1
00:00:00,000 --> 00:00:04,179
Bret: this episode couldn't be
more timely because it just days

2
00:00:04,180 --> 00:00:09,090
ago, like maybe two, two days after
this episode was recorded, we heard

3
00:00:09,090 --> 00:00:11,329
about the HuggingFace hack by OpenAI

4
00:00:11,470 --> 00:00:14,450
on both ends of the spectrum,
we're gonna need some sandboxing

5
00:00:14,450 --> 00:00:15,859
and locking of this stuff down.

6
00:00:19,269 --> 00:00:24,109
This episode is about agent sandboxes,
or just sandboxing, sandboxing anything.

7
00:00:24,119 --> 00:00:27,259
Hell, we've for 30 years have had
sandboxing technologies that we could

8
00:00:27,259 --> 00:00:34,999
label as a sandbox-type thing with
jails and Chroot and Docker and VMs.

9
00:00:35,019 --> 00:00:39,409
Like these are all isolation technologies,
namespaces, cgroups, you name it.

10
00:00:39,409 --> 00:00:44,489
There's been a dozen or more attempts
over the last 30 years, and now we are

11
00:00:44,489 --> 00:00:48,369
focused on agents and AI running amok on
our local systems, but that's not enough.

12
00:00:48,709 --> 00:00:51,059
This is about sandboxing,
specifically with nono.

13
00:00:51,239 --> 00:00:52,939
You can find it at nono.sh.

14
00:00:52,939 --> 00:00:58,099
It's by nolabs, and I had the founder,
Luke Hinds on the show, where we

15
00:00:58,099 --> 00:01:01,219
went long on this one, and that's
because there's a part of it where

16
00:01:01,219 --> 00:01:04,099
we talk about nono, how it works.

17
00:01:04,109 --> 00:01:08,139
It's a command line that you can
wrap any binary on Mac or Linux.

18
00:01:08,429 --> 00:01:12,332
On Windows, you would
use WSL2 to run nono.

19
00:01:12,632 --> 00:01:15,022
But it runs against the kernel primitives.

20
00:01:15,272 --> 00:01:20,022
So unlike many other ideas around
isolation technology that use VMs or

21
00:01:20,022 --> 00:01:24,422
containers or both, this is focused
on just using the native functionality

22
00:01:24,432 --> 00:01:29,892
of the kernel and giving you a profile
for each thing you wanna run in it,

23
00:01:29,892 --> 00:01:30,712
You can use it for everything.

24
00:01:30,712 --> 00:01:31,682
You can use it for kubectl.

25
00:01:31,682 --> 00:01:32,902
You can use it for GitHub command line.

26
00:01:32,902 --> 00:01:36,512
You can use it to run lots of other
interesting things on your computer.

27
00:01:36,522 --> 00:01:40,862
It can even work with GUIs potentially, as
long as you can handle the sophisticated

28
00:01:40,862 --> 00:01:44,062
approach that a GUI requires in terms
of file access and all that stuff.

29
00:01:44,502 --> 00:01:47,152
I'm very, very interested
in sandboxing technology.

30
00:01:47,412 --> 00:01:49,132
Docker is one of the major players here.

31
00:01:49,142 --> 00:01:53,362
They have the, the Sandbox or SBX
command, which is a VM that runs

32
00:01:53,362 --> 00:01:57,312
Docker inside it, that then runs
the agent harness inside that.

33
00:01:57,762 --> 00:02:02,136
And nono tries to take a much more
direct approach by using the kernel

34
00:02:03,266 --> 00:02:06,166
primitives that are already there,
and it's built by some really

35
00:02:06,166 --> 00:02:07,666
smart people that built Sigstore,

36
00:02:07,676 --> 00:02:11,526
So there's all sorts of stuff that we
dabble in, but this show, I think, will

37
00:02:11,526 --> 00:02:15,146
be essential learning for everyone using
agent harnesses, which is essentially

38
00:02:15,146 --> 00:02:19,486
every developer and DevOps and platform
engineer on the planet, because of one

39
00:02:19,486 --> 00:02:24,574
reason As we get tasked to use cheaper
models, the hallucinations will increase.

40
00:02:24,574 --> 00:02:27,524
And in fact, a cheaper model doesn't
mean that hallucinations are more

41
00:02:27,524 --> 00:02:30,594
likely, but we are gonna all probably
at some point need to push the

42
00:02:30,594 --> 00:02:32,864
envelope for how cheap can we get it.

43
00:02:33,144 --> 00:02:38,294
In fact, I know teams that their egos
reside on how little they spend on tokens

44
00:02:38,574 --> 00:02:43,224
by using cheaper and cheaper models, using
Haikus, using the GLMs and the Kimis.

45
00:02:43,514 --> 00:02:46,234
And these models may or may not
be more likely to hallucinate.

46
00:02:46,274 --> 00:02:50,074
But as you push that envelope to how
cheap you can get in a model, how old

47
00:02:50,084 --> 00:02:53,654
of a model can you get, or how cheap
or of a smaller a model can you get to

48
00:02:53,654 --> 00:02:57,201
run some of your workloads and some of
your automations in CI, you're gonna

49
00:02:57,201 --> 00:02:58,971
potentially deal with more hallucinations.

50
00:02:58,981 --> 00:03:02,981
So we've got it on both ends of the
cheaper models are what we need, but that

51
00:03:02,981 --> 00:03:07,541
may mean more hallucinations, which may
mean you need to care about locking your

52
00:03:07,541 --> 00:03:11,331
stuff down, or the models are gonna be
so sophisticated that they might actually

53
00:03:11,331 --> 00:03:16,081
go a little more rogue in just the
service of doing what you asked it to do.

54
00:03:16,411 --> 00:03:19,591
And if you leave them alone long
enough, they may actually do something

55
00:03:19,601 --> 00:03:22,061
bad in search of doing the good thing.

56
00:03:22,351 --> 00:03:24,401
And so they're not necessarily nefarious,
That's what happened with HuggingFace,

57
00:03:24,951 --> 00:03:27,851
was it was just trying to solve a test.

58
00:03:27,851 --> 00:03:30,891
It was trying to prove that
it was intelligent, so it

59
00:03:30,901 --> 00:03:32,991
went crazy and wouldn't quit.

60
00:03:33,441 --> 00:03:38,681
And the sandboxing is an area where
we've got lots of different options,

61
00:03:38,891 --> 00:03:43,121
and I like nono for its simplicity and
its ease of use in my day-to-day, and

62
00:03:43,121 --> 00:03:47,521
I'm now very interested in how can I
use it in my CI and other places as

63
00:03:47,521 --> 00:03:49,991
well to sort of have a blanket approach.

64
00:03:50,391 --> 00:03:52,531
And we talk about a lot of those
ideas in this podcast, so let's

65
00:03:52,531 --> 00:03:52,921
get to it

66
00:03:53,780 --> 00:03:54,750
Bret (2): Welcome to the show.

67
00:03:54,760 --> 00:03:59,110
We've got Luke Hinds here, the
s- co-founder and CEO of nolabs.

68
00:03:59,535 --> 00:04:00,755
Luke: Thank you so much for having me.

69
00:04:01,005 --> 00:04:01,525
Enjoying this

70
00:04:02,177 --> 00:04:06,207
Bret (2): So just a real quick background
on Luke here, 'cause he's a humble guy.

71
00:04:06,207 --> 00:04:07,257
He's probably not gonna tell you.

72
00:04:07,267 --> 00:04:08,407
He's kind of a big deal.

73
00:04:08,627 --> 00:04:12,127
He created Sigstore, which one
of my favorite security projects.

74
00:04:12,297 --> 00:04:13,607
Sigstore is very popular.

75
00:04:13,927 --> 00:04:16,847
If you don't know Sigstore, if you don't
know you don't know, go check it out.

76
00:04:17,057 --> 00:04:20,747
it's there to help secure
your code essentially and give

77
00:04:20,747 --> 00:04:22,467
you some, some assurances.

78
00:04:22,797 --> 00:04:26,637
OpenSSF, which I'm also a very big
fan of, and we talked about at least

79
00:04:26,657 --> 00:04:28,267
multiple times a year on this channel.

80
00:04:28,477 --> 00:04:29,327
You were a board member?

81
00:04:29,587 --> 00:04:30,237
I didn't know that.

82
00:04:30,247 --> 00:04:30,907
That's very cool.

83
00:04:31,617 --> 00:04:33,457
OpenSSF is a, what is it?

84
00:04:33,507 --> 00:04:37,028
A s-security, software
security foundation.

85
00:04:37,037 --> 00:04:37,357
Is that

86
00:04:37,661 --> 00:04:38,571
Luke: Yeah, you got it

87
00:04:38,997 --> 00:04:39,307
Bret (2): Okay.

88
00:04:39,311 --> 00:04:40,021
Luke: on the nail.

89
00:04:40,477 --> 00:04:41,047
Bret (2): Yeah.

90
00:04:41,067 --> 00:04:46,858
And, I love the, it's the rating system
for how secure your supply chain is.

91
00:04:46,858 --> 00:04:48,008
It's like a checkoff list.

92
00:04:48,018 --> 00:04:49,708
I'm trying to remember what
that, what's that called?

93
00:04:50,247 --> 00:04:50,947
Luke: Go cards.

94
00:04:51,657 --> 00:04:51,817
Oh, SLSA.

95
00:04:53,238 --> 00:04:53,428
Bret (2): Oh,

96
00:04:53,627 --> 00:04:55,467
Luke: yeah, they're both scoring systems.

97
00:04:55,747 --> 00:04:58,137
SLSA has levels, so yeah.

98
00:04:58,297 --> 00:04:58,617
Yeah

99
00:05:00,278 --> 00:05:04,518
Bret (2): when I found out about
SLSA a couple years ago, I, I kinda

100
00:05:04,518 --> 00:05:05,688
got a little obsessed with it.

101
00:05:05,728 --> 00:05:08,938
Like I, I wanted all of my
stuff to be the highest number.

102
00:05:08,938 --> 00:05:14,398
It's like points, And the nice thing is
I think it's what this show tries to do,

103
00:05:14,398 --> 00:05:18,068
and it's kinda challenging sometimes, is
to get out of the esoteric, the theory,

104
00:05:18,068 --> 00:05:21,758
and get into the actual implementation
and where's our checkoff list, right?

105
00:05:21,808 --> 00:05:24,548
And so I try to get into those
weeds, 'cause that's just how my

106
00:05:24,548 --> 00:05:26,568
brain thinks, and SLSA is that.

107
00:05:26,598 --> 00:05:28,998
Like it is this wonderful standard.

108
00:05:29,008 --> 00:05:34,028
Hasn't changed a ton, but it, it
allows you this list of hardening

109
00:05:34,038 --> 00:05:35,788
down all the different parts.

110
00:05:35,788 --> 00:05:38,358
all the different parts a little
bit of your supply chain, whether

111
00:05:38,358 --> 00:05:41,938
that's the building or the provenance
information that you need to have, your

112
00:05:41,948 --> 00:05:46,638
artifacts you're building like Docker
images, and sorta steps through all

113
00:05:46,638 --> 00:05:50,708
the different parts you need to think
about, and you kinda just rate yourself.

114
00:05:50,728 --> 00:05:55,108
It's not something where you go and
get someone else's opinion, but you go

115
00:05:55,108 --> 00:06:00,678
through, But somewhere in here, there,
you dig into the individual parts of it.

116
00:06:00,708 --> 00:06:02,448
Okay, we've got the build
track, the source track.

117
00:06:02,458 --> 00:06:03,758
I like that these are broken out now.

118
00:06:04,268 --> 00:06:08,658
And as you dig down into it, you
eventually come to a list of steps that

119
00:06:08,738 --> 00:06:11,558
I learned a lot from years ago when I
think when it first came out, like wh-

120
00:06:11,618 --> 00:06:13,768
when it was in pre-1.0 or something.

121
00:06:14,218 --> 00:06:17,158
And I'm, and so it's cool to have you here
'cause I've never actually had someone

122
00:06:17,218 --> 00:06:21,178
from the OpenSSF on the show, even though
that's not what we're here to talk about.

123
00:06:21,798 --> 00:06:23,598
we're talk, we're here
to talk about sandboxes.

124
00:06:24,198 --> 00:06:29,738
So tell me, how did you get
interested in sandboxes?

125
00:06:29,988 --> 00:06:35,158
Like where's the origin story for you in
helping to lock down binaries essentially?

126
00:06:36,721 --> 00:06:39,201
Bret AI July 2025: Have you been
adding text-to-speech in your apps?

127
00:06:39,371 --> 00:06:42,491
One of my late-night projects
this year was creating a personal

128
00:06:42,491 --> 00:06:46,531
podcast feed so I could listen to
the changelog of my favorite open

129
00:06:46,531 --> 00:06:48,211
source projects while I do my chores.

130
00:06:48,611 --> 00:06:50,831
I needed a text-to-speech API to do that.

131
00:06:51,241 --> 00:06:54,581
I also heard from a colleague this
week who built an app for his kids to

132
00:06:54,591 --> 00:06:58,861
turn their e-books into audiobooks, and
he's using the Speechify AI developer

133
00:06:58,861 --> 00:07:01,381
platform to do that text-to-speech

134
00:07:01,381 --> 00:07:05,371
Speechify AI is a developer platform
for real-time text-to-speech, and

135
00:07:05,371 --> 00:07:06,891
they make their own voice models.

136
00:07:07,121 --> 00:07:12,121
Their Simba 3.2 model ranked number one
on the Artificial Analysis Benchmark

137
00:07:12,351 --> 00:07:13,941
for conversational voice quality.

138
00:07:14,191 --> 00:07:18,601
They've got a free plan, streaming
and REST APIs, TypeScript and Python

139
00:07:18,631 --> 00:07:23,501
SDKs, and if you wanna get fancy, you
can use their SSML metadata support

140
00:07:23,511 --> 00:07:25,571
to add emotion into the speech output

141
00:07:26,486 --> 00:07:30,316
Whether you're shipping a weekend project
or production voice agents at work,

142
00:07:30,336 --> 00:07:32,946
you can start free at speechify.ai.

143
00:07:33,266 --> 00:07:34,396
The link is in the show notes.

144
00:07:34,866 --> 00:07:37,346
Thanks so much to Speechify AI
for sponsoring this episode.

145
00:07:38,515 --> 00:07:43,075
Luke: I'd historically worked with
malware, especially malicious packages,

146
00:07:43,075 --> 00:07:48,125
so obviously been part of the software
supply chain focus, and I needed a way

147
00:07:48,125 --> 00:07:53,975
to very quickly isolate potentially
bad things from running on my machine.

148
00:07:54,195 --> 00:07:56,855
Okay, so you can use, there's
many technologies you can use

149
00:07:56,855 --> 00:08:00,625
here, Dockers, VMs, but I wanted
something very quick, okay?

150
00:08:00,625 --> 00:08:03,695
So I had this little tool that
I used where you could very

151
00:08:03,915 --> 00:08:05,745
quickly isolate a process.

152
00:08:06,135 --> 00:08:08,015
So what do I mean by process?

153
00:08:08,415 --> 00:08:12,165
A process is a running application
on a Unix-type operating system.

154
00:08:12,305 --> 00:08:18,295
So you run PS and you see a list of all
these processes, and this was something

155
00:08:18,295 --> 00:08:22,445
that I had for a while, never really
had any plans to go far with it at all.

156
00:08:23,275 --> 00:08:25,735
And what happened was OpenClaw.

157
00:08:26,005 --> 00:08:30,815
So the OpenClaw agent was
released, and it was carnage.

158
00:08:30,865 --> 00:08:34,215
The security situation was pretty bleak.

159
00:08:34,535 --> 00:08:37,125
A lot of people were being compromised.

160
00:08:37,135 --> 00:08:40,575
They'd never really had
this level of exposure to a

161
00:08:40,575 --> 00:08:42,575
technology this powerful before.

162
00:08:43,205 --> 00:08:45,865
And so I thought, "I'm gonna
just put my little project out.

163
00:08:45,925 --> 00:08:47,375
I'm not gonna promote it much.

164
00:08:47,385 --> 00:08:50,805
I'm gonna just put it out there
to help people." It was kind

165
00:08:50,805 --> 00:08:53,085
of a, an altruistic cause.

166
00:08:53,165 --> 00:08:53,985
That's what it was.

167
00:08:54,635 --> 00:08:56,035
And this thing blew up.

168
00:08:56,125 --> 00:09:00,955
So I went to the top of GitHub trending,
and suddenly loads of people converged

169
00:09:00,965 --> 00:09:04,365
and started making issues and saying,
"Can it do this?" and "Can it do that?"

170
00:09:04,505 --> 00:09:06,165
And then I realized I've
got something popular that's

171
00:09:06,165 --> 00:09:08,235
really resonating with folks.

172
00:09:08,535 --> 00:09:12,845
And I think, what really helped
nono propel was it's a… You'll

173
00:09:12,845 --> 00:09:14,635
see it's a very small CLI.

174
00:09:14,635 --> 00:09:15,575
It's very fast.

175
00:09:15,595 --> 00:09:20,545
There's no infrastructure needed,
no hypervisors, runtimes, and

176
00:09:20,545 --> 00:09:21,895
it's able to wrap anything.

177
00:09:21,945 --> 00:09:23,345
You can wrap an agent in there.

178
00:09:23,795 --> 00:09:25,145
You could wrap curl.

179
00:09:25,655 --> 00:09:27,295
You could wrap LS.

180
00:09:27,325 --> 00:09:28,795
You could wrap Wget.

181
00:09:29,315 --> 00:09:30,925
It basically wraps processes.

182
00:09:31,195 --> 00:09:35,235
It does a lot more than that now,
but it was very unique for a sandbox

183
00:09:35,235 --> 00:09:39,085
really, because a sandbox is normally,
there's quite a bit of apparatus

184
00:09:39,085 --> 00:09:42,115
built around them, and this was
something quite new, and it seemed

185
00:09:42,115 --> 00:09:43,605
to really resonate with folks.

186
00:09:44,361 --> 00:09:48,591
Bret (2): It was my first sandboxing
experience other than, like, all of

187
00:09:48,591 --> 00:09:53,001
the other, Chroot and, jails and, like,
all the other… We could argue that

188
00:09:53,011 --> 00:09:54,831
w- what kind of sandboxing those are.

189
00:09:54,831 --> 00:09:58,141
you could debate that whether
Docker is itself a sandboxing tool.

190
00:09:58,541 --> 00:10:03,791
But it's one of those things where we
have been trying to manage and mitigate

191
00:10:03,791 --> 00:10:08,801
the blast radius of a single binary
as an ecosystem for 30-plus years.

192
00:10:08,871 --> 00:10:11,241
We've been wanting to run more
than-- Ever since we were able to

193
00:10:11,241 --> 00:10:13,131
run more than one process, I guess.

194
00:10:13,631 --> 00:10:14,711
Ever since the '60s.

195
00:10:15,041 --> 00:10:18,301
I have a little mainframe blood in me,
so I'm not quite as old as the '60s,

196
00:10:18,331 --> 00:10:21,751
but we were using '60s mainframes
in the '90s in the Navy, so I get

197
00:10:21,751 --> 00:10:24,481
to go back, way back to the green
d- screen terminals in my career.

198
00:10:25,011 --> 00:10:27,451
We've had limited success,
and I think one of the biggest

199
00:10:27,451 --> 00:10:29,931
challenges is, like, UI/UX, right?

200
00:10:29,931 --> 00:10:32,921
Like if it's too painful, we don't use it.

201
00:10:32,921 --> 00:10:37,391
And in fact, my confession on this show
today will be, like, right now, because

202
00:10:37,391 --> 00:10:40,241
I don't really, I don't have any active
consulting clients at this moment, I'm

203
00:10:40,241 --> 00:10:44,191
just making pure content, so I don't have
anyone that I need to, like, sweat it.

204
00:10:44,271 --> 00:10:46,261
I don't need to sweat every
command on my machine.

205
00:10:46,701 --> 00:10:52,131
So the only sandboxing I use is either
nono or sometimes the built-in, like,

206
00:10:52,131 --> 00:10:56,681
Claude Code stuff, but I actually prefer
nono simply because the other tools that

207
00:10:56,681 --> 00:11:00,541
I've used, either I don't understand
them or, like you said, there's a little

208
00:11:00,541 --> 00:11:03,221
more pomp and circumstance to using them.

209
00:11:03,221 --> 00:11:06,511
There's a little more formality,
and I just don't, since I don't

210
00:11:06,521 --> 00:11:08,401
need that, nono just works.

211
00:11:08,401 --> 00:11:11,801
And I love the templating system,
so I don't have to be an expert in

212
00:11:11,821 --> 00:11:15,831
every… You know, if you think about,
like, the processes, the networking,

213
00:11:16,201 --> 00:11:19,801
the file system access, like these,
all these different parts, n- none

214
00:11:19,801 --> 00:11:24,331
of us really know when we use an app
every day what it needs access to.

215
00:11:24,331 --> 00:11:28,271
Like, I didn't realize until I started
using nono how much Claude Code tries

216
00:11:28,271 --> 00:11:32,211
to creep into my system, try to access
my browser extensions, trying to

217
00:11:32,211 --> 00:11:36,581
access different directories, and nono
immediately helped me understand that.

218
00:11:36,681 --> 00:11:41,801
And I think, like, the only other
tools I've seen that do that are tools

219
00:11:41,801 --> 00:11:43,641
that are more diagnostic in nature.

220
00:11:43,951 --> 00:11:43,961
Luke: Mm-hmm.

221
00:11:44,489 --> 00:11:45,639
Bret (2): Patrick Wardle.

222
00:11:45,669 --> 00:11:49,389
he makes, like, some Mac utilities
for security and firewalling and

223
00:11:49,619 --> 00:11:50,959
file watching and stuff like that.

224
00:11:50,959 --> 00:11:53,479
And then the famous Sysinternals,
WinInternals on the Windows

225
00:11:53,479 --> 00:11:55,309
side from Mark Russinovich.

226
00:11:55,629 --> 00:11:58,189
Those have been around for 30 years,
and those were really all about

227
00:11:58,189 --> 00:12:01,269
tracking fi- You know, you could see
the, every file it touched, did it

228
00:12:01,269 --> 00:12:04,579
write, did it read, and you could
sort of ex- But it didn't, it wasn't

229
00:12:04,579 --> 00:12:06,659
meant as, like, a firewalling system.

230
00:12:06,659 --> 00:12:11,859
So to have this kind of utility feels
almost like a superpower, because if I'm

231
00:12:11,859 --> 00:12:16,269
nervous about something, I can just throw
nono in front of it, and it's gonna,

232
00:12:16,269 --> 00:12:18,519
it's gonna not do nefarious things.

233
00:12:19,929 --> 00:12:24,949
So, tell us a little bit about, like,
the elevator pitch for someone today

234
00:12:24,959 --> 00:12:30,379
who's… They're using agents, they're
using AI, they're still at the shell.

235
00:12:30,389 --> 00:12:34,089
they're a shell fan, and
what would nono do for them?

236
00:12:36,321 --> 00:12:37,171
Luke: Absolutely.

237
00:12:37,181 --> 00:12:43,081
So I'm not particularly great at elevator
pitches, but I'm gonna do my best.

238
00:12:43,241 --> 00:12:44,471
You know, I'm notorious for

239
00:12:44,563 --> 00:12:46,373
Bret (2): an engineering
podcast, so don't… Yeah, this

240
00:12:46,421 --> 00:12:46,751
Luke: yeah.

241
00:12:46,761 --> 00:12:50,151
I kind of probably more of an escalator
pitcher, if you see what I mean?

242
00:12:50,491 --> 00:12:55,121
But no, with nono, you can get
going incredibly quickly, okay?

243
00:12:55,121 --> 00:12:58,981
So you s- pick whatever coding agent
you want, we have a profile for

244
00:12:58,981 --> 00:13:03,441
that, and it's as simple as nono
pull, and the name of the profile.

245
00:13:03,741 --> 00:13:08,281
That will pull everything down for
you securely, and then you do nono

246
00:13:08,291 --> 00:13:11,811
run, and you pass in the name of
the coding agent, and you're off.

247
00:13:12,331 --> 00:13:13,441
nono's in the background.

248
00:13:13,451 --> 00:13:15,871
You need never do anything more, okay?

249
00:13:15,871 --> 00:13:16,651
That's all you need.

250
00:13:17,011 --> 00:13:22,551
So within just a few seconds, you can be
sandboxed and just get on with your work.

251
00:13:22,951 --> 00:13:26,111
Now, if you wanna go
deeper, you absolutely can.

252
00:13:26,201 --> 00:13:28,471
There's a lot to nono under the hood.

253
00:13:28,921 --> 00:13:32,281
But it allows everybody…
It's a big church.

254
00:13:32,551 --> 00:13:36,861
People can come in, get going quickly,
and then the experts, they can find

255
00:13:36,861 --> 00:13:38,421
their way and go deeper and deeper.

256
00:13:40,113 --> 00:13:43,823
Bret (2): Well, I guess the good
point there is that, like even I was

257
00:13:43,823 --> 00:13:45,643
early days, I feel like, for no-no.

258
00:13:45,743 --> 00:13:47,853
actually thanks to my chain--
friends at Chainguard, because they

259
00:13:47,853 --> 00:13:50,233
were bragging about you, telling
me that I should check it out.

260
00:13:50,573 --> 00:13:56,483
But my, my onboarding experience was
like read one page of documentation

261
00:13:56,863 --> 00:14:00,303
and then copy and paste the command,
and I'm back in ch- and I'm back

262
00:14:00,303 --> 00:14:01,973
in Claude Code or back in…

263
00:14:02,263 --> 00:14:04,883
At the time, I actually think I was
trying to use OpenCode, and I think you

264
00:14:04,883 --> 00:14:09,073
all were just developing the OpenCode
profile, and I think I was commenting

265
00:14:09,073 --> 00:14:12,823
on an issue or two, about making sure
that worked, because at the time I was

266
00:14:12,833 --> 00:14:14,163
like kind of obsessed about OpenCode.

267
00:14:14,303 --> 00:14:17,263
I've kinda moved over to the dark side
with the walled garden of Claude Code,

268
00:14:17,273 --> 00:14:22,193
but, it works in both and I also tinker
with Pi and I've played with it there.

269
00:14:22,643 --> 00:14:27,043
That was my first use case, but seeing
all your demos of showing how I can

270
00:14:27,043 --> 00:14:32,193
just wrap any other commands inside
that and how I can control networking

271
00:14:32,213 --> 00:14:37,513
or secrets with this tool has really
made me realize I need to, I basically

272
00:14:37,513 --> 00:14:41,883
need to spend more time with it because
I have, I have like those 1.0 or those

273
00:14:41,893 --> 00:14:47,003
v-vo.1 limitations in my mind, and
I'm now like, "Oh, this can, this can

274
00:14:47,003 --> 00:14:48,463
do, this can do more than I realized."

275
00:14:48,493 --> 00:14:51,013
I need to start leaning
into the, to the egress.

276
00:14:51,013 --> 00:14:54,113
'Cause I, at least for me, that's the
first thing I'm willing to let an agent

277
00:14:54,123 --> 00:14:57,133
do, is I'm like, "Yeah, yeah, yeah," like
as long as you're isolated in my system

278
00:14:57,133 --> 00:15:00,153
somewhere, I'm just gonna let you access
anything on the internet you wanna get to.

279
00:15:00,663 --> 00:15:05,533
And, and I know that I probably
should have a more understand- nuanced

280
00:15:05,533 --> 00:15:11,413
understanding of like where does my agent
actually normally go and where should I

281
00:15:11,613 --> 00:15:14,373
care or should I limit it in that case.

282
00:15:14,373 --> 00:15:17,993
is there like an audit mode where I
can see things, like I can see the

283
00:15:17,993 --> 00:15:22,033
tracking record, but I don't have to
see the, It doesn't actually block

284
00:15:22,033 --> 00:15:25,563
it, it just lets me know what it was
trying to access when it accesses it?

285
00:15:26,937 --> 00:15:27,167
Luke: Yeah.

286
00:15:27,167 --> 00:15:29,037
So, we have two approaches there.

287
00:15:29,097 --> 00:15:34,387
One is when you exit the session, anything
that has attempted to be accessed and

288
00:15:34,387 --> 00:15:38,377
is being denied, it will give you the
option to add that to your profile.

289
00:15:39,167 --> 00:15:40,817
And it will also guide you around.

290
00:15:41,127 --> 00:15:45,127
If something is particularly
sensitive and you want to add it,

291
00:15:45,657 --> 00:15:49,607
then it'll ask you just to double
confirm, like secrets and so forth.

292
00:15:49,707 --> 00:15:53,367
The other system that we have is that
there's an audit of absolutely everything

293
00:15:53,377 --> 00:15:59,187
the agent does, every domain it calls,
the path, the environment variables, the

294
00:15:59,187 --> 00:16:07,127
binary, its fingerprint, SHA-256, the
co- tools that it calls, the specific

295
00:16:07,127 --> 00:16:09,357
tools, the flags, everything is audited.

296
00:16:09,807 --> 00:16:15,567
And we have this model essentially where
everything in the agent space sandbox is

297
00:16:15,567 --> 00:16:21,097
untrusted, but there's an adjacent trusted
side, which we call the supervisor, and

298
00:16:21,097 --> 00:16:25,187
this is the one that captures all of
the audit, and it's the one that feeds

299
00:16:25,187 --> 00:16:27,797
in the, what we call phantom tokens.

300
00:16:27,807 --> 00:16:29,497
So they're not real credentials.

301
00:16:29,517 --> 00:16:31,467
It's not your real GitHub token.

302
00:16:31,887 --> 00:16:36,797
It's a random string which the
agent gets, and we essentially treat

303
00:16:36,827 --> 00:16:39,167
the agent kind of like a prisoner.

304
00:16:39,307 --> 00:16:39,647
Okay?

305
00:16:39,647 --> 00:16:44,649
So if you think about you go to
like a penitentiary You can't just

306
00:16:44,649 --> 00:16:46,039
keep somebody locked in a room.

307
00:16:46,109 --> 00:16:47,979
You need to give them a bit of authority.

308
00:16:47,999 --> 00:16:52,199
They need to go make their phone call,
go to the canteen, walk around the yard.

309
00:16:52,829 --> 00:16:57,229
So we allow agents to do that, but
we limit where they can go, and

310
00:16:57,229 --> 00:17:00,279
we limit what they can have, and
we still keep a good eye on them.

311
00:17:00,749 --> 00:17:04,609
Whereas I think a lot of sandboxes,
it's been more around lock them in

312
00:17:04,619 --> 00:17:05,999
the room and never let them out.

313
00:17:06,779 --> 00:17:09,989
But really for agents to be
good and effective and to do all

314
00:17:09,989 --> 00:17:13,929
these amazing things, you need
to give them a bit of authority.

315
00:17:13,929 --> 00:17:15,019
You need to trust them.

316
00:17:15,199 --> 00:17:19,089
You need to allow them to have access
to things that are a little bit

317
00:17:19,089 --> 00:17:24,459
powerful, and we're able to carve
out very, very safe paths around

318
00:17:24,849 --> 00:17:26,409
what that agent can actually do.

319
00:17:26,409 --> 00:17:34,119
So we have… With dogfood nono a lot, so
things like the AWS CLI, we very much lock

320
00:17:34,119 --> 00:17:39,849
it down around what environment variables
it can have, the URLs that it can call.

321
00:17:40,229 --> 00:17:45,259
we will limit it to just the get method,
so it can't post, it can't change things,

322
00:17:45,309 --> 00:17:48,038
it can only do read-only operations.

323
00:17:48,368 --> 00:17:50,318
We do this with kubectl a lot.

324
00:17:50,438 --> 00:17:54,758
I know you're a Kubernetes guy,
so we prevent like, replicas from

325
00:17:54,758 --> 00:17:58,308
being a large number and clusters
being deleted and namespaces.

326
00:17:58,358 --> 00:18:02,228
And this way we know the agent can just
go for it, it can explore, it can debug

327
00:18:02,248 --> 00:18:06,348
clusters, but we stop it from doing
the dangerous stuff, and we do this

328
00:18:06,378 --> 00:18:08,948
care of what we call tool sandboxing.

329
00:18:09,338 --> 00:18:13,388
So with nono, you've got a main sandbox
that each time the agent wants to

330
00:18:13,428 --> 00:18:17,258
call a tool, we spawn a micro sandbox.

331
00:18:17,258 --> 00:18:21,718
It's a very small, ephemeral,
short-lived sandbox where it gets its

332
00:18:21,718 --> 00:18:26,188
own unique policy, and if it's allowed
a specific secret, it's allowed it,

333
00:18:26,188 --> 00:18:27,628
but the rest of the sandbox doesn't.

334
00:18:28,258 --> 00:18:34,798
So that way your AWS CLI can access
the credentials, but Curl doing

335
00:18:34,798 --> 00:18:39,078
a post and a file read can't,
'cause that's data exfiltration.

336
00:18:39,478 --> 00:18:44,758
So, so I think this is where we're quite
different to a lot of the other sandboxes.

337
00:18:44,788 --> 00:18:45,058
Yeah.

338
00:18:45,118 --> 00:18:45,378
Yeah

339
00:18:46,193 --> 00:18:48,583
Bret (2): Yeah, I saw a couple of
the demos on your YouTube yesterday.

340
00:18:48,583 --> 00:18:49,863
I was checking out the channel

341
00:18:49,943 --> 00:18:49,953
Luke: Mm-hmm.

342
00:18:50,707 --> 00:18:54,687
Bret (2): I was really interested
in how-- I mean, I use the GitHub

343
00:18:54,757 --> 00:18:56,667
command line tool constantly.

344
00:18:56,717 --> 00:18:57,327
Like, it's

345
00:18:57,589 --> 00:18:57,599
Luke: Mm-hmm.

346
00:18:57,607 --> 00:18:59,567
Bret (2): e- it's either me or
the agent using it constantly.

347
00:18:59,567 --> 00:19:03,177
In fact, I built a, this GitHub sec-
security analyzer tool that I built.

348
00:19:03,427 --> 00:19:06,847
It gets your token from the GitHub command
line tool, to talk to the API, 'cause

349
00:19:06,847 --> 00:19:08,437
I just, it's the easier way to do it?

350
00:19:08,447 --> 00:19:09,307
less code on my side.

351
00:19:09,877 --> 00:19:16,887
And seeing the demo of how the profile
will limit the put requests to particular

352
00:19:16,887 --> 00:19:22,877
URLs of GitHub as a way to… the way
I looked at it was that this is a way

353
00:19:22,877 --> 00:19:28,017
for me to use my existing login and not
have to go create a custom PAT, 'cause

354
00:19:28,017 --> 00:19:30,837
that's what I've been doing in some
cases, where I go and I make this…

355
00:19:30,847 --> 00:19:32,827
I mean, I've been making
a lot of PATs this year.

356
00:19:33,087 --> 00:19:38,027
Like fine-grained, personal access tokens
so that I can have these nuanced profiles

357
00:19:38,057 --> 00:19:43,857
and reali- and it's a tedious h- it's a--
And then I gotta store that PAT somewhere.

358
00:19:43,857 --> 00:19:44,417
I gotta put that in 1Password, and then I
gotta get that out into the thing I want.

359
00:19:49,927 --> 00:19:51,857
you have all of this access,"
but you could actually limit

360
00:19:51,867 --> 00:19:55,327
the agent in a different way
'cause it's all just HTTP, right?

361
00:19:55,687 --> 00:20:00,457
I really, I like that approach, and I'm
excited to see that sort of take on,

362
00:20:01,167 --> 00:20:05,857
like to be more prevalent, because it, it
feels like a scale, more scalable model

363
00:20:05,877 --> 00:20:10,197
than 1,000 PATs for agents for every
p- profile and every, Because if I have

364
00:20:10,197 --> 00:20:14,357
three clients as a consultant, I'm, on
GitHub, I'm always very nervous about

365
00:20:14,357 --> 00:20:17,707
that because, some people, they work for
companies, they create a separate user

366
00:20:17,707 --> 00:20:22,077
account because that, the bifurcation
of permissions in the PAT can be really

367
00:20:22,117 --> 00:20:27,567
nerve-wracking when I realize my one PAT
has access to a dozen organizations, and

368
00:20:27,567 --> 00:20:32,807
my login on my local GitHub has way more
authority than it ha- should have probably

369
00:20:32,807 --> 00:20:34,537
for a single login on a single machine.

370
00:20:35,077 --> 00:20:40,057
And it, your profile methodology around
the URLs and whether it's GET versus,

371
00:20:40,497 --> 00:20:43,067
POST and all that is it makes sense to me.

372
00:20:43,067 --> 00:20:43,567
I like it.

373
00:20:43,577 --> 00:20:46,327
So I've not used it a lot yet, but
I watched the demos and thought,

374
00:20:46,357 --> 00:20:47,537
"Now I gotta, I gotta learn this."

375
00:20:49,131 --> 00:20:49,861
Luke: Absolutely.

376
00:20:50,201 --> 00:20:53,961
And this is all discovered through
our own pain really, using agents

377
00:20:53,961 --> 00:20:55,311
and seeing things go astray.

378
00:20:55,811 --> 00:20:59,431
It's, we realized that we wanted to
really limit what the agent could do.

379
00:20:59,431 --> 00:21:05,151
So, so we do L7 filtering, the path,
the method, and so forth, but we also

380
00:21:05,261 --> 00:21:10,511
do the arguments, because what will
happen is an agent will try to use the

381
00:21:10,511 --> 00:21:16,741
GH CLI command, and it'll try to use
arguments, and then we will block it.

382
00:21:16,741 --> 00:21:21,291
We'll say no, and then it will try
to pipe raw GraphQL through, and

383
00:21:21,291 --> 00:21:22,761
we'll pick that up, and we'll say no.

384
00:21:23,671 --> 00:21:25,841
And then it will try
to wrap it in a shell.

385
00:21:25,841 --> 00:21:29,961
It'll do SH pipe, and we pick that
up, and we go, "No." And then you

386
00:21:29,961 --> 00:21:31,501
just see them give up in the end.

387
00:21:31,511 --> 00:21:34,911
You know, it's, I won't name them,
but certain Claude, s- certain agents

388
00:21:35,551 --> 00:21:40,111
will be very, very persistent, and
then eventually they go, I'm done.

389
00:21:40,401 --> 00:21:41,541
You got no, no running.

390
00:21:42,141 --> 00:21:43,811
I give up," essentially.

391
00:21:43,811 --> 00:21:47,501
And this allows us to really kind
of look after ourselves really,

392
00:21:47,501 --> 00:21:52,081
We… Because we don't want agents
posting to our organization settings.

393
00:21:52,641 --> 00:21:54,541
We don't really want them
posting, quite a lot.

394
00:21:54,541 --> 00:21:58,251
the, the- these things will just create
issues when you didn't want them to.

395
00:21:58,251 --> 00:22:03,551
And, and, so we really sort of are able
to… Somebody described it as zero trust

396
00:22:03,551 --> 00:22:06,781
for the terminal, which I thought was
kind of quite a good way of putting it,

397
00:22:06,831 --> 00:22:08,921
Bret (2): Yeah, if you had that
marketing arm, that's probably

398
00:22:08,921 --> 00:22:10,111
what your website would say now.

399
00:22:10,905 --> 00:22:12,895
Luke: Yeah, yeah, absolutely.

400
00:22:13,251 --> 00:22:15,681
Bret (2): yeah, because it,
it-- that sounds like a very

401
00:22:15,711 --> 00:22:18,191
buzzworthy, zero trust CLI.

402
00:22:18,551 --> 00:22:19,851
and I don't disagree.

403
00:22:19,881 --> 00:22:22,521
I mean, it sounds like a good
thing, like it's something I want.

404
00:22:22,541 --> 00:22:25,461
I mean, I love every time I hear zero
trust, I think, "Ooh, that's what the sa-

405
00:22:25,461 --> 00:22:30,951
the safe kids do. I used YOLO mode." so
c- if we back up a minute and talk about,

406
00:22:31,121 --> 00:22:33,541
like, the unique design of this app.

407
00:22:33,711 --> 00:22:36,491
Tell me how it uses the native
kernel, 'cause this thing is

408
00:22:36,491 --> 00:22:38,731
all running on my Mac directly.

409
00:22:38,731 --> 00:22:43,531
Like, it's not creating some sort of VM
or a container or some other abstraction.

410
00:22:43,801 --> 00:22:49,561
It's just right there on my machine,
and then it also works on Linux, which

411
00:22:49,581 --> 00:22:50,681
is a completely different kernel.

412
00:22:50,681 --> 00:22:52,021
I don't know if it works on Windows yet.

413
00:22:52,041 --> 00:22:55,361
I think I saw the website where it said
WSL 2 was the way to do it, but tell

414
00:22:55,361 --> 00:22:57,001
me a little bit about how that works

415
00:22:58,499 --> 00:23:01,779
Luke: So we use two native
sandboxing technologies.

416
00:23:02,339 --> 00:23:06,139
On Apple, we use one called Seatbelt,
which has been around for quite a while.

417
00:23:06,679 --> 00:23:10,559
If you look at Apple's documentation,
they will say it's deprecated,

418
00:23:10,659 --> 00:23:15,089
but it isn't because it's used
by some really huge projects.

419
00:23:15,089 --> 00:23:18,179
Chrome very much relies on it,
so it's not going anywhere.

420
00:23:18,719 --> 00:23:23,939
It's just not as well documented, and
that allows us to do file sandboxing

421
00:23:24,139 --> 00:23:27,219
and basic network sandboxing.

422
00:23:27,829 --> 00:23:33,889
We also then have Landlock, which is in
Linux, and Linux Landlock is, it's what

423
00:23:33,889 --> 00:23:36,419
we call an LSM, a Linux security module.

424
00:23:36,739 --> 00:23:42,629
So it sits alongside SE Linux and
various sort of well-known security

425
00:23:42,649 --> 00:23:47,389
primitives in the kernel, and this again
allows you to do this, file-specific,

426
00:23:47,389 --> 00:23:50,557
network-specific sandboxing.

427
00:23:50,867 --> 00:23:54,107
Now, there are several
approaches within Linux.

428
00:23:54,147 --> 00:23:59,477
You'll hear namespaces, cgroups,
kind of, full-on microVMs

429
00:23:59,487 --> 00:24:02,127
like Firecracker and gVisor.

430
00:24:02,947 --> 00:24:05,877
We actually went with Landlock
because it suited us very well

431
00:24:05,887 --> 00:24:11,047
for this tool-specific, very fast
sandboxing, but also we don't

432
00:24:11,097 --> 00:24:13,727
require any elevation of privileges.

433
00:24:13,787 --> 00:24:15,917
You don't need to use root or sudo.

434
00:24:15,937 --> 00:24:20,957
We run in user space, and this is really
important for nono because this means

435
00:24:20,957 --> 00:24:23,617
nono can practically run everywhere.

436
00:24:24,557 --> 00:24:26,927
You can run nono in a Docker image.

437
00:24:26,987 --> 00:24:28,117
We've mentioned Chainguard.

438
00:24:28,117 --> 00:24:31,877
We use one of the stripped-down Chainguard
Rust images, which we run nono in.

439
00:24:32,447 --> 00:24:36,077
You can run nono on many
different types of comp- computer.

440
00:24:36,197 --> 00:24:38,107
It'll practically run anywhere, okay?

441
00:24:38,347 --> 00:24:42,572
And it's very similar to the, I
think the trajectory that Docker had.

442
00:24:42,612 --> 00:24:44,392
I'm a huge fan of Docker, okay?

443
00:24:44,402 --> 00:24:48,202
And how Docker went from this
localized tool that developers

444
00:24:48,202 --> 00:24:52,862
loved to this large-scale
orchestrated system for workloads.

445
00:24:53,482 --> 00:24:57,332
Now, what typically happens with
nono, somebody will start off in

446
00:24:57,332 --> 00:24:59,092
an individual way, like you are.

447
00:24:59,242 --> 00:24:59,592
Okay?

448
00:24:59,592 --> 00:25:01,622
They'll start to create their own profile.

449
00:25:02,612 --> 00:25:03,902
They'll maybe check it into GitHub.

450
00:25:04,292 --> 00:25:08,542
It becomes their thing that they curate
over time, and then they'll find team

451
00:25:08,542 --> 00:25:11,582
members, and they'll start to share
these things, and they'll start to

452
00:25:11,582 --> 00:25:15,112
set up more and more profiles for all
the different environments they're in.

453
00:25:15,802 --> 00:25:18,962
And then eventually it'll get to the
point where they'll go, "Well, we could

454
00:25:18,962 --> 00:25:23,292
just lift and shift this into a Docker
file so the entry point could be nono

455
00:25:23,432 --> 00:25:30,502
run profile agent." And then like, right,
okay, we're on Kubernetes now, And so

456
00:25:30,512 --> 00:25:36,412
it's got this very seamless ability to run
anywhere, and that's where it's very good

457
00:25:36,412 --> 00:25:38,132
for sort of walking the journey with you.

458
00:25:38,132 --> 00:25:44,722
You can start off with never used
it before, quickly isolate my coding

459
00:25:44,722 --> 00:25:48,602
agent, and perhaps share a home
folder and my development folder.

460
00:25:48,842 --> 00:25:49,922
So you start off there.

461
00:25:50,322 --> 00:25:51,312
You go on the journey.

462
00:25:51,312 --> 00:25:52,172
You learn more and more.

463
00:25:52,172 --> 00:25:56,062
You go down the rabbit hole, and then
you start working in a team capacity,

464
00:25:56,062 --> 00:25:59,652
and then you start looking at, right,
okay, we wanna run this in production,

465
00:25:59,692 --> 00:26:04,112
so how do we do that, and that's where,
nono's experienced a good amount of

466
00:26:04,112 --> 00:26:07,942
adoption essentially, 'cause it's got
that kind of seamless deployability.

467
00:26:09,302 --> 00:26:12,512
Bret (2): I saw that, you had a blog
post, 'cause one of my questions was

468
00:26:12,512 --> 00:26:14,382
gonna be like, where else is this used?

469
00:26:14,402 --> 00:26:17,642
'Cause it seems like such a core
utility, that if it could run on the

470
00:26:17,642 --> 00:26:22,522
Mac kernel, it can run on Linux kernel,
it's, where in the cloud is it running?

471
00:26:22,522 --> 00:26:25,512
And I saw that you had this
post, the GitHub Action supply

472
00:26:25,512 --> 00:26:28,452
chain attacks are here, so stop
giving CI your release token.

473
00:26:28,872 --> 00:26:33,972
We just had, our previous episode that
released on the podcast was about the new

474
00:26:33,982 --> 00:26:38,452
GitHub agentic workflows, which does a lot
of this hardening as an in an automated

475
00:26:38,452 --> 00:26:42,252
way, where they're trying to egress,
ingress/egress, like, read-only file

476
00:26:42,252 --> 00:26:47,232
system, everything in a container that's
got the inputs and outputs are filtered,

477
00:26:47,232 --> 00:26:48,542
like there's all these different steps.

478
00:26:48,862 --> 00:26:51,192
Tell me about, like, what
are you seeing in CI?

479
00:26:51,202 --> 00:26:53,702
Like, what is this, what are the
advantages of using this in CI?

480
00:26:54,554 --> 00:26:57,034
Luke: So we run nono in GitHub Actions.

481
00:26:57,284 --> 00:26:58,864
we realized it was very effective.

482
00:26:59,554 --> 00:27:04,224
So we can do native sandboxing, care
of the fact that GitHub Actions,

483
00:27:04,764 --> 00:27:06,674
the underlying host system is Linux.

484
00:27:07,584 --> 00:27:13,244
And we then released a project called
Runseal, where it's an action that

485
00:27:13,244 --> 00:27:15,054
you can easily consume and use.

486
00:27:15,484 --> 00:27:21,254
And then there's a, a simple YAML
structure where you can set what domains

487
00:27:21,254 --> 00:27:26,544
you want to allow that workflow to connect
to, and you can do credential injection.

488
00:27:26,894 --> 00:27:34,004
So the execution environment where the
action runs, it cannot have a real token.

489
00:27:34,204 --> 00:27:39,094
It gets a spoof token, a phantom
token we call them, and you can

490
00:27:39,094 --> 00:27:41,284
limit which domains it can call to.

491
00:27:41,574 --> 00:27:47,424
So a lot of these sort of fork attacks
that happen in GitHub Actions, typically

492
00:27:47,424 --> 00:27:51,994
they look to exfiltrate a secret,
a GitHub token, and they will look

493
00:27:51,994 --> 00:27:56,714
to exfiltrate to a specific domain,
and we can lock all of that down.

494
00:27:57,024 --> 00:28:01,744
So we can lock down an action to just
being able to talk to api.github.com.

495
00:28:02,454 --> 00:28:07,134
All of the secrets are useless
outside of that operating context.

496
00:28:07,144 --> 00:28:09,674
They're only useful
within that short session.

497
00:28:10,404 --> 00:28:13,174
And we can also do a lot
of supply chain stuff.

498
00:28:13,174 --> 00:28:15,284
So we do a lot of Sigstore
stuff in there as well.

499
00:28:15,284 --> 00:28:19,634
So we do a lot to sign skill files.

500
00:28:19,684 --> 00:28:26,644
You can do a GitHub Action provenance,
like SLSA, of your skill files, and then

501
00:28:26,644 --> 00:28:31,594
when the agent tries to access those
skill files to read them in the sandbox,

502
00:28:31,954 --> 00:28:37,894
we do a verification that the files as
they exist in GitHub have not changed

503
00:28:37,894 --> 00:28:41,634
at the moment that the syscall comes
in and the agent tries to access them.

504
00:28:42,024 --> 00:28:44,034
Because this is how
prompt injections happen.

505
00:28:44,604 --> 00:28:47,614
And a-again, that's one of the
things we do that we're not very well

506
00:28:48,364 --> 00:28:51,464
suited to telling folks about this.

507
00:28:51,514 --> 00:28:55,524
we have full end-to-end supply chain
security in nono as well, which is

508
00:28:55,814 --> 00:28:57,414
something that a few people don't know.

509
00:28:57,604 --> 00:28:58,024
Bret (2): Yeah.

510
00:28:58,334 --> 00:29:04,864
I can see how I like the idea of
signing my skills and then verifying

511
00:29:04,864 --> 00:29:07,134
them, 'cause that's always the, that's
always the, the part that everybody

512
00:29:07,134 --> 00:29:09,264
skips, is the verification at runtime.

513
00:29:09,694 --> 00:29:10,584
It's not always obvious.

514
00:29:10,584 --> 00:29:14,594
It's sometimes hard, when you're pulling
artifacts, like Kubernetes images.

515
00:29:14,594 --> 00:29:17,014
Like I've been, for a decade, I feel
like I've been talking about and

516
00:29:17,014 --> 00:29:20,894
helping people understand, the signing
and verification nature of container

517
00:29:20,894 --> 00:29:24,694
images, and I l- I love the, I love that
we have objects now that we can sign.

518
00:29:24,694 --> 00:29:30,674
I can actually, build my apps and ha- have
Sigstore to sign them and the-- But the

519
00:29:30,674 --> 00:29:36,114
ability to guarantee that, that skill is
indeed my skill, is I th- it's probably

520
00:29:36,114 --> 00:29:40,904
one of those things where, like so many
of the security tools on- there's very

521
00:29:40,904 --> 00:29:45,624
few percentage of engineers, let's just
say 10 or 20%, probably less, that are

522
00:29:45,624 --> 00:29:47,314
really paying attention to that stuff.

523
00:29:47,714 --> 00:29:51,134
And but I tend to, on this podcast,
I tend to kind of try to shout

524
00:29:51,134 --> 00:29:54,354
all this stuff from the rooftop
of like, it's not that hard.

525
00:29:54,364 --> 00:29:55,604
It actually isn't.

526
00:29:55,914 --> 00:29:57,564
And you, and you can
always start somewhere.

527
00:29:57,564 --> 00:29:59,344
Like, it doesn't have to be end to end.

528
00:29:59,354 --> 00:30:04,454
Like, if you just had one, one GitHub
action that used, that you tried nono

529
00:30:04,474 --> 00:30:07,454
with, and you actually signed, bothered
signing a skill or something like that,

530
00:30:07,454 --> 00:30:11,214
or you actually bothered limiting to
the API egress, like that's a start.

531
00:30:11,614 --> 00:30:14,934
And it doesn't-- You don't have to
boil the ocean with these tools and

532
00:30:14,974 --> 00:30:17,694
make sure, think that every single
nook and cranny has to be solved.

533
00:30:17,964 --> 00:30:20,194
Of course, agents I think are, are
gonna make a lot of this easier.

534
00:30:20,194 --> 00:30:25,194
I think I'm finding that one of my,
my favorite use cases for agents is,

535
00:30:25,694 --> 00:30:29,374
is not-- Obviously, we all started
with like writing code in YAML.

536
00:30:29,414 --> 00:30:30,734
mostly for me it was YAML.

537
00:30:31,024 --> 00:30:32,714
Docker file is YAML, TOML.

538
00:30:32,714 --> 00:30:39,114
And I find that implementing sort of
like org-wide changes as a DevOps person

539
00:30:39,114 --> 00:30:42,814
or as a platform engineer has always
been problematic because you end up

540
00:30:42,814 --> 00:30:47,074
having 100 re, repos that you want to
make some sort of change to, or you've

541
00:30:47,074 --> 00:30:51,014
got 50 Kubernetes YAML repos spread
out everywhere, and you wanna make some

542
00:30:51,014 --> 00:30:53,144
find, find, functional change in there.

543
00:30:53,144 --> 00:30:55,164
And then you have to write
your own scripts that would go

544
00:30:55,164 --> 00:30:56,284
through and automate each one.

545
00:30:56,574 --> 00:30:59,844
And I find that agents, agents
make the implementations of a lot

546
00:30:59,844 --> 00:31:02,534
of these things so much easier
because the repe- repetitive nature

547
00:31:02,534 --> 00:31:05,934
of a lot of the, the work that I
feel like we do in the operations

548
00:31:05,934 --> 00:31:07,884
space can be alleviated with this.

549
00:31:07,894 --> 00:31:11,154
So I'm looking at this tool and I'm
thinking, "Well, that's a change to

550
00:31:11,154 --> 00:31:14,994
my workflows, and that's me tracking
some URLs and extra things." Not

551
00:31:15,084 --> 00:31:19,364
that much work, but once I've done it
once, I kinda can just ask the agent,

552
00:31:19,364 --> 00:31:21,324
"Please give me PRs for all of them.

553
00:31:21,334 --> 00:31:24,864
We're gonna review them together, and then
you're gonna implement the PRs." Where

554
00:31:24,864 --> 00:31:30,244
else outside of CI, like what is… Okay,
so you talked about Kubernetes production.

555
00:31:30,474 --> 00:31:34,944
We started with the idea of local
harnesses, which is, I think, where

556
00:31:34,954 --> 00:31:36,304
probably a lot of us are getting started.

557
00:31:36,314 --> 00:31:39,104
Then we realized it's str- it's
for more than just our harnesses.

558
00:31:39,104 --> 00:31:43,634
Then I realized, oh, I can put this in
a CI and I can help harden, like the

559
00:31:43,634 --> 00:31:46,584
fact that GitHub Actions doesn't even
have egress filtering firewalls today.

560
00:31:46,584 --> 00:31:49,124
I know it's coming, they're saying
it's coming this year, but, like, we

561
00:31:49,124 --> 00:31:52,564
don't have it yet, and, we haven't
had it for the eight years or six

562
00:31:52,564 --> 00:31:53,924
years that we've had GitHub Actions.

563
00:31:54,484 --> 00:31:57,574
So, so people can start doing that,
and they can start limiting the

564
00:31:57,574 --> 00:32:01,174
secrets access into their apps,
which we also can't very easily do

565
00:32:01,174 --> 00:32:04,314
with GitHub Actions without using
environments and other fancy features.

566
00:32:04,694 --> 00:32:07,334
And so they start to get it into
more of their CI, and then they

567
00:32:07,334 --> 00:32:09,144
realize they might be able to
harden some workflows, workloads in

568
00:32:09,734 --> 00:32:15,284
production, particularly agents that
we're all building with agent SDKs.

569
00:32:15,534 --> 00:32:18,884
Is that-- So is that an area that you're,
you explained that earlier, but that's,

570
00:32:19,454 --> 00:32:22,524
is that, I guess that's a very common
d- dev thing to do, is we're all trying

571
00:32:22,524 --> 00:32:27,164
to build these agents, whether it's for
our own automation or for a, a line of

572
00:32:27,164 --> 00:32:31,274
business app, and we put these things
in containers and we think we're done.

573
00:32:31,324 --> 00:32:32,344
We think we're okay.

574
00:32:33,094 --> 00:32:35,724
What, what does this do in a container?

575
00:32:36,344 --> 00:32:38,564
Like, what's my, what's the
argument for why I need this

576
00:32:38,574 --> 00:32:40,254
in my containers in Kubernetes?

577
00:32:41,844 --> 00:32:42,704
Is it because I could,

578
00:32:42,793 --> 00:32:43,013
Luke: they?

579
00:32:43,363 --> 00:32:43,733
Yeah

580
00:32:43,794 --> 00:32:46,744
Bret (2): s- set a policy to lock down
to non-root and all that in there?

581
00:32:47,501 --> 00:32:47,961
Luke: Yeah.

582
00:32:47,961 --> 00:32:52,091
So this, you're touching on a great point
here to really kind of differentiate

583
00:32:52,871 --> 00:32:57,741
nono from containers and microVMs, and
it's not a one is better than the other.

584
00:32:57,751 --> 00:32:59,661
They really complement each other well.

585
00:32:59,811 --> 00:33:00,131
Okay?

586
00:33:00,131 --> 00:33:03,181
So one of the things you're, that
you're picking up with nono, it's

587
00:33:03,211 --> 00:33:05,111
what we call a capability-based model.

588
00:33:05,121 --> 00:33:06,121
It's fine-grained.

589
00:33:06,391 --> 00:33:06,741
Okay?

590
00:33:06,741 --> 00:33:13,191
So you're able to be very specific around
individual files that can be accessed,

591
00:33:13,611 --> 00:33:20,971
perhaps read or write or execute very
fine-grained URL filtering, the secrets

592
00:33:20,971 --> 00:33:23,141
injection, the skill attestations.

593
00:33:24,557 --> 00:33:28,177
Now, with a Docker image, if you
were to try to do that, that's

594
00:33:28,177 --> 00:33:31,027
gonna be a lot of volume mounts
that you're gonna be constantly…

595
00:33:31,257 --> 00:33:34,577
Operationally it's gonna be very
expensive to do that because you're

596
00:33:34,597 --> 00:33:36,987
gonna have to maintain all of that, okay?

597
00:33:37,387 --> 00:33:43,607
And so nono was built more for this
new world of this very fine-grained

598
00:33:44,177 --> 00:33:49,697
agent in its operating context,
protecting the spaces there essentially.

599
00:33:50,167 --> 00:33:58,137
And nono is not as good as containers
and microVMs at complete isolation.

600
00:33:59,397 --> 00:34:02,776
They are… It's, it's,
it's, it's brilliant.

601
00:34:02,776 --> 00:34:04,186
It's on, it's protected.

602
00:34:04,186 --> 00:34:08,296
I mean, you get kernel exploits of
course, but generally it's a very good

603
00:34:08,616 --> 00:34:10,986
solid monolithic layer of isolation.

604
00:34:11,076 --> 00:34:12,006
You know where you stand.

605
00:34:12,016 --> 00:34:13,206
It's a safety belt.

606
00:34:13,866 --> 00:34:20,056
Nono is more of a… Like I
said, it's a very fine-grained,

607
00:34:20,626 --> 00:34:22,736
very customizable thing.

608
00:34:23,306 --> 00:34:30,316
And so we often say to folks, "When you
run nono in an operational production type

609
00:34:30,316 --> 00:34:37,946
scenario, run it on top of a microVM, run
it on top of a, in a container," okay?

610
00:34:37,946 --> 00:34:42,376
And then you've got the best of both
worlds then, because I see microVMs,

611
00:34:43,666 --> 00:34:49,536
containers, where they're really strong
is the threat model is really about an

612
00:34:49,536 --> 00:34:54,496
agent lets off, it executes something
malicious, something bad, untrusted

613
00:34:54,526 --> 00:34:57,386
code is executed, it's contained.

614
00:34:57,556 --> 00:34:58,086
Okay?

615
00:34:58,816 --> 00:35:03,146
Now, our threat model is partially
to do with that, but we're actually

616
00:35:03,146 --> 00:35:06,176
looking at agents that have good intent.

617
00:35:06,536 --> 00:35:10,436
I know an LLM doesn't have intentions
as such, but we've all seen this

618
00:35:10,456 --> 00:35:15,676
thing where you d- go, "Claude,
what, you've deleted the data?" And,

619
00:35:16,026 --> 00:35:17,646
"Oh gosh, I'm frightfully sorry.

620
00:35:17,646 --> 00:35:20,056
I should never do that again,"
and da, da, da, da, da.

621
00:35:20,106 --> 00:35:21,416
Bret (2): You're absolutely right

622
00:35:21,969 --> 00:35:25,749
Luke: They can hurt you while
they're trying to do their job.

623
00:35:25,749 --> 00:35:26,529
Do you see what I mean?

624
00:35:26,529 --> 00:35:29,669
And that's the whole new threat model
that I think you need something like

625
00:35:29,699 --> 00:35:34,449
nono for, which is how do we let
these things have a bit of power,

626
00:35:34,519 --> 00:35:37,709
give them a bit of responsibility,
like we spoke about earlier, give the

627
00:35:37,729 --> 00:35:42,199
kids the cars, the car keys, they're
going off to university, you start to

628
00:35:42,199 --> 00:35:45,539
give them a bit more responsibility,
but you want to keep it safe.

629
00:35:45,549 --> 00:35:46,279
Do you see what I mean?

630
00:35:46,279 --> 00:35:48,429
You want to have those
guardrails there still.

631
00:35:48,669 --> 00:35:53,409
So it's not around completely
contained, lock you in a box so you

632
00:35:53,409 --> 00:35:56,569
can't do anything, and then it's
very difficult for you to do things.

633
00:35:57,425 --> 00:35:59,785
And what we all love
about agents is magic.

634
00:35:59,825 --> 00:36:01,355
That it's incredible what they can do.

635
00:36:01,405 --> 00:36:04,795
I'm not particularly good
with OpenTofu and YAML and

636
00:36:05,115 --> 00:36:08,135
I could learn it, but there's only
so many things you can do in a day.

637
00:36:08,485 --> 00:36:10,605
Whereas an agent can
go off and can do that.

638
00:36:10,605 --> 00:36:15,005
It can debug, "Why is this not deploying?"
It can solve things really quickly,

639
00:36:15,545 --> 00:36:20,175
but there's a lot of risk in that,
because of if it goes off course, it

640
00:36:20,175 --> 00:36:22,345
can really cause a lot of problems.

641
00:36:22,395 --> 00:36:26,005
And so I think that's the kind of the
key differentiator with us really is

642
00:36:26,005 --> 00:36:28,815
we're fixing a, a different threat
that we now have in our midst.

643
00:36:29,254 --> 00:36:33,464
Bret (2): Like, the way these
tools work is often very much

644
00:36:33,474 --> 00:36:35,364
based on their origin story.

645
00:36:35,374 --> 00:36:40,504
And for example, like Docker, Doc-
whether it's Docker or Kubernetes,

646
00:36:40,504 --> 00:36:42,954
it's all running containerd,
y- 99% of the time anyway.

647
00:36:42,954 --> 00:36:49,574
So i- in containerd, there is probably
a way to look at system logs to see that

648
00:36:49,574 --> 00:36:53,094
it tried to access a kernel primitive
that Docker didn't allow, right?

649
00:36:53,434 --> 00:36:58,974
But that is not a user-facing default
thing that you're seeing in Sesh because

650
00:36:59,004 --> 00:36:59,014
Luke: Mm-hmm.

651
00:36:59,360 --> 00:37:02,520
Bret (2): the tool was designed in a
world where we thought the code was good.

652
00:37:02,850 --> 00:37:06,930
We weren't terribly worried about
the good code trying to do weird

653
00:37:06,940 --> 00:37:10,550
things with the file system that
weren't necessarily trying to exploit.

654
00:37:10,560 --> 00:37:11,710
It's just trying to get a job done.

655
00:37:11,710 --> 00:37:12,930
It just wants to be helpful.

656
00:37:13,240 --> 00:37:13,399
it's

657
00:37:13,547 --> 00:37:13,717
Luke: Absolutely.

658
00:37:13,717 --> 00:37:14,037
Yeah,

659
00:37:14,103 --> 00:37:14,403
Bret (2): Yeah.

660
00:37:14,823 --> 00:37:17,973
I, if I had another analogy for you
besides the car key thing, it would

661
00:37:17,983 --> 00:37:21,833
be like I could see Docker as being
described as the butcher knife,

662
00:37:21,933 --> 00:37:25,753
where it's a blunt instrument, and
you're like the paring knife, where

663
00:37:25,753 --> 00:37:27,893
I'm doing that fine detailed work on

664
00:37:27,943 --> 00:37:28,813
Luke: Precisely.

665
00:37:28,943 --> 00:37:31,193
Bret (2): And in fact, Do you see
with these templates, and I haven't

666
00:37:31,193 --> 00:37:32,433
checked, maybe you already have this.

667
00:37:32,833 --> 00:37:37,288
Do you see where… Like, I'm imagining
a workflow for me and my advice to

668
00:37:37,288 --> 00:37:40,648
people eventually, especially part
of this, this DevOps guild that I've

669
00:37:40,648 --> 00:37:43,208
created, is we're really looking at
patterns and practices, trying to

670
00:37:43,208 --> 00:37:45,668
figure out where we can operate safely.

671
00:37:45,668 --> 00:37:49,688
Like, what's the responsible way
to use agents as an adult, right?

672
00:37:49,718 --> 00:37:52,968
as someone who's been in this craft for
decades, as most of the people that are

673
00:37:52,968 --> 00:37:54,678
in the guild are a little bit of gray.

674
00:37:54,788 --> 00:37:57,538
they've got some, at least they've got
some experiences and some battle wounds.

675
00:37:57,968 --> 00:38:01,538
And everybody's on a different end
of the spectrum around, concerned

676
00:38:01,548 --> 00:38:04,848
around security and safeguards and
s- whether how many token- how many

677
00:38:05,148 --> 00:38:08,298
paths do I have on my machine that it
can get access to in Claude, right?

678
00:38:08,298 --> 00:38:09,738
Or in, in Cl- Codex.

679
00:38:09,948 --> 00:38:12,848
there's a lot of utilities that
have a lot of logins on my machine,

680
00:38:12,898 --> 00:38:16,668
across a wide spectrum of tools that
could do a crazy amount of damage.

681
00:38:16,988 --> 00:38:21,878
And I never have to worry about
that until AI, because I was the

682
00:38:21,878 --> 00:38:24,368
only one typing in my… we all
worried about the front gate, right?

683
00:38:24,598 --> 00:38:25,618
My password's strong.

684
00:38:25,618 --> 00:38:27,958
I, my, you can't get into
my code on my machine.

685
00:38:28,408 --> 00:38:30,448
And, my, my d- my hard drive's encrypted.

686
00:38:30,448 --> 00:38:32,398
I go, "Oh, I'm doing all the right
things. I got my firewall on."

687
00:38:32,748 --> 00:38:36,898
But I'm now running this very helpful
thing that's a little too eager sometimes.

688
00:38:37,318 --> 00:38:41,218
And so we're trying to figure out,
like, what does the day-to-day look like

689
00:38:41,618 --> 00:38:46,108
of someone who's op- running an agent
locally, running a harness, they're

690
00:38:46,108 --> 00:38:49,218
operating infrastructure, they're maybe
writing some code and doing some PRs,

691
00:38:49,618 --> 00:38:52,368
but they've got this blast radius where
they technically could take down the

692
00:38:52,368 --> 00:38:54,248
entire AWS cluster with a single command.

693
00:38:54,778 --> 00:38:59,148
And that's on their machine, logged in
by, you know, it's saved in a config file.

694
00:38:59,588 --> 00:39:02,098
is it something where, like, you
would have multiple profiles and I

695
00:39:02,098 --> 00:39:05,688
would have… Like, I would bring
up my agent for troubleshooting.

696
00:39:05,718 --> 00:39:07,268
I got something g-going on in the cluster.

697
00:39:07,298 --> 00:39:10,578
I got an idea of where I need to look,
but I need to point the agent at it.

698
00:39:10,868 --> 00:39:16,058
So I spin up nono with my OpenCode or my
Claude Code or whatever, and I'm using

699
00:39:16,058 --> 00:39:19,458
a sp- very specific profile that maybe
I've named, like, Kubernetes Read-Only

700
00:39:19,518 --> 00:39:24,728
or GitHub Read-Only, and I lot it, allow
it to access certain things, certain

701
00:39:24,728 --> 00:39:28,318
URLs, and it does that troubleshooting.

702
00:39:28,338 --> 00:39:31,218
And then I realize, oh, this is
a policy change that happened in

703
00:39:31,218 --> 00:39:34,168
Kubernetes that I need to quickly
undo, and I'm not a GitOps.

704
00:39:35,048 --> 00:39:36,488
I'm not gonna do it the GitOps PR way.

705
00:39:36,488 --> 00:39:38,238
I'm just gonna go right to kubectl.

706
00:39:38,698 --> 00:39:39,808
But I want the agent to do it.

707
00:39:39,808 --> 00:39:43,708
So now I've got to flip my nono pro-
profile over to a writable profile,

708
00:39:44,028 --> 00:39:46,628
but maybe I only want it for this
one cluster because I don't want

709
00:39:46,628 --> 00:39:49,288
it to have every Kubernetes token.

710
00:39:49,358 --> 00:39:53,198
and so now I've switched profiles
to one that's maybe specific to

711
00:39:53,228 --> 00:39:55,818
a Kubernetes specific cluster.

712
00:39:55,818 --> 00:39:57,088
It's got a specific key.

713
00:39:57,418 --> 00:40:00,798
It's maybe given me a limi- I've given
it limited write access in that profile.

714
00:40:00,818 --> 00:40:04,248
Is that something where, like,
there's a list of profiles

715
00:40:04,258 --> 00:40:05,748
the team manages together?

716
00:40:05,748 --> 00:40:06,938
Is that a thing you see?

717
00:40:06,978 --> 00:40:09,658
I'm just trying to imagine the
workflow of, like, the daily

718
00:40:10,488 --> 00:40:12,108
efforts of a platform engineer.

719
00:40:13,578 --> 00:40:17,658
Luke: So, with nono
pro-profiles, they're JSON, okay?

720
00:40:17,708 --> 00:40:21,638
And they are composable,
so you can inherit.

721
00:40:21,878 --> 00:40:25,688
So you could… there's a Claude
Code profile which is available.

722
00:40:26,278 --> 00:40:33,148
Now, if you wanted to extend that
and add your own specific grants and

723
00:40:33,148 --> 00:40:37,828
denies, you can just do extends, and
it will pull that profile in, it'll

724
00:40:37,828 --> 00:40:42,478
inherit it as a parent, and then
you create your profile as a child.

725
00:40:42,848 --> 00:40:44,938
So you've got this kind of composability.

726
00:40:45,308 --> 00:40:49,288
So this sort of works very well
in a, an enterprise setting.

727
00:40:49,398 --> 00:40:52,668
We've got a bit, little bit more work
to do, but you could have, like, your

728
00:40:52,938 --> 00:40:54,968
kind of corporate thou shall not pass.

729
00:40:55,188 --> 00:40:56,868
Absolutely never, never, never.

730
00:40:57,318 --> 00:41:00,838
And then you can allow different
teams to be perhaps a little bit

731
00:41:00,838 --> 00:41:05,248
looser or access certain environments,
test environments and so forth.

732
00:41:05,838 --> 00:41:08,598
Probably would've been quite useful
for the stuff that happened a couple of

733
00:41:08,598 --> 00:41:11,228
days ago with HuggingFace and OpenAI.

734
00:41:11,888 --> 00:41:15,428
And but yeah, we've got this,
it's composable policy, okay?

735
00:41:15,818 --> 00:41:18,738
Now, the interesting point, you
really raised on a really good

736
00:41:18,738 --> 00:41:24,298
point, which is what if I wanna
swap profiles mid-session, okay?

737
00:41:24,678 --> 00:41:29,838
Now, that's very difficult to do with
a sandbox because it kind of breaks

738
00:41:29,838 --> 00:41:32,168
the fundamentals of what a sandbox is.

739
00:41:32,188 --> 00:41:35,568
They're, they're meant to be, you
start them, they're immutable,

740
00:41:36,634 --> 00:41:36,894
Bret (2): Right

741
00:41:36,978 --> 00:41:37,938
Luke: then they exit.

742
00:41:38,068 --> 00:41:38,538
Okay?

743
00:41:38,808 --> 00:41:42,968
But we have come up with a really
good solution where we're actually

744
00:41:42,988 --> 00:41:49,298
able to expand grants during
the sandbox's life cycle, okay?

745
00:41:49,298 --> 00:41:53,638
And, and we do this with a, a lot of
kind of trickery pokery with, with Unix

746
00:41:53,638 --> 00:41:56,068
processes into process communication.

747
00:41:56,068 --> 00:42:01,658
It's a, a lot of kernel stuff again, where
we're able to, if a, an agent needs a file

748
00:42:01,688 --> 00:42:06,388
that it doesn't have access to, we feed
something called a file descriptor, which

749
00:42:06,388 --> 00:42:07,728
is, it doesn't actually get the file.

750
00:42:07,728 --> 00:42:12,538
When it gets the file access
care of this supervisor.

751
00:42:13,168 --> 00:42:15,898
And the supervisor, it's a little
bit like the jailer, where we

752
00:42:15,898 --> 00:42:18,098
spoke about the penitentiary.

753
00:42:18,158 --> 00:42:21,938
So if you want something, you've gotta go,
"Guard," and bang on the door essentially.

754
00:42:22,698 --> 00:42:26,438
And so we are able to do that now and
some people have been looking at using

755
00:42:26,438 --> 00:42:31,558
this approval backend to plug into a
policy system like, for example, OPA.

756
00:42:32,228 --> 00:42:34,858
So some people have
existing policy engines.

757
00:42:35,388 --> 00:42:38,378
They're like, we really like how you've
done policy in nono, but we've already got

758
00:42:38,398 --> 00:42:43,498
a policy engine." So that's where these
approval backends come in effectively.

759
00:42:43,638 --> 00:42:46,848
And, and you can also do things
like, I've seen folks, they

760
00:42:46,848 --> 00:42:48,708
wrote a Slack approval system.

761
00:42:49,268 --> 00:42:53,898
So when an agent gets stuck, it's,
there's a web hook and it posts to Slack,

762
00:42:54,748 --> 00:42:56,818
and then they can approve it in Slack.

763
00:42:56,928 --> 00:43:01,778
Now, obviously, some people are gonna
be more security stringent than others.

764
00:43:01,818 --> 00:43:02,278
Okay?

765
00:43:02,628 --> 00:43:05,808
They may not like the idea of Slack
being an approval system for an

766
00:43:05,808 --> 00:43:09,868
agent, but this system is… You
can build around it effectively.

767
00:43:09,898 --> 00:43:11,388
You can build around this interface

768
00:43:11,924 --> 00:43:12,234
Bret (2): That is

769
00:43:12,444 --> 00:43:16,794
Luke: And so a very long way of saying you
can actually expand that runtime now, so

770
00:43:17,464 --> 00:43:18,014
Bret (2): That is cool.

771
00:43:18,014 --> 00:43:20,304
Is that a, is that a Linux unique feature?

772
00:43:20,304 --> 00:43:21,724
Are you able to do that
on Mac as well, or is

773
00:43:22,868 --> 00:43:27,888
Luke: Yeah, it's, so with Linux
you definitely get a lot more bang

774
00:43:27,888 --> 00:43:30,988
for your buck, 'cause what we can
do with the kernel, but it does

775
00:43:30,988 --> 00:43:36,398
actually work on Apple with the tool
execution, the sort of tool sandboxing.

776
00:43:36,746 --> 00:43:37,566
Bret (2): Oh, right.

777
00:43:38,238 --> 00:43:42,138
Luke: Yeah, so for example, like
the GitHub CLI, if it wants access

778
00:43:42,138 --> 00:43:47,118
to something that it doesn't have
because it's not in the local

779
00:43:47,148 --> 00:43:50,648
policy, the JSON, there is an order.

780
00:43:50,728 --> 00:43:54,728
So if not local, then fall back
to the approval system, and then

781
00:43:54,728 --> 00:43:56,088
it can ask the approval system.

782
00:43:56,518 --> 00:44:01,398
So I've seen people rig that
into the, the Apple fingerprint

783
00:44:02,390 --> 00:44:02,710
Bret (2): Hmm.

784
00:44:02,920 --> 00:44:03,490
Touch ID.

785
00:44:03,560 --> 00:44:07,110
Luke: We've done a lot of interesting
work where we originally started doing a

786
00:44:07,110 --> 00:44:11,180
lot of stuff around machine learning and
training models, so we're looking to do

787
00:44:11,530 --> 00:44:16,290
some work there around to make it easier
for folks to understand what to approve.

788
00:44:16,660 --> 00:44:20,110
'Cause there's this thing called
approval fatigue where it's just kind

789
00:44:20,110 --> 00:44:24,000
of, you just eventually you're just
kinda hitting the tab or whatever it is,

790
00:44:24,050 --> 00:44:24,830
Bret (2): You got like the,

791
00:44:24,904 --> 00:44:25,304
Luke: And,

792
00:44:25,304 --> 00:44:28,294
Bret (2): the little, wa- bird
thing on your desk that just sh-

793
00:44:28,341 --> 00:44:30,011
Luke: Yes, precisely.

794
00:44:30,134 --> 00:44:31,364
Bret (2): the enter key this…

795
00:44:31,941 --> 00:44:33,431
Luke: Yeah, very much, yeah.

796
00:44:33,641 --> 00:44:34,001
You know.

797
00:44:34,371 --> 00:44:37,501
So we're all engineers trying to
use these agents, so we tend to

798
00:44:37,501 --> 00:44:40,741
experience these problems ourselves.

799
00:44:40,741 --> 00:44:44,081
They're pains for us, and we seek
to solve them, and luckily that

800
00:44:44,121 --> 00:44:45,761
works for others as well, you

801
00:44:46,518 --> 00:44:46,898
Bret (2): Yeah.

802
00:44:46,898 --> 00:44:49,418
The best products are always the
ones that the, the builders are using

803
00:44:49,418 --> 00:44:50,708
themselves to get their work done.

804
00:44:50,821 --> 00:44:52,751
Luke: Yeah, absolutely.

805
00:44:53,828 --> 00:44:56,708
Bret (2): do you think there
will be a day where harnesses…

806
00:44:56,898 --> 00:45:01,538
Like, when you talk about these
approvals in session, is this an

807
00:45:01,538 --> 00:45:05,428
extension of, I, I'm trying to
think if I've experienced this.

808
00:45:06,498 --> 00:45:11,518
I only remember experiencing it when I
exited the, the Claude Code or whatever.

809
00:45:11,768 --> 00:45:14,358
Is this something that you think
would be, like, an extension into

810
00:45:14,358 --> 00:45:17,788
the harness that would give it
abilities for approvals through nono?

811
00:45:18,358 --> 00:45:20,568
Is that a thing that's happening

812
00:45:20,583 --> 00:45:21,363
Luke: very much, yeah.

813
00:45:22,393 --> 00:45:23,263
Absolutely, yeah.

814
00:45:23,263 --> 00:45:27,593
So, uh, w- we've got a, a, a video
that demonstrates this with kubectl,

815
00:45:27,873 --> 00:45:34,353
and it's running on a, an Apple Mac
silicon machine, and there is, aspects

816
00:45:34,543 --> 00:45:38,593
of the operations it needs to perform
that aren't granted in the policy.

817
00:45:39,043 --> 00:45:43,383
So we run a simple Python web server
that's able to pick that up, and

818
00:45:43,383 --> 00:45:47,143
then you can approve things like it
wants to scale the amount of pods.

819
00:45:47,863 --> 00:45:48,903
We don't allow that.

820
00:45:49,043 --> 00:45:53,093
That's considered a kind of a write
operation, but we allow it to go

821
00:45:53,133 --> 00:45:54,783
to the apr- the approval system.

822
00:45:55,343 --> 00:46:00,803
And so it's not something that comes
batched in with nono at the moment, but it

823
00:46:00,803 --> 00:46:06,553
is a, it's a programmatic interface that's
there to integrate with essentially, yeah.

824
00:46:06,873 --> 00:46:11,482
And so I mean, us, obviously we love
open source, but I, I have a company,

825
00:46:11,732 --> 00:46:14,462
a, a dog, a family to look after.

826
00:46:14,582 --> 00:46:17,362
So eventually… we're building a
product essentially, but we'll always

827
00:46:17,362 --> 00:46:19,202
keep the open source powerful and free.

828
00:46:19,302 --> 00:46:20,972
You know, that's the way
I've always done things.

829
00:46:21,442 --> 00:46:25,692
But that's where we will start to
really introduce how this works

830
00:46:25,762 --> 00:46:27,522
at a large scale effectively.

831
00:46:27,522 --> 00:46:33,132
how do we handle thousands of engineers
that are, and agents that are, that

832
00:46:33,132 --> 00:46:40,012
need these very sort of multidimensional
threat assessments around approving and

833
00:46:40,012 --> 00:46:41,762
denying and what should be allowed and…

834
00:46:42,046 --> 00:46:44,536
Bret (2): you've already kind of hinted
at this, but I'm guessing that a lot

835
00:46:44,536 --> 00:46:48,396
of this is like, it's almost feels a
little bit like a cat and mouse with an

836
00:46:48,396 --> 00:46:53,206
agent where you block, you block, you
block, and then the more… when Fable

837
00:46:53,206 --> 00:46:56,046
comes out and it tends to be a little
bit more tenacious, it tends to be a

838
00:46:56,046 --> 00:47:01,486
little more eager as a model, and so
it tries different or new innovative

839
00:47:01,486 --> 00:47:03,956
approaches to getting around the sandbox.

840
00:47:04,506 --> 00:47:08,466
And so, is that, is… Do you feel
like that it's a little bit of that, of

841
00:47:08,466 --> 00:47:12,686
this, of like, "Aren't you cheeky, for
figuring like, oh, you did that in Python.

842
00:47:12,686 --> 00:47:17,586
I didn't think about that," or you did
some weird HTML escape that somehow got

843
00:47:17,586 --> 00:47:20,996
a… Like, I'm just, I'm sure there's
some good war stories you've got.

844
00:47:21,935 --> 00:47:22,835
Luke: Absolutely.

845
00:47:22,845 --> 00:47:29,385
So what we do is we, we test
where we lock an agent up, and

846
00:47:29,385 --> 00:47:31,955
then we pipe lots of tasks in.

847
00:47:32,085 --> 00:47:32,455
Okay?

848
00:47:32,795 --> 00:47:36,865
And some of them are tasks
that interpreted a certain

849
00:47:36,865 --> 00:47:38,375
way could cause trouble.

850
00:47:38,455 --> 00:47:38,885
Okay?

851
00:47:39,225 --> 00:47:42,465
And then we, we make a cup of coffee,
sit back and just watch it go.

852
00:47:43,235 --> 00:47:45,665
And it's like, like D-
Homer Simpson, "D'oh, d'oh,

853
00:47:46,470 --> 00:47:46,890
Bret (2): Yeah

854
00:47:46,935 --> 00:47:50,335
Luke: He just… And then eventually
it's so satisfying it, it just

855
00:47:50,365 --> 00:47:55,725
gives up, and it says, "No, you need
to change your no-no policy, man.

856
00:47:55,785 --> 00:47:56,745
I can't do this.

857
00:47:56,795 --> 00:47:59,165
Bret (2): it's like you've won
against a friendly Terminator.

858
00:47:59,165 --> 00:48:02,685
You're like, "Okay, I, you admit
defeat. I still can control the AI."

859
00:48:03,727 --> 00:48:03,737
Luke: Ah.

860
00:48:03,737 --> 00:48:04,307
it's funny.

861
00:48:04,317 --> 00:48:09,357
Sometimes I'm like, "Seriously? You're
gonna use Perl?" Like, is that how

862
00:48:09,387 --> 00:48:10,587
desperate you're getting, you know?

863
00:48:12,277 --> 00:48:14,517
'cause they are… Yeah,
they're incredibly crafty,

864
00:48:14,617 --> 00:48:17,217
Bret (2): Mine, mine, mine lately has
started to get confused sometimes with

865
00:48:17,227 --> 00:48:23,347
web, web searching and web crawling or
web fetching tools, and it will resort to

866
00:48:23,347 --> 00:48:25,607
bash calling curl sometimes for websites.

867
00:48:25,607 --> 00:48:28,507
And, and I have to, like, stop
it and l- like, "Okay, let's…

868
00:48:28,737 --> 00:48:29,727
You're, you're going crazy.

869
00:48:29,737 --> 00:48:32,147
This is not how we're gonna
search the internet, by

870
00:48:32,601 --> 00:48:33,101
Luke: Absolutely.

871
00:48:33,127 --> 00:48:34,167
Bret (2): names and curling them."

872
00:48:35,017 --> 00:48:37,067
Luke: and you just reminded
me of something else there.

873
00:48:37,117 --> 00:48:39,097
Of course, we can do
this with MCP as well.

874
00:48:40,107 --> 00:48:42,967
So, we can kind of, MCP
is a set of tools, okay?

875
00:48:43,367 --> 00:48:50,537
And, so we can kind of do a safe path
around MCP execution, especially the

876
00:48:50,597 --> 00:48:53,227
STDIO stuff, which is all localized,

877
00:48:53,287 --> 00:48:53,777
Bret (2): Right.

878
00:48:54,147 --> 00:48:57,747
Is that something where it's like an,
it would be like a command line option

879
00:48:57,747 --> 00:48:58,977
or it's just a part of your profile?

880
00:48:58,977 --> 00:49:02,697
Like you have files and other things
and there would be a section for MCP?

881
00:49:03,815 --> 00:49:08,955
Luke: So I mean, like, if it's, stdio,
typically people will do MPX, and

882
00:49:08,955 --> 00:49:10,765
they'll pass in the name of the MCP,

883
00:49:11,309 --> 00:49:11,749
Bret (2): Mm-hmm.

884
00:49:11,945 --> 00:49:16,005
Luke: It's a kind of like… I guess it's
like a JavaScript, compiled JavaScript,

885
00:49:16,555 --> 00:49:19,185
and you then say what that is allowed.

886
00:49:19,265 --> 00:49:22,185
You can give it a phantom token rather
than it getting a real credential.

887
00:49:22,765 --> 00:49:27,055
You can say what URLs it can access
and… Because, that's another

888
00:49:27,105 --> 00:49:32,065
tool that's incredibly powerful,
but with, what is it they say?

889
00:49:32,065 --> 00:49:35,525
With power comes great
responsibility, and, and these

890
00:49:35,535 --> 00:49:37,345
things don't have responsibility.

891
00:49:37,365 --> 00:49:38,935
So that's where nono comes in.

892
00:49:40,215 --> 00:49:40,775
Yeah, yeah

893
00:49:40,837 --> 00:49:43,387
Bret (2): There, there's a couple of
good taglines probably that, the future

894
00:49:43,387 --> 00:49:44,787
marketing team could work out with that.

895
00:49:44,817 --> 00:49:46,667
Luke: I mean, I'm not here
to promote my company, but

896
00:49:46,667 --> 00:49:47,897
that's why we're called NoLabs.

897
00:49:48,567 --> 00:49:50,827
'Cause we thought, well, somebody's
gotta learn… Somebody's gotta

898
00:49:50,827 --> 00:49:52,167
be looking at how to say no.

899
00:49:53,047 --> 00:49:56,927
'Cause we're all saying yes, and just
yes, yes, more, more, more, And just

900
00:49:56,967 --> 00:49:58,997
giving, more and more power to agents.

901
00:49:58,997 --> 00:49:59,107
And we thought somebody's gotta
look at the nuances of no.

902
00:49:59,107 --> 00:49:59,117
When,

903
00:50:02,037 --> 00:50:03,727
when do you say no?

904
00:50:03,727 --> 00:50:05,227
So yeah, teach your agents when to say no.

905
00:50:05,777 --> 00:50:06,157
Bret (2): Yeah.

906
00:50:06,617 --> 00:50:07,157
I like it.

907
00:50:07,227 --> 00:50:11,507
it gives you a very specific
purpose, which my company name is

908
00:50:11,507 --> 00:50:14,457
extremely vague, so it c- can do
anything, so I have no purpose.

909
00:50:14,837 --> 00:50:17,897
Luke: I was just gonna say,
and we don't have a model, so

910
00:50:17,977 --> 00:50:19,337
our interests are in saying

911
00:50:20,212 --> 00:50:20,712
Bret (2): Right.

912
00:50:20,857 --> 00:50:23,927
Luke: you've got a model, sometimes
I'm not gonna… Okay, I've gotta be

913
00:50:23,927 --> 00:50:27,997
careful here, but the more that model
can roam, the more products it can find.

914
00:50:28,287 --> 00:50:28,707
Okay?

915
00:50:28,707 --> 00:50:30,257
So, no is no with us

916
00:50:31,434 --> 00:50:32,504
Bret (2): Yeah, the incentives aren't

917
00:50:32,585 --> 00:50:33,195
Luke: So yeah.

918
00:50:33,464 --> 00:50:34,294
Bret (2): with model companies,

919
00:50:34,335 --> 00:50:35,195
Luke: Exactly.

920
00:50:35,355 --> 00:50:36,795
Bret (2): so what's next for nono?

921
00:50:36,955 --> 00:50:39,715
like, what, what are you excited
about for the rest of the year?

922
00:50:40,535 --> 00:50:42,305
give us a… Can you give
us a little preview taste?

923
00:50:42,845 --> 00:50:43,085
A little,

924
00:50:43,095 --> 00:50:43,535
Luke: Yeah.

925
00:50:43,535 --> 00:50:48,475
So, do you know, it's, it's not
very exciting, but it's essential.

926
00:50:48,765 --> 00:50:49,595
Stability.

927
00:50:50,245 --> 00:50:50,595
Okay.

928
00:50:50,595 --> 00:50:55,575
So we are now really focused on… We've
got an incredibly powerful payload, so

929
00:50:55,575 --> 00:50:59,885
we're trying to just slow the roll a
little bit when new features come in, and

930
00:50:59,885 --> 00:51:07,045
really improve the documentation, give
people lots of examples, really make the,

931
00:51:07,065 --> 00:51:14,095
the user experience as seamless and as
least brittle as possible, investigate

932
00:51:14,105 --> 00:51:20,045
more ways of surfacing and solving
profile denials and, and, and, and really

933
00:51:20,045 --> 00:51:21,995
just starting to dial in the quality.

934
00:51:22,285 --> 00:51:26,555
Because, a lot of people are starting
to use this as their day-to-day tool.

935
00:51:26,555 --> 00:51:27,935
They're running this in teams.

936
00:51:27,945 --> 00:51:30,455
Some people are running production agents.

937
00:51:30,455 --> 00:51:33,825
We have people using nono in production
already, One of the things with

938
00:51:33,825 --> 00:51:37,095
nono, we've been looking at coding
agents, but this could quite easily

939
00:51:37,115 --> 00:51:42,195
be Pydantic AI, LangChain, ADK.

940
00:51:42,195 --> 00:51:44,105
You can run anything in there essentially.

941
00:51:44,105 --> 00:51:49,415
So it could be nono run Python main.py,
and it will, you'll immediately get all

942
00:51:49,415 --> 00:51:53,015
that nono has to offer for your agent
that you've developed essentially.

943
00:51:53,325 --> 00:51:57,585
And so yeah, we're really looking at
improving the quality around things.

944
00:51:57,635 --> 00:52:01,845
And of course, as NoLabs, we're looking
to build on top of this effectively.

945
00:52:02,155 --> 00:52:08,605
Because again, to use Docker, I, it's…
I'm just so fond of Docker and they,

946
00:52:08,615 --> 00:52:14,035
they had this model of kind of the, the,
the, the, the chef's kiss of developer

947
00:52:14,035 --> 00:52:19,135
experience locally, but you needed a
Kubernetes to orchestrate and scale this.

948
00:52:19,895 --> 00:52:22,455
And, and that's where we're doing
a lot of research at the moment.

949
00:52:22,465 --> 00:52:27,025
How do we make nono operate, this
policy operate across a diverse

950
00:52:27,475 --> 00:52:31,165
large fleet of agents effectively
and be able to track everything and

951
00:52:31,576 --> 00:52:31,926
Bret (2): Yeah.

952
00:52:32,755 --> 00:52:35,775
Luke: resolve all of these
approvals and… Yeah, exactly.

953
00:52:35,825 --> 00:52:38,855
Bret (2): centralized, logging
and, policy generation.

954
00:52:38,925 --> 00:52:42,105
I can see that, that, I can envision
the management portal coming soon.

955
00:52:43,695 --> 00:52:45,225
It f- it feels like the right approach.

956
00:52:45,225 --> 00:52:47,555
I, I mean, it feels like a,
a, one of those things where

957
00:52:47,585 --> 00:52:49,155
it catches on in a dev team.

958
00:52:49,175 --> 00:52:52,865
I've got some DevSec engineers and
some security engineers in our, in

959
00:52:52,865 --> 00:52:57,705
our dev- agentic DevOps guild, and
they're all very much looking at the

960
00:52:57,705 --> 00:53:01,535
sec- you know, not just the security
of agents, but the security of skills.

961
00:53:01,625 --> 00:53:02,305
Luke: Yeah.

962
00:53:02,432 --> 00:53:05,102
Bret (2): they gotta pay more attention
to NoLabs to see if there's anything

963
00:53:05,102 --> 00:53:09,802
coming down the pike for, for them to
administrate and, and manage centrally.

964
00:53:10,102 --> 00:53:14,252
And then the idea of, like, s- signing
skills, it's we're, we're kind of,

965
00:53:14,252 --> 00:53:17,392
like, in our skills moment with, with
the learning and, that we're doing

966
00:53:17,392 --> 00:53:19,782
in the team, where we're trying to
figure out centralized management.

967
00:53:19,782 --> 00:53:23,372
It's-- None of this stuff is
really figured out in the industry.

968
00:53:23,372 --> 00:53:26,752
We've got lots of ideas, and we've
got lots of walled garden proprietary

969
00:53:26,752 --> 00:53:30,372
solutions, but a lot of what we do
in open source is, like, well, we

970
00:53:30,372 --> 00:53:33,602
kinda wait for them to figure out
the market, and then we figure out if

971
00:53:33,602 --> 00:53:35,012
there's an opportunity for open source.

972
00:53:35,012 --> 00:53:39,522
And this feels like that moment where
we've got the registries for skills, but,

973
00:53:39,522 --> 00:53:44,202
like, the idea of signing it and then
validating it on runtime, that feels like

974
00:53:44,239 --> 00:53:45,059
Luke: Very much.

975
00:53:45,552 --> 00:53:48,012
Bret (2): And, and so it feels like
there's maybe an opportunity for someone

976
00:53:48,012 --> 00:53:53,092
to make a, an open source project that
could kind of be, like, the cloud native,

977
00:53:53,102 --> 00:53:54,352
you know, we got the CNCF and the

978
00:53:54,433 --> 00:53:55,313
Luke: Absolutely.

979
00:53:55,393 --> 00:53:58,773
Bret (2): something there for skills as
well as for sandboxes because, it feels

980
00:53:58,773 --> 00:54:02,223
like we need-- We're, we're gonna need
a little more formality in the standards

981
00:54:02,223 --> 00:54:04,583
as the harnesses all sort of bifurcate

982
00:54:04,811 --> 00:54:05,941
Luke: 100% agree.

983
00:54:06,323 --> 00:54:06,753
Bret (2): Yeah.

984
00:54:07,191 --> 00:54:11,581
Well, I definitely gotta use this more
because I think it's kind of like agents

985
00:54:11,581 --> 00:54:14,641
themselves, where I feel like nono is
one of those things where you get a taste

986
00:54:14,641 --> 00:54:18,601
for it and you get comfortable with it,
and it starts to be-become something

987
00:54:18,601 --> 00:54:22,091
that you're using more and more, and
then pretty soon my vision of, like, all

988
00:54:22,091 --> 00:54:26,111
these different profiles I'm extending,
that I have ones for certain use cases

989
00:54:26,161 --> 00:54:30,811
on my infrastructure, and I start to get
more comfortable because I think like

990
00:54:30,811 --> 00:54:32,701
a lot of us, I have been YOLOing it.

991
00:54:32,751 --> 00:54:37,021
My Claude command line def- is an alias
to Claude dangerously skip permissions.

992
00:54:37,491 --> 00:54:43,281
And I, we have been lucky to rely on these
super high-end state-of-the-art models

993
00:54:43,631 --> 00:54:46,601
that mostly don't, at least this year.

994
00:54:46,631 --> 00:54:47,801
Like, last year was crazy.

995
00:54:47,851 --> 00:54:50,961
Last year it was trying to d- you know,
delete my hard drive and I think at

996
00:54:50,961 --> 00:54:54,791
one point it, I was trying to get it
to build a SwiftUI app and it, last

997
00:54:54,791 --> 00:54:58,101
year with, like, a Claude, like, it
was like a Sonnet 3.5 or something.

998
00:54:58,321 --> 00:55:02,301
It was determined that my Xcode
installation was broken and it was

999
00:55:02,301 --> 00:55:06,951
gonna delete the entire directory
off of the system profile 'cause it

1000
00:55:06,951 --> 00:55:09,931
was like, "Oh, no, you, I can't…"
The build was failing, but it wasn't

1001
00:55:09,931 --> 00:55:13,161
the fault of his code or its code,
it was the fault of my build tool.

1002
00:55:13,171 --> 00:55:15,071
So it was trying to delete
all the build tools and I

1003
00:55:15,101 --> 00:55:16,391
luckily caught it, last second.

1004
00:55:16,441 --> 00:55:17,181
Luke: Yeah.

1005
00:55:17,221 --> 00:55:19,891
Bret (2): I think some of us have
gotten a little, more comfortable

1006
00:55:19,891 --> 00:55:21,691
with the models behaving better.

1007
00:55:22,281 --> 00:55:25,651
But what I'm now seeing, and this is
maybe, I, I don't know if this is a

1008
00:55:25,651 --> 00:55:29,911
trend overall, but as people start to
reduce costs because, like, Opus is

1009
00:55:29,911 --> 00:55:34,601
crazy expensive, so they start to try to
see how cheap they can get the models.

1010
00:55:34,761 --> 00:55:38,721
Like, they, they sort of, we use skills
testing and, and evals to try to see

1011
00:55:38,721 --> 00:55:40,451
how cheap we can get this token budget.

1012
00:55:40,841 --> 00:55:44,841
But in doing so, you inevitably,
you, there's like this gray fine

1013
00:55:45,171 --> 00:55:49,271
area in the middle where you get
just cheap enough and then it starts

1014
00:55:49,271 --> 00:55:53,221
to hallucinate, which means it's, I
need, I now at that point I need nono.

1015
00:55:53,941 --> 00:55:57,821
And so what I'm finding in, in our
guild is that as people mature and they

1016
00:55:57,821 --> 00:56:02,381
realize not everything needs Claude
models, like you can use GLMs, you can

1017
00:56:02,381 --> 00:56:05,211
use some Kimis now, you can use some
of these cheaper open weight models,

1018
00:56:05,711 --> 00:56:08,731
but Now, as you go down the rabbit
hole of how cheap I, can I get it, and

1019
00:56:08,731 --> 00:56:11,411
there, I have a couple of teams where
they're, they're now the inverse of

1020
00:56:11,411 --> 00:56:15,451
this token maxing thing where they're
bragging about how little their spend is.

1021
00:56:15,451 --> 00:56:20,101
Like, it's sort of a sign of engineering
expertise that I've been able to do all

1022
00:56:20,101 --> 00:56:22,001
this with a, with a super cheap model.

1023
00:56:22,321 --> 00:56:25,831
But I think that they're gonna need more
guardrails and so this is almost like a,

1024
00:56:25,881 --> 00:56:30,571
a, a specialized use case of you could
argue in a marketing campaign, use minimax

1025
00:56:30,601 --> 00:56:36,551
at, cents on the token comparatively to,
at, at 5% the cost of Sonnet, but you're

1026
00:56:36,551 --> 00:56:38,141
gonna need some harness protection.

1027
00:56:38,151 --> 00:56:40,811
You're gonna need to, like,
keep it on its rails, yeah.

1028
00:56:41,187 --> 00:56:41,557
Luke: Yeah.

1029
00:56:41,827 --> 00:56:45,267
And as you rightly put, we,
we're completely agnostic.

1030
00:56:45,997 --> 00:56:49,957
You can run any agent, and, whereas,
other sort of s- enterprise sandboxes

1031
00:56:50,497 --> 00:56:52,987
that are coupled to the, uh, the lab

1032
00:56:53,971 --> 00:56:54,331
Bret (2): Yep

1033
00:56:55,471 --> 00:56:58,051
Luke: They, they can't, they
cannot be split apart effectively.

1034
00:56:58,061 --> 00:57:04,121
So you can, as the next new call
Py OpenCode, whatever comes out,

1035
00:57:04,383 --> 00:57:05,203
Bret (2): Whatever's next.

1036
00:57:05,381 --> 00:57:07,921
Luke: You use your same profile,
maybe adjust it a little bit

1037
00:57:08,701 --> 00:57:10,311
Bret (2): All right, last
question 'cause we're running

1038
00:57:10,311 --> 00:57:11,651
long and I apologize for that.

1039
00:57:11,823 --> 00:57:13,203
Luke: I've so enjoyed this.

1040
00:57:13,333 --> 00:57:13,503
Mm-hmm

1041
00:57:13,741 --> 00:57:15,051
Bret (2): what about GUI apps?

1042
00:57:15,071 --> 00:57:17,571
Like, where's the rough edges on this?

1043
00:57:17,581 --> 00:57:21,621
Because at first I started using it
and then I realized I maybe couldn't

1044
00:57:21,621 --> 00:57:25,521
run Mac apps in it, and I wasn't
really sure if that would work, and

1045
00:57:25,749 --> 00:57:26,199
Luke: Hmm.

1046
00:57:26,871 --> 00:57:27,081
Bret (2): like

1047
00:57:27,141 --> 00:57:27,851
Luke: You can

1048
00:57:28,003 --> 00:57:29,363
Bret (2): are using the GUI harnesses,

1049
00:57:29,413 --> 00:57:30,813
Luke: Yeah, absolutely.

1050
00:57:31,113 --> 00:57:36,513
So you can use nono to
isolate in a sandbox a GUI.

1051
00:57:37,313 --> 00:57:42,623
The real aspect to consider is if you've
got something like an Electron app,

1052
00:57:43,973 --> 00:57:50,683
like Bun is one, quite often spray a
lot of file access all over the place.

1053
00:57:50,763 --> 00:57:51,013
Okay?

1054
00:57:51,063 --> 00:57:54,443
So, you would be able to eventually
write a profile for it, but they

1055
00:57:54,443 --> 00:57:58,193
tend to be, you know, they tend to
kind of a little bit feely grabby.

1056
00:57:58,433 --> 00:58:01,003
And but we, we are, we
are able to do that.

1057
00:58:01,083 --> 00:58:03,713
I've seen people get the Claude GUI.

1058
00:58:03,713 --> 00:58:06,183
I've seen people get VS
Code running in nono.

1059
00:58:06,793 --> 00:58:09,473
And but then it starts to get complex
when you've got all these different

1060
00:58:09,473 --> 00:58:15,013
extensions and, and, and I've heard of
people trying to get nono to isolate

1061
00:58:15,013 --> 00:58:17,803
extensions as well, which is interesting.

1062
00:58:17,813 --> 00:58:20,413
And, but basically there's an entry point.

1063
00:58:20,803 --> 00:58:23,873
At some point, the rubber hits the road,
you're gonna call an executionable,

1064
00:58:23,873 --> 00:58:24,303
a script, and it's going to execute

1065
00:58:27,763 --> 00:58:31,023
a process, and that's where nono sits.

1066
00:58:31,053 --> 00:58:34,023
So it's, there's a level of
complexity that's involved.

1067
00:58:34,893 --> 00:58:38,623
If, like if you had something like
a video editing app, you could

1068
00:58:38,623 --> 00:58:41,803
probably run nono in that, but it's
gonna be very, it's gonna have a

1069
00:58:41,803 --> 00:58:43,873
very wide blast around what it needs,

1070
00:58:43,923 --> 00:58:44,473
Bret (2): Yeah.

1071
00:58:44,753 --> 00:58:47,623
Your Electron de- description,
especially like with VS Code

1072
00:58:47,623 --> 00:58:50,573
extensions, I mean, we just recently
had the big VS Code extension hack.

1073
00:58:50,953 --> 00:58:55,183
So it made everybody wake up and realize
that, extensions are still code running

1074
00:58:55,183 --> 00:58:57,863
on your system and you don't, y- you,
we all knew we shouldn't download

1075
00:58:57,863 --> 00:59:01,433
random ones, but also, like, even the
reputable ones can also be attacked.

1076
00:59:01,833 --> 00:59:05,243
And that's why I've, I've,
I love, I really like Go.

1077
00:59:05,283 --> 00:59:06,713
I love static binaries now.

1078
00:59:06,723 --> 00:59:07,783
Like, it's my whole thing.

1079
00:59:08,123 --> 00:59:11,563
I, I don't want a distributed code
base that's to compile at runtime.

1080
00:59:11,763 --> 00:59:15,413
Like, I preach about this a little
bit at conferences about, like, we've

1081
00:59:15,413 --> 00:59:19,593
got 40 years of programming languages
we're all using, and they were all

1082
00:59:19,593 --> 00:59:21,933
created at different eras of technology.

1083
00:59:22,243 --> 00:59:25,243
And this is a little bit of a rabbit
hole, but, like, we were optimizing

1084
00:59:25,253 --> 00:59:29,643
for the problem of the time, and now,
like, the problem of the time is I

1085
00:59:29,643 --> 00:59:31,093
need five different Python versions.

1086
00:59:31,093 --> 00:59:32,453
That's, like, why Docker exists.

1087
00:59:32,473 --> 00:59:36,593
One of the reasons it exists is because
we, we couldn't use the same s- system

1088
00:59:36,593 --> 00:59:40,553
library for every app, and we, we
needed separate installs, but the

1089
00:59:40,553 --> 00:59:42,033
systems don't really account for that.

1090
00:59:42,293 --> 00:59:43,783
So then we have to come
up with abstractions.

1091
00:59:44,093 --> 00:59:49,193
And here we are today, and I'm, I'm, like,
all in on, whether it's Rust or, or Go.

1092
00:59:49,193 --> 00:59:51,703
Like, I, I want that
single binary experience.

1093
00:59:51,703 --> 00:59:53,623
But I know that l- with a
lot of these Electron apps,

1094
00:59:54,023 --> 00:59:56,213
it's dozens of node binaries.

1095
00:59:56,233 --> 00:59:59,633
It's, like with Chrome, you've
got a process for every tab.

1096
00:59:59,643 --> 01:00:02,353
You've got extension
processes in every tab.

1097
01:00:02,363 --> 01:00:06,143
Like, you've got a ton of stuff there,
so I can only imagine how, how big these,

1098
01:00:06,323 --> 01:00:10,133
these profiles… So it d- it re- seems
like it's gonna require a certain level

1099
01:00:10,133 --> 01:00:13,583
of determination to, to get it working,
but it's, it's cool that it's possible.

1100
01:00:13,623 --> 01:00:16,583
I, I was assuming that it was just
maybe something on Mac that wasn't

1101
01:00:16,583 --> 01:00:20,063
gonna be possible because of the
way the, the notarization and…

1102
01:00:20,073 --> 01:00:22,653
Because there, there was already a
security system built into Macs that

1103
01:00:22,653 --> 01:00:27,333
we as users see as pop-ups that are
very user-friendly and, and weirdly

1104
01:00:27,333 --> 01:00:30,033
still tell you nothing about exactly
what you're asking permission for.

1105
01:00:30,443 --> 01:00:34,283
And I've always assumed that that
model, whatever that locking, system

1106
01:00:34,283 --> 01:00:38,443
lock model is, is, was a little
bit different than shell tools.

1107
01:00:38,903 --> 01:00:39,213
Luke: Yeah.

1108
01:00:39,213 --> 01:00:44,303
We do stuff around, within profiles you
can provide access to things like IOKit

1109
01:00:44,313 --> 01:00:47,343
and kind of Apple fundamentals like that.

1110
01:00:47,663 --> 01:00:53,663
we had to get in the ability to allow
GPUs, which meant, there was a lot of sort

1111
01:00:53,663 --> 01:00:56,833
of, I didn't actually work on that, so
I can't speak with any authority there.

1112
01:00:56,833 --> 01:01:02,103
But we had to kind of, there's
these sort of Apple primitives

1113
01:01:02,103 --> 01:01:04,353
that we had to allow effectively.

1114
01:01:04,383 --> 01:01:06,153
So you can do that as well here.

1115
01:01:06,493 --> 01:01:09,443
And nono's developed in Rust.

1116
01:01:09,573 --> 01:01:11,203
So we… I love Go as well.

1117
01:01:11,423 --> 01:01:14,713
Wrote most of Sigstore in
Go, and we went for Rust.

1118
01:01:14,713 --> 01:01:21,133
we're really strict around use of unsafe
and unwrap, and we do lots of, we do

1119
01:01:21,133 --> 01:01:27,033
lots of security checks on the code and
look for race conditions and So yeah,

1120
01:01:27,093 --> 01:01:30,953
yeah, we landed on Rust, 'cause it's…
I don't wanna argue one's more secure

1121
01:01:30,953 --> 01:01:34,673
than the other, but it's, it's one
where we, we knew where we stood really.

1122
01:01:34,712 --> 01:01:35,732
Bret (2): Yeah, it feels right.

1123
01:01:35,742 --> 01:01:36,692
It feels right for the job.

1124
01:01:37,192 --> 01:01:39,812
And I love that, I mean, most
people that are… I don't know.

1125
01:01:40,032 --> 01:01:41,702
I know a lot of engineers
that are fans of both.

1126
01:01:41,782 --> 01:01:42,652
Like, they use both,

1127
01:01:42,845 --> 01:01:43,865
Luke: Yeah, absolutely.

1128
01:01:43,865 --> 01:01:45,175
I, I, I, I adore Go.

1129
01:01:45,962 --> 01:01:46,322
Bret (2): Yeah

1130
01:01:46,605 --> 01:01:47,685
Luke: just a, it's a work of

1131
01:01:48,584 --> 01:01:49,094
Bret (2): Yeah.

1132
01:01:49,874 --> 01:01:51,254
Yeah, Docker was my gateway.

1133
01:01:51,304 --> 01:01:54,014
Docker and Kubernetes were my gateway
to go to, and now it's like, it's,

1134
01:01:54,024 --> 01:01:56,834
it's like to me, to me it's like
the replacement for Python as the

1135
01:01:56,834 --> 01:01:59,604
s- sysadmin, sysadmin language.

1136
01:01:59,604 --> 01:02:01,004
But hey, I, it's just a preference.

1137
01:02:01,004 --> 01:02:04,514
Like, I know people that spend their
whole day in Python as a system

1138
01:02:04,514 --> 01:02:06,314
engineer or a, a platform engineer.

1139
01:02:06,544 --> 01:02:11,334
And thanks to Luke for being
a, a, an awesome security

1140
01:02:11,334 --> 01:02:13,784
engineer making open source hits.

1141
01:02:14,164 --> 01:02:16,614
Let's hope this… I mean, this already
sounds like this is a hit, but let's hope

1142
01:02:16,614 --> 01:02:21,264
it blows through the stratosphere and
stays, stays in the top, top GitHub repos,

1143
01:02:21,284 --> 01:02:23,914
because I, I, as someone who likes to…

1144
01:02:24,314 --> 01:02:26,164
I'm always, like, security team adjacent.

1145
01:02:26,464 --> 01:02:28,934
Never really a, a dedicated
security engineer, but always

1146
01:02:28,934 --> 01:02:31,994
that, that DevOps guy sitting next
to them going, "Hey, let's work.

1147
01:02:31,994 --> 01:02:36,434
Let's hold hands." so I love when
security tools are fun and easy to use

1148
01:02:36,454 --> 01:02:41,344
and, like, make me feel like an elite
hacker, and that's kinda what this makes

1149
01:02:41,344 --> 01:02:45,414
me feel like, is like I'm, I'm paying
attention to primitives, but I'm also

1150
01:02:45,854 --> 01:02:49,684
reigning in and ev- And any security
engineer standing over my shoulder would

1151
01:02:49,684 --> 01:02:55,324
not judge me harshly for my, my, my
dangerously bypassed permissions defaults.

1152
01:02:56,813 --> 01:02:57,843
Luke: Absolutely, yeah.

1153
01:02:57,893 --> 01:02:58,833
That's by design.

1154
01:02:58,883 --> 01:03:02,643
Security tools, it's hard to get
adoption because you're normally kind

1155
01:03:02,643 --> 01:03:06,073
of scolding people, hitting them on the
head, telling them they can't do things.

1156
01:03:06,320 --> 01:03:07,110
Bret (2): tell him what's wrong.

1157
01:03:07,610 --> 01:03:10,840
Luke: Yeah, so you know, I mean,
Sigstore's one where we managed to

1158
01:03:11,390 --> 01:03:11,970
kind of make it almost seamless.

1159
01:03:12,500 --> 01:03:15,750
The developers liked it, 'cause it's rare
that developers like a security tool.

1160
01:03:15,750 --> 01:03:17,790
And, and nono it's the same really.

1161
01:03:17,790 --> 01:03:20,760
It's, it's, it's out of the
way if you want it to be.

1162
01:03:21,404 --> 01:03:21,864
Bret (2): Yeah.

1163
01:03:22,334 --> 01:03:25,104
And, I'm sure there's gonna be a
dozen more use cases for it, so

1164
01:03:25,104 --> 01:03:26,404
we'll have to have you on again,

1165
01:03:26,794 --> 01:03:27,414
Luke: Absolutely.

1166
01:03:27,414 --> 01:03:29,404
Bret (2): talk about all
the new use cases for nono.

1167
01:03:29,434 --> 01:03:35,004
'Cause I got a feeling that as we all
start to venture out into the ether of new

1168
01:03:35,014 --> 01:03:40,034
models, other harnesses, building agent
SDK model, harnesses, like we're all gonna

1169
01:03:40,084 --> 01:03:42,914
learn these lessons, I think, a little
bit the hard way and look for solutions.

1170
01:03:42,914 --> 01:03:44,214
Hopefully nono's the one they pick.

1171
01:03:44,664 --> 01:03:45,184
So,

1172
01:03:45,234 --> 01:03:45,404
Luke: I hope so

1173
01:03:45,544 --> 01:03:47,614
Bret (2): gl- glad to have you on, Luke.

1174
01:03:47,664 --> 01:03:51,354
Everybody can get started over at nono.sh.

1175
01:03:51,834 --> 01:03:53,184
there's a really quick guide.

1176
01:03:53,184 --> 01:03:57,914
You can install it with Brew and all
the typical utility ways to install.

1177
01:03:57,944 --> 01:04:02,004
And of course, because they're
security focused, they, they, like

1178
01:04:02,004 --> 01:04:05,264
the Mac is, the Mac is notarized, like
all the, all the good stuff there.

1179
01:04:05,604 --> 01:04:09,214
So, if you wanna know more about
the, like the future of where nono

1180
01:04:09,214 --> 01:04:11,674
is going, maybe head over to NoLabs.

1181
01:04:12,184 --> 01:04:15,714
That's nolabs.ai, where they've
got a couple other things they're

1182
01:04:15,714 --> 01:04:17,064
playing around with, it looks like.

1183
01:04:17,064 --> 01:04:18,674
You got, got some other ideas.

1184
01:04:19,274 --> 01:04:20,924
So I'm excited to see what
comes out of the team.

1185
01:04:21,274 --> 01:04:23,754
And where, where else-- And I guess
they can see you on all the socials,

1186
01:04:23,754 --> 01:04:26,404
and you have a YouTube channel for nono.

1187
01:04:26,764 --> 01:04:29,944
Luke: Channel, yeah, if anybody
runs into any issues, we've got

1188
01:04:29,944 --> 01:04:31,584
a Discord that's pretty popular.

1189
01:04:31,634 --> 01:04:34,194
A lot of NoNauts, as we call them, in

1190
01:04:34,204 --> 01:04:34,434
Bret (2): NoNauts.

1191
01:04:35,254 --> 01:04:39,444
Luke: and you'll be able to find that on
the, I think nono.sh and the GitHub repo.

1192
01:04:39,534 --> 01:04:40,864
It's got a link to the Discord.

1193
01:04:41,724 --> 01:04:45,464
And, uh, yeah, nono doesn't really have
any other social channels apart from that,

1194
01:04:45,464 --> 01:04:46,104
Bret (2): keep it simple.

1195
01:04:46,224 --> 01:04:46,704
all right.

1196
01:04:47,064 --> 01:04:48,044
Thanks so much for joining me, Luke.

1197
01:04:48,619 --> 01:04:49,449
Luke: Pleasure to be here.

1198
01:04:49,499 --> 01:04:50,399
Thank you so much.

1199
01:04:51,169 --> 01:04:51,549
Bye-bye

1200
01:04:51,843 --> 01:04:52,273
Bret (2): Ciao.

1201
01:04:52,846 --> 01:04:55,186
Bret AI July 2025: Thanks for joining
us, and I'll see you in the next episode.