Macro Mayhem

FOLLOW UPS
  1. Deep dish is indeed pizza not a pie. (Is it though?)
  2. Hologram is written in Elixir
NEWS
  1. OTP Emergency Patch releases for OTP 27, 28, 29 fix a bunch of vulnerabilities 
    1. https://elixirforum.com/t/patch-package-otp-29-0-4-released/76127
    2. https://elixirforum.com/t/patch-package-otp-28-5-0-4-released/76128
    3. https://elixirforum.com/t/patch-package-otp-27-3-4-15-released/76129
  2. Gleam 1.18 released
    1. https://gleam.run/news/a-field-day-for-gleams-language-server/
  3. ElixirConf US 2025 Talks are being published on YouTube
    1. https://forum.elixirforum.com/tag/elixirconf/147
  4. Version 0.3.0 of the Programming Nerves book by Alex Koutmos and Hugo Barauna is out
    1. https://www.programmingnerves.dev/
    2. https://bsky.app/profile/akoutmos.bsky.social/post/3mrpthmrm6k2v
BLOGS
  1. Mike Zornek - Shimming your way off a dead Elixir dependency
    1. https://mikezornek.com/posts/2026/7/shim-off-a-dead-elixir-dependency
  2. Johanna Larson - Distributed rate limiter with HRW in Elixir
    1. https://jola.dev/posts/distributed-ratelimiter-with-hrw
  3. Paul Ricks - Profiling Rust NIFs in Elixir (with hotpath)
    1. https://blog.smaller-infinity.com/posts/profiling-rust-nifs-in-elixir
  4. Jacob Swanner - Batching Phoenix LiveView Updates
    1. https://jacobswanner.com/development/2026/batching-phoenix-liveview-updates/
  5. Paraxial - Security Vendor's AI Best Practices Labels Critical Elixir RCE Safe
    1. https://paraxial.io/blog/ai-spam
  6. German Velasco - Diverge then converge with LLMs
    1. https://www.germanvelasco.com/blog/diverge-then-converge-with-llms
  7. PSA - Don’t write on medium
MEETUPS & CONFERENCES
  1. Nerves Meetup - online via Zoom, this week (August 12)
  2. UnConference before ElixirConf US (Sept 9) and CodeBEAM EU (Oct 20)
    1. https://luma.com/erlef
  3. Goatmire - Varberg, Sweden Sept 28 - Oct 3
    1. https://goatmire.com
DISCUSSION
  1. Deployment strategies in 2026 - Fly.io shifting focus:
    1. https://fly.io/blog/kurt-scott-money-sprites/
    2. https://community.fly.io/t/will-the-apps-and-machine-platform-start-winding-down/28380
    3. https://github.com/dmkenney/xamal
    4. https://coolify.io/
  2. What will more intelligence actually do for us?
    1. https://www.noahpinion.blog/p/what-will-more-intelligence-actually
  3. GCC To Decline Any Significant Contributions Made Via AI/LLMs - Except For Test Cases
    1. https://www.phoronix.com/news/GCC-Declining-AI-Contributions

What is Macro Mayhem?

The latest Elixir news and general software industry topics

Welcome  to  another  episode  of,  uh,  what  do  we  call  it?  Macro  Mayhem. 

It  has  been  a  week. 

I  have  my  buddy,  Gus  Workman,  with  me. 

My  name  is  Peter  Ulrich. 

Um,  Yeah. 

Thank  you  for  tuning  in  to  another  episode. 

Gus,  how  are  you  doing  this  week?  How's  it  been  for  you?  It's  been  a  busy  week. 

It's  been  a  busy  one. 

It's  been. 

I  feel  like  a  lot  of  people  are  on,  like,  vacation  right  now,  and  maybe  that's  me  soon. 

Hopefully,  I  can  get  into  some  vacation  mode,  but,  like,  this  week  has  been  it's  been  a  week. 

Exactly. 

For  me  too. 

So  just  to  give  you  a  time  stamp,  today  is  August  the  seventh. 

We  are  recording  at  eleven  thirty  nine  in  the  morning,  Amsterdam  time  slash  Luxembourg  time. 

Yeah. 

This  is  the  second  episode  of  Macro  Mayhem. 

We're  gonna  go  over  the  news  of  the  last  one  and  a  half  weeks. 

We  are  recording  a  couple  of  days  early  because  Gus  is  gone  and  away  next  week. 

I  believe  you're  on  vacation,  or  are  you  doing  something  else?  Yep. 

I'll  be  Vacation. 

Hiking. 

Yeah. 

So  for  the  Americans,  vacation  is  these  days  where  you  don't  work. 

Usually,  Europeans  get,  like,  twenty  to  thirty  days  a  year,  you  know,  just  to  get,  you  know,  be  culturally 

inclusive  here. 

So  first  of  all,  we  have  a  couple  of  follow  ups  from  the  last  episode. 

We  got  comments. 

People  screamed  at  us,  and  they  said,  you're  absolutely  wrong. 

Deep  dish  in  Chicago  is  indeed  a  pizza  and  not  a  pie. 

Is  it,  though?  Is  it  though?  It's  Is  it  though?  I  think  I  said  last  time  it's  like  a  casserole. 

It's  a  casserole. 

I'm  I'm  gonna  stand  by  that. 

But  Good. 

It's  been  maybe  what,  four  years  since  I  had  Chicago  deep  dish  pizza  last. 

Was  in  Chicago  a  couple  years  ago. 

Yes. 

And  I'll  be  back  for  Electric  Conf  US. 

So  maybe  maybe  in  September  Yeah. 

We  can  report. 

I'll  report  back  on  on  whether  I  still  think  it's  a  casserole  or  Yes. 

Gus  is  gonna  be  our  reporter  on  the  ground,  so  he  will  bring  you  the  latest  news  of  deep  dish  in  Chicago 

and  whether  it's  a  pizza  or  a  pie  or  a  casserole. 

Yeah. 

Second  of  all,  a  follow-up  to  the  hologram  news  last  week. 

Indeed,  we  were,  uh,  we  confirmed  Hologram's  written  in  Elixir,  and  it  can  be  compiled  on  JavaScript. 

And,  uh,  there  also  has  been  news  on  Hologram. 

Uh,  lately,  they  added  regexes  that  can  be  cross  compiled  and  so  on. 

So  there's  a  nice  blog  post  out  there. 

You  are  following  the  hologram  project,  go  and  check  out  that  blog  post. 

But  let's  get  started  with  the  news. 

First  of  all,  in  the  last  week  or  so,  OTP  has  released  a  couple  of  emergency  patches  for  OTP  twenty  seven, 

twenty  eight,  and  twenty  nine. 

Each  one  of  these  releases  contains  six  to  seven  pretty  critical  CVEs,  so  that's  vulnerabilities. 

And  if  you  haven't  updated  the  OTP  version,  please  do  so. 

There  are  some  very  serious  vulnerabilities  in  here  that  can  be  exploited  in  the  wild. 

One  of  them  that  I  would  like  to  highlight  is,  for  example,  that  if  you  use  TLS  one  point  two  or  earlier, 

if  you  make,  you  know,  SSL  or,  yeah,  SSL  connections  to  another  server  using  the  the  OTP  functionality, 

a  man  in  the  middle  attack  is  completely  possible. 

Like,  if  you  use  TLS  one  point  two  or  one  point  one,  a  man  in  the  middle  attack  can  happen. 

There  is  an  attacker  that  would  put  just  himself  or,  like,  the  attacker  would  be  between  you  and  the 

destination. 

And  usually,  the  destination  server  so  the  the  server  that  connects  to  another  destination,  they  send 

a  list  of  algorithms  of  TLS  algorithms  they  support,  and  then  the  server  has  to  pick  an  algorithm  out 

of  that  list. 

And  if  they  don't  select  such  an  algorithm  out  of  that  list,  the  connection  is  rejected  and,  you  know, 

there  won't  be  an  insecure  connection  established. 

Unfortunately,  in  OTP,  there  has  been  a  bug  or  a  vulnerability  where  the  server  could  select  any  algorithm 

that  was  not  advertised. 

And  there  are  some  algorithms  which  are  just  anonymous. 

You  know,  I  don't  wanna  have  any  algorithm  between  us. 

So  that  is  what  an  attack  can  use  to  become  a  man  in  the  middle  where  they  just  say,  well,  I'm  I'm  just 

gonna  choose  the  anonymous  algorithm. 

I  don't  wanna  I  don't  have  to  send  you  any  certifications. 

That  means  also  OTP  won't  verify  the  domain  of  the  attacker. 

So,  yeah,  it's  it's  very  much  just,  yeah,  sure. 

I  would  like  to  connect  to  you  anonymously,  and  please  don't  check  my  validity  or  my  identity. 

So,  yeah,  this  is  now  fixed. 

It  is  pretty  pretty  it's  a  nine  point  one,  one  of  the  highest  CVEs  I've  ever  seen  out  of  ten. 

So,  yeah,  if  you  haven't  updated  your  OTP  version,  please  do  so  very  fast. 

And  the  new  versions  that  you  should  check  for  are  twenty  nine  dot  zero  dot  four,  twenty  eight  dot  five 

dot  zero  dot  four,  twenty  seven  dot  three  dot  four  dot  fifteen. 

That's  a  mouthful. 

But  Yes. 

Check  your  check  your  versions  and  get  upgraded  to  those  ones  there. 

Yeah. 

And  yeah. 

Update  now. 

And  also,  if  you  haven't  updated  in  a  while  because  you  have  a  legacy  system,  if  you're  not  up  now,  you 

are  setting  yourself  up  for  a  security  event. 

So  there's  no  excuse  anymore  to  not  update. 

Alright. 

Right. 

Next  item. 

Right. 

Gleam  one  dot  eighteen  was  released,  and  this  one  looks  like  a  big  release  focusing  on  the  developer 

experience. 

A  few  a  number  of,  uh,  updates  to  the  language  server,  a  lot  of  really  cool  things,  rename  and  find  references 

now  work  properly,  uh,  on  certain  types  of,  uh,  fields. 

I  think  that's  records  and  types. 

And  then  renaming  a  file  rewrites  on  rewrites  all  the  imports. 

So  a  lot  of  these  things  that  if  you're  just  using  Gleam  and,  you  know,  making  updates  with  your  editor, 

you're  gonna  update  and  you're  gonna  have  a  couple  of  nice  nice  features  now  available  to  you. 

So  the  Gleam  team  has  been  hard  at  work  there  and  know  that  they're  we're  gonna  link  the  blog  post  with 

all  of  the  descriptions  of  the  changes  down  below. 

But  if  you're  a  Gleam  user,  go  check  it  out. 

If  you're  not  a  Gleam  user,  go  check  it  out. 

Go  check  out  Gleam  in  general. 

It's  a  small  and  friendly  language  as  I  was  told. 

It  is. 

Yeah. 

And  Next  up. 

Next. 

ElixirConf  US  twenty  twenty  five. 

So  last  year,  the  talks  are  being  published  on  YouTube. 

I  think  they  link  every  video  to  a  forum  post  on  the  Elixir  forum. 

So  you  can  go  there  and  check  out  all  of  the  videos  that  are  being  released. 

There's  a  lot  of  good  talks  that  are  coming  out  now. 

Yeah. 

There's  about  one  talk  a  day,  I  think,  they  release  now. 

The  latest  one  was  about  Elixir's  configuration  layers,  a  visual  journey  by  Stephanie  Lane,  and  many 

more. 

So,  yeah,  the  the  videos  of  last  year's  ElixirConf  are  released  now  just  ahead  of  the  the  ElixirConf 

US  this  year,  like  three,  four  weeks  ahead  of  time. 

So  you  can  already,  you  know,  get  up  that  that  feeling  of  being  at  a  conference  than  listening  to  smart 

people  educators  educate  you. 

And  last  news  item  is  that  the  version  zero  point  three  point  zero  of  the  programming  nerves  book  by 

my  good  friend  Alex  Kutmos  and  Yugo  Baruna  is  out. 

So,  uh,  Alex  and  Yugo,  they  are  actively  working  on  this  new  book  called  programming  nerves,  and  it's 

a  really  nice  introduction  book  into  getting  started  with  NERFs. 

So  if  you're  interested  in  in,  you  know,  having  a  couple  of  projects  handed  to  you  with  a  part  list  you 

can  buy  and  then  exactly  how  to  wire  everything  together  and  and  to  learn  the  the  fundamentals  of  hardware 

design,  hardware  programming,  and  the  nurse  framework. 

The  programming  nurse  book  is  an  amazing  material,  like  an  amazing  resource  for  you. 

And  Alex  and  and  actively  working  on  this  book. 

So  they  release  a  new  chapter  every  every  month  or  every  two  months  or  every  couple  months. 

I  don't  wanna  put  pressure  on  on  Alex  here. 

But  yeah. 

So  it's  it's  out  now. 

You  can  already  buy  it  for  a  a  lower  price  of  forty  nine  dollars  for  the  beater,  and  eventually,  it's 

gonna  be  seventy  nine  dollars. 

It  has  four  chapters  by  now,  which  I  think  includes  three  projects  already. 

So  it's  already  worth  a  purchase. 

And  then  once  you  purchase  now,  going  forward,  you  will  you  will  get  the  latest  chapters  as  they  come 

out. 

Right. 

And  Alex  and  Hugo  are  authors  of  other  Elixir  books. 

So  they're  experienced  authors. 

They  have  some  really  good  content  out  there. 

I  also  know  that  Alex  and  Frank,  the  creator  of  Nerves,  are  giving  a  training  based  on  the  book  at  ElixirConfUS 

and  I  know  that  there's  a  you  get  a  free  copy  of  the  book  with  workshop  registration. 

So  Wow. 

If  you're  gonna  be  in  Chicago  and  you  want  the  book,  might  as  well  get  the  training  too. 

Right?  And  just  to  give  you  a  glimpse,  I  believe  the  project  that  you  will  work  on  at  the  workshops  is 

gonna  be  an  etch  and  sketch. 

Is  that  the  right  word?  Yep. 

So,  yeah,  two  knobs  you  can  turn,  and  then  you  have  kinda  like  a  was  that  a  display?  Is  that  a  e  ink 

display?  Yeah. 

So  I  made  the  hardware  for  that. 

So  they'll  they'll  they'll  be  using  the  nerve  starter  kit,  is  something  I'm  working  on,  early  version. 

Exactly. 

But  with  some  rotary  encoders  for  the  Etch  A  Sketch  knobs. 

It'll  be  fun. 

Yeah. 

So  you  can  draw  with  two  knobs  on  an  e  ink  display,  you  know,  kinda  like  this  old  Etch  A  Sketch  where 

you  can  create,  yeah,  drawings  on  an  e  ink  display. 

Alright. 

Well,  moving  on  to  the  blog  post  section. 

Again,  we  kinda  tried  to  just  highlight  the  news  this  week,  but  there  are  a  bunch  of  blog  posts  that 

came  out. 

So  I'm  gonna  start  with  the  first  one  by  Mike  Zornick. 

He  also  has  been  busy  during  the  summer  months. 

He  wrote  another  blog  post  called  shimming  your  way  off  a  debt  elixir  dependency. 

And  this  is  a  very  interesting  one  because  now,  especially  with  the  vulnerabilities  coming  out,  you  always 

have  a  delay  of  your  libraries  adopting  new  versions  of  another  library. 

Right?  So  in  in  Mike's  issue  situation,  he  used  the  Timex  library,  and  that  library  was  blocking  the 

x  money  library  that  that  he  also  had  in  his  project  because  Timex  was  not  yet  up  hasn't  upgraded  yet 

to  GetText,  and  there  was  a  a  version  mismatch,  basically. 

So  Mike,  he  created  kinda  like  a  a  little  module  in  between  that  he  could  put  in  front  of,  I  believe, 

Timex,  And  that  meant  that  he  could  kinda  give  the  old  GetText  API  to  Timex,  but  already  update  GetText 

to  a  new  version. 

And,  you  know,  this  way,  he  had  backwards  compatibility  to  Timex  that  hasn't  yet  updated  to  a  new  version 

of  GetText. 

So  this  is  a  very  nice  and  and  small  and  easy  way  to  kinda  keep  an  old  version  of  a  to  keep  a  library 

working  while  you  already  update  another  library  depends  on  through  a  version  that  has  breaking  changes. 

So  this  is  a  very  nice  and  neat  trick  that  I  liked. 

And  thank  you,  Mike,  for  writing  this  blog  post. 

Yeah. 

That  was  a  good  one. 

Also,  next  up,  Joanna  Larson,  who  was  also  featured  last  time  for  one  of  her  blog  posts,  published  a 

new  one  in  her  distributed  elixir  series  on  building  a  distributed  rate  limer  with  HRW  in  Elixir. 

And  I  think  HRW  stands  for  what  was  it?  Hash  random  waiting. 

No. 

Highest  random  waiting. 

And  it's  a  way  that  if  you  have  a  cluster  of  nodes  that  you  can  largely  direct  the  the  requests  to  the 

same  node  based  off  of  a  hashed  ID  or  something  like  that. 

But  this  is  another  good  post,  and  it's  very  approachable  in  her  description  on  how  to  get  started  with 

distributed  elixir. 

I  think  this  was  the  second  or  is  this  the  third  post  in  her  Oh,  she  she  has  written  so  much  this  summer. 

I  think  she  has,  like,  seven,  eight  blog  posts. 

So  she's  been  a  busy  bee. 

Busy  bee  indeed. 

I  saw  another  one  recently  that  that  she  also  made  an  AT  Proto  Yes. 

A  loss  library. 

So  that's  another  cool  one. 

So  if  you're  interested  in  AT  Proto,  Blue  Sky,  all  that  world,  check  that  out  too. 

But  highlighted  specifically,  if  you're  interested  in  the  the  distributed  elixir  world,  she's  got  a  really 

good  intro  with  these  series  of  posts. 

So  I'm  excited  to  see  the  next  Yeah. 

Next  couple  ones  that'll  come  out  too. 

Very  excited. 

The  the  other  one  you  mentioned  is  called  Latch,  that  library  to  add  Elixir  based  OAuth  authentication 

with  AT  Proto,  so  with  the  Blue  Sky  protocol. 

And  actually,  the  OAuth  authentication  with  Blue  Sky  is  quite  tricky  because  they  implemented  it  by  the 

book,  you  know,  not  by  kinda  developer  experience,  but  just  by  specifications. 

And  that's  why  there  are  a  lot  of  tricks  and  steps  involved  that  you  need  to  get  right. 

And  Johanna,  she  wrote  a  a  library  that  makes  it  easy  to  just  have  your  Elixir  application  be  able  to 

authenticate  with  your  Blue  Sky  account,  and  that's  called  Latch. 

And  she  also  wrote  a  blog  blog  post  about  that. 

A  t  proto. 

A  t  proto. 

A  t  proto  is  not  just  Blue  Sky. 

That's  the  big  one. 

Yes. 

There's  lots  of  apps  on  AT  Proto  these  days. 

So  Exactly. 

And  if  you  wanna  build  them  with  Elixir,  now  it's  a  little  bit  easier. 

Exactly. 

The  next  blog  post  we  have  is  by  Paul  Wicks,  and  that  I  found  really  interesting. 

It's  called  profiling  Rust  Nifts  in  Elixir  with  Hot  Path. 

That  addition  that  that's  an  addition  by  mine. 

But  the  issue  that  Paul  explains  here  is  that  he  wanted  to,  yeah,  profile  or  benchmark  a  Elixir  application 

that  also  uses  a  Rust  NIF. 

And  he  used  the  Benchy  benchmarking  library  written  by  my  good  friend,  Toby. 

But  Benchy  only  benchmarks  your  Elixir  code,  and  it  cannot,  for  example,  measure  the  memory  consumption 

in  your  entire  system. 

So  if  you  have  very  memory  high  or  a  high  memory  consumption  in  your  Rust  code,  Benchy  isn't  able  to 

measure  that  right  now. 

So  it  might  actually  just  say,  oh,  zero  bytes  memory  use,  which  you  think  is  kinda  weird,  but  it's  great, 

so  you  move  on. 

But  the  issue  here  is  that  the  Rust  code,  you  know,  is  not  measured. 

And  Paul  wrote  a  really  nice  blog  post  about  how  you  use  the  hot  path  Rust  library  to  also  extend  the 

the  benchmarking  and  the  profiling  to  the  Rust  side  of  things. 

And  I  gotta  say,  I  use  a  lot  of  Rust  in  in  my  applications,  and  I  also  ran  benchmarks  on  them,  but  only 

focused  on  speed. 

And  then  I  take  the  the  kinda  the  system  memory  as  a  snapshot,  and  I  kinda  try  to  estimate  what  is  the 

memory  consumption  of  this  function. 

So  this  blog  post  actually  helped  me  also  ready  to  benchmark  my  Rust  code  and  the  connection  to  the  Elixir 

code  much  better. 

So  thank  you,  Paul,  for  writing  this  blog  post. 

It's  always  fun,  though,  when  you  look  at  the  Benchy  output  when  you're  looking  at  a  NIF  and  it  says 

zero  memory  consumption. 

You  just  gotta  move  on. 

It's  like,  oh,  it's  perfect. 

Another  What  do  you  realize?  Another,  uh,  caveat  here  is  that  also  Benchy  doesn't  measure  other  processes 

memories. 

I  think  it's  only  the  process  that  is  under,  yeah,  the  the  the  supervision  tree. 

So,  yeah,  if  you  do  some  async  work  between  processes  in  your  benchmark,  it  also  won't  measure  that  kind 

of  stuff. 

So,  yeah,  just  be  aware  that  there  are  some  limitations  to  this. 

Right. 

Next  up,  uh,  blog  post  by  Jacob  Swanner,  um,  batching  phoenix  live  view  updates. 

This  was  a  short  but  sweet  one,  uh,  really  interesting  based  on  some  issues  that  Jacob  had  at  work  with 

live  views  that  were  having  a  lot  of  events,  like  I  think  hundreds  of  events  per  second  and  sending  those 

down  the  WebSocket  and  rendering  them  on  the  client  was  really  slow  for  them  and  so  he  implemented  a 

way  of  batching  those  updates  so  that  you  can  not  have  a  stream  of  DOM  patches  but  really  just  one  one 

big  one  that  happens  every  every  periodically,  every  time  out. 

The  way  that  he  did  that  was  using  the  private,  uh,  key  in  the  socket,  which  I  don't  even  know  like, 

before  reading  this  blog  post,  I  didn't  know  that  there  was  a  private  key  in  the  It's  Jose  does  Jose 

want  you  to  know  about  it?  It's  private. 

It's  private. 

Maybe  they  didn't  want  you  to  know  about  it,  so  that's  why  it's  not  documented. 

Well,  I  think  I  think  this  is  probably  the  use  for  it. 

So  it's  not  included  in  the  change  tracking,  so  you  can  assign  assign. 

I  don't  know  if  there's  an  assign  private  function. 

I  think  he  uses  assign. 

Yeah. 

Was  it  we'll  have  to  check  that. 

Yeah. 

But  you  you  you  stash  some  data  in  that  private,  uh,  that  private  key,  in  that  map  under  the  private 

key,  and  then  he  sets  up  a  timer  with,  um,  with  a  timeout. 

And  every  two  hundred  milliseconds  or  one  second  or  however  long  the  period  that  you're  interested  in, 

it  would  fire  that  event  and  then  copy  all  of  that  data  from  the  private  key  into  your  assigns  where 

then  it  gets  change  tracked  and  sent  down  the  wire  to  the  client. 

So  pretty  cool. 

And  I  really  appreciate  Jacob  that  he  had  a  a  single  file  phoenix  playground  snippet  that  you  could  run 

and  and  see  this  with  just,  like,  thirty  lines  of  code  right  at  the  end  of  his  blog  post. 

So  if  you're  curious,  you  can  just  paste  that  into  IDX  and  watch  it  run. 

Very  nice. 

And  it's  actually  true. 

You  can  just  do  update  in  socket  dot  private  dot  count,  for  example,  and  then  update  the  the  assignment 

there. 

And,  yeah,  usually,  you  would  do  socket  dot  assigns  dot  count,  and  those  are  the  change  tracked  assigns. 

But,  yeah,  the  only  thing  you  need  to  change  is  socket  dot  assigns  dot  count. 

You  need  to  change  to  socket  dot  private  dot  count. 

And  out  of  a  sudden,  you  have,  like,  a  private  state  that  has  not  changed  tracked. 

Very  smart. 

Very  smart. 

Indeed. 

Thank  you,  Jacob. 

So  the  next  blog  post  is  by  my  good  friend  Michael  from  Parexial. 

He  wrote  a  blog  post  about  how  other  security  vendors,  AIs,  they  you  know,  when  they  look  at  Elixir  code, 

they  often  either  don't  find  vulnerabilities  because  they  don't  understand  the  language  or  they  over 

report  every  single  thing. 

That  is  actually  a  cornerstone  of  the  language. 

For  example,  cookies  between  Erlang  notes. 

Like,  that  is  something  I've  seen  quite  a  bit. 

So  Michael  just  he  wrote  a  blog  post  about  just  be  careful  when  you  use  these  security  vendors  tools 

and  then  point  them  at  Elixir  applications  because  most  likely  they  have  no  clue  what  Elixir  is  or  what 

it  does  and  what  makes  it  special. 

And  he  took  one  particular  example  where  there  was  a  security  vendor  and  they  wrote  a  blog  post  about 

an  an  Erlang  function,  the  binary  to  term  function,  which  we  all  know  is  very  insecure  and  you  should 

not  be  using  it,  especially  on  user  controlled  input. 

But  some  people  think,  well,  if  I  use  binary  to  term  and  then  I  just  add  the  save  option,  well,  it  makes 

it  safe,  doesn't  it?  That's  what  it  says. 

And  that  is  in  Obviously. 

Obviously. 

Right?  It's  just,  you  know,  safe  version  of  this  function. 

That  that  doesn't  exist  really. 

It  only  if  you  add  the  safe  option,  the  only  thing  that  binary  to  term  does  not  do  is  create  new  atoms, 

which  is  good. 

But  it  still,  for  example,  creates  a  function  based  on  your  input. 

So  I  can  still  give  you  a  binary  input  that  that  defines  a  function. 

And  when  you  do  binary  to  term,  even  with  the  save  option  on  it,  it  will  create  a  function  in  memory. 

And  then  if  I  you  know,  if  you  if  in  the  code  you  use  that  the  output  of  binary  to  term,  for  example, 

just  do  an  enum  map  on  it. 

Enum  map  can  actually  execute  a  function. 

It  might  realize,  oh,  that  seems  to  be  the  mapping  function. 

Right?  So  I'm  gonna  execute  it  and  poof. 

Out  of  a  sudden,  you  have  a  ticker  controlled  function  execution,  which  is  a  remote  control  execution, 

an  RCE,  in  your  application. 

So  although  you  use  binaries  to  term  with  a  safe  option,  there's  still  an  option,  yeah,  to  create  functions, 

modules,  overrides,  configurations,  all  the  good  like,  bad  stuff. 

Good  stuff. 

Good  stuff. 

Yeah. 

In  your  application. 

So  just  don't  use  binary  to  term. 

And  if  you  use  it,  use  it  with  a  save  option. 

But  even  then,  be  aware  that  it's  actually  not  safe. 

It  just  doesn't  create  atoms,  but  it  can  still  create  modules,  functions,  and  and  configurations,  and 

that  kind  of  stuff. 

So  yeah. 

And  Michael  wrote  this  blog  post  as  a  warning  to  say  two  things. 

One  of  them,  binary  to  term  is  not  safe. 

Although  there  is  a  safe  error  alternative,  which  is  Pluck  Crypto  dot  non  executable  binary  to  term, 

you  need  to  know  about  that. 

But  even  then,  just  don't  use  it. 

You  know,  if  you  reach  to  binary  to  term  full  binary  to  term  on  user  controlled  input,  just  don't. 

Just  don't. 

Yeah. 

So  I  I  like  this  blog  post  because,  also,  I  didn't  know  that  binary  to  term  with  the  safe  option  is  still 

unsafe. 

So  thank  you,  Michael,  for  writing  this  blog  post. 

Yeah. 

Security  is  a  big  one  these  days,  and  and  Parac's  still  doing  good  work  in  the  Elixir  community. 

Yes. 

Michael  is  is  definitely  the  smartest  person  on  that  topic,  I  would  say,  in  in  in  our  industry. 

And  the  next  blog  post  is  by  also  another  friend  of  mine,  Herman  Velasco. 

He  wrote  a  very  nice  blog  post  about  diverge  then  converge  with  LLMs. 

And  what  he  wrote  about  a  little  bit  is  his  workflow  when  he  works  on  big  projects. 

And,  you  know,  when  we've  all  got  started  with  LLMs  maybe  a  year  or  two  ago,  our  approach  was  kind  of 

a  sequential  serial  approach  where  you  do  one  thing  and  you  wait  for  the  LLM  to  finish,  and  then  you 

do  the  next  thing  based  on  that  output  and  then  the  next  thing. 

So  if  you  do  research,  you  know,  first  one  LLM  and  then  another  research  task,  another  research  task, 

and  then  you  would,  you  know,  condense  it  or  verify  it,  and  then  you  would  write  an  execution  plan  based 

on  that. 

Now  that  obviously  changed  in  the  last,  what,  six  months  since  we  now  got  agents  or  sub  agents  to  do 

to  fan  out  the  work,  basically. 

So  instead  of  having  one  LLM  agent  doing  research,  you  can  fan  out  to  thirty,  fifty,  a  hundred  agents. 

And,  you  know,  that's  what  websites  complain  about  when  out  of  a  sudden  they  get  hammered  by  agent  HTTP 

requests,  you  know,  that  all  wanna  have  the  information. 

So,  yeah,  there's  a  downside  to  this,  but  the  structural  change  now  is  that  you  can  fan  out  a  big  task 

into  smaller  task  one  per  sub  agent. 

And,  yeah,  German,  he  writes  about  his  approach  where  he  deliberately  diverges,  you  know,  fans  out,  and 

then  eventually  he  converges  the  results  back  into  a  single  document  or  plan,  and  then  he  moves  from 

there,  um,  so  on. 

So  he  has  a  really  nice,  uh,  example  here,  yeah,  where  he  splits  a  review  of  a  pull  request  into  different 

agents  that  all  focus  on  particular  parts  of  the  review. 

And,  for  example,  a  couple  of  agents  focus  on  correctness,  other  was  focused  on  security,  and  then,  again, 

others  focus  on  simplicity  of  the  code  and  also  bug  fixes,  you  know,  simple,  thorough,  and  creative  bug 

fixes. 

So,  like,  he  he  and  this  is  actually  what  Claude  does. 

If  you  just  do  slash  code  review,  it  does  exactly  the  same  thing. 

It  also  spans  out,  like,  I  had  a  hundred  agents  looking  at  my  code  at  the  same  time,  all  focused  on  a 

different  aspect  of  the  code  and  kind  of  the  topic  they  look  at. 

So,  yeah,  thank  you,  Herman,  for  writing  this  blog  post. 

And  the  last  item  that  I  would  like  to  just  announce,  it's  a  little  public  service  announcement. 

I  also  saw  a  blog  post  and  I  still  see  blog  post  written  on  Medium. 

And  I  gotta  say  guys,  please  don't  write  on  Medium. 

I'm  at  a  motorcycle  outside  my  window. 

Sorry  about  that. 

But  the  problem  with  Medium  is  that  now  it's  just  the  private  company  trying  to  make  as  much  money  as 

possible. 

And  they  kinda  hide  your  content  behind  all  these  pop  ups  that  ask  you  to  subscribe,  and  then  they  only 

show  half  of  the  blog  post. 

And  for  the  other  blog  post,  you  need  to  start  a  subscription. 

And,  I  mean,  there  are  so  many  hosted  services  for  writing  blogs. 

I  yeah. 

Ghost  dot  org,  for  example,  is  a  good  one. 

People  know  about  Substack,  but  there's  always  political  problems  with  Substack,  you  know,  that  support, 

like,  right  wing  very  right  wing  extremist  writers  as  well. 

So  just  from  a  personal  standpoint,  I  would  just  say  start  your  own  blog. 

Like,  start  your  own  website. 

You  know,  it  takes  you  an  afternoon. 

It  doesn't  have  to  be  Elixir. 

It  can  just  be  like  a  Yugo  or  or  Eleventy  is  also  another  good  framework  that  people  use  these  days, 

and  you  can  just  throw  that  at  Netlify,  and  you  have  a  website  running  in  thirty  minutes. 

And  especially  with  LLMs  these  days,  just  point  it  at  the  problem,  and  it  will  post  the  website,  and 

then  start  writing  on  your  own  website  under  your  own  domain. 

Like,  I  I  think  nobody  should  be  a  medium  anymore. 

If  you  wanna  have  a  managed  system  or,  like,  a  managed  hosting  experience,  you  know,  Ghost  is  a  good 

one. 

And  there  are  also  a  bunch  on  the  Blue  Sky  ecosystem  like  Leaflet,  Overleaf  no,  Overleaf  something  else. 

Leaflet,  PocketBlog  Yeah. 

And  a  third  one  that  I  always  forget. 

But,  yeah,  they're  a  bunch. 

So  There's  a  bunch  these  days. 

Yeah. 

And  if  you  wanna  do  it  in  Elixir,  Nimble  Publisher  is  from  DashBit  is  the  The  Nimble  the  standard  way 

in  the  ecosystem  for  writing  blog  post. 

You  can  use  Nimble  publisher. 

Down  markdown  files,  and  it  just  post  converts  it  straight  into  HTML  on  your  on  your  homepage. 

Yeah. 

All  all  you  need  with  live  use. 

All  you  need  is  a  markdown  file  and  m  dex  and  Nimble  Publisher  if  you  want  to. 

That  is  from  DashBit. 

So  it's  very  easy  to  spin  up  your  own  thing. 

And  it's  also  kinda  like  a  rite  of  passage  to  build  your  own  blog. 

So  just  don't  use  Medium. 

And  sorry,  but  we  will  also  not  mention  blog  posts  on  Medium. 

Like,  I  don't  wanna  support  that. 

Too  many  paywalls. 

Personal  pay  Yeah. 

Beef. 

And  just  you  write  those  tags  to  be  available  to  the  world. 

And  then  Medium  goes  in  between  and  says,  no. 

Actually,  we  don't  want  that. 

You  know?  And  then  you  can  only  like,  people  can  only  read  three  Medium  articles  per  month,  and  then 

they  have  to  start  paying. 

It's  just  that's  not  the  idea  of  blog  posts. 

So  yeah. 

Anyways,  that  has  been  the  blog  section. 

Last  up,  the  meetups  and  conferences. 

Yes. 

So  we're  probably  gonna  rehash  these  until  they  happen,  but  this  month  we  have  next  week  on  Wednesday 

the  Nerves  meetup  online  via  Zoom. 

Come  join  us  for  a  good  time  discussions  on  Nerves  and  Elixir. 

Yeah. 

We  always  have  a  good  time. 

Around  thirty  people  tend  to  show  up. 

Oh,  it's  me  speaking. 

Right?  Yes. 

And  it's  you  speaking. 

I  it's  me  speaking. 

Listening  to  this  podcast  and  you  like  the  sound  of  Peter's  voice,  you  can  come  listen  to  him  some  more 

next  week  Yeah. 

Live. 

I  might  actually  also  have  content  that  you  might  enjoy,  you  know,  other  than  my  voice  and  my  my  German 

accent. 

So  What?  Really?  I  I  yeah. 

I  won't  just  read  a  book  to  you. 

I  will  actually  talk  about  how  to  not  get  pound  pawned  by  mythos. 

I  never  know  how  to  say  the  word. 

But,  yeah,  basically,  in  these  days  of  AI  and  LLMs  finding  all  the  vulnerabilities,  hacking  all  the  systems, 

you  know,  where  do  we  stand  right  now,  and  what  can  you  do  to  protect  yourself  and  contribute  to  the 

ecosystem?  So  it's  gonna  be  a  fun  one. 

Yeah. 

It's  next  week,  August  twelfth. 

The  next  well,  it's  actually  an  unconference. 

So  it's  not  officially  a  conference,  but  it  is  not  a  meetup  either. 

So  it's  an  unconference. 

Unconference. 

Yeah. 

It's  literally  called  unconference. 

So  it's  a  single  day,  single  track,  sometimes  two  tracks,  where  people  just  come  together  in  the  morning. 

Everyone  presents  a  topic  they  would  like  to  talk  about. 

Well,  not  everyone  who  has  a  topic. 

Not  everyone  has  to  present  a  topic,  you  know,  but  everyone  who  has  a  topic  presents  it,  then  people 

vote  on  the  topics  that  they  would  like  to  hear  about. 

And  then,  yeah,  people  give  these  talks  and  and,  you  know,  demos  and  that  kind  of  stuff  throughout  the 

day. 

It's  a  very  social  event. 

It's  a  very  low  key,  no  stress  event. 

It's  very  much  just  a  social  meetup  gathering  with  a  couple  of  talks. 

So,  yeah,  it's  gonna  happen  before  the  ElixirConf  US  on  September  ninth. 

So  that's  one  day  before  the  on  September  tenth,  the  ElixirConf  begins. 

And  it  will  also  happen  in  October  before  the  CodeBeam  EU  that  happens  on  October  twenty  first  and  twenty 

second  in  Harlem,  the  Netherlands. 

Yeah. 

There's  gonna  be  another  Unconference  the  day  before  on  October  twentieth. 

And  you  can  sign  up  to  these  unconference  and  get  all  the  information  and  the  location  and  whatnot  if 

you  go  to  luma  dot  com  slash  earl  at  e  f. 

So  Erling,  e  r  l  e  f,  and  then  you  will  see  both  unconference  and  the  the  dates  and  locations  there. 

Yeah. 

And  if  it's  not  clear  from  the  Luma  link  there,  it's  put  on  by  the  the  Erling  Ecosystem  Foundation. 

This  is  some  of  the  work  done  to  support  local  events. 

You  don't  have  to  register  for  elixirconf  u  s  or  code  being  EU. 

You  can  just  go  to  the  UN  Conference  if  you  if  you  wish. 

They're  independent,  but  still  a  lot  of  really  fun  content. 

You  did  you  go  to  you  went  to  the  Unconference  in  Malaga. 

Malaga. 

Yeah. 

It  was  very  nice. 

It  was  a  very  nice,  you  know,  pre  conference  conference  where  you  just  meet  everyone  and  you  can  chat 

to  people  and  yeah. 

Because  on  the  conference  day,  everyone  just  starts  going  to  these  meetups  and  then  it's  like,  you  know, 

game  on  kinda  for  two  days  straight. 

So  the  unconference  before,  it's  nice  to  already  kinda  warm  up,  meet  the  people  that  you  wanna  talk  to 

and  yeah. 

I  really  enjoyed  it. 

Feels  a  little  bit  lower  lower  stress,  I  would  say. 

Definitely. 

It's  a  smaller  group  of  people  and  it's  like  a  nice  warm  up  intro  to  Yeah. 

Conference  mode. 

Exactly. 

And  then  Plus,  it's  fun. 

It's  fun. 

Yeah. 

So  the  last  conference,  Gus?  Yes. 

Gothmeier  happening  in  Warburg,  Sweden,  September  twenty  eighth  to  October  third. 

Basically,  the  whole  week  of  elixir  festivities. 

There's  workshops. 

There's  talks. 

Talks  are  three  days. 

It's  single  track. 

Workshops  are  two  days  before  that. 

So,  yeah,  I  there's  not  gonna  be  a  GoatMire  next  year,  and  jury's  out  on  twenty  twenty  eight. 

So  if  you  want  your  GoatMire  experience,  if  you  missed  out  last  year,  you  gotta  get  a  ticket. 

It's  not  your  ticket. 

Gotta  get  a  ticket. 

And  there's  also  gonna  be  the  AshConf  on  the  October  third,  the  Saturday,  and  we  will  also  do  a  Hackathon 

on  October  third. 

So  you  can  stay  one  day  longer  this  Saturday,  then  you  have  either  AshConf  or  Hackathon. 

They  will  be  in  the  same  building,  you  know,  so  you  can  also  go  in  between  these  two  events,  but,  you 

know,  that's  just  gonna  be  an  extra  day  of  stuff. 

Right. 

And  there's  gonna  be  a  lot  of  fun  stuff  there. 

Yep. 

I  can't  confirm  or  deny  anything,  but,  um,  we  we  have  given  out  hardware  in  the  past. 

So  if  you're  interested  in  in  that,  maybe  that's  another  reason  to  Exactly. 

They  might  or  might  not  be  hardware  handed  out  to  you. 

So  Exclusive. 

Exclusive  hardware. 

It  any  other  way  than  going  to  Govire. 

That's  true. 

That's  true. 

Alright. 

Well,  that  kinda  concludes  our  news,  blog,  and  meetup  section. 

So  if  you're  only  interested  in  that,  please  feel  to  hop  off. 

But  if  you  wanna  stay  around  for  the  discussion,  we  have  three  topics,  and  we're  gonna  keep  a  little 

bit  shorter  this  time  around. 

Last  year  last  week  was,  you  know,  a  little  bit  too  long. 

We  got  carried  away. 

We  got  carried  away. 

Yeah. 

And,  you  know,  like,  had  too  many  topics,  so  we  cut  it  down  a  little  bit  more. 

Yeah. 

So  let's  start  with  discussion. 

Gus,  you  had  the  first  topic  about  deployment  strategies  in  twenty  twenty  six,  the  Fly. 

Io  shifting  focus. 

What  is  this  about?  Right. 

So  I  don't  know  if  you  saw  this  one,  Peter,  but  Fly. 

Io  has  published  recently. 

Their  CEO  is  stepping  down  and  is  gonna  be  replaced  by  I  think  it  was  the  previous  Docker  CEO. 

Yep. 

He's  stepping  down. 

I  mean,  this  is  all  kinda  normal  startup  stuff. 

It's  maturing  into  a  bigger  company. 

He  wants  to  focus  on  other  things. 

Mhmm. 

That  all  makes  sense. 

But  what's  interesting  about  the  blog  post  is  that  he  said  that  Fly. 

Io  shifting  their  focus,  shifting  their  priorities  to  their  Sprites  platform,  which,  um,  if  you  have 

heard  of  Fly. 

Io  in  the  context  of  Elixir,  typically  it's  a  solution  that  people  like  to  use  for  hosting. 

They  have  a  very  nice  CLI. 

You  run  Fly  Launch  or  fly  publish  or  whatever,  fly  deploy,  something  like  that,  and  boom,  your  app  is 

on  a  hosted  website,  and  it  kinda  takes  care  of  a  lot  of  things  for  you. 

It's  been  very  elixir  friendly. 

Chris  McCord  does  work  at  Fly. 

I  think  he  still  is  there  to  this  day,  but  he's  been  there  for  the  past  couple  of  years. 

So  they've  been  done  a  lot  of  work  to  be  very  elixir  and  phoenix  friendly,  and  it  kinda  come  came  as 

a  little  bit  of  a  surprise  when  this  blog  post  came  out  because  they  basically  said  we're  shifting  focus. 

We're  shifting  focus  and  working  on  these  sprites. 

Uh,  sprites  is  kind  of  their  product  for  disposable  computers. 

A  lot  of  people  apparently  point  their  agents  at  them. 

It's  not  disposable  computers. 

Right?  It's  not  disposable  hardware. 

It's  like  a  single  use  computer  they  throw  away  after,  you  know,  it  was  tainted  by  an  LLM  or  so. 

No. 

It's  it's  more  of  you  they  spin  up,  uh,  really  quickly  instances  of  Ubuntu  or  whatever  it  is  to  let  your 

agent  roam  free  in  its  own  little  sandbox. 

It's  an  interesting  product. 

I  haven't  personally  used  it  yet,  but  but  that's  where  they've  seen  a  lot  of  their  growth  recently  according 

to  this  blog  post. 

And  that  has  the  Elixir  community  wondering  what's  gonna  happen  to  their  hosting  services  if  they're 

not  focusing  on  it  so  much. 

Now  there  was  an  Elixir  forum  post  by  Alex  Slade,  I  believe  it  was  Mhmm. 

That  prompted  this  kinda  discussion. 

And  I  did  see  some  later  links  that  that  the  machine  platform  and  how  they  host  stuff  and  how  you  host 

your  apps  is  actually  a  lower  level  to  their  sprites. 

Mhmm. 

So  they  need  that  machine  and  app  platform  to  do  the  the  stuff  that  they're  doing  with  sprites. 

But  this  also  kinda  got  me  thinking  and  also  related  to  my  work  this  week  because  I  had  set  up  a  a  new 

deployment  of  an  app  that  I'm  working  on  for  a  client. 

And  deployment  strategies  in  twenty  twenty  six  with  Fyde. 

Io  shifting  focus,  like,  how  do  you  think  this  changes  things?  What  do  you  use  for  hosting,  Peter?  And 

yeah. 

Yeah. 

I  gotta  be  honest  with  you. 

I  I  love  Fly  and  I  wish  them  to  succeed,  but  I  stopped  using  them  two  two  years  ago,  maybe. 

For  I  I  for  anything  other  than  the  smaller  side  projects. 

You  know,  anything  that  needs  to  run,  well,  twenty  four  seven,  you  know,  I  do  not  put  on  Fly. 

And  I  I  I  don't  know,  but  maybe  going  to  sprites  that  are  more  short  term  running,  you  know,  that,  like, 

they  run  for  maybe  minutes  until  the  LLM  has  completed  the  the  the  task,  and  then  they  spin  down  the 

sprite  and  start  up  a  new  one. 

Maybe  that  is  the  right  goal  for  Fly. 

You  know?  Maybe  maybe  that's  actually  a  good  strategy  shift  because  I  I'm  sorry,  but,  you  know,  I  I  heard 

many  people  saying  that  they  migrated  away  for  their  production  servers  from  Fly  because  they  had  outages 

that  are  not  always  visible. 

So  it's  not  that  your  web  that  your  server  is  down. 

You  don't  get  any  notification,  but  maybe  their  routing  is  down,  which  happens. 

Or  then  whatever. 

Like,  they  can't  start  new  machines  because  the  machines  API  responds  with  a  five  hundred. 

I  I  had  that  a  few  times  where  you  just  run  fly  deploy  on  a  new  project  and  everything  looks  good  and 

then  just,  yeah,  five  hundred. 

We  can't  start  your  machine. 

Sorry. 

And  you're  like,  well,  great. 

You  know,  I  guess. 

It's  the  one  thing  I  wanted  to  do. 

Yeah. 

It's  like,  just  wanted  to  take  this  project  and  put  it  online,  you  know,  and  I  have  a  talk  in  thirty 

minutes. 

So  it  needs  to  be  online. 

Wow. 

That  never  happened  before,  did  it?  No. 

Almost  never. 

But  Yeah. 

I  mean,  I've  I've  heard  other  people  talking  about  reliability  issues. 

I've  used  them  a  lot  for  I  I  throw  my  side  projects  on  there  usually  because  it's  just  so  easy  to  get 

started. 

I  haven't  I  mean,  I  haven't  seriously  been  monitoring  those  side  projects,  so  I  haven't  really  noticed 

Mhmm. 

Reliability  issues. 

But  and  I  think  they've  gotten  better  in  past  years. 

But  what  did  you  migrate  to?  When  what  prompted  that  decision,  and  what  do  you  recommend?  Would  you  keep 

going  with  that  today?  Yeah. 

So  I  Are  you  on  AWS,  the  Behemoth,  or  No. 

I  didn't  I  didn't  go  to  the  big  ones. 

I  I  moved  to  DigitalOcean  for  a  while  because  they  just  have  a  nice  developer  experience,  and  it's  you 

know,  they're  stable. 

Like,  I  never  had  any  issues  with  them. 

And  I  also  run  at  least  five  or  six  production  servers  on  DigitalOcean  still  for  American  businesses. 

So,  like,  they're  great. 

You  know?  They  have  pivoted  a  little  bit  too  hard  on  the  AI  thing,  I  think,  now. 

So  they  they  have  a  new  data  center  in  Atlanta,  and  I  was  excited  because  they  had  new  machines  and  a 

better  connection  to  all  the  corners  of  the  states. 

But  then  a  couple  months  after  I  added  my  service  there,  they  just  completely  pivoted  that  entire  data 

center  to  GPUs. 

And  then  you  couldn't  Oh,  wow. 

You  couldn't  spin  up  a  second  CPU  machine  anymore,  and  you  had  to  migrate  to  New  York  or,  you  know,  San 

Francisco. 

So  now  I  have  that  little  migration  issue. 

But,  generally,  DigitalOcean  was  always  great. 

But  then,  I  think  beginning  of  this  year,  because  of  all  the  political  tension,  I  decided  to  move  all 

my  stuff  to  European  servers. 

And  what  I  just  did  is  I  rented  a  Hetzner  machine,  and  I  installed  Kudify  on  it,  you  know,  and  you  can 

just  click  together  things. 

So  it's  So  what  is  Cooldify?  Cooldify  is  kinda  like  Heroku,  but  self  hosted. 

So  if  you  loved  Heroku  and  just  like  the  click,  you  know,  your  architecture  together  experience,  Koolify 

is  very  much  the  same  and  better  and  more  features. 

And,  yeah,  you  can  just  install  it,  and  then  you  say,  hey,  this  is  my  Docker  container  that  I  have  in 

this  registry. 

You  know,  I  now  use  the  GitHub  registry  because  it's,  like,  connected  to  my  GitHub  actions. 

And  then  I  point  Qualify  at  the  GitHub  registry  and  just  click  deploy. 

And  it  fetches  the  Docker  image. 

It  spins  up  the  Docker  image. 

It  has  a  switch  over,  you  know,  like  blue  green  where  you  first  set  the  the  new  one,  you  make  sure  it's 

healthy,  and  then  you  switch  over  the  traffic  to  the  to  the  new  one,  and  you  spin  down  the  old  one. 

It  has  that. 

But  the  the  coolest  thing  about  Coolify  is  also  if  you  wanna  deploy  any  systems  like  Grafana,  Clickhouse, 

what  Postgres,  obviously,  any  s  three  object  storage  that  you  wanna  host  yourself  like  Minio. 

Man,  there  are,  like,  hundreds  and  hundreds  of  kind  of  recipes  that  you  can  just  select. 

You  just  select  servers,  and  then  you  say,  I  wanna  have  a  new  service. 

And  you  just  one  click  deploy,  you  know,  just  like  spin  up  this  thing. 

And  I  have  Grafana  running,  and  I  never  got  Grafana  to  work  anywhere  else,  to  be  honest. 

It's  just  It's  a  prickly  one. 

Yeah. 

I  mean,  you  can  use  the  manage,  but  even  then,  I  I  don't  I  don't  know  what  the  connection  string  is  to 

the  managed  hosting  for  I  could  and  they  have  so  many  websites. 

I  don't  understand  any  of  it. 

So  with  Coolify,  I  was  just  like,  yeah. 

Sure. 

I  wanna  have  the  whole  Grafana,  Loki,  Prometheus  stack. 

Click. 

Done. 

And  then  and  then  it  gives  you  a  basic  setup,  and  I  copy  the  Docker  Compose  to  to  Claude. 

And  I  said,  I  have  these  applications  running  here,  like,  in  Docker  as  well,  and  they  are  named  this. 

Please  add  them  to  whatever. 

I  don't  care. 

Just  let  me  look  at  the  metrics  in  Grafana. 

And,  yeah,  it  edited  my  Docker  Compose. 

It  pointed  to  the  right  applications,  applications,  and  then  I  added  Promax  to  all  my  Lixi  applications 

to  expose  the  telemetry  data. 

And  then  I  I  guess  that's  Prometheus  then  goes  and  fetches  the  metrics,  puts  it  in  Loki. 

I  don't  know. 

There's  so  many. 

And  then  Grafana  is  the  the  UI  part  of  things  where  it  pulls  the  telemetry  and  shows  it. 

And  all  of  this  was  literally  one  click  deployment,  and  then  I  had  the  stack  running,  and  then  it  was 

a  couple  of  configurations  that  Claude  did  for  me. 

And  within  an  hour  at  most,  I  have  a  Grafana  dashboard  that  shows  all  the  telemetry  of  all  my  applications 

running  on  the  same  host. 

And,  you  know,  it's  like  the  Grafana  as  a  dashboard,  those  are  JSON  files,  so  you  can  give  those  to  Claude 

and  just  say  add  me  another  graph  that  shows  me  x  y. 

And  you  can  run  it  in  your  application  code  base,  so  it  knows,  oh,  these  telemetries  are  sent. 

So  it  immediately  knows  the  the  structure  of  the  telemetry  event,  and  it  can  just  add  the  dashboard. 

Anyway,  long  story  short,  like,  I  have  a  Hetzner  machine  running. 

I'm  unhappy  that  they  had  to  increase  their  prices  by,  like,  almost  fifty  percent  in  the  last  couple 

of  months. 

But  it's  great. 

It's  super  fast. 

I  have,  like,  twenty  CPUs  that  I  barely  use,  and  I  can  run  everything  on  it. 

So  you  run  all  your  apps?  Because  you  have  you  have  quite  a  few,  don't  you?  I  have,  like,  five  or  so. 

Yeah. 

Five  apps  running  on  one  machine. 

Yeah. 

But  it's  still  at  like  less  than  one  percent  usage. 

Right. 

But  I  Wait. 

That's  I  I  mean,  that's  really  great  for  this  type  of  deployment  is  that  you  can  throw  everything. 

Like,  I  mean,  long  as  you're  not  doing  ginormous  resource  intensive  apps,  which  might  want  to  be  distributed 

and  clustered,  which  I  think  you  can  also  do  on  Hetzer. 

You  can  set  up  the  Yeah. 

Private  network  and  stuff  like  that. 

But  if  you're  running  this  and  you  have  small,  medium  sized  apps,  you  can  throw  them  all  on  the  same 

machine. 

And  Yeah. 

And  that's  that's  really  nice. 

Yeah. 

I  have  so  I  have  my  own  Hetzner  machine  for  my  private  project. 

So  my  blog  is  there. 

Letter  to  yourself,  like  a  small  thing  that  I  built  five  years  ago  is  on  there. 

That  is  all  on  Hetzner. 

But  then  I  also  use  that  Hetzner  machine  to  build  local  docker  images. 

So  different  story. 

For  more  production  ready  applications,  I  use  Scaleway. 

Scaleway  is  the  European  hosting  provider. 

It's  one  of  the  two  biggest. 

The  other  one  is  OVH,  and  they're  both  in  France. 

But  OVH  is,  you  know,  kinda  like  the  Amazon  that  has  it  all  in  big  data  centers. 

And  the  second  one  is  Scaleway,  which  also  has  data  centers  in  Paris,  Amsterdam,  and  Warsaw. 

So  for  Scaleway,  it's  very  much  you  you  just  rent  a  bare  metal  machine,  or  they  also  have  managed  servers, 

but  I  use  bare  metal,  you  get  an  IP  and  you  can  add  an  SSH  key  to  it. 

And  then  I  use  Kamal,  the  Mhmm. 

The  one  from  Basecamp. 

Right?  I'm  not  happy. 

I  I  I  it's  fine. 

Like,  you  know,  I  I  kinda  I  kinda  wish  there  was  something  better  that  is  not  built  by  DHH. 

But  for  now,  I'm  okay  with  Kamal  because  it  makes  Have  you  you  seen  the  Xamal?  The  one  that  someone  Oh. 

No. 

Made  an  elixir?  I  have  not. 

Maybe  I  should  look. 

What's  it  called?  You  have  to  it's  like  Kamal  but  with  an  x  instead  of  a  k. 

I  wrote  that  thing. 

That's  mine. 

You  wrote  that. 

I  wrote  that. 

Yeah. 

But,  like,  I  I  didn't  even  stop  start  like,  finish  it. 

Did  I  send  it  to  you?  I  don't  No. 

That's  not  from  me,  XML. 

I  okay. 

Sorry. 

I  had  exactly  the  same  library  with  exactly  the  same  name. 

Yeah. 

Okay. 

This  one  is  great. 

This  is  exactly  what  I  wanted  to  do. 

It's  a  port  of  Kamal  to  Elixir. 

Okay. 

I  gotta  look  into  this. 

It's  amazing. 

You  gotta  look  into  it. 

Apparently,  this  this  is  one  of  those,  what,  great  minds  think  alike  moments. 

Yeah. 

Definitely. 

It  is  even  the  same  name. 

I  I  literally  took  x  a  a  a  m  a  l. 

So  That's  funny. 

Oh,  that's  funny. 

I  don't  remember  you  sending  me  anything,  at  least  not  recently. 

So  No. 

I  started  building  it  locally,  then  I  abandoned  it  because,  yeah,  it  had  other  projects. 

But,  yeah,  what  I  wanted  so  what  what's  great  about  Kamal,  and  I  hope  that  Chamal  or  Samal  is  gonna  reproduce 

or  maybe  another  project's  gonna  reproduce,  is  with  Kamal,  you  have  all  the  configuration  locally  and 

gets  version  control. 

And  the  only  thing  you  need  to  change  is  the  IP  of  your  servers. 

And  then  you  say,  come  out  deploy,  and  it's  gonna  install  Docker. 

It's  gonna  install  everything  it  needs. 

It's  gonna  pull  the  Docker  image,  and  it's  gonna  deploy  it  on  every  machine. 

It  has  different  deployment  strategies. 

And,  yeah,  you  don't  need  to  touch  your  server  other  than  just  having  an  SSH  connection  to  it. 

That  that's  it. 

Right. 

So  spinning  up  a  new  server  is  literally  adding  one  extra  IP  to  your  configuration  file  and  then  saying, 

come  on,  deploy. 

So  Right. 

That's  really  that's  really  sleek  and  nice  how  that  that  works  like  that. 

I  think  that  this  is  really  interesting  that  I  feel  like  with  these  options  now,  there  is  it's  like  it's 

a  feasible  push  to  have  kind  of  that  managed  platform  as  a  service  experience,  but  still  self  hosted 

and  not  on  some  big  cloud  providers  Yeah. 

Platform. 

Right?  Yeah. 

And  so,  I  mean,  with  Camel  or  XAML  or  whatever,  you  can  you  can  you  can  port  it  to  not  just  not  just 

AWS  Mhmm. 

Or  or  DigitalOcean  or  Hetzner  or  Scaleway  or  whatever. 

Like,  you  can  go  you  can  put  a  server  on  all  of  those  or  none  of  them  or  your  own  server  in  in  your  basement. 

Right?  Exactly. 

Yeah. 

You  can  point  it  at  the  Raspberry  Pi,  and  it  will  try  to  deploy  a  Docker  image  on  it. 

I'm  not  sure  whether  it  works  or  not. 

Yeah. 

But  the  That's  cool. 

The  only  downside  or  the  the  few  downsides,  I  mean,  Kamal,  the  original  Kamal,  it's  man,  the  configuration 

of  it  is  so  bare  that  it  it's  just,  you  know,  it  they  stopped  Basecamp  stopped  developing  it  after  what 

they  needed. 

And  then  they  just  stopped. 

Right. 

Yeah. 

And  then,  you  know,  when  people  said,  please  add  this,  they're  like,  well,  you  can  always  fork  it  and 

build  your  own. 

You  know?  Like,  they  didn't  take  any  ownership  of  it  really  as  a  project,  as  a  community  project. 

So  if  you  have  any  most  for  example,  in  Elixir,  you  have  the  EPMD  ports,  like  the  six  nine  something. 

Just  to  open  that  freaking  port  on  your  proxy  that  you  have  running  on  your  machine  to  another  machine 

so  that  you  can  cluster  your  Elixir  nodes,  you  have  to  spin  up  a  second  HTTP  proxy  next  to  the  traffic 

one,  uh,  instead  of  just  configuring  the  damn  one  that's  already  running,  but  only  for  port  eighty  and 

four  four  three. 

You  know?  Okay. 

And  so,  yeah,  you  have  to  spin  up  another  Docker  container  that  is  also  an  proxy,  but  only  for  this  one 

port  so  that  your  Elixir  nodes  can  cluster  through  it. 

It's  just  why. 

Is  that  a  Kamal,  or  is  that  a  coolifier?  No. 

It's  it's  Kamal. 

Okay. 

Interesting. 

That's  one  of  these  things  where  it's  just  like,  yeah. 

We  don't  care. 

Just  yeah. 

We  don't  care. 

Yeah. 

Well,  hopefully,  maybe  you'll  have  to  look  at  the  the  Kamal  Yeah. 

Project  and  see  if  they've  I  mean,  with  Elixir  Native  I  will. 

Keeping  that  in  mind. 

I  will. 

They  they  might  have  thrown  that  as  an  option. 

Yeah. 

But  So  to  to  kinda  wrap  this  up,  so  I  ended  up  also  doing  a  similar  deployment  as  you  did  this  past  week 

with  my  client  project,  and  I  got  a  Hetzner  server  and  used  Docploit  Mhmm. 

Instead  of  instead  of  Coolify,  which  is,  I  think,  a  similar  product. 

Maybe  the  UI  is  a  little  sleeker,  but,  generally,  it  works  the  same  way. 

And  that  was  a  suggestion,  I  think,  from  one  of  Johanna  Larsen's  blog  posts  that  I  had  read  a  while  back, 

and  I  was  like,  maybe  I  should  give  that  a  try  for  this. 

Nice. 

So  I  did. 

And,  yeah,  it's  it's  impressive  how  far  these  tools  have  kinda  come  because  it  really  feels  like  like 

a  like  a  managed  solution  Yeah. 

That  I  don't  have  to  worry  about  too  much. 

I  really  appreciate  the  fact  that  you  spin  up  the  Postgres  next  to  the  app,  and  then  you  can  configure 

the  Postgres  to  have  automatic  backups  Yeah. 

And  and  all  that  good  stuff  to  to  s  three  bucket  somewhere. 

Automatic. 

You  can  pull  those  back  down  and  restore. 

Very  cool. 

I  love  to  see  these  projects. 

I  still  think  this  space  is  not  yet  solved. 

Maybe  it  will  never  be. 

No. 

But  the  the  downside  with  Coolify  is  that  it  really  only  works  on  one  machine. 

So  if  you  wanna  have  two  machines  running  your  apps,  you  shouldn't  use  Coolify. 

The  problem  with  Camaro  that  if  you  wanna  dynamically  upscale,  you  know,  add  another  machine  dynamically 

and  spin  it  down  again. 

That's  just  not  possible. 

You  need  to  add  and  delete  the  IP  from  your  configuration  file. 

So  it's  very  much,  you  know  yeah. 

It's  not  that  hard  to  spin  up  another  machine. 

I  use  Ansible  for  configuring  it  and  then  run  Kamal  on  it  to  deploy  the  application. 

But  that  takes,  what,  half  an  hour  until  you're  there. 

Right?  So  if  you  have  a  spike  in  traffic,  that's  why  people  use  still  the  managed,  you  know,  AWS  and 

whatnot  services  because  they  can  spin  up  a  machine  in  in,  like,  seconds. 

So,  yeah,  they're  all  different  angles  to  this,  and  I  don't  think  there's  one  solution  that  does  it  all 

well. 

Yeah. 

Definitely  no  silver  bullet,  but  but  this  one  that  that  that  from  your  recommendation  and  also  from  Yana's 

Mhmm. 

Blog  post,  it's  it's  it  works  well  for  me  at  the  stage  that  we're  Yeah. 

Developing  at. 

So  Yeah. 

Might  be  interesting  for  other  people. 

And  if  anyone  who's  listening  has  other  alternative  platforms  or  methods  that  the  user  deployed,  they 

wanna  shout  out,  leave  us  a  message  because,  yeah,  this  is  it's  interesting. 

It  there's  a  I  feel  like  it's  always  evolving. 

It  is. 

Right?  Yeah. 

And  I'm  Did  you  see  Mhmm. 

The  new  one,  potions  dot  I  o?  No. 

Isn't  that  from  from  Michael?  No. 

That's  both  potion  shop. 

From  I  don't  know  who  would  the  name  of  the  person  behind  it,  but  ElixirCasts. 

Okay. 

Potions  dot  I  o. 

Deploy  phoenix  to  your  own  VPS  without  the  work. 

That's  cool. 

Dedicated  resources,  no  cold  starts,  no  surprise  builds. 

The  ease  of  a  prop  platform  as  a  service  on  infrastructure  you  own. 

That  sounds  very  much  like  Kamal. 

Yeah. 

Yeah. 

It's  definitely  Elixir  oriented. 

I  think  it  is  a  paid  product. 

I've  not  tried  it. 

I'd  be  curious  to. 

But  Alright. 

Kinda  interesting. 

There's  still  a  lot  of  development  in  this  deployment. 

I'm  very  happy  there's  a  a  healthy  competition  going  on  here. 

Yeah. 

Yeah. 

Alright. 

Let's  there  are  two  more  discussion  topics,  giving  the  time,  I'm  gonna  super  quickly  do  the  next  one. 

Maybe  no  discussion. 

Just  kinda  like  a  if  you  if  you,  listener,  wanna  read  more  on  this,  there's  a  nice  blog  post  out  there. 

The  question  that  the  author  I  think  his  name  is  Nor. 

Well,  Norpinion  is  the  blog,  but  that's  probably  not  his  name. 

But  his  name  is  Nor  Smith. 

And  the  blog  post  is  called  what  will  more  intelligence  actually  do  for  us?  And  the  thing  here  is  the 

argument  here  is  that  people  when  they  think  about  LLMs  and  AI,  they  think  about  the  intelligence  of 

an  AI  in  terms  of  a  linear  scale. 

So  it  will  always  become  smarter,  And  it's  kinda  unlimited  or  infinity  is  the  end,  you  know,  how  smart 

it  can  be. 

But  the  author,  Noah,  he  kinda  dis  argues  against  this  and  says  that  if  you  look  at  human  intelligence, 

you  know,  we  don't  have  humans  who  have  an  IQ  of  a  thousand. 

Well,  most  like,  the  chance  for  that  is  so  small  that  it  probably  won't  be  there. 

And,  you  know,  and  the  scale  for  IQ  is  also  it  has  an  end  to  it. 

Maybe  you  reach  that  end  and  you  might  be  a  little  bit  smarter  than  the  the  upper  bound  of  that  scale, 

but  it  eventually  you  you  won't  have  an  IQ  of  three  hundred. 

Right?  You  know,  so  so  human  intelligence  already  is  not  linear  and  also  is  is  bounded. 

There's  an  upper  boundary. 

And  the  the  nor  the  author  here,  he  argues  that  the  same  principle  holds  also  for  artificial  intelligence. 

And  the  the  reason  for  this  is  that  the  that  how  intelligence  becomes  useful  is  not  that  the  more,  the 

better,  but  rather,  the  better  the  output  and  the  efficiency,  the  better. 

Right?  So  if  you,  yeah,  have  better  output,  but  you  have  to  do  a  billion  trillion  calculations  that  take 

you  a  hundred  thousand  years,  that  is  not  useful  intelligence,  you  know,  unless  you  watched  the  oh,  you 

read  The  Hitchhiker's  Guide  to  the  Galaxy,  you  know,  where  that  computer  It's  just  gonna  bring  Yeah. 

Right?  Where  the  computer  thought  Forty  two. 

Exactly. 

The  number's  forty  Is  it  useful?  Is  it  useful  though?  Like,  the  answer,  maybe  not. 

So  argument  here  of  Nor  is  basically  that  human  intelligence,  if  you  look  at  it,  it  is  rather  specialized 

in  certain  areas,  and  we,  humans,  are  really  good  on  these  areas  of  of  kind  of  problem  solving. 

But  but  we  have  an  upper  bound,  you  know. 

So  at  one  point,  like,  we're  not  more  intelligent  because  that  doesn't  give  us  any  more  you  know,  we 

would  need  to  use  more  brain  capacity  and  and  energy  to  to  go  there. 

And  we  also,  you  know,  physically  restricted. 

Like,  we  can't  have  a  head  that  is  one  meter  square,  for  example. 

So  if  you  look  at  human  intelligence  already,  we  see  that  it  is  rather  bounded  and  it  is  has  an  optimal 

peak  at  or  like  an  optimal,  yeah,  peak  at  one  point  after  which  you  it  drops  off  inefficiency. 

And  the  argument  here  is  that  AI  will  probably  do  something  similar  where  it  becomes  better  until  it 

reaches  a  certain  peak,  and  then  there's  a  drop  off  of,  you  know,  efficiency,  but  also  the  output,  the 

result,  because  it  just  starts  overthinking  the  result,  although  it's  correct. 

And  then  it  might  have  an  incorrect  result. 

Right?  So  yeah. 

And  and  the  the  last  thing  here  is  that  the  real  intelligence  as  we  see  it  rather  comes  from  connecting 

the  dots  of  different  areas  and  different  problems  than  brute  force  calculations  of,  for  example,  math 

problems. 

Right?  I  mean,  even  math  problems  are  not  a  calculation. 

They're  rather,  hey. 

Let's  try  this  approach,  and  then  we  can  add  that  mathematical  trick  to  it. 

And  then  we  can  add  this  approach,  and  that  kinda  is  like  a  zigzag  way  of  getting  from  point  a,  your 

starting  point,  to  the  solution  in  the  end. 

So  it's  not  a  straight  line  where  more  power,  more  brute  force  will  get  you  there  faster. 

It's  definitely  more  like  a,  hey. 

We  need  to  add  tricks  and  and  whatnot. 

So  yeah. 

Right. 

And  I  think  one  of  the  things  that  we've  seen  with  AI  is  that  there  are  problems  in  some  domains  that 

are  unsolved  hard  problems  that  in  similar  domains  they  have  solutions  for. 

Yeah. 

But  because  those  domains  are  not  closely  related,  it's  hard  for  that  information  to  kinda  flow  between 

Exactly. 

Yeah. 

And  that's  why,  like,  cross  functional  teams  are  always  a  big  thing  because  you  you  wanna  cross  pollinate 

some  of  those  ideas. 

Yeah. 

It  But  AI  has  been  able  to  do  this  as  well. 

Exact  yeah. 

If  you  think  about  very  specific  AI  models  that  can  spot  cancer  in  MRI  scans  or,  you  know,  radios  I  don't 

know  what  it's  called. 

Yeah. 

Radios  scans  in  your  body. 

Right?  They  they  look  at  the  scan,  and  they  can  spot  cancer  cells  in  it. 

Like,  even  I  have  a  friend  who  does  a  PhD  in  the  Netherlands,  and  the  the  model  they  use  or  there's  a 

model  that  can  that  they  trained  to  spot  dementia,  like  the  onset  symptoms  of  dementia  in  MRI  scans. 

That  is  a  model  that  has  good  accuracy,  but  only  on  one  single  scanner  in  one  single  hospital. 

Because  if  they  take  that  model  to  another  scanner  in  the  same  country  fifty  kilometers  away,  that  MRI 

scanner  will  have  its  own  characteristics,  its  own  biases,  its  own  inaccuracies  in  the  image  that  it 

gives  that  the  model  loses  a  lot  of  of  correctness,  of  validity. 

So  her  job,  her  entire  PhD  is  focused  on  finding  the  parameters  that  differ  between  MRI  scanners  and 

then  correcting  the  image  in  such  a  way  that  it's  normalized  for  the  model  to  then  do  the  inference  on. 

Right?  That  is  just  one  tiny  problem  in,  you  know,  one  country. 

That's  cool. 

Yeah. 

But  that  shows  you  how  Small  one. 

It's  it's  small. 

But  yeah. 

I  mean,  that's  the  thing. 

If  I  if  I  get  scanned  here  in  Leiden  and  I  have  an  MRI  scan,  I,  you  know,  then  go  to  Groningen,  which 

is  in  the  north  of  the  country,  like,  that  MRI  scan  is  gonna  have  a  different  I  can't  use  the  the  two 

and  compare  the  two,  you  know,  because  the  scan  is  different. 

Funny  is  that,  like,  to  us,  looking  at  them  Yeah. 

They're  the  same. 

Right?  But  the  data  that's  encoded  underneath  is  just  so  slightly  different  that  it  Exactly. 

So  so  that's  why,  you  know,  this  this  blog  post  by  Nora,  it  it  gives  you  a  think,  like  a  good  just  a 

couple  of  points  to  think  about  in  terms  of  does  more  intelligence  help  us,  or  do  we  rather  need,  you 

know,  more  specific  and  then  cross  functional,  cross  area  intelligence?  Yeah. 

So  have  a  read  and  and  tell  us  what  you  think  about  it. 

Right. 

Alright. 

And  last  up  here,  we'll  keep  this  short  because  we're  already  at  an  hour. 

But  so  the  GCC,  the  new  c  compiler. 

Is  that  right?  The  new  g  n  u  c  compiler. 

I  think  that's  on  all  the  Linux  c  compiler. 

All  the  Linux  distributions. 

Recently  announced  that  they  will  decline  any  significant  con  contributions  made  with  AI  or  LLMs  with 

the  exception  of  test  cases. 

And  I  think  I  mean,  this  is  it's  not  really  news  for  us  on  this  elixir  focused  podcast  to  discuss  GCC, 

but  this  is  something  that  I  think  we're  starting  to  see  industry  wide  is  AI  use  policies,  um,  and  this 

is  just  a  big  project  that  that  uses  this. 

What  I  thought  was  interesting  specifically  about  GCC  is  the  language  that  they  used  saying  that  they 

would  decline  legally  significant  Yeah. 

Code. 

Legally  significant. 

And  that  it  was  the  legally  significant  code  that  was  written  by  LLMs  in,  I  guess,  the  compiler  itself 

or  but  it  also  excluded  any  legally  significant  code  written  by  LLMs  for  test  cases. 

So  the  the  language  there  is  interesting,  and  I'm  wondering  if  they  have  concerns  about  IP  ownership 

and  because,  I  mean  Yeah. 

These  these  these  these  big  projects  have  really  strict  adherence  to  licenses. 

Right?  Yeah. 

It  is  interesting  because  the  same  argument  was  made  by  CodeBerg  when  they  said  that  they  don't  wanna 

host  LLM  generated  repositories  because  of  the  legal  implications  of  it. 

And  I'm  curious  to  understand  and  that  that's  maybe  discussion  that  hasn't  really  surfaced  that  much 

yet  in  the  community. 

But  we  are  what  is  the  copyright  question  about  LLM  generated  code  where  Right. 

The  entire  function  that  it  might  generate  or  the  entire  test  case  it  might  generate  is  literally  taken 

one  to  one  from  another  project,  another  repo  that  has  a  license  that  forbids  the  copy  of  that,  for  example. 

You  know?  And  then,  yeah,  that  is  something  it's  kinda  like  what's  it  called?  When  you  write  your  your 

PhD  thesis  and  then  you  take  parts  of  other  Plagiarism. 

Yeah. 

Plagiarism. 

Plagiarism. 

Yeah. 

Where,  yeah,  out  of  a  sudden,  sentences  and  paragraphs  you  that  you  copy  paste  it  from  other  theses  or 

other  articles  into  your  thesis,  you  know,  they  are  actually  people  who  scan  the  thesis  and  compare  them 

to  others  just  to  spot  these  little  sentences  and  paragraphs  between  the  two  documents. 

And  I'm  curious,  maybe  this  will  also  start  to  happen  if  there  is  a  big  law  law  case  against,  you  know, 

one  of  the  big  labs  that  says  you  generated  copyrighted  code  or  you  basically  not  generated. 

You  just  copied  copyrighted  code  into  this  project  that  you  took  one  to  one  from  this  other  project. 

You  know?  And  if  if  there's  like,  if  lawyers  can  make  money  with  it,  I  think  this  will  become  a  new  industry. 

You  know?  Maybe  so. 

And  it  it  and  this  kinda  goes  back  to  what  we  talked  about  last  time  is  who  is  to  blame  here?  I  would 

say  that  the  operator  is  the  one  that  holds  the  legal  implication  because  how  do  you  hold  Claude  accountable? 

How  do  you  hold  Yeah. 

Codex  accountable?  You  can't. 

Right?  Just  because  you  although  Codex  or  Claude  or  whoever  whatever  LLM  of  choice  put  that  code  in  your 

project,  you're  the  one  that  merged  the  PR  probably. 

Yeah. 

You  should  have  done  the  due  diligence. 

Right?  But  I  mean,  would  I  don't  know. 

Yeah. 

But  would  you  do  the  due  diligence  on  every  single  line  of  code  that  the  LLM  generates?  I  mean,  you  wouldn't. 

Right?  Right. 

So  then  can't  yeah. 

I  don't  think  they  will  go  after  the  clots  and  the  the  op  the  codexes  of  the  world. 

They  will  go  after  the  individual  small,  you  know,  software  engineers,  especially  then  people  who  put 

their  code  public  again  because  then  they  can  easily  scan  it  and  compare  it. 

And  then,  yeah,  big  projects  like  the  GCC  and  CodeBrick,  they  have  potentially  a  legal  issue  there  where 

a  lawyer  could  come  and  say,  hey,  you  host  code  that  was  one  to  one  copied  from  this  other  project,  you 

know,  take  it  down  or,  you  know,  pay  a  fine,  for  example. 

So  Right. 

Interesting. 

Let's  see  where  this  goes. 

Problem. 

I'm  curious  if  there's  any  projects  in  the  Alexa  community  that  have  already  implemented  LLM  AI  usage 

guidelines,  LLM,  these  types  of  things  similar  in  a  similar  vein. 

I  do  think  that,  of  course,  everyone  knows  that  that,  like,  drive  by,  sloppy  PRs  are  are  a  big  problem 

right  now. 

Maintainers  don't  have  bandwidth  to  review  walls  of  LLM  generated  text,  don't  have  bandwidth  to  review 

sloppy  LLM  code  from  people  that  aren't  invested  and  committed  to  the  project  that  they're  contributing 

to. 

No. 

So  that's  a  problem,  but  I  wonder  if  people  have  started  to  address  that  in  in  our  audience. 

What  do  they  think?  It  yep. 

It  it  definitely  has  some  potential  to  become  a  problem  in  the  industry,  you  know. 

Because  even  today,  if  you  copy  code  from  was  it  like  an  Apache  license  software?  Mhmm. 

You  need  to  put  the  copyright  notice  in  the  code  you  copy. 

And,  you  know,  then  you  have  commercial  limitations  sometimes. 

And  you  also  have  you  need  to  contribute  back  to  the  upstream  repo  requirements. 

Right?  Where,  like,  if  you  change  the  code  in  any  way  or  you  improve  it,  you  need  to  upstream  the  the 

the  fix  back  to  the  original  repo. 

So  Right. 

Yeah. 

Let's  see  what  the  lawyers  decide. 

I  mean,  this  side  of  the  pawns,  maybe  we  have  fewer  problems,  but,  you  know,  like,  uh,  America  Inc. 

With  all  the  lawyers,  they  they  might  have  another  problem  there  or  a  bigger  problem. 

Well,  we'll  wait  and  see. 

They'll  still  have  to  settle  before  we  make  any  final  judgment  on  that. 

Exactly. 

Alright. 

And  with  that,  we  are  at,  well,  more  than  time. 

This  has  been  a  fun  hour,  Peter. 

It  has  been. 

Yeah. 

Thank  you  very  much,  Gus,  for  being  with  me  here. 

Thank  you,  listener,  for  sticking  around  until  the  end. 

We  will  take,  well,  a  break  that  we  always  take  next  week,  and  then  the  week  after,  we  will  be  back  with, 

yeah,  another  another  episode  of  Macro  Mayhem. 

If  you  have  anything  you  would  like  us  to  feature  on  the  show,  please  tag  us  on  Blue  Sky  or  LinkedIn 

or  Elixir  Forum,  and,  you  know,  we  will  we  will  most  likely  put  it  on. 

We  always  need  to  plan  for  time  obviously,  but,  know,  we  do  our  best. 

So  any  last  words,  Gus?  Yeah. 

Check  out  our  blue  sky. 

I  think  we  have  auto  post  notifications  now. 

So  when  when  the  recording  is  live,  you  can  get  it  right  away  in  your  feed. 

And  Thank  you. 

We  haven't  really  decided  on  a  release  schedule,  have  we?  Last  time  was  on  a  Monday. 

Now  it's  a  Friday. 

Yeah. 

So  that's  part  of  the  mayhem. 

Yeah. 

You  just  It's  mayhem. 

Just  gotta  accept  it. 

Exactly. 

It'll  be  out  when  it's  out. 

Yeah. 

Yeah. 

We  tried  for  every  two  weeks,  but,  you  know,  like,  today,  we  had  to  do  it  a  little  bit  earlier  because 

Gus  is  away  next  week,  but  around  every  two  weeks. 

Yeah. 

So  subscribe  to  on  your  favorite  podcast  show,  uh,  podcast  app  or  YouTube  and,  uh,  or  our  Blue  Sky  account 

or  the  website,  micro  mayhem  dot  com. 

No. 

Sorry. 

Macro  mayhem  dot  f  m. 

Nope. 

Dot  f  m. 

Dot  f  m. 

We're  one  of  those  podcast  extensions. 

Exactly. 

And,  yeah,  you  will  be  notified  when  the  next  episode  airs. 

And  until  then,  thank  you  very  much,  and  have  a  good  day. 

Bye  bye.