:10,494
So it always felt to me like it was
becoming The Docker, I didn't have to tell

453
00:24:10,494 --> 00:24:14,144
it, Hey, please go read the documentation
because it's changed or, Hey, don't

454
00:24:14,144 --> 00:24:17,334
use the version statement and compose
anymore because that's six years old.

455
00:24:17,334 --> 00:24:18,284
We don't do that anymore.

456
00:24:18,284 --> 00:24:21,344
Like it, it started to
understand the latest habits.

457
00:24:21,344 --> 00:24:24,394
So that was then, but I
haven't tried it lately.

458
00:24:24,394 --> 00:24:28,014
So what's going on with the Gordon
beta is Gordon back in beta or

459
00:24:28,014 --> 00:24:29,364
is Gordon always been in beta?

460
00:24:29,829 --> 00:24:32,929
Yeah, it's always been in beta, and
yeah, I don't know when it's going

461
00:24:32,944 --> 00:24:34,364
I mean, AIs in general are

462
00:24:34,479 --> 00:24:35,199
the new Gmail.

463
00:24:35,874 --> 00:24:36,144
right?

464
00:24:36,154 --> 00:24:38,914
Like beta, AIs all should be
labeled beta at this point.

465
00:24:38,924 --> 00:24:39,664
Like they're all beta.

466
00:24:39,804 --> 00:24:40,474
It's always changing.

467
00:24:40,979 --> 00:24:43,569
yeah, so what we've done with
Gordon is, we've actually

468
00:24:43,569 --> 00:24:44,999
completely re architected it.

469
00:24:45,019 --> 00:24:47,719
And, we'll talk about CAgent
slash DockerAgent, a little

470
00:24:47,719 --> 00:24:48,529
bit more in a little bit.

471
00:24:48,529 --> 00:24:51,449
But actually, Gordon is
backed by DockerAgent now.

472
00:24:51,749 --> 00:24:55,419
and so it, it provides opportunities
to do multi agent kind of stuff.

473
00:24:55,419 --> 00:24:58,049
And so it's much smarter
about how it does things.

474
00:24:58,049 --> 00:25:00,709
So, this is through the CLI interface.

475
00:25:01,069 --> 00:25:01,439
I'll get it.

476
00:25:01,799 --> 00:25:04,979
the prompt was give me a summary of my
running containers, and it's pulling up

477
00:25:04,979 --> 00:25:06,419
a coding agent and that kind of stuff.

478
00:25:06,749 --> 00:25:09,809
and you'll see like coding agent
and DHI expert, DHI migration.

479
00:25:10,199 --> 00:25:14,269
so we were just talking about
migrating to DHI just a little bit ago.

480
00:25:14,589 --> 00:25:19,219
We actually have an agent that's
specifically tuned for Migrating images

481
00:25:19,249 --> 00:25:24,779
to the DHI, and so I've pulled up node
apps and it's, you know, here's a single,

482
00:25:24,999 --> 00:25:27,519
stage thing, and it's smart enough to
know, okay, I'm going to have to pull a

483
00:25:27,519 --> 00:25:32,129
dev variance and install stuff and copy it
over into multi stage, so, so yeah, Gordon

484
00:25:32,129 --> 00:25:37,834
is, Got the support now for delegating
out various tasks to other agents that

485
00:25:37,834 --> 00:25:39,814
are more optimized for that kind of task.

486
00:25:40,164 --> 00:25:43,054
like you said, it is still very
Docker oriented and container

487
00:25:43,054 --> 00:25:44,484
oriented and that kind of stuff.

488
00:25:44,484 --> 00:25:47,704
But it is kind of interesting to see
folks that try to, use it for all

489
00:25:47,704 --> 00:25:50,004
kinds of, adventures, as well, too.

490
00:25:50,004 --> 00:25:50,274
Yeah.

491
00:25:50,274 --> 00:25:51,594
are basically a public service.

492
00:25:51,594 --> 00:25:54,384
So you probably have to have
some pretty stiff guardrails.

493
00:25:54,884 --> 00:25:58,004
so, so yeah, when you said earlier
it's available for free, I almost.

494
00:25:58,504 --> 00:25:58,904
Caught myself.

495
00:25:59,264 --> 00:26:04,024
There are rate limits in place, especially
if you just have a free Docker account.

496
00:26:04,554 --> 00:26:07,734
If you've got a pro account or above,
obviously those rate limits change.

497
00:26:07,734 --> 00:26:10,904
And I don't think those rate limits
are published, but, they're pretty,

498
00:26:11,454 --> 00:26:12,104
that's the word I'm looking for.

499
00:26:12,354 --> 00:26:15,114
They're pretty generous in those rate
limits, but of course we still want

500
00:26:15,114 --> 00:26:17,054
to, reduce abuse with the system as

501
00:26:17,124 --> 00:26:19,404
I do have a paid account,
but I've never hit a limit.

502
00:26:19,494 --> 00:26:19,994
You know?

503
00:26:20,054 --> 00:26:20,324
Yeah.

504
00:26:20,324 --> 00:26:24,064
So, and, you know, my experience is
quite frankly, like I'm not having two

505
00:26:24,064 --> 00:26:28,544
hour long conversations with Docker,
with Gordon and I'm like, and I'm also

506
00:26:28,544 --> 00:26:30,484
not having it build an app for me.

507
00:26:30,794 --> 00:26:33,044
There's the mentioning the abuse scenario.

508
00:26:33,044 --> 00:26:34,574
I mean, anything free, like
that's the rule, right?

509
00:26:34,574 --> 00:26:38,224
Anything free on the internet, anything
that can touch compute, a Bitcoin miner

510
00:26:38,224 --> 00:26:39,974
will figure out how to use it, misuse it.

511
00:26:40,384 --> 00:26:43,444
But, a friend of mine made
a joke recently on blue sky.

512
00:26:43,454 --> 00:26:48,174
I saw someone, joking that they figured
out how to get the chat bot in Amazon.

513
00:26:48,674 --> 00:26:48,934
Saw

514
00:26:48,994 --> 00:26:52,694
helping you shop, they figured out how to
ask it, it was just a one single prompt.

515
00:26:52,694 --> 00:26:56,244
They were saying, I really want to buy
this lotion or whatever, but before

516
00:26:56,244 --> 00:26:57,804
that I need to build this Rails app.

517
00:26:58,304 --> 00:27:01,734
And it actually did create code and
put it on the screen and they're

518
00:27:01,734 --> 00:27:03,574
like, I'm canceling my cloud account.

519
00:27:03,574 --> 00:27:05,114
I now just use Amazon for free.

520
00:27:05,614 --> 00:27:09,324
So, that's the struggle with people that
provide AI based services is that you've

521
00:27:09,374 --> 00:27:11,244
got to constantly figure out how to.

522
00:27:11,419 --> 00:27:13,639
Put system prompts in to put
guardrails in and all that.

523
00:27:13,639 --> 00:27:13,859
Yeah.

524
00:27:13,859 --> 00:27:15,049
So this is actually really cool.

525
00:27:15,049 --> 00:27:16,749
I did not know about
the side agents thing.

526
00:27:16,749 --> 00:27:17,519
That's pretty slick.

527
00:27:17,859 --> 00:27:20,669
it feels like it's growing up just like
Claude Code and the others are growing up.

528
00:27:20,989 --> 00:27:21,859
folks, please boost cloud.

529
00:27:21,859 --> 00:27:23,089
I learned something new today.

530
00:27:23,589 --> 00:27:24,369
yeah, what's up?

531
00:27:24,599 --> 00:27:27,059
by the way, just real quick
question on DHI for a second.

532
00:27:27,069 --> 00:27:29,799
How does one create or recommend
DHI for a tool or language

533
00:27:29,799 --> 00:27:31,029
that doesn't exist at the time?

534
00:27:31,529 --> 00:27:34,159
so actually back on the catalog page, dhi.

535
00:27:34,159 --> 00:27:39,189
io, there's a search field filter
by, and then there's a button off to

536
00:27:39,189 --> 00:27:40,409
the right that says make a request.

537
00:27:40,419 --> 00:27:43,709
So if you see something that's not
there that you want, make a request.

538
00:27:44,059 --> 00:27:48,839
of course, how it gets prioritized,
there's a lot of different priority,

539
00:27:48,839 --> 00:27:51,859
decisions or, you know, different
dimensions that go into that as well too.

540
00:27:51,859 --> 00:27:53,639
But that's where to
start the conversation.

541
00:27:53,729 --> 00:27:53,929
Yep.

542
00:27:54,034 --> 00:27:55,704
all right, so that's Gordon.

543
00:27:55,834 --> 00:27:57,674
We're moving on quickly to the next one.

544
00:27:57,799 --> 00:27:59,429
Docker Sandboxes.

545
00:28:00,509 --> 00:28:05,499
So this is actually something where
I feel like relatively, it's like

546
00:28:05,529 --> 00:28:08,419
old is what, what's old is new
again, I guess is what I should say.

547
00:28:08,679 --> 00:28:09,659
What's old is new again.

548
00:28:09,669 --> 00:28:15,929
So, what's old was spinning things up in
VMs or having, you know, doing custom work

549
00:28:15,929 --> 00:28:18,419
and stuff inside of containers or VMs.

550
00:28:18,729 --> 00:28:23,339
And, you know, then we all go kind of
go back between using local tools on

551
00:28:23,339 --> 00:28:27,799
our host and then, doing things inside
of containers and, you know, years ago

552
00:28:27,799 --> 00:28:32,889
we all had Vagrant and we had these
custom VM setups pre Docker and now

553
00:28:33,229 --> 00:28:37,369
what we're all realizing is that if
we're, if we've got coding agents and we

554
00:28:37,369 --> 00:28:39,219
really want to just let them loose on a

555
00:28:42,084 --> 00:28:44,484
So, we wanted to build an
app one step at a time.

556
00:28:44,484 --> 00:28:49,034
Maybe someone has heard of Ralph Loops
or Chef Wiggum or all these different

557
00:28:49,044 --> 00:28:52,804
paradigms that we're all quickly adopting
that didn't even exist six months ago,

558
00:28:53,044 --> 00:28:56,734
maybe even not even three months ago,
and we're realizing that we would much

559
00:28:56,734 --> 00:28:58,184
rather just let the AI do the work.

560
00:28:58,184 --> 00:29:05,414
at the command line, and we just need to
give it a shell with some tooling, but

561
00:29:05,424 --> 00:29:09,454
also wouldn't it be nice if it didn't
have complete control over my computer?

562
00:29:09,714 --> 00:29:13,414
And more importantly for us DevOps
people, I also might have a bunch

563
00:29:13,414 --> 00:29:16,704
of credentials logged in on my
system that I don't necessarily want

564
00:29:16,704 --> 00:29:18,114
my AI to have those credentials.

565
00:29:18,124 --> 00:29:19,214
I'm logging into GitHub.

566
00:29:19,254 --> 00:29:21,494
My GitHub command line tool
has all my permissions.

567
00:29:21,864 --> 00:29:25,484
I don't even know how to scope my
GitHub tool to a limited set of

568
00:29:25,484 --> 00:29:28,514
permissions unless I create a new
user, log out, and log back in.

569
00:29:28,524 --> 00:29:30,634
there, we've got challenges
in the industry we're going to

570
00:29:30,644 --> 00:29:32,004
have to keep solving around.

571
00:29:32,349 --> 00:29:36,779
Taking our agent and giving it some
permissions, but not all permissions.

572
00:29:36,819 --> 00:29:39,979
And how do I do that without
ruining my environment?

573
00:29:39,999 --> 00:29:42,929
And it's almost like at the end of
the day, do I just create all these

574
00:29:42,929 --> 00:29:45,219
accounts for my AI to give it access?

575
00:29:45,219 --> 00:29:47,439
But now I've got to literally
double the amount of account

576
00:29:47,449 --> 00:29:49,359
managements and licensing fees.

577
00:29:49,359 --> 00:29:52,039
there's just a lot of problems
that the industry has to work

578
00:29:52,039 --> 00:29:53,059
through that we haven't solved yet.

579
00:29:53,069 --> 00:29:58,479
So that's my setup for the problem
set of, We, if you look around

580
00:29:58,509 --> 00:30:01,549
at all these toolings, Claude
Code, I'm a big OpenCode fan.

581
00:30:01,599 --> 00:30:06,989
but these tools, especially like ones like
OpenCode, they default to not prompting

582
00:30:06,989 --> 00:30:11,179
for every single command and they run
with my privileges on my machine locally.

583
00:30:11,649 --> 00:30:16,319
So, I, especially being a security
minded DevOps person, I'm already

584
00:30:16,319 --> 00:30:19,469
nervous about that, and I never thought
about the fact that if it, if I had

585
00:30:19,489 --> 00:30:24,569
Terraform to production, if I had AWS
auth keys on my machine, it technically

586
00:30:24,579 --> 00:30:28,639
has access to those, and if it ran
an AWS command, Could have access to

587
00:30:28,639 --> 00:30:30,209
infrastructure I don't intend it to have.

588
00:30:30,209 --> 00:30:32,259
So I need to sandbox it.

589
00:30:32,289 --> 00:30:34,879
I need to put it somewhere,
whether it's local or remote.

590
00:30:35,349 --> 00:30:41,159
And therein lies the problem of
how do I run IDEs and shell TUIs?

591
00:30:41,419 --> 00:30:43,549
I'm calling it the TUI GUI WUI problem.

592
00:30:43,589 --> 00:30:45,319
Web UI is too many syllables.

593
00:30:45,329 --> 00:30:47,869
So I have to say TUI GUI WUI, of agents.

594
00:30:47,889 --> 00:30:53,019
And how do we get these agent harnesses
to work safely in an isolated environment?

595
00:30:53,414 --> 00:30:57,334
So that's me setting you up
for the release of sandboxes.

596
00:30:59,249 --> 00:31:03,379
so we've been working on sandboxes and
I'll go ahead and say first, like sandbox

597
00:31:03,379 --> 00:31:05,309
is totally an overloaded term right now.

598
00:31:05,339 --> 00:31:05,719
so many

599
00:31:06,044 --> 00:31:06,874
As well as agent.

600
00:31:07,374 --> 00:31:08,414
Yeah, exactly.

601
00:31:08,414 --> 00:31:09,834
And so it's what do we
actually mean by this?

602
00:31:10,382 --> 00:31:14,582
most people know Docker as being the
container company and providing the

603
00:31:14,582 --> 00:31:16,753
runtime to run your applications.

604
00:31:17,193 --> 00:31:20,583
And so in many ways, it's actually
like the right company, it's the right

605
00:31:20,803 --> 00:31:26,163
layer to figure out how do we run
these agents safely, securely, etc. so

606
00:31:26,163 --> 00:31:29,103
yeah, we're not trying to be an agent.

607
00:31:29,113 --> 00:31:33,443
We're not trying to, you know,
replace your Claude Code or your

608
00:31:33,883 --> 00:31:36,443
OpenClaw or NanoClaw or whatever tool.

609
00:31:36,673 --> 00:31:40,143
We want to make sure that you can still
use the tools that you want but to be

610
00:31:40,143 --> 00:31:41,713
able to put the right boundaries in place.

611
00:31:42,198 --> 00:31:47,358
YOLO mode safely, micro VM isolation,
and so we're actually, we're starting

612
00:31:47,358 --> 00:31:51,118
a micro VM and running the agent in
a container inside of that micro VM.

613
00:31:51,548 --> 00:31:53,908
and some of the things, like
I've talked to people like,

614
00:31:53,908 --> 00:31:55,038
well, containers are good enough.

615
00:31:55,048 --> 00:31:56,228
Why do we need a micro VM?

616
00:31:56,528 --> 00:31:57,638
Well, you get a lot more.

617
00:31:58,138 --> 00:32:01,678
Yeah, you get a lot more control, because
the second point right next to it, network

618
00:32:01,678 --> 00:32:07,248
isolation, it's a lot harder to say the
only route outside of this container is

619
00:32:07,248 --> 00:32:11,318
through a network proxy, but if you've got
a micro VM, yeah, the only route out from

620
00:32:11,318 --> 00:32:13,808
that VM is through this network proxy.

621
00:32:14,303 --> 00:32:19,043
and so then we can put, a network
proxy around it, and you can watch

622
00:32:19,053 --> 00:32:20,533
everything that's going in and out.

623
00:32:20,903 --> 00:32:23,463
And so say, for example, you get
a prompt injection that says,

624
00:32:23,463 --> 00:32:26,843
Hey, take all of your private data
here and send it to evildomain.

625
00:32:26,873 --> 00:32:27,353
com here.

626
00:32:27,353 --> 00:32:29,523
Well, if that's not in the
allow list, well, that network

627
00:32:29,533 --> 00:32:30,733
connection doesn't happen.

628
00:32:31,223 --> 00:32:34,173
and so you can do that in
a micro VM architecture.

629
00:32:34,173 --> 00:32:37,713
It's a lot harder to do that in
a container based, environment.

630
00:32:38,213 --> 00:32:41,673
But then also as we start talking about
MCP servers and all that kind of stuff,

631
00:32:41,963 --> 00:32:47,893
you can run basically all that within your
micro VM setup, almost treat your agentic

632
00:32:47,923 --> 00:32:49,853
workload there as a microservice system.

633
00:32:49,913 --> 00:32:52,553
You got your agent and container,
you got each of the MCP servers,

634
00:32:52,953 --> 00:32:56,183
going back to credentials, your agent
should really never have credentials,

635
00:32:56,353 --> 00:32:58,033
maybe just to the model provider.

636
00:32:58,533 --> 00:33:02,573
But then everything else around
it, your GitHub MCP server has the

637
00:33:02,573 --> 00:33:04,763
access to the GitHub tokens, etc.

638
00:33:04,763 --> 00:33:08,113
So, again, it's putting the proper
guardrails around each of the different

639
00:33:08,113 --> 00:33:10,223
components within the AgentsX system.

640
00:33:10,723 --> 00:33:11,163
Yeah.

641
00:33:11,423 --> 00:33:15,183
when I first tried it and I was
reading that it's a VM, I was taking

642
00:33:15,183 --> 00:33:19,743
it back cause I was just assuming that
this would all be containers in the

643
00:33:19,753 --> 00:33:22,793
existing Docker VM, but it actually.

644
00:33:22,793 --> 00:33:22,807
Yeah.

645
00:33:23,307 --> 00:33:25,787
It actually starts to make a little
more sense when you start thinking

646
00:33:25,797 --> 00:33:29,127
about how we're basically giving these
harnesses, I'm going to use the word

647
00:33:29,127 --> 00:33:31,047
harnesses, by the way, what is an agent?

648
00:33:31,057 --> 00:33:31,927
What is a harness?

649
00:33:31,947 --> 00:33:32,897
What is a model?

650
00:33:33,047 --> 00:33:34,127
Where do these things live?

651
00:33:34,427 --> 00:33:40,017
And exactly what do I get when I launch
code, OpenCode or Claude Code or or

652
00:33:40,127 --> 00:33:45,787
cursor or VS code and trying to help
people understand that, one, we probably

653
00:33:45,797 --> 00:33:47,497
shouldn't call Claude Code an agent.

654
00:33:47,517 --> 00:33:48,907
We should probably be
calling it a harness.

655
00:33:48,907 --> 00:33:52,427
That's actually what the internal
teams at Anthropic call it.

656
00:33:52,427 --> 00:33:55,807
And that harness has one
or more agents inside it.

657
00:33:56,307 --> 00:33:59,677
And those agents like there's a build
agent, there's a plan agent, you can

658
00:33:59,677 --> 00:34:03,557
make these custom agents and the agent
part talks about that if you are in

659
00:34:03,557 --> 00:34:07,787
the plan agent, it's really just a
system prompt, plus some tool access,

660
00:34:07,967 --> 00:34:11,507
plus some permissions to those tools
and various things, and then a model

661
00:34:11,517 --> 00:34:15,452
choice, and then you give that to
your harness and your harness can run

662
00:34:15,452 --> 00:34:19,412
that in a loop and use that model and
all those features to get a job done.

663
00:34:19,422 --> 00:34:21,852
Then you can switch to a different
agent or you can have subagents where

664
00:34:21,852 --> 00:34:25,312
one agent manages many agents, but
at the end of the day, they're all

665
00:34:25,332 --> 00:34:29,242
accessing models and those models all
come through subscriptions that you buy.

666
00:34:29,682 --> 00:34:32,072
And those subscriptions
determine your availability

667
00:34:32,072 --> 00:34:33,312
of what you can get access to.

668
00:34:33,312 --> 00:34:36,272
there's a lot of complexity
in this entire game.

669
00:34:36,772 --> 00:34:39,412
At the end of the day, we all
just start up VS Code or Claude

670
00:34:39,432 --> 00:34:42,182
Code or something, and we don't
really think about all that mess.

671
00:34:42,482 --> 00:34:46,742
But when we run it, and we're running
it in a directory usually on a

672
00:34:46,742 --> 00:34:50,772
project, and we typically want it
scoped to that directory, unless we're

673
00:34:50,772 --> 00:34:52,252
maybe working on something larger,

674
00:34:52,302 --> 00:34:55,142
But the point is there that you usually
don't need it to have access to slash

675
00:34:55,162 --> 00:34:57,462
bin on your system or a slash user.

676
00:34:57,672 --> 00:34:59,632
you need it to just be there.

677
00:34:59,992 --> 00:35:04,852
And then when you're still running that,
you need to run another one in a different

678
00:35:04,852 --> 00:35:07,852
directory because that thing's going to
go cook for 20 minutes and you need to

679
00:35:07,852 --> 00:35:09,112
work on something else in the meantime.

680
00:35:09,462 --> 00:35:12,242
So you actually need multiple sandboxes.

681
00:35:12,632 --> 00:35:16,462
That these agents don't have necessarily
access to each other's stuff.

682
00:35:16,952 --> 00:35:21,172
And one of them might, especially in the
DevOps world where you deal with certain

683
00:35:21,172 --> 00:35:24,502
things of privilege and certain things
of not, you might have one agent that

684
00:35:24,522 --> 00:35:29,202
actually has like a Terraform production
key in it, or a staging key, and another

685
00:35:29,202 --> 00:35:31,157
one that you want, Very isolated.

686
00:35:31,157 --> 00:35:34,397
That is going wild on a code base
that you're just making a crazy

687
00:35:34,407 --> 00:35:36,647
PR that you've just let it loose.

688
00:35:36,987 --> 00:35:40,567
And you're going YOLO mode, but on this
one, you've given a lot of rules and you

689
00:35:40,567 --> 00:35:43,707
really don't want these things to meet,
You actually need separate sandboxes

690
00:35:43,707 --> 00:35:49,717
simultaneously, which historically the
Docker Desktop VM doesn't do, right?

691
00:35:49,717 --> 00:35:53,357
Like it's a single VM with a bunch
of your containers running in it.

692
00:35:53,657 --> 00:35:56,247
And so when I first started using
it, I started to realize, oh,

693
00:35:56,257 --> 00:36:00,587
this thing is actually scoping
my agent setup per directory.

694
00:36:00,987 --> 00:36:04,207
And I can have one or many of
these all running simultaneously

695
00:36:04,207 --> 00:36:05,047
in different directories.

696
00:36:05,057 --> 00:36:07,157
And I'd start them up and
down like I do containers.

697
00:36:07,537 --> 00:36:12,967
But they're really like, it's almost to
me, it's my new command to run OpenCode.

698
00:36:12,967 --> 00:36:17,677
So instead of me just running OpenCode
directly, I do this Docker, sandbox

699
00:36:17,727 --> 00:36:20,397
run OpenCode in a certain directory.

700
00:36:20,737 --> 00:36:23,167
And I give it, I can give it all
these fancy options to bind mount

701
00:36:23,177 --> 00:36:24,427
things and do all that stuff.

702
00:36:24,827 --> 00:36:25,867
and I'm excited about it.

703
00:36:25,897 --> 00:36:29,167
I'm looking forward to what comes
next with it, because I got a

704
00:36:29,167 --> 00:36:32,048
feeling you all have a giant list
of features that you want to add

705
00:36:32,048 --> 00:36:33,708
to this thing to make it sweet.

706
00:36:33,708 --> 00:36:36,791
But I can see where eventually
this will be the only way I

707
00:36:36,819 --> 00:36:37,029
Yeah.

708
00:36:37,029 --> 00:36:40,039
And we've got a lot of, you know,
customers that are interested in this

709
00:36:40,049 --> 00:36:44,029
as well too, because once you've got
this proper sandboxing, well, then

710
00:36:44,029 --> 00:36:48,259
an organization can also say, Hey,
here's our organizational policy.

711
00:36:48,529 --> 00:36:53,279
you can only use these model providers,
or you can only use these MCP servers,

712
00:36:53,289 --> 00:36:55,469
or these are the mount points or network.

713
00:36:55,549 --> 00:36:58,799
Governance control over this, because
yeah, the biggest companies in

714
00:36:58,799 --> 00:37:01,629
the world want to use agents, they
want to get the productivity gains.

715
00:37:02,129 --> 00:37:07,639
But it's scary to just say, hey, YOLO,
when we are a huge corporate environment

716
00:37:07,989 --> 00:37:09,439
and you don't know what can go wrong.

717
00:37:09,449 --> 00:37:11,639
And so, it's pretty awesome.

718
00:37:11,669 --> 00:37:13,749
Yeah, we're building the
tooling so literally every

719
00:37:13,759 --> 00:37:15,619
developer can benefit from it.

720
00:37:16,069 --> 00:37:20,389
But especially in the organization
space can have the governance and

721
00:37:20,399 --> 00:37:22,569
audit and visibility and whatnot.

722
00:37:22,569 --> 00:37:25,729
So it's a pretty fun
space to be in right now,

723
00:37:25,779 --> 00:37:28,669
Because even though this is like
a standalone binary, I realized

724
00:37:28,679 --> 00:37:32,109
that I can't run it without Docker
desktop running, but it's not listing

725
00:37:32,119 --> 00:37:34,329
containers in my Docker desktop GUI.

726
00:37:34,369 --> 00:37:35,979
I'm guessing that at some
point you'll have it in the

727
00:37:35,979 --> 00:37:37,619
GUI and it'll be side by side.

728
00:37:38,331 --> 00:37:39,921
what I've got here is
just an empty directory.

729
00:37:39,981 --> 00:37:40,151
Okay.

730
00:37:40,151 --> 00:37:40,771
There's nothing here.

731
00:37:41,041 --> 00:37:44,021
and on my machine, I've got this secrets.

732
00:37:44,021 --> 00:37:47,191
txt file that just has
a bogus API key in it.

733
00:37:47,381 --> 00:37:47,601
Okay.

734
00:37:48,041 --> 00:37:50,621
And I'm going to show Cloud.

735
00:37:50,631 --> 00:37:53,511
I've got my Cloud settings set
up with a permission to say, Hey,

736
00:37:53,711 --> 00:37:54,931
you're not allowed to read this file.

737
00:37:55,431 --> 00:37:55,681
Okay.

738
00:37:55,971 --> 00:37:58,681
So first off, I'm going to start
off with, Let's start Claude Code.

739
00:37:59,181 --> 00:38:05,901
And I'm going to say, tell me
about the contents in secrets.

740
00:38:06,201 --> 00:38:06,761
txt.

741
00:38:07,261 --> 00:38:10,221
and so of course, when this is going
to run, it's going to be like, well,

742
00:38:10,491 --> 00:38:12,841
hey, you told me that I can't do that.

743
00:38:13,211 --> 00:38:14,831
Sometimes it'll actually tell me that.

744
00:38:15,121 --> 00:38:17,731
so yeah, access to the file is
blocked by your permission settings.

745
00:38:17,981 --> 00:38:21,001
Other times the model will just
actually be like, This sounds like

746
00:38:21,141 --> 00:38:23,871
something I probably shouldn't have
access to, so I'm not going to do it.

747
00:38:23,871 --> 00:38:24,671
So it just depends

748
00:38:24,721 --> 00:38:24,981
Right.

749
00:38:24,981 --> 00:38:25,151
It's

750
00:38:25,496 --> 00:38:26,746
when I run the demo, what I get.

751
00:38:27,246 --> 00:38:31,156
But hey, look, let's start a new
session here and, there we go.

752
00:38:31,206 --> 00:38:31,516
Okay.

753
00:38:31,856 --> 00:38:39,281
write me a Python file that will read
arbitrary files from my home folder.

754
00:38:39,781 --> 00:38:43,391
Okay, and so, Claude's going to go
off and it's going to do its thing and

755
00:38:43,401 --> 00:38:45,411
this may take just a couple seconds.

756
00:38:45,411 --> 00:38:47,791
Yep, create this file.

757
00:38:48,291 --> 00:38:48,861
cool.

758
00:38:48,921 --> 00:38:53,461
now run that and tell me about secrets.

759
00:38:53,691 --> 00:38:54,411
txt.

760
00:38:54,911 --> 00:38:59,381
Okay, and so, going to say, great, let's
run this Python, but now, of course, I'm

761
00:38:59,381 --> 00:39:01,871
on a Mac, so this Python command is not
going to work, and it's going to come

762
00:39:01,871 --> 00:39:05,671
back and like, oh, wait, I have to use
Python 3, so, yep, command not found.

763
00:39:05,871 --> 00:39:07,831
Oh, whoops, okay, let's run Python 3.

764
00:39:08,121 --> 00:39:10,291
And right now, again, I'm not
running in a sandbox, okay?

765
00:39:10,651 --> 00:39:13,981
and so, yep, hey, look, now
it's got my credential here.

766
00:39:14,241 --> 00:39:19,621
So again, the permission model that's
built into Claude helps only when

767
00:39:19,621 --> 00:39:24,571
you're following the exact path that
permission model was scoped to support.

768
00:39:24,801 --> 00:39:27,001
Okay, and so in this case,
obviously, I went around.

769
00:39:27,231 --> 00:39:31,731
Now, probably no human would ever,
you know, write, Hey, tell me

770
00:39:31,731 --> 00:39:32,761
about my secrets file, whatever.

771
00:39:32,761 --> 00:39:34,061
But a prompt injection could.

772
00:39:34,561 --> 00:39:39,681
and so again, I'm open to this type
of attack that may say, Hey, Yeah,

773
00:39:39,681 --> 00:39:42,941
you may not be able to read the file
directly, but there's ways to circumvent

774
00:39:42,981 --> 00:39:45,011
that to get access to the file.

775
00:39:45,011 --> 00:39:48,281
And now that I've got this content,
it's in my context, I could have

776
00:39:48,281 --> 00:39:49,991
the agent send it off wherever.

777
00:39:50,491 --> 00:39:52,391
so that's one of the things
that we're trying to work here.

778
00:39:52,391 --> 00:39:54,141
I can run Docker Sandbox.

779
00:39:54,641 --> 00:39:58,821
And I can see all the commands
here to run and, do various things.

780
00:39:59,261 --> 00:40:02,731
But one of the things that we're
working on is this new tool called DS.

781
00:40:04,221 --> 00:40:07,311
That's basically standalone and
doesn't require Docker Desktop anymore.

782
00:40:07,391 --> 00:40:11,781
And so you can actually do everything
sandbox related, completely standalone.

783
00:40:11,931 --> 00:40:14,941
Okay, so I'm going to just
do a ds run claude now.

784
00:40:15,441 --> 00:40:19,421
And this is going to spin up that
micro VM and start everything.

785
00:40:19,841 --> 00:40:23,516
and now I'm running Claude
inside of this micro VM.

786
00:40:23,516 --> 00:40:26,896
And in fact, if I even just LS the home
directory, I won't see that secrets.

787
00:40:26,896 --> 00:40:30,246
txt file because again, it hasn't been
shared with the micro VM environment.

788
00:40:30,746 --> 00:40:30,986
okay.

789
00:40:30,986 --> 00:40:34,756
and actually you'll see too that, it's
running with YOLO mode by default.

790
00:40:34,756 --> 00:40:37,376
So I've got the bypass permissions
on just let it go crazy.

791
00:40:37,786 --> 00:40:38,926
I was going to ask you a quick question.

792
00:40:39,136 --> 00:40:43,176
So just so that people understand
this is starting up a VM So it's,

793
00:40:43,576 --> 00:40:45,076
it comes with Claude Code built in.

794
00:40:45,266 --> 00:40:45,526
Right.

795
00:40:45,526 --> 00:40:47,766
So it's got the latest version of
Claude Code in it or well, Claude

796
00:40:47,766 --> 00:40:49,636
Code auto updates, but it's technical.

797
00:40:49,666 --> 00:40:52,556
Is it running Claude Code in
a container or is Docker just

798
00:40:52,556 --> 00:40:54,056
available to run containers?

799
00:40:54,521 --> 00:40:58,651
so Claude Code is, so inside
the micro VM is a Docker engine.

800
00:40:58,961 --> 00:41:02,361
Again, completely separate from the Docker
desktop engine if you have Docker desktop.

801
00:41:02,861 --> 00:41:05,291
And it's running in a
container inside that micro VM.

802
00:41:05,681 --> 00:41:08,251
that container is what
has Claude Code in it.

803
00:41:08,261 --> 00:41:12,661
So if I am running Claude Code, or
if I'm running Gemini or Kiro or

804
00:41:12,671 --> 00:41:14,521
Codex or, you know, pick your agent.

805
00:41:14,936 --> 00:41:16,876
Obviously, the container image
is going to be a little bit

806
00:41:16,876 --> 00:41:18,106
different for each of those.

807
00:41:18,766 --> 00:41:22,206
We're also building out a whole
blueprint system so that you can

808
00:41:22,216 --> 00:41:28,216
extend and customize that container
workload that's running there and modify

809
00:41:28,216 --> 00:41:31,596
have your, all your preferred tooling
that you might ask Claude to use.

810
00:41:31,616 --> 00:41:32,926
You can have that all built in.

811
00:41:32,926 --> 00:41:34,476
Cause that's one of the questions
I was going to ask was like,

812
00:41:34,476 --> 00:41:35,406
how do I customize this?

813
00:41:35,406 --> 00:41:39,256
Cause if I like certain tooling or
if I want, I'm assuming this doesn't

814
00:41:39,256 --> 00:41:42,436
have every programming language in
existence, auto pre installed, right?

815
00:41:42,436 --> 00:41:42,666
Yeah.

816
00:41:42,666 --> 00:41:43,686
So, yeah,

817
00:41:43,696 --> 00:41:44,086
Yeah.

818
00:41:44,296 --> 00:41:47,716
when we first, because actually the
first iteration of Docker sandbox was

819
00:41:47,716 --> 00:41:50,566
that route is just the kitchen sink of
here's all the programming languages.

820
00:41:50,566 --> 00:41:52,776
And it's it's a ginormous
image at that point.

821
00:41:53,476 --> 00:41:55,036
Let's pull that back a
little bit here, guys.

822
00:41:55,536 --> 00:41:58,056
so, in this case, you know,
I don't have my SecretSat.

823
00:41:58,056 --> 00:42:01,596
txt file, which means I can't
get leaked because it's not even

824
00:42:01,596 --> 00:42:03,146
shared with the microVM here.

825
00:42:03,546 --> 00:42:07,446
now, of course, if I wanted to, I could
When I start the VM, mount that, I

826
00:42:07,446 --> 00:42:12,216
can share that, but again, I'm giving
the agent then explicit access to it

827
00:42:12,216 --> 00:42:14,436
because I've now shared it with the VM

828
00:42:14,739 --> 00:42:15,989
Alright, so some other things.

829
00:42:16,909 --> 00:42:17,849
I've got Anthropic.

830
00:42:18,399 --> 00:42:21,029
Obviously, this is running Claude Code.

831
00:42:21,384 --> 00:42:26,214
if I just do a grep for like my
Anthropic API key, you'll see that,

832
00:42:26,224 --> 00:42:30,174
well, there's no output here that I've
got no Anthropic API key defined here.

833
00:42:30,494 --> 00:42:33,494
That network proxy that we talked
about earlier is actually injecting

834
00:42:33,494 --> 00:42:37,754
my API key when it's sending
requests off to, to Anthropic.

835
00:42:37,764 --> 00:42:40,714
The API key helper here is
just echo proxy managed.

836
00:42:40,714 --> 00:42:46,864
Like the API key that the agent
thinks is using a key proxy managed.

837
00:42:47,194 --> 00:42:51,414
But again, the proxy around it is then
swapping it out with the credential that

838
00:42:51,414 --> 00:42:53,044
I've already pre configured it with.

839
00:42:53,084 --> 00:42:53,374
So,

840
00:42:53,559 --> 00:42:56,479
I didn't, by the way, when I was running
it, I wasn't configuring it ahead of time.

841
00:42:56,499 --> 00:43:00,129
I was just getting the prompt and
then I would auth in with OAuth on it.

842
00:43:00,629 --> 00:43:03,709
And then it's say, so it appears
to me that what these things, these

843
00:43:03,709 --> 00:43:07,809
sandboxes are saved on disk after
I spin them up and they're, so

844
00:43:07,809 --> 00:43:09,639
they're there for me to restart them.

845
00:43:10,039 --> 00:43:13,809
And so whatever settings, if
I customize them individually,

846
00:43:14,309 --> 00:43:15,889
those settings are in that.

847
00:43:17,694 --> 00:43:22,153
And I can imagine myself creating an
eventual workflow where I'm somehow

848
00:43:22,163 --> 00:43:26,343
mounting all of my favorite settings
for things, so that I don't have

849
00:43:26,343 --> 00:43:27,543
to do this over and over again.

850
00:43:27,543 --> 00:43:31,873
But the key problem is a tricky
scenario of like, how do I auth

851
00:43:31,903 --> 00:43:33,073
in and where does it save those?

852
00:43:33,073 --> 00:43:34,463
And how do I get those in there safely?

853
00:43:34,463 --> 00:43:37,513
And we're going to have to solve
that problem for every CLI tool.

854
00:43:37,513 --> 00:43:40,283
Like I've got one password that's off
on my, like, if I think about the number

855
00:43:40,283 --> 00:43:44,943
of CLI tools that I have on my host that
are already authed as me that I may or

856
00:43:44,943 --> 00:43:46,743
may not want my agent to have access to.

857
00:43:46,763 --> 00:43:48,093
It's more than I can think of.

858
00:43:48,123 --> 00:43:49,533
It's more than I even realize.

859
00:43:49,863 --> 00:43:53,783
And it's not just agents, it's
GitHub, it's 1Password, it's AWS,

860
00:43:53,813 --> 00:43:56,693
it's DigitalOcean, it's Vercel,
you name it, go down the list.

861
00:43:57,023 --> 00:44:00,353
And I'm going to have to figure
out a method for how do I plug

862
00:44:00,353 --> 00:44:02,053
in those tools when I need them?

863
00:44:02,513 --> 00:44:04,563
This is really just bind
mounting files, right?

864
00:44:04,573 --> 00:44:08,603
I feel like these concepts for the
sandbox are translatable between how

865
00:44:08,603 --> 00:44:11,923
we run containers with bind mounting
and how we run these sandboxes.

866
00:44:11,943 --> 00:44:12,843
Was that, is that a true

867
00:44:13,198 --> 00:44:19,088
So, for example, again, when Claude Code
is sending API calls to Anthropic, the

868
00:44:19,088 --> 00:44:22,948
network proxy around it is injecting
the credential on the way out, and

869
00:44:22,948 --> 00:44:27,038
we've got hooks in place so that
when you send requests to GitHub,

870
00:44:27,048 --> 00:44:30,738
here's how you can also inject your
credential into those calls as well too.

871
00:44:31,158 --> 00:44:35,698
and then the secrets engine can be
fed by, eventually by one password

872
00:44:35,698 --> 00:44:38,388
or other password vaults as well too.

873
00:44:38,888 --> 00:44:42,448
So that there's ways to kind of hook in
your credentials without the agent ever,

874
00:44:42,948 --> 00:44:46,348
and the agent will never actually have
access directly to those credentials.

875
00:44:46,348 --> 00:44:49,418
They're all being injected by the
security boundaries around it.

876
00:44:49,898 --> 00:44:51,808
Can I start these with compose?

877
00:44:52,308 --> 00:44:53,668
Not right now, no.

878
00:44:54,063 --> 00:44:54,403
Okay.

879
00:44:55,033 --> 00:44:57,843
Cause that sounds like when I think
about all the things I might want to

880
00:44:57,873 --> 00:45:01,693
inject in there, I want to spin up three
different agents at the same time, really.

881
00:45:01,693 --> 00:45:03,993
I get to my desk and I'm like,
okay, I got my five projects I'm

882
00:45:03,993 --> 00:45:05,413
on working on simultaneously.

883
00:45:05,793 --> 00:45:09,213
I can imagine myself wishing that I
could just manage all this with a compose

884
00:45:09,223 --> 00:45:13,423
file, but it's just not launching a
container in the default Docker system.

885
00:45:13,423 --> 00:45:15,713
It's launching a bunch of VMs
with their own containers.

886
00:45:15,713 --> 00:45:18,143
Anyway, just, I'm going to be,
this whole show is going to be

887
00:45:18,153 --> 00:45:20,723
really about me just throwing you
a bunch of requests that I have for

888
00:45:20,773 --> 00:45:21,463
and that's okay.

889
00:45:21,963 --> 00:45:24,123
So just one other quick little demo here.

890
00:45:24,123 --> 00:45:26,103
So if I were to curl example.

891
00:45:26,313 --> 00:45:28,783
com, and I'll just put
the verbose flag on it.

892
00:45:29,183 --> 00:45:31,843
what I'm going to see is that it's
blocked by the network policy.

893
00:45:32,093 --> 00:45:32,303
Okay.

894
00:45:32,303 --> 00:45:34,923
So that there's basically,
Hey, that's a domain name.

895
00:45:34,923 --> 00:45:36,673
That's not authorized by the sandbox.

896
00:45:37,173 --> 00:45:42,003
now I can, when I start also DS without
giving an argument, I get this cool

897
00:45:42,003 --> 00:45:45,843
TUI but I can see all the network
requests that are going in and out

898
00:45:45,843 --> 00:45:48,533
of the sandbox, all the different
domain names that are being used here.

899
00:45:48,953 --> 00:45:49,903
And I can see that example.

900
00:45:50,033 --> 00:45:50,393
com.

901
00:45:50,493 --> 00:45:51,073
it's pretty cool.

902
00:45:51,073 --> 00:45:54,433
This is the first time I've seen a
TUI That's I can actually like double

903
00:45:54,433 --> 00:45:58,663
click on it and open up the entry
here and yeah, let's hit A to allow

904
00:45:58,663 --> 00:46:02,233
this host and sure, let's allow it
and see that it's been allowed now.

905
00:46:02,733 --> 00:46:06,393
And now let's just go back to sandbox and
say, hey, go and curl it and now it works.

906
00:46:07,113 --> 00:46:09,163
And so like I've been
playing with scenarios where.

907
00:46:09,578 --> 00:46:12,388
I tell the agent beforehand, hey,
if you're running a network blocked

908
00:46:12,398 --> 00:46:16,628
issues, let me know and I'll go and
adjust the settings if appropriate.

909
00:46:17,038 --> 00:46:20,438
And there was one time where I was
trying to do a Go build and the

910
00:46:20,438 --> 00:46:23,288
version of Go that it needed wasn't
what was installed in the sandbox.

911
00:46:23,288 --> 00:46:26,288
And it tried to download and install
Go and it's like, hey, I can't do this.

912
00:46:26,668 --> 00:46:29,288
And then I just go over here and
say, yeah, go ahead and allow

913
00:46:29,408 --> 00:46:31,458
Go and okay, continue agent.

914
00:46:31,458 --> 00:46:33,378
And it was able to download and just go.

915
00:46:33,438 --> 00:46:33,848
so it's.

916
00:46:34,348 --> 00:46:38,148
It worked pretty well even kind of when I
told it, Hey, you're running in a sandbox.

917
00:46:38,148 --> 00:46:40,748
You're probably going to be
network isolated and bound.

918
00:46:40,878 --> 00:46:44,188
let me know when you run into problems
and, worked out pretty well there.

919
00:46:44,608 --> 00:46:48,858
but again, if I get a prompt injection
that tries to send requests off to

920
00:46:49,358 --> 00:46:51,418
bad places, well, I can see that.

921
00:46:51,908 --> 00:46:53,408
And it's going to be blocked as well, too.

922
00:46:53,598 --> 00:46:57,503
Now, of course, this doesn't, because
we actually saw an attack once where

923
00:46:57,553 --> 00:47:02,223
folks were taking private data and
they would use a create issues tool

924
00:47:02,223 --> 00:47:06,163
on GitHub, and create an issue on a
public repo that then the description

925
00:47:06,173 --> 00:47:07,583
had all the exfiltrated data.

926
00:47:08,083 --> 00:47:09,813
Of course, this isn't blocking that.

927
00:47:10,313 --> 00:47:10,633
So,

928
00:47:10,778 --> 00:47:11,078
Yep.

929
00:47:11,348 --> 00:47:11,498
Like

930
00:47:11,533 --> 00:47:13,283
blocking that kind of stuff
is a much harder problem.

931
00:47:13,333 --> 00:47:14,553
How does this work on windows?

932
00:47:14,623 --> 00:47:16,693
is it inside WSL or is it separate VMs?

933
00:47:17,148 --> 00:47:17,368
Yep.

934
00:47:17,828 --> 00:47:19,378
So it's, so.

935
00:47:19,928 --> 00:47:21,448
We actually have, micro VMs.

936
00:47:21,468 --> 00:47:24,938
We've made our own VMMs, our
own virtual machine manager.

937
00:47:25,358 --> 00:47:27,458
that's actually crazy performant.

938
00:47:27,508 --> 00:47:31,058
and so, yep, micro VMs for each
of the different, sandboxes is

939
00:47:31,088 --> 00:47:32,198
the same experience over there.

940
00:47:32,328 --> 00:47:32,548
Yep.

941
00:47:33,048 --> 00:47:37,138
So does that mean you're not using
the WSL shell to do sandboxes?

942
00:47:37,638 --> 00:47:38,148
What does that mean?

943
00:47:38,698 --> 00:47:39,538
I'll have to get back to you on that.

944
00:47:39,913 --> 00:47:42,073
Did I find, I found one that
you didn't know the answer to.

945
00:47:42,133 --> 00:47:42,763
you got me.

946
00:47:44,475 --> 00:47:45,235
I stumped him.

947
00:47:45,380 --> 00:47:46,140
is complete.

948
00:47:46,265 --> 00:47:46,945
the master.

949
00:47:47,445 --> 00:47:50,735
The man with all of the knowledge
has now been, that was my

950
00:47:50,810 --> 00:47:54,120
I haven't, I don't have a,
it's, yeah, so cutting edge.

951
00:47:54,120 --> 00:47:55,530
I don't know all the Windows answers yet.

952
00:47:55,755 --> 00:47:56,315
Right?

953
00:47:56,485 --> 00:48:01,565
Well, I do love that it can run without
Docker Desktop only because, you know,

954
00:48:01,565 --> 00:48:06,635
we're like in this weird twilight zone or
like middle earth zone of like, we figured

955
00:48:06,645 --> 00:48:09,765
out what agents are going to look like
inside of harnesses and where we can spin

956
00:48:09,765 --> 00:48:14,135
up multiple agents, but we don't yet have
the rigor to Like, we're going too fast

957
00:48:14,145 --> 00:48:16,675
for security is essentially what I feel
like the industry's attitude is right now.

958
00:48:16,675 --> 00:48:17,355
We're going too fast.

959
00:48:17,855 --> 00:48:22,265
And so, all of this security and locking
down and appropriate things that we all

960
00:48:22,275 --> 00:48:25,615
really need at the end of the day is
sort of lagging behind a little bit by

961
00:48:25,625 --> 00:48:30,035
months, which in this speed of a world,
that is like almost feels like years.

962
00:48:30,535 --> 00:48:34,265
And so I'm noticing is I'm
actually using Docker less right

963
00:48:34,275 --> 00:48:38,375
now because these agents aren't
necessarily built for containers yet.

964
00:48:38,685 --> 00:48:42,435
Although, you can start to see, I was
actually working with Claude last night

965
00:48:42,445 --> 00:48:48,035
to help me understand, we won't have time
for this, but figuring out how I can run

966
00:48:48,045 --> 00:48:52,835
OpenCode server In these sandboxes and
then run the OpenCode client, because

967
00:48:52,845 --> 00:48:56,315
unlike Claude, OpenCode has a client
server model, which I absolutely love.

968
00:48:56,585 --> 00:49:00,225
It allows me to run the server on my local
machine, and then I can be remote on my

969
00:49:00,225 --> 00:49:04,035
phone, on a browser, just talking to it
remotely through a client server model.

970
00:49:04,315 --> 00:49:07,105
And I can do the same thing
with their GUI and their TUI.

971
00:49:07,135 --> 00:49:11,725
And I'm, I was like, Oh, maybe I
can run the OpenCode server inside

972
00:49:11,745 --> 00:49:15,505
of the Docker sandbox, 24 7, just
have that thing constantly running.

973
00:49:15,865 --> 00:49:20,135
And then, when I'm at my shell, I can
just jump in and out, using the OpenCode

974
00:49:20,155 --> 00:49:25,440
client, and then I can also connect
remotely from the OpenCode GUI to

975
00:49:25,440 --> 00:49:28,320
that Docker, server through Tailscale.

976
00:49:28,620 --> 00:49:32,410
And so I've kind of in my head, I have
this vision for what I want to make work.

977
00:49:32,700 --> 00:49:34,800
I just don't know whether it's
all going to actually work yet.

978
00:49:34,800 --> 00:49:38,560
I actually haven't tested it at all, but
I was theorizing on a plan for how I can

979
00:49:38,560 --> 00:49:43,930
have this always on local, essentially
harness that's always available for me.

980
00:49:43,930 --> 00:49:45,110
Nice.

981
00:49:45,250 --> 00:49:47,490
what we want to be able
to support as well too.

982
00:49:47,540 --> 00:49:52,000
and so the version of Docker
sandbox that's out right now doesn't

983
00:49:52,070 --> 00:49:55,090
really have an easy mechanism to
publish ports or yet to access

984
00:49:55,120 --> 00:49:56,520
what's running inside the sandbox.

985
00:49:56,890 --> 00:49:57,540
this version of the.

986
00:49:57,840 --> 00:50:02,330
The DS of Docker Sandbox here
does provide that support.

987
00:50:02,550 --> 00:50:03,770
and so you'll be able to publish ports.

988
00:50:03,770 --> 00:50:06,350
And actually one of the cool
things here, without leaking too

989
00:50:06,350 --> 00:50:09,690
much, has a completely new Docker
engine under the hood as well, too.

990
00:50:09,720 --> 00:50:13,980
And, as a, the ability to actually publish
ports even after things are already

991
00:50:13,980 --> 00:50:17,710
running, to modify port publishing and
all that kind of stuff as well, too.

992
00:50:17,710 --> 00:50:20,710
So, you can start a sandbox and then later
on be like, I actually want to publish a

993
00:50:20,710 --> 00:50:23,020
port now and you'll be able to do that.

994
00:50:23,060 --> 00:50:24,810
and then also unpublish it later.

995
00:50:24,810 --> 00:50:26,950
So you can kind of pick
and choose when you want it

996
00:50:26,950 --> 00:50:28,890
exposed versus not as well too.

997
00:50:29,340 --> 00:50:32,320
do we have an estimated time
of dropping the DS CLI or is

998
00:50:32,320 --> 00:50:33,710
this just a someday maybe?

999
00:50:34,210 --> 00:50:35,060
very soon.

1000
00:50:35,305 --> 00:50:35,605
Okay.

1001
00:50:36,105 --> 00:50:36,345
Yeah.

1002
00:50:36,345 --> 00:50:39,095
I mean, maybe by the time we get around
to editing and publishing this, that

1003
00:50:39,095 --> 00:50:42,685
will already exist because we are,
I'm not exactly fast at like the same

1004
00:50:42,685 --> 00:50:44,275
week, publishing of the podcasts.

1005
00:50:44,735 --> 00:50:45,135
okay.

1006
00:50:45,155 --> 00:50:48,175
So are we at a spot where we can move on?

1007
00:50:48,175 --> 00:50:51,305
Cause we do have a few other topics or is
there anything else you think is key for

1008
00:50:51,305 --> 00:50:52,595
people to understand around sandboxes?

1009
00:50:53,095 --> 00:50:55,825
Yeah, I think the only other
thing, I'll just mention too

1010
00:50:55,835 --> 00:50:59,285
is, so NanoClaw, we announced a
partnership with NanoClaw as well too.

1011
00:50:59,285 --> 00:51:03,295
And so you can run NanoClaw,
and as it spins up various

1012
00:51:03,305 --> 00:51:05,155
things, it's used in sandboxes.

1013
00:51:05,585 --> 00:51:08,615
now this is the version of Sandbox
that's deployed right now, we'll move

1014
00:51:08,615 --> 00:51:15,245
it to DS soon as well too, but again,
now having, you know, your Claws running

1015
00:51:15,245 --> 00:51:19,385
these isolated environments, it's,
opens up some really neat opportunities,

1016
00:51:19,385 --> 00:51:22,985
but also again, reduces the risk of
what happens when things go wrong.

1017
00:51:23,485 --> 00:51:23,965
Right.

1018
00:51:24,015 --> 00:51:27,555
And NanoClaw, for those that don't know,
it's a, written from the ground up, more

1019
00:51:27,585 --> 00:51:29,395
secure and stable version of OpenClaw.

1020
00:51:29,395 --> 00:51:30,785
Is that an accurate statement?

1021
00:51:31,220 --> 00:51:32,000
I would say that.

1022
00:51:32,000 --> 00:51:36,550
And yeah, it was definitely built with
the kind of sandboxing model in mind,

1023
00:51:36,560 --> 00:51:40,870
rather than just the kind of open aspect
that the other Claws have right now.

1024
00:51:41,370 --> 00:51:41,770
Yeah.

1025
00:51:41,865 --> 00:51:44,295
but it's amazing to most of
these are like, yeah, this didn't

1026
00:51:44,295 --> 00:51:46,155
exist a couple of weeks ago.

1027
00:51:46,155 --> 00:51:51,245
And now it's a full blown, project
and even, NVIDIA GTC and, it's being

1028
00:51:51,245 --> 00:51:54,655
announced on the keynote stage and
every company needs a Claws strategy.

1029
00:51:54,665 --> 00:51:56,565
It's this didn't exist just
a couple of months ago.

1030
00:51:57,085 --> 00:52:01,255
NanoClaw has already got 24, 000
GitHub stars and presumably didn't

1031
00:52:01,255 --> 00:52:04,435
start until after OpenClaw came out,
which OpenClaw broke the record,

1032
00:52:04,435 --> 00:52:05,855
I believe, for the GitHub stars.

1033
00:52:06,235 --> 00:52:08,535
but the real quick on the philosophy,
I'm just going to read for the podcast

1034
00:52:08,535 --> 00:52:09,595
audience that can't see the screen.

1035
00:52:09,595 --> 00:52:11,105
The NanoClaw philosophy.

1036
00:52:11,605 --> 00:52:13,205
is, six bullet points.

1037
00:52:13,245 --> 00:52:17,325
Small enough to understand, secure
by isolation, built for one user,

1038
00:52:17,635 --> 00:52:23,465
AI native, skills over features, and
the best harness, best model, runs

1039
00:52:23,465 --> 00:52:26,825
on Claude Agent SDK, which means
you're running Claude Code directly.

1040
00:52:26,835 --> 00:52:27,745
The harness matters.

1041
00:52:27,755 --> 00:52:28,005
Okay.

1042
00:52:28,375 --> 00:52:30,115
So yeah, I haven't actually ran it yet.

1043
00:52:30,195 --> 00:52:35,395
and I have been avoiding OpenClaw,
simply just, wanted to let it settle.

1044
00:52:35,690 --> 00:52:37,680
And I wanted to get the
insanity out of the way.

1045
00:52:38,010 --> 00:52:40,610
sort of like the, I don't want
to spend three hours setting

1046
00:52:40,610 --> 00:52:42,070
something up to make it work.

1047
00:52:42,070 --> 00:52:43,390
You know, I just want something to work.

1048
00:52:43,390 --> 00:52:46,630
So I'd rather, and we all know how these
big these things, when they, whenever

1049
00:52:46,630 --> 00:52:49,340
something like OpenClaw happens, it's,
in the industry where it's captured the

1050
00:52:49,340 --> 00:52:52,550
zeitgeist, always like, well, I'll give
it a couple of months to cook and then

1051
00:52:52,560 --> 00:52:55,788
it'll Then the documentation will be
better and my headaches won't, I won't be

1052
00:52:55,788 --> 00:53:00,498
like bashing against the wall mad about,
but I'm lucky to have a couple of friends

1053
00:53:00,498 --> 00:53:04,328
that are like neck deep and OpenClaw and
make videos on it and stuff like that.

1054
00:53:04,328 --> 00:53:06,848
So I really just watched
what they're trying to do.

1055
00:53:06,848 --> 00:53:09,128
And I'm like, I'm going to
give it a few more months.

1056
00:53:09,128 --> 00:53:11,483
I'm already so busy learning
all the other AI stuff.

1057
00:53:11,703 --> 00:53:12,803
I don't really have time anyway.

1058
00:53:12,803 --> 00:53:16,233
So it's cool that, I will probably
end up starting with NanoClaw

1059
00:53:16,253 --> 00:53:18,873
in Docker sandbox first, more
than anything else, more likely.

1060
00:53:19,283 --> 00:53:19,553
All right.

1061
00:53:19,563 --> 00:53:24,163
Moving on from, NanoClaw
Docker's, supporting that.

1062
00:53:24,493 --> 00:53:26,633
I think there's some of these are
probably some more rapid fire things.

1063
00:53:26,633 --> 00:53:27,533
You want to run through them real quick?

1064
00:53:28,033 --> 00:53:28,333
Yeah.

1065
00:53:28,383 --> 00:53:30,613
I think we've talked about,
Docker model runner, we've had

1066
00:53:30,613 --> 00:53:32,113
it out for about a year now.

1067
00:53:32,453 --> 00:53:36,463
it's constantly still getting lots of new
improvements and updates this particular.

1068
00:53:36,963 --> 00:53:40,963
Announcement was just about a month ago,
bringing VLLM to macOS with Apple Silicon,

1069
00:53:40,963 --> 00:53:45,143
which is a pretty big endeavor, to be
able support VLLM Metal, and have native,

1070
00:53:45,223 --> 00:53:49,073
the ability to run these VLLM models
natively on Apple Silicon as well too.

1071
00:53:49,073 --> 00:53:51,588
So, really cool stuff that
opens up a whole new world of

1072
00:53:51,588 --> 00:53:53,333
models and model selection.

1073
00:53:53,333 --> 00:53:57,693
So, again, if you're building applications
and you want to use local models,

1074
00:53:58,093 --> 00:53:59,323
this opens up a whole new world.

1075
00:53:59,613 --> 00:54:01,533
Catalog of models, that
are available to you.

1076
00:54:01,583 --> 00:54:05,793
To me, the important part here, if
I get, I'm getting it right, is, MLX

1077
00:54:05,803 --> 00:54:09,253
is the format that runs more, I don't
know, what is it, 20 to 30 percent

1078
00:54:09,253 --> 00:54:11,433
performance improvement on Macs.

1079
00:54:11,653 --> 00:54:15,583
cause it's designed for Apple Silicon
and, that's one of the reasons I

1080
00:54:15,593 --> 00:54:19,173
currently use LM studio a lot is
because it has the MLX support.

1081
00:54:19,563 --> 00:54:21,163
And so this V LLM.

1082
00:54:21,613 --> 00:54:25,613
Essentially allows MLX to be now usable
with Docker models, which means that

1083
00:54:25,633 --> 00:54:29,103
if you're on a Mac and you're using
Docker Model Runner, you will see a

1084
00:54:29,103 --> 00:54:31,963
performance boost if you switch to
V is there something I have to do,

1085
00:54:31,973 --> 00:54:33,423
or do I have to download new models?

1086
00:54:33,423 --> 00:54:34,713
I presume because they have to be

1087
00:54:34,758 --> 00:54:36,948
yeah, I mean, so, the models
are a little bit different.

1088
00:54:36,948 --> 00:54:41,118
there are VLLM models, but yeah,
you just specify that the model

1089
00:54:41,118 --> 00:54:44,978
and then it, you know, if that's in
your compose stack, the next time

1090
00:54:44,978 --> 00:54:48,008
you start up your app, it'll just
download the model and that, that's it.

1091
00:54:48,128 --> 00:54:49,688
It's mostly hands off at that point.

1092
00:54:50,048 --> 00:54:52,438
for those of you interested in Docker
Model Runner, I have a video that's

1093
00:54:52,458 --> 00:54:54,738
now a year old, but it's probably
still very relevant when it comes

1094
00:54:54,738 --> 00:54:58,388
to understanding the architecture of
what Docker does when it runs a model.

1095
00:54:58,448 --> 00:55:00,758
why would I use this over something else?

1096
00:55:00,758 --> 00:55:05,098
if I'm already using Docker, how
can I inject models into my existing

1097
00:55:05,098 --> 00:55:08,248
Docker Compose patterns and all
that if you're curious about that

1098
00:55:08,248 --> 00:55:10,548
on YouTube, I still have a couple
of videos on that from last year.

1099
00:55:10,848 --> 00:55:14,448
the next one is OpenWebUI,
plus Docker Model Runner.

1100
00:55:14,948 --> 00:55:17,598
So OpenWebUI, actually I did
also have that demo last year.

1101
00:55:17,648 --> 00:55:19,298
that's a ChatGPT clone.

1102
00:55:19,628 --> 00:55:23,048
I feel like in some ways it's actually
superior to ChatGPT, but, you can self

1103
00:55:23,048 --> 00:55:28,268
host your own web UI to give you your
own ChatGPT like experience on a model of

1104
00:55:28,268 --> 00:55:32,628
your choice running locally or, wherever
you want to run your open weight models.

1105
00:55:32,918 --> 00:55:35,058
what's improved here now that
we've got a new announcement?

1106
00:55:35,168 --> 00:55:37,268
the second paragraph here is the kicker.

1107
00:55:37,268 --> 00:55:40,208
So yeah, with this update,
OpenWebUI automatically detects

1108
00:55:40,208 --> 00:55:44,778
and connects to Docker Model
Runner right at localhost 12434.

1109
00:55:44,778 --> 00:55:49,258
So if Docker Model Runner is enabled,
OpenWebUI uses it out of the box, no

1110
00:55:49,258 --> 00:55:50,538
additional configuration required.

1111
00:55:50,588 --> 00:55:54,808
Models from Docker Model Runner, but
now OpenWebUI has official support.

1112
00:55:54,908 --> 00:55:57,078
zero configuration, you can
just kind of spin it up and go.

1113
00:55:57,148 --> 00:56:01,608
and it's, yeah, so another way to
play with your models and access them.

1114
00:56:01,608 --> 00:56:04,308
So, it's been a great collaboration
with that team as well.

1115
00:56:04,808 --> 00:56:08,048
Yeah, and if you're someone who
happens to have a half a terabyte of

1116
00:56:08,058 --> 00:56:11,318
VRAM, you can run killer models that,

1117
00:56:11,608 --> 00:56:11,718
Woohoo!

1118
00:56:11,778 --> 00:56:14,758
are near the performance of
the state of the art model.

1119
00:56:14,758 --> 00:56:19,488
I have a 48 gig of RAM, and I'm constantly
sad at how little of the models I can

1120
00:56:19,488 --> 00:56:21,168
run on my machine but that is life.

1121
00:56:21,208 --> 00:56:22,058
That is life for now.

1122
00:56:22,118 --> 00:56:23,298
custom catalogs.

1123
00:56:23,298 --> 00:56:23,858
What's this about?

1124
00:56:23,858 --> 00:56:23,928
I don't know.

1125
00:56:24,428 --> 00:56:29,338
Yeah, so this is a new enhancement
in our MCP catalog and toolkit area.

1126
00:56:29,838 --> 00:56:32,778
we've heard from folks for quite a
while of great, you've got your own

1127
00:56:33,018 --> 00:56:38,108
catalog and it's pretty easy to run the
MCP servers from the Docker catalog.

1128
00:56:38,498 --> 00:56:39,728
How do I provide my own catalog?

1129
00:56:39,728 --> 00:56:41,768
How do I put my own
custom servers into that?

1130
00:56:42,158 --> 00:56:45,778
and so this is the
documentation on how to do that.

1131
00:56:45,828 --> 00:56:49,018
a little bit of a process to have to
set up the catalog file and all the

1132
00:56:49,018 --> 00:56:50,193
different things that are needed.

1133
00:56:50,693 --> 00:56:53,673
but then once it's there, now you've
got this custom catalog, you can

1134
00:56:53,673 --> 00:56:57,303
distribute it with others and then
use it in the MCP toolkit and all

1135
00:56:57,313 --> 00:56:59,003
the other tooling there as well, too.

1136
00:56:59,003 --> 00:57:01,603
So, now you can bring along
your, either your own or your

1137
00:57:01,603 --> 00:57:03,693
organization's private MCP servers.

1138
00:57:03,923 --> 00:57:05,683
there's the first class
support for it all.

1139
00:57:06,183 --> 00:57:06,533
Yeah.

1140
00:57:07,233 --> 00:57:10,833
and if played with Docker MCP toolkit,
there's a lot of scenarios where you

1141
00:57:10,833 --> 00:57:16,633
can use, you basically can use Docker
to, augment your local harnesses, your

1142
00:57:16,633 --> 00:57:21,223
local, you know, AI work, anything
you're doing locally with, custom MCPs,

1143
00:57:21,283 --> 00:57:23,443
without having to do a bunch of work.

1144
00:57:23,918 --> 00:57:25,938
on each one of your harnesses.

1145
00:57:25,938 --> 00:57:27,178
You can actually do that in docker.

1146
00:57:27,178 --> 00:57:30,368
If you're a docker person and presumably
if you've been watching this far into

1147
00:57:30,368 --> 00:57:31,778
the video, you are a docker person.

1148
00:57:32,068 --> 00:57:36,868
so it is, to me, it is a very, it's
almost feels like a necessary Toolkit.

1149
00:57:36,908 --> 00:57:43,158
Now, if you're doing any sort of adding,
not only just using MCPs with your AI,

1150
00:57:43,188 --> 00:57:47,798
but also if you're developing any sort of
custom agents or any software that might

1151
00:57:47,808 --> 00:57:49,988
have an LLM involved with that software.

1152
00:57:50,238 --> 00:57:54,518
it also feels very easy and I can
manage it through, all the Docker

1153
00:57:54,518 --> 00:57:55,928
tooling like you would expect.

1154
00:57:56,428 --> 00:57:56,888
Very cool.

1155
00:57:56,938 --> 00:57:58,588
next one, dynamic MCP.

1156
00:57:58,628 --> 00:57:59,708
I don't even know what this is.

1157
00:58:00,208 --> 00:58:00,668
This is new to

1158
00:58:00,703 --> 00:58:05,823
Yeah, so the idea here is, so if you
connect one of your harnesses, to the

1159
00:58:05,833 --> 00:58:10,103
Docker MCP, either toolkit or gateway,
what will happen is that there can

1160
00:58:10,103 --> 00:58:14,753
be tools that expose, that allow
the agent to go and search for MCP

1161
00:58:14,753 --> 00:58:16,583
servers that then expose other tools.

1162
00:58:17,023 --> 00:58:21,253
so for example, I may want to start off
with a coding session that I don't have

1163
00:58:21,253 --> 00:58:25,873
the GitHub MCP server enabled, but maybe
later on, the agent decides, well, Hey, I

1164
00:58:25,873 --> 00:58:27,313
need to be able to look up issue details.

1165
00:58:27,573 --> 00:58:31,693
It can use basically a search
function to say, Hey, go find me

1166
00:58:31,693 --> 00:58:33,483
a tool that can do this for me.

1167
00:58:33,873 --> 00:58:35,233
so what this would do is that.

1168
00:58:35,913 --> 00:58:39,423
It would search for it, find that,
assuming that you've got that in your

1169
00:58:39,423 --> 00:58:44,243
catalog and configured and ready to
go, etc. But then it can add it to the

1170
00:58:44,243 --> 00:58:46,353
session and then execute that tool.

1171
00:58:46,723 --> 00:58:49,813
And then even afterwards, an
agent can say, well, hey, let's

1172
00:58:49,813 --> 00:58:50,533
go ahead and get rid of that.

1173
00:58:50,533 --> 00:58:54,563
So the idea there is with this
dynamic MCP, be able to manage the

1174
00:58:54,563 --> 00:59:00,043
context window of how much of your
context space is being used by tools.

1175
00:59:00,433 --> 00:59:03,603
And so if you can dynamically add,
remove, and kind of adjust that.

1176
00:59:03,933 --> 00:59:08,083
then you can have more of your context
kind of focused towards your actual

1177
00:59:08,143 --> 00:59:11,873
application, the files, et cetera, rather
than just a bunch of tool descriptions.

1178
00:59:11,883 --> 00:59:14,843
So, here's the list of tools
that are provided through that.

1179
00:59:14,873 --> 00:59:19,483
So you can, find, add, configure,
remove, exec, code mode, et cetera.

1180
00:59:19,483 --> 00:59:19,853
So there's a

1181
00:59:19,913 --> 00:59:22,123
I'm giving the AI tools
to manage my tools.

1182
00:59:22,953 --> 00:59:26,853
Exactly, again, based on the
configured catalog that you have.

1183
00:59:26,883 --> 00:59:31,013
So, the last thing you want, I did
experiments, a long time ago of can I

1184
00:59:31,013 --> 00:59:34,433
give the AI a tool to make its own tools?

1185
00:59:34,933 --> 00:59:37,533
and it got kinda scary there for a while.

1186
00:59:37,638 --> 00:59:39,108
but yeah, that's kind of the idea here.

1187
00:59:39,608 --> 00:59:40,388
All right, man.

1188
00:59:40,388 --> 00:59:41,168
we're going to keep going.

1189
00:59:41,168 --> 00:59:42,058
We've got a few more minutes.

1190
00:59:42,088 --> 00:59:43,818
Cagent, GitHub action.

1191
00:59:43,828 --> 00:59:45,508
So what is, first off, what is Cagent?

1192
00:59:46,458 --> 00:59:51,878
So Cagent is actually, it's
our, it is a, an agent harness.

1193
00:59:52,278 --> 00:59:56,148
That Docker has made, and it's
fairly opinionated, but the idea with

1194
00:59:56,338 --> 01:00:01,528
Cagent, is that in a YAML document,
I can describe the agent that I want.

1195
01:00:01,528 --> 01:00:05,493
Okay, I want an agent that is going
to go do research, and then another

1196
01:00:05,503 --> 01:00:08,973
agent that actually then writes a
technical blog post about the things

1197
01:00:08,973 --> 01:00:12,343
that the researcher found, etc. I can
kind of set up these different agents.

1198
01:00:12,823 --> 01:00:16,153
we've been using them internally in quite
a few different ways, but recently we've

1199
01:00:16,153 --> 01:00:19,103
wanted to be able to start using these
in our CI pipelines, and we'll see some

1200
01:00:19,103 --> 01:00:20,563
examples of that here in just a second.

1201
01:00:20,953 --> 01:00:25,403
this was a GitHub action that we made
that allows you to basically plug

1202
01:00:25,403 --> 01:00:28,903
in an agent into your CI workflow.

1203
01:00:28,903 --> 01:00:33,618
Again, using Cagent, which is open source
tooling, and so in this small snippet

1204
01:00:33,618 --> 01:00:36,638
here, it's going to point to an agent.

1205
01:00:36,648 --> 01:00:40,708
yaml, which describes what's the prompt
for the agent, and what tools does it have

1206
01:00:41,008 --> 01:00:46,248
access to, what models is it going to use,
etc. but in this case, prompt is going to

1207
01:00:46,248 --> 01:00:48,018
analyze this code and take a look at it.

1208
01:00:48,323 --> 01:00:50,923
and there's a lot of other
things that the action can do.

1209
01:00:51,423 --> 01:00:55,113
but for a couple examples, And
this is coming from our docs team.

1210
01:00:55,613 --> 01:01:01,073
all of our Docker docs now are using
this agent to review pull requests.

1211
01:01:01,623 --> 01:01:05,233
there's a specific workflow that we
have in that action to review a PR.

1212
01:01:05,683 --> 01:01:08,183
and so it's going to, have a base prompt.

1213
01:01:08,593 --> 01:01:11,113
But then since this is Docs,
there's also an additional prompt.

1214
01:01:11,113 --> 01:01:14,393
So here's an additional prompt of
things that we want to look for

1215
01:01:14,393 --> 01:01:17,483
and, style guides and priority
issues and basically the agent's

1216
01:01:17,483 --> 01:01:21,353
going to look at this and determine,
does this pass the rules or not?

1217
01:01:21,688 --> 01:01:25,888
and so that's dramatically reducing
the time it takes for our docs team

1218
01:01:25,888 --> 01:01:27,368
to actually review a lot of these PRs.

1219
01:01:27,928 --> 01:01:30,788
For the most part, if the agent
says, yeah, this looks good for the

1220
01:01:30,808 --> 01:01:33,328
most part, then it's just kind of
up to the human to look at it and

1221
01:01:33,328 --> 01:01:37,348
say, just final validation, is this
file in the right place, et cetera.

1222
01:01:37,748 --> 01:01:39,488
Let's sign off and let's go.

1223
01:01:40,178 --> 01:01:43,548
So we're starting to use these
agents more in our CI pipelines

1224
01:01:43,558 --> 01:01:44,778
to review our documentation.

1225
01:01:45,098 --> 01:01:48,338
And the final link here is actually
a pretty slick thing that the

1226
01:01:48,378 --> 01:01:52,218
docs team did is they're using
this agent and running it nightly.

1227
01:01:52,248 --> 01:01:53,938
So there's a cron job
that runs each night.

1228
01:01:54,438 --> 01:01:59,148
And what it's doing is basically
freshness checks on the documentation.

1229
01:01:59,488 --> 01:02:02,263
And just saying, hey, you know,
are things still accurate?

1230
01:02:02,263 --> 01:02:03,193
Are they still valid?

1231
01:02:03,523 --> 01:02:06,563
And, if for example, we
update our style guide.

1232
01:02:06,988 --> 01:02:10,788
Then the next time that the agent runs
through and kind of scans things, it'll

1233
01:02:10,788 --> 01:02:14,888
pick up issues and it'll automatically
create the GitHub issues and, document it.

1234
01:02:14,898 --> 01:02:18,558
so yeah, there's some like scanner
state and just some cache mechanism,

1235
01:02:18,588 --> 01:02:22,508
things that, yeah, it basically
just, It goes off and does its thing.

1236
01:02:22,558 --> 01:02:27,418
and it's, so again, this is something
that now runs nightly, and we have these

1237
01:02:27,418 --> 01:02:29,988
agents running and then we wake up in
the morning and say, okay, well, hey,

1238
01:02:30,258 --> 01:02:31,708
what documentation needs to be updated?

1239
01:02:31,988 --> 01:02:35,218
And it does like even little things
with like, I saw one recently, it

1240
01:02:35,228 --> 01:02:38,548
flagged a page that said, Hey, this
feature, was just recently announced.

1241
01:02:38,588 --> 01:02:43,138
And the agent was like, recently announced
was true, maybe six months ago, when

1242
01:02:43,138 --> 01:02:45,748
it was actually recently announced, we
should probably update this documentation.

1243
01:02:46,468 --> 01:02:50,048
and so like, it's catching little
things like that, where again, as

1244
01:02:50,048 --> 01:02:53,438
a human, I'd have to take time to
go and find all those things, but

1245
01:02:53,438 --> 01:02:55,828
that's hard to catch in a style guide.

1246
01:02:56,168 --> 01:02:59,428
but it's something that an LLM can
pick up and call out right away.

1247
01:02:59,903 --> 01:03:00,153
Yeah.

1248
01:03:00,153 --> 01:03:02,813
That's, that's the little stuff
that's annoying, especially when

1249
01:03:02,813 --> 01:03:05,478
you're trying to like, understand
something and you're seeing this

1250
01:03:05,488 --> 01:03:09,458
inconsistent, information, I think I
even pinged in the Captain's channel.

1251
01:03:09,478 --> 01:03:13,168
We were, because we were, a couple of us
were trying sandboxes and I noticed on

1252
01:03:13,168 --> 01:03:15,998
one page it said the OpenCode sandbox was.

1253
01:03:16,443 --> 01:03:20,153
build, in development and on another
page, it said it was available.

1254
01:03:20,413 --> 01:03:24,683
And those little things are so hard,
unless you're like the person, unless

1255
01:03:24,683 --> 01:03:27,853
you made a mental note, not even a mental
note, you have to physically make a

1256
01:03:27,853 --> 01:03:29,803
JIRA ticket or some, ticket that you.

1257
01:03:30,303 --> 01:03:32,403
You were like, okay, we're going to
have to come back to this later when we

1258
01:03:32,403 --> 01:03:36,563
launch, because this per currently, this
stuff shows this current status, and

1259
01:03:36,563 --> 01:03:37,573
we're going to have to update that page.

1260
01:03:37,593 --> 01:03:39,363
But then later, you actually
make it on a different page.

1261
01:03:39,363 --> 01:03:40,803
So then you don't even
think about the old page.

1262
01:03:41,153 --> 01:03:43,153
But documentation doesn't
tend to have those dates.

1263
01:03:43,493 --> 01:03:48,093
So we don't look at a documentation
and go, well, this documentation

1264
01:03:48,093 --> 01:03:50,603
page was written six months ago,
so I expect it to be outdated.

1265
01:03:50,603 --> 01:03:52,893
Like, we expect documentation to
be current for the current version.

1266
01:03:53,293 --> 01:03:57,303
And this is, this is one of those things
where pretty soon we're all going to

1267
01:03:57,303 --> 01:04:01,203
just be We're going to have, we're
honestly going to be more critical, I

1268
01:04:01,223 --> 01:04:02,713
think, of documentation that's outdated.

1269
01:04:02,713 --> 01:04:04,483
because we're going to be like,
you just had, all you got to

1270
01:04:04,483 --> 01:04:06,423
do is put an AI agent on this.

1271
01:04:06,423 --> 01:04:09,203
I understand that you don't have all
the staff to do this stuff constantly.

1272
01:04:09,203 --> 01:04:12,653
the documentation team at Docker
has always been fantastic.

1273
01:04:12,653 --> 01:04:16,913
it's amazing how, if you remember, even
just five years ago, much less 10 years

1274
01:04:16,913 --> 01:04:20,131
ago, it's a lot of different things,
but I think what's really important is

1275
01:04:20,131 --> 01:04:22,879
the level of upkeep and maintenance of
the Docker documentation over the years,

1276
01:04:22,879 --> 01:04:26,222
and as it's evolved, and as products
have become launched and fallen off

1277
01:04:26,222 --> 01:04:29,672
of, you know, Docker launches lots of
ideas that don't always make it into

1278
01:04:29,902 --> 01:04:34,032
production, and don't always last
forever, and it's just got to be a lot.

1279
01:04:34,052 --> 01:04:35,842
not all of us have public documentation.

1280
01:04:35,842 --> 01:04:40,132
we all have got private documentation
and the idea that I can come into work

1281
01:04:40,372 --> 01:04:44,822
and just approve 10 different things
that fix one line documentation errors.

1282
01:04:44,822 --> 01:04:47,292
And that's like so much better than me.

1283
01:04:47,652 --> 01:04:49,082
what was the alternative, right?

1284
01:04:49,092 --> 01:04:53,902
It was literally rereading documentation
over and over again, manually, just

1285
01:04:53,902 --> 01:04:59,022
so that we can find that one little
line where Oh, we're not on V13.

1286
01:04:59,032 --> 01:05:00,102
We're now on V20.

1287
01:05:00,602 --> 01:05:02,522
And we've got to update
one line of the doc file.

1288
01:05:02,522 --> 01:05:05,022
these are the kind of
things that, just suck.

1289
01:05:05,627 --> 01:05:09,307
And the fatigue is so real for a human
to do that, but an agent like, great,

1290
01:05:09,337 --> 01:05:10,347
yeah, I'm going to do it every night.

1291
01:05:10,357 --> 01:05:10,847
Who cares?

1292
01:05:10,867 --> 01:05:11,287
Kind of thing.

1293
01:05:11,287 --> 01:05:14,737
And so, yeah, it'll pick up on
those things that we would just

1294
01:05:15,187 --> 01:05:16,707
simply gloss over and miss.

1295
01:05:16,707 --> 01:05:21,627
I think that brings us to the end of
the list, which is only a partial list,

1296
01:05:21,677 --> 01:05:23,637
and there are a lot of other things.

1297
01:05:23,637 --> 01:05:27,207
I'd love to spend more time
on Cagent and Sandboxes.

1298
01:05:27,297 --> 01:05:32,167
it sounds did you come to, other than the
DS tool, which is a great little, drop.

1299
01:05:32,177 --> 01:05:33,097
Is there anything else?

1300
01:05:33,377 --> 01:05:35,737
Is there anything else for,
like You're working on,

1301
01:05:35,827 --> 01:05:36,087
now,

1302
01:05:36,137 --> 01:05:37,157
you're thinking about?

1303
01:05:37,657 --> 01:05:40,847
I mean, there, there's a lot more
that we could hint at, but, we may

1304
01:05:40,847 --> 01:05:42,177
have to save it for another episode,

1305
01:05:42,207 --> 01:05:43,617
Okay, we have to save it for another time.

1306
01:05:44,117 --> 01:05:49,987
Well, I appreciate all of this, upkeep
on my audience understanding how Docker

1307
01:05:49,987 --> 01:05:56,357
is essentially trying, you know, I look
at this as like Docker is like every

1308
01:05:56,357 --> 01:06:00,107
software company right now, adjusting
to the current climate and figuring

1309
01:06:00,107 --> 01:06:05,457
out how On one way, in one way, it
feels like the AI world forgot that

1310
01:06:05,457 --> 01:06:07,557
containers existed and that they've moved.

1311
01:06:07,767 --> 01:06:12,477
It's like they're going back to the
roots of what we learned over the last

1312
01:06:12,477 --> 01:06:15,237
decade of how really we need to be
confining all this stuff to containers.

1313
01:06:15,237 --> 01:06:18,507
And they forgot all that because it
containers requires a little bit of

1314
01:06:18,507 --> 01:06:21,747
extra effort and they don't want to
slow down and they're all competing.

1315
01:06:21,797 --> 01:06:22,787
So I like that.

1316
01:06:23,887 --> 01:06:28,857
Not only is Docker trying to figure out
how do we fit into this AI space, but

1317
01:06:28,857 --> 01:06:31,007
also how can we make the AI world better.

1318
01:06:31,037 --> 01:06:36,307
And, I think you recently announced that
you were a part of a new Linux foundation.

1319
01:06:36,317 --> 01:06:37,807
What's the new AI thing called?

1320
01:06:37,817 --> 01:06:38,387
Do you remember?

1321
01:06:38,887 --> 01:06:40,257
AI Foundation.

1322
01:06:40,667 --> 01:06:45,347
In December, Docker announced joining
the Agentic AI Foundation, which,

1323
01:06:45,397 --> 01:06:47,457
I don't actually, a lot of us are
like, well, what does that even mean?

1324
01:06:47,817 --> 01:06:53,337
To me, my take on it is there is a lot
of proprietary stuff happening right now.

1325
01:06:53,397 --> 01:06:55,207
Claude Code is completely proprietary.

1326
01:06:55,557 --> 01:07:00,597
it is definitely gathered the
zeitgeist in the industry and nothing

1327
01:07:00,597 --> 01:07:03,287
against, we all have private code.

1328
01:07:03,287 --> 01:07:04,327
We all have SASSes.

1329
01:07:04,357 --> 01:07:08,247
We all have a closed source code
that, that all of our machines,

1330
01:07:08,247 --> 01:07:11,127
we're all running on machines usually
with some sort of code like that.

1331
01:07:11,347 --> 01:07:11,927
And so that's.

1332
01:07:12,427 --> 01:07:15,857
That is fine, and I do not judge
that, but historically in the

1333
01:07:15,857 --> 01:07:17,307
world of developer tooling.

1334
01:07:17,802 --> 01:07:20,972
Things don't stay closed source in a
large portion of the community very

1335
01:07:20,972 --> 01:07:25,782
long, most people are on an open source
IDE now, most people are running open

1336
01:07:25,782 --> 01:07:31,092
source, you know, gone are the years
of closed source programming languages,

1337
01:07:31,092 --> 01:07:35,162
which used to be a thing, gone are the
days of a lot of this base tooling we

1338
01:07:35,162 --> 01:07:37,192
all run things on being closed source.

1339
01:07:37,562 --> 01:07:43,202
So I am very interested in how we've
got these AI companies creating a lot of

1340
01:07:43,202 --> 01:07:44,762
closed source for competitive advantage.

1341
01:07:45,142 --> 01:07:48,202
But also, developers will
not tolerate that very long.

1342
01:07:48,202 --> 01:07:52,182
Like, they only, will only tolerate
that as long as they have a competitive

1343
01:07:52,182 --> 01:07:53,452
advantage over the open source.

1344
01:07:53,472 --> 01:07:57,922
And so we have the teams like the OpenCode
team and the, obviously, OpenClaw and all

1345
01:07:57,922 --> 01:08:00,562
these other, offshoots of that, that are,

1346
01:08:01,002 --> 01:08:03,822
I feel like, maybe, heroes may be a
little bit of a strong word, but they

1347
01:08:03,822 --> 01:08:06,482
are doing, you So, I think we're doing
the good work of making sure that

1348
01:08:06,482 --> 01:08:11,402
open source doesn't fall behind the
closed source option because I think

1349
01:08:11,402 --> 01:08:14,452
a lot of us don't necessarily want to
replace all of our open source tooling

1350
01:08:14,452 --> 01:08:15,842
with a bunch of closed source tooling.

1351
01:08:16,172 --> 01:08:19,502
these AIs are not as magical as we all
sometimes try to put them on a pedestal.

1352
01:08:19,842 --> 01:08:23,952
So I look at this Docker joining the,
Agentic AI Foundation as, as a good thing.

1353
01:08:24,452 --> 01:08:28,622
Basically, the Linux Foundation and
the Kubernetes groups, which are part

1354
01:08:28,622 --> 01:08:32,752
of the CNCF, which is a part of the
Linux Foundation, basically drawing

1355
01:08:32,752 --> 01:08:37,072
a line and saying, we are going to be
leaders, not laggards, not followers.

1356
01:08:37,072 --> 01:08:39,922
We're going to be leaders in the
AI open source tooling space.

1357
01:08:40,202 --> 01:08:42,772
And there will be plenty of
opportunity for vendor solutions.

1358
01:08:43,082 --> 01:08:47,362
But not just developing with harnesses
and agents, but also everything that

1359
01:08:47,362 --> 01:08:50,772
runs AI, everything that runs our
agents in the servers and production

1360
01:08:50,782 --> 01:08:54,412
like these foundational technologies
should all really be open source.

1361
01:08:54,412 --> 01:08:58,482
So let's bring all that together under
one umbrella organization so that we can

1362
01:08:58,482 --> 01:09:02,872
do things like patent protection and, you
know, guiding the working groups so that

1363
01:09:02,872 --> 01:09:05,812
we can get all the people in the same
room to make these really hard decisions.

1364
01:09:06,312 --> 01:09:08,812
And I'm super excited about
that because for the longest

1365
01:09:08,822 --> 01:09:10,662
time at KubeCon and these other

1366
01:09:14,277 --> 01:09:18,697
As an industry, in the ops industry,
which is what KubeCon is, that we

1367
01:09:18,697 --> 01:09:21,187
were all focused on running the AIs.

1368
01:09:21,257 --> 01:09:24,167
And for years now at KubeCon,
it's really been about the

1369
01:09:24,187 --> 01:09:26,377
infrastructure of running AI.

1370
01:09:26,397 --> 01:09:29,437
And then maybe eventually started to
talk about running agents, which a

1371
01:09:29,437 --> 01:09:30,677
lot of people are still not doing.

1372
01:09:30,897 --> 01:09:33,447
A lot of people are really
just using agent harnesses

1373
01:09:33,447 --> 01:09:34,677
locally, and they're not yet.

1374
01:09:35,062 --> 01:09:38,582
Actually running AI in their
production with LLMs connected to it.

1375
01:09:38,942 --> 01:09:41,512
And so I'm, encouraged that
we're finally, I feel like in

1376
01:09:41,512 --> 01:09:43,752
2020, late 2025, early 2026.

1377
01:09:44,252 --> 01:09:48,132
We're finally having these conversations
around what does the local tooling

1378
01:09:48,372 --> 01:09:52,282
ecosystem look like and how do we
engage developers to make their

1379
01:09:52,282 --> 01:09:54,672
life better in open source for AI?

1380
01:09:55,442 --> 01:09:59,072
And I love that Cagent exists and that
now sandboxes is going to be a thing.

1381
01:09:59,472 --> 01:10:00,682
Which one of that is open source?

1382
01:10:00,682 --> 01:10:02,002
Is Cagent open source?

1383
01:10:02,492 --> 01:10:03,642
So Cagent's open source.

1384
01:10:03,642 --> 01:10:03,982
Yep.

1385
01:10:04,292 --> 01:10:05,532
and, see how anybody can try.

1386
01:10:05,682 --> 01:10:08,972
one thing I'll add to that as well,
is there's an interesting movement

1387
01:10:08,982 --> 01:10:12,002
happening right now because, I was
kind of joking with somebody a couple

1388
01:10:12,002 --> 01:10:15,772
of days ago, like, to me, in many
ways, this feels like early PHP days.

1389
01:10:15,772 --> 01:10:18,072
And that may be a terrible,
scary thing to say.

1390
01:10:18,332 --> 01:10:23,022
one of the things that PHP did for the
space was it lowered the barrier of entry

1391
01:10:23,492 --> 01:10:25,612
for anybody to make web applications.

1392
01:10:25,997 --> 01:10:30,017
and so obviously that introduced a lot
of security risk and vulnerabilities

1393
01:10:30,017 --> 01:10:32,747
and like anybody could just write
a website and oops, there's a

1394
01:10:32,747 --> 01:10:33,987
SQL injection on it or whatever.

1395
01:10:34,487 --> 01:10:37,027
in many ways, we're like in the same
environment right now where like

1396
01:10:37,027 --> 01:10:40,747
anybody can create an application now
because the AI has gotten that good.

1397
01:10:40,857 --> 01:10:43,277
but yeah, at the same time,
how do we do so safely?

1398
01:10:43,277 --> 01:10:44,517
How do we do so securely?

1399
01:10:45,017 --> 01:10:49,107
and in fact, I spoke at a local meetup
not long ago, and there was a woman

1400
01:10:49,107 --> 01:10:52,607
that came up to me afterwards, and
this was a pretty technical meetup,

1401
01:10:52,607 --> 01:10:54,437
and we were talking about models
and, you know, the chat completions

1402
01:10:54,437 --> 01:10:56,537
API, and it was pretty technical.

1403
01:10:56,967 --> 01:10:59,597
And she's like, I understood
maybe 10 percent of what you said.

1404
01:11:00,017 --> 01:11:01,467
I'm just a small business owner.

1405
01:11:01,807 --> 01:11:06,697
I want to learn how I can use AI to
better my processes within my business and

1406
01:11:06,797 --> 01:11:08,397
basically have my own little secretary.

1407
01:11:08,777 --> 01:11:11,907
And I think we may not be quite there yet.

1408
01:11:12,277 --> 01:11:16,607
But we're getting pretty close to it
where now she could go and say, great.

1409
01:11:16,617 --> 01:11:18,737
I need a, I'm just going
to make up something.

1410
01:11:18,737 --> 01:11:21,077
She didn't actually say this,
but like, I need an inventory

1411
01:11:21,077 --> 01:11:22,597
management system that works for me.

1412
01:11:22,947 --> 01:11:25,827
and wouldn't it be great if
I could somehow run this.

1413
01:11:26,327 --> 01:11:29,817
One of the many Claws out there, and
now I can just open up WhatsApp and I

1414
01:11:29,817 --> 01:11:33,027
can text my agent and just say, Hey, how
many shoes do we still have in stock yet?

1415
01:11:33,037 --> 01:11:35,977
And then the agent can go and figure
it out and give me my report back.

1416
01:11:36,477 --> 01:11:40,017
How do we enable that kind of
workflow for the everyday person?

1417
01:11:40,477 --> 01:11:44,727
I think we're not far from it, but
it's still very technically oriented.

1418
01:11:44,997 --> 01:11:49,277
So I think we as a technical audience
need to be thinking about how do

1419
01:11:49,277 --> 01:11:54,407
we, ' cause the technology definitely
has the capability of going out to

1420
01:11:54,407 --> 01:11:56,597
the masses, to the everyday person.

1421
01:11:57,007 --> 01:11:58,357
how do we enable those folks?

1422
01:11:58,857 --> 01:12:01,437
But also at the same time
too, how do we ensure that the

1423
01:12:01,437 --> 01:12:02,727
proper guardrails are in place?

1424
01:12:02,747 --> 01:12:05,397
And so again, that's why I'm excited
that, sandboxes and all these

1425
01:12:05,397 --> 01:12:08,587
different things that we're doing and
the foundations in place, et cetera.

1426
01:12:08,867 --> 01:12:11,947
So there's the right people
thinking about these problems.

1427
01:12:12,447 --> 01:12:16,627
So when, once we hit those levels of
scale, the right eyeballs are on it.

1428
01:12:17,257 --> 01:12:18,527
So it's an exciting time.

1429
01:12:19,027 --> 01:12:19,317
Yep.

1430
01:12:19,477 --> 01:12:20,657
What a time to be alive.

1431
01:12:21,157 --> 01:12:21,977
I'm not getting much sleep.

1432
01:12:22,477 --> 01:12:23,817
what a time to not sleep.

1433
01:12:24,167 --> 01:12:27,737
well, it's great to have you on
and we waited too long and now

1434
01:12:27,737 --> 01:12:29,757
that we have so much stuff that
we can't fit all into a podcast.

1435
01:12:29,757 --> 01:12:32,167
So for those of you still listening
on the audio podcast version of

1436
01:12:32,167 --> 01:12:35,117
this edited episode later, thank
you so much for sticking through it.

1437
01:12:35,362 --> 01:12:37,422
Hopefully there's something
in here for everyone.

1438
01:12:37,432 --> 01:12:41,062
And if you're a Docker container person,
which would be the reason you're listening

1439
01:12:41,062 --> 01:12:44,572
to DevOps and Docker talk podcast,
that you take a second look at some of

1440
01:12:44,572 --> 01:12:49,542
these for how they might augment your
changing workflow as you evolve into the

1441
01:12:49,542 --> 01:12:54,202
AI harness and agents locally space, I
too am also playing catch up on this.

1442
01:12:54,202 --> 01:12:57,102
That's why one of the reasons
I had Michael on was I feel

1443
01:12:57,212 --> 01:12:58,922
like I am not able to keep up.

1444
01:12:59,067 --> 01:13:02,187
So, with everything the AI companies
are releasing, much less adding

1445
01:13:02,187 --> 01:13:06,147
Docker and GitHub, releasing a
constant slew of things as well.

1446
01:13:06,157 --> 01:13:08,197
there's just, we're all overwhelmed.

1447
01:13:08,207 --> 01:13:09,157
It's very normal.

1448
01:13:09,357 --> 01:13:10,097
you're fine.

1449
01:13:10,107 --> 01:13:12,017
We're all, nobody is the expert right now.

1450
01:13:12,017 --> 01:13:13,077
Nobody knows everything.

1451
01:13:13,357 --> 01:13:15,572
And this is the common theme
I have with every release.

1452
01:13:16,072 --> 01:13:18,842
Whenever I talk to the smartest people
in the world, I was just having a

1453
01:13:18,842 --> 01:13:22,382
conversation with our friend Victor Farcic
yesterday of DevOps Toolkit channel.

1454
01:13:22,622 --> 01:13:26,092
like he was kept saying, Bret, not
everybody knows everything right now.

1455
01:13:26,242 --> 01:13:28,312
And we are at the tip of the
spear in this, and we still

1456
01:13:28,312 --> 01:13:29,312
can't figure all this out.

1457
01:13:29,642 --> 01:13:32,072
there is just a lot to get through.

1458
01:13:32,392 --> 01:13:37,877
But it does give me the pause to go,
okay, maybe There is a safer, better way

1459
01:13:37,877 --> 01:13:41,577
that today I could start experimenting
with Claude Code if I was maybe on

1460
01:13:41,577 --> 01:13:43,567
the fence about, you know, YOLO mode.

1461
01:13:43,577 --> 01:13:46,527
Which, to me, YOLO mode is
the next unlock, really.

1462
01:13:46,527 --> 01:13:50,447
because if I have to sit here and wait for
every question and answer every question,

1463
01:13:50,777 --> 01:13:53,307
that really hampers my AI's ability.

1464
01:13:53,557 --> 01:13:56,127
And a year ago, that,
I think, was necessary.

1465
01:13:56,127 --> 01:13:59,757
But I think we're now at a point where
even if I don't sandbox it, like,

1466
01:13:59,757 --> 01:14:02,287
I'll be honest, I've not had these
sandboxes running for three or four

1467
01:14:02,287 --> 01:14:05,020
months, but when I'm using Opus 4.

1468
01:14:05,050 --> 01:14:08,360
It's not a single time tried
to delete my entire hard drive.

1469
01:14:08,390 --> 01:14:11,140
Not once, like a year
ago, that was not true.

1470
01:14:11,150 --> 01:14:13,380
It was actually trying to
do wild and crazy things.

1471
01:14:13,390 --> 01:14:16,210
I think I remember in the spring of
this year, right around the time Claude

1472
01:14:16,210 --> 01:14:19,620
Code was released, I was trying to
get it to build me in without having

1473
01:14:19,620 --> 01:14:21,540
Xcode installed, just the CLI tools.

1474
01:14:21,540 --> 01:14:26,820
I was trying to have it build me a iOS
app, to do something and it couldn't get

1475
01:14:26,820 --> 01:14:30,480
it built, it kept building, failing on
the build and eventually decided that the.

1476
01:14:30,660 --> 01:14:33,980
The problem was, is that things
weren't installed, even though

1477
01:14:33,980 --> 01:14:35,120
it was running those commands.

1478
01:14:35,140 --> 01:14:40,440
So it was ready to delete the system
directory of my Xcode CLI installs,

1479
01:14:40,690 --> 01:14:42,080
because that was the problem.

1480
01:14:42,420 --> 01:14:45,180
And it's just not, it's
a little bit smarter now.

1481
01:14:45,180 --> 01:14:46,810
So it's not doing that to me anymore.

1482
01:14:46,810 --> 01:14:49,720
I haven't had it try to remove or
get so confused down a rabbit hole

1483
01:14:49,720 --> 01:14:50,870
that it's ready to delete stuff.

1484
01:14:51,330 --> 01:14:57,430
and so I think we've YOLO mode, but
also at the same time, It's not perfect.

1485
01:14:57,440 --> 01:15:00,650
And it would be, I now
realize that for me, the next.

1486
01:15:01,150 --> 01:15:06,210
Concern is as I get back into consulting
and touching production infrastructure

1487
01:15:06,210 --> 01:15:10,910
on occasion, that I'm going to have a
whole different posture for what I give

1488
01:15:10,920 --> 01:15:15,410
my local AI, because realizing that it
has access to every single CLI tool that

1489
01:15:15,410 --> 01:15:20,750
I've already authed with is of, almost
on the level of security nightmare.

1490
01:15:21,070 --> 01:15:26,380
And I think I need a new paradigm
shift in how I'm going to design

1491
01:15:26,390 --> 01:15:31,490
my local editing and tooling To
segment the human involvement and

1492
01:15:31,490 --> 01:15:33,930
the human access from the AI access.

1493
01:15:33,930 --> 01:15:36,970
So it looks like Docker is going
to be one of those major players

1494
01:15:36,970 --> 01:15:37,910
that are playing in that space.

1495
01:15:37,910 --> 01:15:41,930
And I'm excited for it because it turns
out I know a little thing about Docker and

1496
01:15:41,930 --> 01:15:43,690
I'm excited to make some videos on that.

1497
01:15:43,690 --> 01:15:45,720
So hopefully we'll have
you back on, in the future.

1498
01:15:45,720 --> 01:15:48,220
And maybe this will inspire me
to make some more Docker videos

1499
01:15:48,220 --> 01:15:50,110
about how to use Docker with AI.

1500
01:15:51,880 --> 01:15:52,800
Where can people find you?

1501
01:15:52,810 --> 01:15:53,340
you're on what?

1502
01:15:55,555 --> 01:15:57,965
I'm on LinkedIn, probably that's
going to be the easiest to get

1503
01:15:57,995 --> 01:16:01,035
me, I'm technically on, X and
BlueSky and all that kind of stuff.

1504
01:16:01,535 --> 01:16:02,775
Probably LinkedIn is the best though.

1505
01:16:03,150 --> 01:16:03,540
Yeah.

1506
01:16:03,900 --> 01:16:06,460
So yeah, follow Michael Erwin on LinkedIn.

1507
01:16:06,540 --> 01:16:09,060
You and I will have to meet at
a conference in the future and

1508
01:16:09,060 --> 01:16:11,180
we will, we will hang out again.

1509
01:16:11,220 --> 01:16:11,980
thanks again, Michael,

1510
01:16:12,080 --> 01:16:12,260
All right.

1511
01:16:12,260 --> 01:16:12,690
Thanks Bret.

1512
01:16:12,740 --> 01:16:13,030
Thanks all.

1513
01:16:13,530 --> 01:16:15,690
Thanks for listening and I'll
see you in the next episode