Techlist.io - Korean Tech Blog Curator

stripe2 min readCurated summary

Giving agents the ability to pay

Agents are increasingly capable, but making purchases still requires access to today’s payment systems. Stripe is addressing this with Link’s wallet for agents, which lets users authorize purchases without exposing raw payment credentials. The system uses one-time cards or Shared Payment Tokens (SPTs), with users reviewing each request before approval. ## Link’s Wallet for Agents - Consumers connect an agent to their Link wallet through OAuth. - Agents can request: - One-time-use virtual cards - Shared Payment Tokens backed by cards or bank accounts in Link - Credentials can be restricted by amount, currency, and merchant. - Users approve requests on the web or through Link’s iOS and Android apps. - Users can track spending and manage connected agents in Link. - Stablecoins, agentic tokens, and additional payment methods are planned. ## Approval and Spending Controls - Each spend request currently requires explicit user review. - Link provides transaction context so users can understand what they are approving. - Future controls will support spending limits and allow agents to act without approval in predefined situations. - Agents never receive users’ underlying payment credentials. ## Stripe Issuing for Agents - Link’s wallet is built on Stripe Issuing infrastructure. - Businesses can use Issuing APIs to create customized agent wallets and card experiences. - Developers can control: - Onboarding and fund flows - Card-level permissions - Transaction authorization and fraud checks - Real-time and historical spending visibility - The infrastructure includes virtual cards, fund storage, spending controls, transaction monitoring, and fraud prevention tools. ## Potential Use Cases - Developers can automate business purchases and recurring spend. - Fintech companies can issue cards for real-time expense management and reconciliation. - Vertical SaaS platforms can let SMB agents make purchases under the platform’s brand. - Marketplaces can enable supplier payments, logistics, and fulfillment purchases through agent-issued cards. Stripe’s offering gives agents a practical way to transact through existing payment networks while preserving user oversight and credential security. Developers can use Link for a ready-made wallet or Stripe Issuing to build customized agentic payment workflows.

Read original(opens in new tab)
google2 min readCurated summary

Four ways Google Research scientists have been using Empirical Research Assistance

Empirical Research Assistance (ERA) is being used by Google researchers to tackle practical scientific problems rather than only benchmark exercises. Early applications span public-health forecasting, cosmology, and climate monitoring, showing that AI can improve prediction, solve difficult mathematical problems, and extract new value from existing data. The results suggest ERA could make advanced computational research more accessible while producing interpretable, scientifically grounded models. ## Public Health Forecasting - Google expanded ERA-based hospitalization forecasts from COVID-19 to influenza and RSV. - The team submits weekly forecasts for every U.S. state, covering horizons of up to four weeks. - Google forecasts have performed at or near the top of public CDC flu and COVID-19 leaderboards, with similarly strong internal results for RSV. - Forecast accuracy is evaluated using the Weighted Interval Score on log-transformed hospitalization data. - This approach could broaden access to epidemiological modeling and support forecasting for more diseases and regions. ## Cosmology: Cosmic Strings - Cosmic strings are theoretical spacetime defects that may emit gravitational radiation. - Calculating their radiation spectrum is difficult because the governing equations contain singularities. - Earlier work found only a partial solution for a square loop with an angle of 90 degrees. - By combining ERA with Gemini Deep Think, researchers derived six general solutions and a concise formula for the asymptotic limit. - The result demonstrates how AI systems can help explore advanced mathematical techniques and address previously unsolved cosmological problems. ## Climate Monitoring with Weather Satellites - Existing CO₂ satellites provide highly precise but infrequent and geographically limited measurements. - Geostationary satellites such as GOES East scan large areas every 10 minutes, but were not designed to measure CO₂. - Researchers used ERA to create a physics-guided neural network that combines: - 16 GOES East wavelength bands - Lower-troposphere meteorology - Solar angles - Time of year - Trained using sparse OCO-2 and OCO-3 observations, the model estimated column-averaged CO₂ continuously across the satellite’s coverage area. - Comparisons with independent satellite and ground-based observations showed that it captured real CO₂ variation. - The work illustrates how AI can repurpose existing instruments and improve the value of expensive scientific datasets. ERA’s early applications indicate that AI-assisted empirical software can support accurate forecasting, novel mathematical discovery, and higher-resolution environmental monitoring. Its greatest potential may lie in combining domain expertise with existing data and infrastructure to solve problems that would otherwise require substantial time and specialized resources.

Read original(opens in new tab)
figma2 min readCurated summary

How to Design Agentic Tools for Work | Figma Blog

Gemini Enterprise is designed to make complex, multi-agent business workflows feel simple without hiding AI’s role. Its core principle is to keep users focused on goals while making intervention, accountability, and data context visible. The result is an agentic system that supports not only individual productivity but shared team intelligence. ## A Familiar Brand with Business-Specific Capabilities - Gemini Enterprise shares Gemini’s visual language, including the sparkle icon, gradients, rounded shapes, and motion. - Its enterprise experience emphasizes integrations with tools such as Google Workspace, Jira, and Notion. - Connectors are made prominent in the prompt experience so agents can access the business context needed to produce useful results. ## Moving Beyond Chat with the AI Inbox - Enterprise work often involves multiple tools, data sources, deadlines, and agents working simultaneously. - The AI Inbox provides a visual overview of: - Tasks agents are currently handling - Completed work - Items requiring human intervention - Deliverables awaiting review - This dashboard is intended to feel more like a team status check-in than a sequence of chat messages. ## Collaborative Projects as Shared Workspaces - Gemini Enterprise replaces isolated chat threads with persistent, shared project spaces. - AI participates as a visible team member by: - Performing tasks - Summarizing discussions - Finding project files - Answering questions about shared material - Requests are attributed to individual team members, improving accountability and helping others understand the context behind an agent’s actions. - Shared spaces reduce information silos by allowing teammates to discover and use one another’s uploaded materials. - The assistant becomes a single source of truth and a “team intelligence amplifier,” rather than merely a personal productivity tool. ## Multiple Modes of Team Interaction - Teams can communicate with AI in group chats within Collaborative Projects. - In Canvas Mode, the assistant can generate and edit documents. - These modes allow AI to remain embedded in ongoing team workflows instead of being limited to isolated prompts. Gemini Enterprise’s design recommendation is to combine powerful orchestration with clear visibility and human control. Agents should work proactively, but their actions, sources, status, and opportunities for intervention must remain understandable to the people responsible for the outcome.

Read original(opens in new tab)
gitlab2 min readCurated summary

Teaching software development the easy way using GitLab

GitLab for Education can turn the administrative work of teaching software development into a scalable, professional workflow. University of Washington lecturer Stephen G. Dame uses GitLab groups, controlled permissions, merge requests, and inline comments to distribute materials, protect solutions, and provide contextual feedback. The approach helps students build real-world version-control and code-review habits while reducing instructor overhead. ## Building a Course Structure with Groups - Dame organizes the university in a root group such as `UWTeaching`, with one subgroup per course, such as `css430`. - Course subgroups contain: - Private lecture materials and code repositories - Student subgroups - Grader subgroups - Permissions inherit through the hierarchy, allowing instructors to control access centrally. - Students receive Reporter access with an expiration date tied to the academic quarter. - They can clone and pull assignment repositories but cannot push to instructor-controlled repositories. - Students use SSH keys across local machines, cloud shells, and virtual machines, then copy code into private repositories for their own version history. ## Automating Enrollment for Large Classes - Manually creating student accounts and permissions becomes impractical for large cohorts. - GitLab’s REST API can automate: - Creating personal subgroups for students - Looking up GitLab users - Assigning Reporter permissions - Setting membership expiration dates - GitLab also provides an open source class-management project with additional automation tools. ## Feedback Through Merge Requests - Students submit assignments by opening merge requests in their repositories. - Instructors immediately see a complete diff of the student’s work. - Comments can be attached directly to individual lines of code. - Inline feedback lets instructors explain both what is wrong and why, while directing students toward the next step. - Because feedback appears beside the relevant code, it is more actionable than comments on a separate document. ## Starting with GitLab for Education - The initial setup requires planning, but the workflow becomes largely self-sustaining once established. - GitLab for Education provides qualifying institutions with GitLab Ultimate features, including expanded storage, compute minutes, and merge-request capabilities. - Instructors are advised to begin with one course group, one assignment template, and a basic pipeline before expanding. A simple GitLab structure can make course administration more efficient while giving students practical experience with the collaborative development tools used in industry.

Read original(opens in new tab)
discord3 min readCurated summary

You’ve Got (Too Much) Mail: Behind the Scenes of the 3/25/26 Voice Outage

Discord’s March 25, 2026 voice outage began when a Kubernetes configuration change abruptly terminated 17% of session processes. The resulting reconnection storm propagated through Discord’s realtime systems and overloaded voice-routing infrastructure, preventing many users from starting or joining calls. The incident exposed how failures in one distributed subsystem can create cascading load several services away. ## The Infrastructure Background - Discord is migrating stateful Elixir services to Kubernetes. - Each host runs thousands of in-memory processes for guilds, presence, messaging, and calls. - Deployments normally wait for a server’s entity count to reach zero before shutting it down, allowing processes to hand off their state safely. - The sessions service maintains one process for every connected device and carries websocket traffic, messages, presence updates, and other realtime events. - To reduce weekend CPU utilization, Discord planned to increase pod CPU and memory while proportionally reducing the number of pods. ## The Session Loss - The resource change was deployed to the first availability zone at 12:13 PDT. - Kubernetes terminated half of that zone’s pods because of the reduced replica count. - A safety check delayed process handoffs until other events completed, but the Kubernetes termination grace period expired first. - Because the service operated across three balanced zones, approximately 17% of Discord’s sessions stopped without a graceful handoff. - The outage lasted from 12:13 to 15:30 PDT, with users commonly seeing “Awaiting Endpoint.” ## How Elixir Monitoring Amplified the Failure - Discord relies heavily on Elixir `GenServer` processes, which process one mailbox message at a time. - Process monitors notify dependent processes whenever a monitored process exits. - The sudden loss of sessions therefore generated a large number of `{:DOWN, …}` notifications throughout the realtime infrastructure. - Guild and other processes stopped attempting to deliver updates to disconnected users, while the gateway began driving those users to reconnect. ## Reconnecting Users - The gateway handles websocket ingress and egress, creating sessions and maintaining client connections. - Session disconnections are normally expected and recoverable, whether caused by hardware, network problems, software bugs, or temporary connectivity loss. - When a session disappears, the gateway immediately instructs the client to reconnect. - It optimistically tries to resume the session through a gateway instance in the same zone, but the mass failure created a much larger reconnection surge than the system was designed to absorb. The incident demonstrates that reducing pod count can be dangerous in stateful distributed systems: an apparently routine capacity adjustment can cause abrupt process loss, trigger widespread retries, and overload unrelated downstream services. Changes to stateful workloads should be evaluated not only for steady-state resource usage but also for graceful shutdown behavior and synchronized failure scenarios.

Read original(opens in new tab)
gitlab2 min readCurated summary

GitLab Patch Release: 18.11.2, 18.10.5 | GitLab Docs

GitLab released patch versions 18.11.2 and 18.10.5 on April 29, 2026, for Community and Enterprise Editions. The releases address an observability gap affecting disaster recovery RTO/RPO commitments for GitLab Dedicated and fix several regressions and bugs. No security fixes are included. ## Changes in GitLab 18.11.2 - Reverts the `ia-refactor-role-permission-enablement` merge. - Adds Code Suggestions to DAP-supported features for self-hosted models. - Preserves DAP code review access for Duo Core users. - Clears persisted filters when loading the `/work_items` page. - Adds a GraphQL mutation for retrying failed reassignment operations. - Resolves Sidekiq spikes when users are banned. - Fixes MCP OAuth discovery for installations using relative URLs. - Adds the `*_oldest_unsynced_time` metric. - Includes additional changes related to disaster recovery observability. ## Changes in GitLab 18.10.5 - Adds Code Suggestions support for self-hosted models through DAP. - Updates the Duo CLI version used for remote flows. - Skips three migrations that reference dropped tables. - Preserves DAP code review access for Duo Core users. - Resolves Sidekiq spikes caused when users are banned. - Fixes missing `model_definitions` in self-hosted feature settings. - Prevents `CreateOrUpdateDefaultTrackedContextWorker` from running on Geo secondaries. - Adds the `*_oldest_unsynced_time` metric. ## Upgrade and migration impact - **Single-node installations:** Expect downtime because migrations must finish before GitLab starts. - **Multi-node installations:** Zero-downtime procedures can allow upgrades without downtime. - **Regular migrations:** Included in version 18.10.5. - **Post-deploy migrations:** Included in both 18.11.2 and 18.10.5. Administrators should follow GitLab’s standard upgrade guidance for single-node systems and zero-downtime procedures for multi-node deployments before updating.

Read original(opens in new tab)
aws3 min readCurated summary

Top announcements of the What’s Next with AWS, 2026 | Amazon Web Services

The 2026 “What’s Next with AWS” event focused on how AI agents are reshaping business operations. Major announcements included Amazon Quick, an AI work assistant; four specialized Amazon Connect solutions; and an expanded AWS–OpenAI partnership bringing OpenAI models and Codex to Amazon Bedrock. Together, these offerings emphasize integrated agents that can connect to existing systems, make decisions, and execute tasks within enterprise-controlled infrastructure. ## Amazon Quick Becomes a Broader AI Work Assistant - Amazon Quick connects to workplace information, learns user preferences, and takes action on users’ behalf. - A new desktop app, currently in preview, can access local files, calendars, and communications without requiring a browser. - Free and Plus plans are available without an AWS account. Users can register with a personal email or Google, Apple, GitHub, or Amazon credentials. - Quick can generate documents, presentations, infographics, and images directly within chat. - New native integrations include Google Workspace, Zoom, Airtable, Dropbox, and Microsoft Teams. ## Amazon Connect Expands into Four Agentic AI Products AWS is repositioning Amazon Connect as a portfolio of solutions for specific business workflows: - **Amazon Connect Decisions:** A supply-chain planning and intelligence platform using AI teammates, Amazon’s operational expertise, and more than 25 specialized tools to support proactive planning. - **Amazon Connect Talent:** A hiring solution in preview that provides AI-led interviews, science-backed assessments, and standardized evaluations for large-scale recruiting. - **Amazon Connect Customer:** The renamed customer-experience product, supporting voice, chat, and digital channels. New configuration tools aim to let organizations deploy conversational AI in weeks rather than months. - **Amazon Connect Health:** Automates patient verification, appointments, patient insights, ambient documentation, and medical coding to improve access to care and reduce administrative workloads. ## AWS and OpenAI Expand Their Partnership The companies announced several limited-preview offerings that bring OpenAI capabilities into AWS environments: - **OpenAI models on Amazon Bedrock:** Models including GPT-5.5 and GPT-5.4 will be accessible through existing Bedrock APIs, with AWS security, governance, and cost controls. - **Codex on Amazon Bedrock:** Organizations can run OpenAI’s coding agent using AWS credentials and infrastructure, with usage counting toward AWS cloud commitments. Initial access includes the Codex CLI, desktop app, and Visual Studio Code extension. - **Bedrock Managed Agents powered by OpenAI:** This service combines OpenAI models with AWS-managed infrastructure and the OpenAI harness for building production-ready agents capable of reasoning through long-running tasks. AWS’s announcements point toward a future in which AI agents are embedded directly into workplace tools, operational systems, customer-service platforms, and cloud development environments. Organizations looking to adopt these capabilities should evaluate the available previews, integrations, governance controls, and workflow fit before moving to production.

Read original(opens in new tab)
github1 min readCurated summary

GitHub for Beginners: Getting started with Markdown

Kedasha is a GitHub Developer Advocate who shares her software development experience with the broader developer community. She is passionate about helping others learn about the technology industry and can be found online as **@itsthatladydev**. ### Professional Role - Works as a Developer Advocate at GitHub. - Shares lessons and experiences with developers. ### Community and Education - Enjoys helping others learn about technology and the tech industry. - Uses her experience as a software developer to support the wider community. Kedasha’s work centers on developer education, community engagement, and sharing practical industry knowledge.

Read original(opens in new tab)
github1 min readCurated summary

Securing the git push pipeline: Responding to a critical remote code execution vulnerability

Alexis Wales is GitHub’s Chief Information Security Officer, responsible for protecting the platform, its products, and the open source community. She leads security experts supporting more than 150 million developers and draws on two decades of experience defending critical networks. Her work has reinforced the importance of public-private collaboration in addressing major technology security threats. ## Leadership at GitHub - Oversees GitHub’s security strategy and teams. - Focuses on safeguarding developers, products, the platform, and the broader open source ecosystem. - Supports secure software development and deployment for more than 150 million developers. ## Cybersecurity Experience - Has 20 years of experience protecting national and private-sector networks. - Previously held roles with the Department of Defense and CISA. - Developed a strong interest in cooperation between government and industry. ## Focus on Collaboration - Advocates public-private partnerships to address complex cybersecurity challenges. - Applies her experience to threats affecting the technology people rely on every day.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Shutdowns, power outages, and conflict: a review of Q1 2026 Internet disruptions

Q1 2026 saw a sharp increase in major Internet disruptions, especially government-directed shutdowns in Uganda, Iran, and the Republic of Congo. Power failures, military attacks, severe weather, cable damage, and technical problems also caused significant regional outages. The disruptions demonstrate how connectivity remains vulnerable to political decisions, conflict, infrastructure failures, and environmental events. ## Government-Directed Shutdowns ### Uganda’s Election Shutdown - Authorities ordered a nationwide shutdown ahead of the January 15 presidential election. - Public Internet access was suspended from January 13 through January 17, when partial service resumed after President Yoweri Museveni’s reelection was announced. - Traffic at the Uganda Internet Exchange Point fell from roughly 72 Gbps to 1 Gbps. - Full restoration was announced on January 26. - The shutdown was justified as a measure against misinformation, electoral fraud, and related risks. - It prompted lawsuits and criticism from digital rights groups, particularly because Uganda had also restricted connectivity during the 2021 election. ### Iran’s Prolonged Disruptions - Iran experienced two nationwide shutdowns during the quarter. - The first began January 8 and kept traffic near zero for much of the month, with only brief and limited restorations. - A sharp loss of announced IPv6 address space preceded the first traffic collapse, but IPv4 announcements remained relatively stable. This suggests filtering, rather than widespread route withdrawal, was the primary mechanism. - A second shutdown began February 28 as military strikes intensified. - Traffic fell below 1% of normal levels, while small amounts of Web and DNS traffic continued. - Continued IP announcements and limited connectivity support reports of aggressive filtering, including whitelist-based access and restricted “white SIM cards.” - Iran remained largely offline through the end of Q1, making the disruption one of the longest observed in recent years. ### Republic of Congo’s Election Disruption - Internet traffic dropped to near zero around March 15, during the country’s presidential election. - The outage lasted approximately 60 hours before service rapidly recovered on March 17. - Authorities did not provide an official explanation. - Similar election-related shutdowns had occurred in 2016 and 2021. ## Military Action and Infrastructure Damage ### Power-Related Outages in Ukraine - Russian attacks on energy infrastructure caused major connectivity declines in Dnipropetrovsk on January 7–8. - Regional traffic fell nearly 50% before recovering as electricity was restored. - A January 26 drone and missile attack on Kharkiv’s energy infrastructure caused another approximately 50% traffic reduction. - Connectivity gradually recovered on January 27. ### AWS Facilities in the Middle East - Drone strikes damaged Amazon Web Services facilities in the United Arab Emirates and Bahrain. - Two UAE facilities in the me-central-1 region were directly hit. - A Bahrain facility in the me-south-1 region was taken offline after nearby damage. - The incident illustrated that military conflict can affect not only consumer connectivity but also hyperscaler cloud infrastructure. ## Other Causes of Disruption - Cuba experienced three separate collapses of its national electrical grid, causing Internet outages. - Severe weather disrupted connectivity in Portugal. - Cable damage affected service in the Republic of Congo. - Verizon Wireless experienced a technical problem in the United States. - Brief, unexplained disruptions affected providers in Guinea and the United Kingdom. The quarter’s events show that Internet outages increasingly arise from a combination of intentional shutdowns, physical infrastructure damage, power instability, and conflict. Monitoring traffic, routing announcements, and regional infrastructure remains essential for distinguishing the causes and measuring the impact of these disruptions.

Read original(opens in new tab)
figma3 min readCurated summary

FigJam Is Now Your Coding Agent’s Whiteboard Too | Figma Blog

FigJam is being positioned as a shared whiteboard for coding agents and engineering teams. New MCP skills let agents generate architecture and ER diagrams, write to and read from FigJam, and turn research or project plans into collaborative visual boards. The workflow connects agent-generated planning, human review, and implementation, reducing architectural confusion as teams ship code faster. ## Turning Agent Output into Visual Plans - The author built on Figma’s existing `generate_diagram` MCP tool to support more complex architecture and ERD layouts. - The new `figma-use-figjam` MCP skill allows agents to read and write directly to FigJam boards. - Skills such as `generate-project-plan` can transform documentation, codebases, and conversations into visual project plans. - Diagrams can include: - Architecture and entity-relationship diagrams - Notes and annotations - Code blocks - Implementation context and technical decisions ## Step 1: Research, Plan, and Visualize - The coding agent gathers relevant documentation, codebase structure, existing patterns, and implementation constraints. - It evaluates possible solutions, researches tradeoffs, identifies affected services and files, and proposes stacked PRs and testing strategies. - Instead of leaving the plan in a dense Markdown document, the agent exports it to FigJam as an interactive architecture review. - Visualizing the options helps teams understand the system and identify the cleanest approach more quickly. ## Step 2: Collaborate Before Coding - Engineers share the FigJam board with teammates for asynchronous or live review. - Team members can comment on concrete design questions, such as: - Whether a tool should support multiple file types - Whether it should accept a `folderId` - Where newly created files should be stored - FigJam provides a collaborative format that preserves technical context for distributed teams. - Teams can review and refine agent-generated diagrams before implementation begins. ## Step 3: Feed Decisions Back to the Agent - After review, the author uses the `get_figjam` tool to retrieve the board’s diagrams, comments, and decisions. - The coding agent uses that context to update the implementation plan and begin coding. - Pull requests can link back to the FigJam board, preserving the architectural rationale alongside the code. - Because the design has already been reviewed, the resulting PR is easier to evaluate and merge. ## Broader Figma Integration - The workflow builds on `use_figma`, which lets agents create or edit designs directly on the Figma canvas using real components. - `create_new_file` allows agents to generate designs in new Figma files. - Together, these capabilities extend agent collaboration beyond code into design, architecture, planning, and technical communication. Teams adopting coding agents can use FigJam as a reviewable source of shared context: let agents generate the initial plan, have humans refine the architecture visually, then return the approved decisions to the agent for implementation.

Read original(opens in new tab)
gitlab3 min readCurated summary

How to build CI/CD observability at scale

CI/CD observability is essential for improving pipeline performance at enterprise scale, particularly in self-managed GitLab environments. The post presents a containerized solution built with `gitlab-ci-pipelines-exporter`, Prometheus, Grafana, and Node Exporter to turn pipeline and infrastructure data into actionable insights. Its conclusion is that centralized dashboards help teams identify bottlenecks, plan runner capacity, and measure delivery performance. ## Defining CI/CD Performance - Teams should first determine: - Which metrics matter, such as pipeline duration, job success rates, queue times, and runner utilization. - Who needs access, including developers, DevOps engineers, platform teams, and leadership. - Which decisions the data will support, such as infrastructure investment, bottleneck remediation, and capacity planning. ## Observability Architecture - The solution uses two exporters: - **Pipeline Exporter:** Collects pipeline duration, job status, and deployment metrics through the GitLab API. - **Node Exporter:** Collects host CPU, memory, and disk metrics for infrastructure correlation. - Prometheus gathers and stores the metrics. - Grafana provides real-time and historical dashboards. - Dashboards are provisioned automatically through Grafana’s file-based provisioning and can be filtered by project, branch, or time range. ## Grafana Dashboards - **Pipeline Overview:** Displays pipeline volume, success and failure rates, cancelled runs, and average duration trends. - **Job Performance:** Shows job-duration histograms, the ten slowest jobs, and failure heatmaps by project and stage. - **Runner & Infrastructure:** Correlates runner queue times with CPU, memory, and disk usage to support capacity planning. - **Deployment Frequency:** Tracks deployment counts and durations by environment, supporting DORA-style delivery analysis and detection of environment drift. ## Kubernetes Deployment - The recommended enterprise deployment runs each component as a separate workload in a dedicated `gitlab-observability` namespace. - A Kubernetes secret stores the GitLab personal access token, which requires the `read_api` scope. - The Pipeline Exporter runs as a Deployment with a service on port `8080`. - Node Exporter runs as a DaemonSet so each node can expose host metrics on port `9100`. - Prometheus and Grafana are deployed alongside the exporters and configured to scrape and visualize their metrics. - Kubernetes deployment supports existing cluster infrastructure, secrets managers, network policies, and scalable operations. ## Prerequisites - GitLab Self-Managed 18.1 or later. - Kubernetes for enterprise deployments, or Docker/Podman for smaller environments and proof-of-concept testing. - A GitLab personal access token with `read_api` permissions. - Secure secret-management practices, preferably using external secret operators in production. The practical recommendation is to begin with clearly defined performance questions, then deploy the exporter–Prometheus–Grafana stack in a controlled namespace. Combining pipeline data with host metrics provides the context needed to distinguish inefficient jobs from infrastructure capacity problems.

Read original(opens in new tab)
gitlab2 min readCurated summary

GitLab and Anthropic: Governed AI for enterprise development

GitLab is expanding its integration with Anthropic Claude to provide enterprise teams with more capable AI inside a governed software development platform. Claude supports GitLab Duo Agent Platform features such as code generation, review, agentic chat, and vulnerability resolution. The central argument is that organizations should not have to trade advanced AI capabilities for security, compliance, and auditability. ## Governed AI across the SDLC - Claude-generated changes follow GitLab’s existing merge request process, approval rules, security scans, and audit trails. - AI agents do not bypass controls; their actions remain attributable, reviewable, and subject to policy enforcement. - This governance becomes increasingly important as agents autonomously plan, code, test, secure, and deploy software. - GitLab positions built-in governance as a core architectural differentiator rather than an added feature. ## Flexible enterprise deployment - Claude is available in GitLab through: - Google Cloud Vertex AI - Amazon Bedrock - Organizations can use existing cloud contracts, governance frameworks, and data-residency arrangements. - GitLab’s availability in the Claude Marketplace lets customers purchase GitLab Credits and apply them toward Anthropic spending commitments. - These options simplify procurement and consolidate AI spending. ## Supporting an agentic development model - GitLab is selecting model partners based on reasoning ability, reliability, and safety. - The platform is designed to maintain visibility into what AI agents do, when they act, and how their changes are tracked. - As agents take on more complex engineering tasks, GitLab argues that strong models must be paired with equally strong governance. ## Implications for customers - Existing GitLab Duo users gain deeper Claude-powered assistance without changing their established governance processes. - Organizations evaluating AI development platforms can access advanced models while retaining enterprise control. - GitLab presents the integration as a way to accelerate development without compromising compliance or oversight. The practical recommendation is to evaluate AI platforms not only by model capability, but also by how well they integrate governance, auditability, cloud deployment options, and existing enterprise workflows.

Read original(opens in new tab)
aws3 min readCurated summary

AWS Weekly Roundup: Anthropic & Meta partnership, AWS Lambda S3 Files, Amazon Bedrock AgentCore CLI, and more (April 27, 2026) | Amazon Web Services

This week’s AWS news centers on deeper AI infrastructure partnerships and tools for building production-ready agents. AWS and Anthropic are expanding Claude’s integration with AWS hardware and Amazon Bedrock, while Meta is adopting Graviton for large-scale agentic AI workloads. New services for Lambda, EKS, Aurora, and Bedrock also emphasize simpler data access, hybrid networking, serverless scaling, and faster agent development. ## Anthropic and Meta Expand AWS AI Partnerships - Anthropic is training advanced foundation models on AWS Trainium and Graviton processors. - Anthropic and AWS’s Annapurna Labs are co-engineering at the silicon level to improve efficiency across the stack. - Claude Cowork is now available through Amazon Bedrock, allowing enterprise teams to collaborate with Claude while keeping data within AWS. - A unified Claude Platform on AWS is planned, offering a single experience for building, deploying, and scaling Claude applications. - Meta signed an agreement to deploy tens of millions of AWS Graviton cores for CPU-intensive agentic AI tasks, including reasoning, code generation, search, and orchestration. ## New Lambda and Kubernetes Infrastructure - AWS Lambda can mount Amazon S3 buckets as file systems using S3 Files. - Functions can perform standard file operations without downloading data first. - Built on Amazon EFS, S3 Files combines file-system access with S3’s scalability, durability, and cost model. - Multiple Lambda functions can share the same workspace, supporting AI agents that need persistent memory or shared state. - The Amazon EKS Hybrid Nodes gateway simplifies networking between cloud-based EKS resources and on-premises Kubernetes Pods. - It enables pod-to-pod traffic, control-plane webhook communication, and access to AWS services without making on-premises pod networks routable. - The gateway is available at no additional charge. ## Aurora Serverless and Bedrock Agent Development - Aurora Serverless now offers up to 30% better performance on platform version 4. - Its scaling algorithm better handles competing workloads, including busy APIs and bursty agentic AI applications. - The service continues to scale to zero during idle periods, with no additional charge for the improvements. - Amazon Bedrock AgentCore adds a managed harness in preview, allowing developers to define a model, system prompt, and tools without writing orchestration code. - Harnesses can later be exported as Strands-based code for greater control. - The AgentCore CLI supports governed, auditable deployments through AWS CDK, with Terraform support planned. - The CLI is available in 14 AWS Regions at no additional charge, and AgentCore skills support coding assistants. ## Cost Management, Operations, and Machine Learning - Granular cost attribution for Amazon Bedrock enables teams to track usage by project or organization and support detailed chargeback. - AWS DevOps Agent can work with the Salesforce MCP Server to investigate incidents, diagnose causes, and notify customers through Salesforce Service Cloud. - AWS microcredentials are now free through AWS Skill Builder in supported countries. - These hands-on assessments use simulated business scenarios and live AWS environments rather than traditional multiple-choice testing. - Amazon SageMaker AI can recommend optimized generative AI inference configurations, including instance types, containers, and inference parameters, helping reduce latency and deployment costs. ## Upcoming AWS Events - “What’s Next with AWS” is scheduled as a virtual event on April 28. - AWS Summits continue in May across cities including Singapore, Tel Aviv, Warsaw, Stockholm, Sydney, Hamburg, Seoul, Amsterdam, Bangkok, and Milan. AWS’s latest releases point toward a more integrated AI platform: specialized hardware for model execution, managed agent tooling, shared state through serverless storage, and stronger cost and operational controls. Builders should evaluate S3 Files and AgentCore for AI workflows, while teams running production inference can benefit from SageMaker recommendations and Bedrock’s improved cost attribution.

Read original(opens in new tab)
toss3 min readCurated summary

Why We Adopted Post-Quantum Cryptography a Decade Before Quantum Computers Arrive

Toss Payments’ biggest legacy-overhaul challenge was not the technology itself, but improving security without disrupting tens of thousands of merchants using decades-old integrations. Because payment systems depend on outdated client environments and small businesses with limited technical resources, security upgrades had to be gradual and carefully communicated. The effort ultimately led from modernizing transport security to adopting post-quantum cryptography in 2026. ## The Challenge of Changing a Legacy Payment Network - Toss Payments supports merchants integrated with its PG system for many years, sometimes decades. - Server-side clients are harder to update than browsers, which update automatically to support new standards. - Security changes such as upgrading TLS, removing weak ciphers, or changing encryption can affect every API call, payment window, and server connection. - Many merchants are small businesses without dedicated developers, making complex security requirements difficult to understand and implement. - As a result, security is a shared responsibility: Toss Payments can strengthen its systems, but legacy merchant environments may still leave connections partially exposed. ## Why Existing Encryption Is Becoming Unsafe - Modern HTTPS and payment systems commonly rely on public-key algorithms such as RSA and ECDSA. - These algorithms are considered secure because conventional computers cannot practically factor enormous numbers or solve elliptic-curve problems. - Quantum algorithms have been mathematically shown to solve these problems efficiently once sufficiently powerful quantum computers exist. - This would make current encryption systems vulnerable, undermining decades of digital-security assumptions. ## Q-Day and “Harvest Now, Decrypt Later” - “Q-Day” refers to the point when quantum computers can break today’s widely used encryption. - Attackers can already intercept and store encrypted payment communications that they cannot currently decrypt. - Once quantum computers become practical, the stored data could be decrypted in bulk. - Payment information is especially valuable because it can remain sensitive for years; data transmitted today could be exposed in the 2030s. - The threat therefore requires action before quantum computers are fully operational. ## A Four-Year Security Upgrade Toss Payments chose a phased approach rather than replacing its security stack all at once: - **2022:** Became the first payment gateway in Korea’s PG industry to implement HTTP/3. - **2022–2025:** Removed weak TLS cipher suites. - **2022–2025:** Completed the rollout of TLS 1.3. - **April 2026:** Implemented post-quantum cryptography (PQC). Each stage balanced stronger protection against the risk of disrupting merchant payments. The gradual rollout gave merchants time to update their systems while ensuring that security improvements continued instead of being postponed indefinitely. ## Starting with HTTP/3 - HTTP/3 is a newer web-transport protocol designed to improve speed and stability, especially on unreliable networks. - It requires TLS 1.3, meaning that adopting HTTP/3 also enforces the use of a modern security protocol. - Toss Payments began with HTTP/3 because it offered both performance improvements and a relatively direct path toward stronger encryption. The broader lesson is that legacy security cannot be improved through a single disruptive upgrade. A phased migration, combined with clear communication and preparation for post-quantum cryptography, allows payment providers to raise security standards while keeping existing merchants operational.

Read original(opens in new tab)