#cloud-development-environments
GPT-6 is here on Diploi! ✨️

We just added Astra, Sol and Luna, so you can build with all three from a single tab, no separate keys or logins to set up.

👉 diploi.com

#AI #devtools #GPT6
Diploi
Diploi is a platform that lets you build apps using cloud development environments and host them online with a single click, without configuring servers manually.
diploi.com
September 28, 2026 at 7:15 AM
Between HR using AI to auto-generate fake employee praise and video bots staring at screenshots of their own mistakes, enterprise software has officially become a self-contained fever dream.
Now I must review two full days of uninterrupted cloud agent commits
The 30-Second Rundown * **Headless content systems now integrate vector search directly, allowing teams to launch company knowledge tools without setting up separate database infrastructure.** — Reduces tech stack complexity and cuts enterprise vector database spend. * **Autonomous coding agents are moving into secure cloud environments that can run uninterrupted development loops for up to two full days.** — Enables complex software builds without locking up developer laptops or risking security. * **Video editing tools are shifting from manual timeline software to code-rendered web graphics powered by vision verification loops.** — Unlocks automated video post-production with built-in quality control. * **Enterprise platforms are using compressed instruction files to prune bloated prompt contexts down by over 80 percent.** — Lowers operational artificial intelligence expenses while reducing response latency. ## Guru Chatter ### Sandboxed Cloud Execution and Continuous Long-Horizon AI Agents **TL;DR:** Artificial intelligence tools are moving off personal laptops and into isolated cloud servers. This lets software programs run multi-day projects continuously without keeping a web browser or laptop open. AI platform architectures are shifting from synchronous turn-based chat endpoints to asynchronous, headless cloud sandboxes. Using hypervisor-level isolation (e.g., Linux micro-VMs) alongside Rust-based harnesses and security proxies like Sentinel, agents can execute long-horizon code and web actions without exposing raw user credentials to prompt injection attacks. Systems running models like Claude Opus 5.5 inside persistent CLI environments are now capable of executing continuous 24- to 48-hour build loops. **Market impact:** Fundamentally shifts compute demand from client-side hardware to serverless cloud orchestration nodes and secure enclave providers. Long-term portfolio positioning should favor zero-trust agent proxy infrastructure, confidential computing networks, and serverless background runtime platforms over client device hardware refresh cycles. **Sources:** Fireship · AI News & Strategy Daily | Nate B Jones · The AI Advantage * * * ### Programmatic Web Animation and Vision-Verified Video Post-Production **TL;DR:** Video creation tools are shifting from clicking around on traditional video software timelines to writing web code that creates graphics automatically. The artificial intelligence then looks at screen grabs of its own work to fix mistakes. Media generation workflows are abandoning traditional GUI timeline editing software (e.g., Adobe After Effects) in favor of programmatically generated HTML/CSS/JS animations (using toolsets like Hyperframe). Large language models render typography, spatial layouts, and motion overlays directly from structured text. To maintain visual quality, platforms implement agentic vision verification loops: agents render video frames, take screenshots, evaluate legibility and contrast against visual design rules, and iteratively refactor the code before final export. **Market impact:** Disrupts legacy desktop video editing platforms while increasing multimodal inference spend. Compute demands will shift heavily toward high-throughput vision API endpoints, fast frame-rendering environments, and headless web graphics execution engines. **Sources:** Nate Herk | AI Automation * * * ### Native Vector Retrieval in Headless CMS for Enterprise Knowledge Portals **TL;DR:** Content management systems are building smart search capabilities directly into their core databases. This makes it easy to create intelligent internal company wikis that answer questions accurately without extra database setups. Headless Content Management Systems (CMS) such as Sanity are natively integrating automated vector embeddings, dynamic hybrid search, and Model Context Protocol (MCP) integrations directly into the content store. This architectural shift eliminates the need for separate dedicated vector databases (e.g., Pinecone, Qdrant) in corporate Retrieval-Augmented Generation (RAG) applications, allowing modern Next.js documentation frameworks (like Fuma Docs) to query, stream, and attribute internal knowledge seamlessly. **Market impact:** Consolidates software enterprise infrastructure by folding vector storage directly into modern database engines. Lowers total cost of ownership for internal search portals and shifts enterprise software budgets toward API-first, unified content infrastructure rather than standalone vector database services. **Sources:** Dave Ebbelaar * * * ### Multi-Agent Workspace Collaboration and Parallel Model Routing **TL;DR:** Instead of using one artificial intelligence tool for everything, companies are assigning small teams of specialized software helpers to work inside team chat apps like Slack, sending only complex tasks to top-tier reasoning models. Enterprise systems are evolving from single-prompt assistants to multi-agent worker networks integrated into workspace messaging platforms like Slack. Tasks are broken down across tiered LLM architectures where lightweight models handle background processing, while top-tier reasoning models operate on complex problems. Human-in-the-loop (HITL) governance models ensure high-risk executions (such as pull request merges or public postings) require explicit manual sign-offs. **Market impact:** Optimizes enterprise operational expenditure by eliminating over-provisioning of expensive frontier reasoning models for simple routines. Drives investment toward intelligent meta-orchestrators, team chat integration layers, and automated API cost management utilities. **Sources:** Fireship · AI News & Strategy Daily | Nate B Jones * * * ### Instruction Compression and Modular Skill Repositories **TL;DR:** Developers are shrinking massive setup instructions down into small, modular guide files. This helps smart assistants follow rules better while saving money on background processing fees. System instructions and repository prompt guidelines often suffer from context bloat, leading to increased token latency, hallucinations, and high API billings. Tech teams are replacing massive static system prompts with modular Markdown skill files (e.g., `.claude/skills/` or `agents.md`). By auditing and distilling 10,000-word prompt setups into lean 1,200-word instruction files, systems retain governance limits while drastically reducing token consumption. **Market impact:** Shifts developer focus toward modular context engineering and automated instruction pruning. Software platforms that provide dynamic context optimization and token usage capping will capture enterprise market share by managing model costs. **Sources:** AI News & Strategy Daily | Nate B Jones · Nate Herk | AI Automation * * * ### Long-Context Financial Auditing and Automated Regulatory Analysis **TL;DR:** People and small businesses are using smart reading tools to scan through years of old bank statements, tax forms, and receipt emails to discover forgotten tax write-offs. The expanding context windows of frontier models (e.g., ChatGPT, Claude) are being applied to retrospective personal and small-business financial audits. By processing years of unstructured receipts, emails, and tax returns in a single context window, models cross-reference historical expense data against local tax regulations to identify omitted deductions and draft explicit tax amendment filings (such as IRS Form 1040-X). **Market impact:** Accelerates disintermediation in traditional tax preparation and personal finance software. Capital allocation shifts toward privacy-preserving local context caching, secure OAuth personal connector pipelines, and specialized regulatory compliance wrappers. **Sources:** AI News & Strategy Daily | Nate B Jones * * * ### Low-Code HR Asset Generation and Performative Enterprise Automation **TL;DR:** Human resource teams are using automated image generators and social posting bots to handle employee recognition activities at a very low cost. Enterprise non-technical units (such as HR and Internal Comms) are adopting low-code generative media models to create internal recognition banners, event collateral, and programmatic social media posts. This lowers administrative software licensing overhead while standardizing employee advocacy broadcasts via automated APIs. **Market impact:** Increases reliance on corporate employee advocacy software and lightweight image synthesis APIs. While administrative operating expenditures drop, software investments favor automated equity management and direct compensation platforms to offset developer attrition risks. **Sources:** Joshua Fluke ## Master Workflows Today's Top Pick ### Building an AI-Powered Enterprise Knowledge Base with Next.js, Sanity CMS, and OpenAI Intermediate1-2 hrs **Why it's worth it:** Eliminates separate vector database costs and creates a unified, search-ready internal company knowledge base with streaming answers. Deploys a secure documentation portal using Next.js and Fuma Docs, connected to Sanity CMS for headless content editing with auto-generated vector search. An embedded AI chat assistant queries this data in real time using OpenAI models and attributes sources back to specific team owners. Node.jsNext.jsFuma DocsSanity CMSOpenAI APICursor IDEModel Context Protocol (MCP)Git 1. Clone the knowledge base repository and install all Node environment packages. git clone https://github.com/daveebbelaar/company-knowledge-base.git cd company-knowledge-base npm install 2. Copy the local environment template file and configure your mandatory secret authentication password. cp .env.example .env.local 3. Start the Next.js local development server and verify the authentication view in your web browser. npm run dev 4. Configure your Sanity CMS environment keys in .env.local, then run setup and import script routines. NEXT_PUBLIC_SANITY_PROJECT_ID="your_project_id" SANITY_API_TOKEN="your_developer_token" CONTENT_SOURCE="sanity" npm run sanity setup npm run sanity import 5. Launch and deploy the Sanity Studio interface to manage knowledge schemas and enable Model Context Protocol endpoints. npm run studio npx sanity deploy 6. Add your OpenAI key to .env.local, launch the portal search modal using Cmd+K, and verify interactive streaming RAG query responses. OPENAI_API_KEY="sk-proj-YOUR_OPENAI_KEY" **Links:** https://sanity.io **Sources:** Dave Ebbelaar ### Programmatic Motion Graphics Pipeline with Vision Self-Correction Intermediate45-60 min **Why it's worth it:** Replaces manual graphic video editing by generating web-rendered animations and B-roll clips using automated visual quality check loops. Transcribes source audio, generates code-rendered web animations via Hyperframe inside Claude Code, pulls dynamic visual assets from specialized media tools, and verifies frame quality by taking screenshots and running automated vision correction cycles. Claude CodeClaude 3.5 SonnetHyperframeWhisperElevenLabs APIKling AIKey.ai 1. Transcribe source audio or raw video footage using Whisper to generate precise sync timestamps. whisper input_video.mp4 --model medium --output_format json 2. Clone the Hyperframe web graphics engine into your local development repository. git clone https://github.com/hyperframe/hyperframe.git 3. Launch Claude Code and connect Hyperframe to build dynamic HTML, CSS, and JavaScript motion graphic overlays. claude --prompt "Hook hyperframe into current project to render motion graphic titles with glassmorphism card styling." 4. Configure asset synthesis hooks to fetch B-roll visuals dynamically from Key.ai and Kling AI based on transcript context. # Prompt directive inside Claude Code: "When transcript mentions system architecture, trigger Key.ai API to generate server diagram, then animate via Kling AI." 5. Enable the agent visual verification mode to render preview frames, evaluate contrast and alignment via screenshots, and auto-correct rendering code before final video export. # Prompt directive inside Claude Code: "Take preview screenshots of rendered frame 120 and 240. Evaluate legibility against brand guidelines, fix alignment in CSS, and re-render." **Links:** https://github.com/hyperframe/hyperframe **Sources:** Nate Herk | AI Automation ### Sandboxed AI Agent Runtime with Security Proxy Isolation Advanced1-2 hrs **Why it's worth it:** Protects production enterprise credentials from prompt injection attacks while executing web-connected autonomous agent loops. Runs an autonomous agent loop inside an isolated Linux micro-VM using a custom Rust runtime harness. All network traffic passes through an egress proxy server that dynamically swaps out mock application tokens for valid credentials safely outside the agent's environment. Linux Micro-VMRustSentinel Gatekeeper ProxyMuse Spark 1.3 1. Provision an isolated Linux micro-virtual machine host running a low-latency hypervisor such as Firecracker. sudo systemctl start firecracker 2. Build and install the agent execution harness in the guest virtual environment using Rust. cargo build --release --bin hatch_harness 3. Inject dummy authentication tokens into the isolated agent session context. export AGENT_SESSION_TOKEN="mock_token_xyz123" 4. Configure firewall rules on the host to block raw outbound connections and route micro-VM web traffic through the Sentinel token-swapping proxy. sudo iptables -A FORWARD -i vm-tap0 -p tcp --dport 443 -j ACCEPT sudo iptables -t nat -A PREROUTING -i vm-tap0 -p tcp --dport 443 -j REDIRECT --to-ports 8080 **Sources:** Fireship ### Continuous Long-Horizon App Development via Claude Code CLI AdvancedOvernight (24-48 hrs) **Why it's worth it:** Executes uninterrupted, multi-day coding tasks to construct full-stack software applications without manual step-by-step guidance. Initializes the Claude Code terminal tool on a headless server or local system to execute long-running build tasks. The agent autonomously edits code, catches compilation errors, and verifies dependencies across uninterrupted 24- to 48-hour development cycles. Claude Code CLIClaude Opus 5.5Node.jsTerminal 1. Install the Claude Code CLI utility globally on your terminal system. npm install -g @anthropic-ai/claude-code 2. Define architectural specifications and feature constraints inside a project requirements file. mkdir my-project && cd my-project touch project_spec.md 3. Launch the continuous development loop with elevated skip permissions to enable headless autonomous file generation. claude --dangerously-skip-permissions --prompt "Read project_spec.md. Construct a fully functioning 3D interactive web simulation, handling all file creation and error fixes autonomously." 4. Monitor process execution logs on your headless server or terminal window as the application compiles over extended build cycles. tail -f ~/.claude/logs/current.log **Links:** https://docs.anthropic.com/en/docs/agents-and-tools/claude-code **Sources:** The AI Advantage ### Deploying Autonomous Multi-Agent Slack Workspaces with GitHub Integration Intermediate30-45 min **Why it's worth it:** Automates code drafting and technical research inside team chat channels with built-in human approval safeguards. Sets up specialized AI agents (Research, Coding, Marketing) inside target team Slack channels. When requests are raised, low-cost LLMs handle background processing, while coding agents open branches and pull requests using explicit human-in-the-loop review approvals. Hyper Agent WorkspacesSlack APIGitHub CLICost-Optimized LLMs 1. Create a workspace in Hyper Agent and authenticate the integration tokens for your primary Slack team channel. hyper-agent workspace init --slack-token xoxb-YOUR-SLACK-TOKEN 2. Define specialized agent roles and attach shared project memory repositories inside your workspace config. hyper-agent agent create --role "Coding Agent" --model "claude-3-5-sonnet" 3. Connect the Coding Agent to your GitHub codebase repository. gh auth login hyper-agent link repo owner/repository 4. Configure automated pull request generation triggered by team Slack feature requests, enforcing explicit human owner approval before merging. git checkout -b agent/feature-request git commit -am "feat: implemented requested feature" gh pr create --title "Agent PR: Requested Feature" --body "Automated PR generated by Hyper Agent. Requires human review." **Sources:** Fireship ### Multi-Year AI Tax and Financial Audit Pipeline Intermediate~30 min **Why it's worth it:** Uncovers omitted tax write-offs and prepares draft tax amendment documentation across multi-year personal or business expense files. Consolidates unstructured receipts, bank statements, and tax returns into high-context language models. A structured prompt instructs the model to cross-reference historical expenses against tax rules to identify missed deductions and generate draft filing forms. ChatGPTClaudeLocal File SystemPDF ParserEmail Connector 1. Gather historical tax returns, bank statements, and expense logs into a single folder, or export target email receipts as standard files. mkdir ~/TaxAudit2023-2025 cp ~/Downloads/*.pdf ~/TaxAudit2023-2025/ 2. Attach target tax returns and raw expense data to your high-context AI session window. # Connect files via workspace UI upload or local directory context 3. Run a comprehensive auditing prompt against the attached files to highlight unclaimed write-offs. Act as a professional tax auditor. Review my attached tax returns alongside my raw expense logs and receipt records for the past 3 years. Cross-reference my reported deductions with applicable tax laws for those years. Identify any omitted deductions, tax credits, or misclassifications, and calculate estimated refund adjustments. 4. Review flagged line items against legal requirements and export structured draft values directly into tax amendment forms (e.g., IRS Form 1040-X). # Export generated markdown report to PDF or plain text for CPA review cat audit_summary.md **Sources:** AI News & Strategy Daily | Nate B Jones ### Asynchronous Cloud Task Execution and Context Compression Pipeline Advanced30-45 min **Why it's worth it:** Saves up to 80 percent on API token consumption while running persistent agent projects asynchronously in the cloud. Prunes bloated project instruction files down to lean Markdown guidelines to curb token usage. Tasks are submitted to headless cloud sandboxes, letting local desktop machines shut down safely while background processes complete. ChatGPT Desktop AppCodexCloud Execution SandboxMarkdown 1. Open your repository configuration instructions file (e.g., agents.md) and execute an auditing prompt to strip redundant instructions. # Audit Prompt run inside Codex: "Analyze this instruction file. Identify redundant procedures, duplicate examples, and obsolete constraints while preserving mandatory safety boundaries. Distill output to under 1,200 words in Markdown format." 2. Save the distilled context guidelines back to your repository instruction file. cat <<EOF > agents.md # Lean Project Guidelines [Insert compressed instructions here] EOF 3. In your agent workspace settings, switch execution mode from 'Control Local' to 'Cloud'. # Select execution dropdown setting -> Switch to 'Cloud Sandbox' 4. Submit task objectives using explicit goal and stopping criteria parameters, then shut down your local application or desktop device safely. /goal Execute full data parsing pipeline on attached cloud assets. Save output to storage bucket and terminate when complete. **Sources:** AI News & Strategy Daily | Nate B Jones ### Interactive Application Prototyping from Hand-Drawn Sketches Beginner~15 min **Why it's worth it:** Converts hand-drawn visual UI concepts directly into working web applications within a single prompt generation session. Takes a photo of a hand-drawn interface sketch and passes it to an expressive frontier model alongside voice or text feature requirements. The model interprets the spatial layouts and creates functional HTML, CSS, and JavaScript applications directly inside an interactive browser preview. Claude.aiClaude Opus 5.5Screen Capture Tool 1. Draw your proposed application design or game mechanics clearly on paper or a digital canvas. # Take a screenshot or capture a photo file (e.g., sketch.png) 2. Upload the image file directly to Claude.ai and select Claude Opus 5.5 as your active model. # Attach sketch.png into the message bar 3. Provide detailed styling and interaction instructions alongside the visual upload. Build a functional interactive web application based on this sketch layout. Apply a modern dark theme with smooth CSS transitions. Include interactive controls, score tracking, and clean component organization. 4. Execute the generation request and test your new web asset directly inside the artifact container view. # Interact with output artifact in browser container window **Links:** https://claude.ai **Sources:** The AI Advantage ### Automated Corporate Milestone Visual Synthesizer and Social Broadcaster Intermediate~30 min **Why it's worth it:** Automates the creation and social media publishing of custom employee milestone graphics. Uses Python to call image generation models to create personalized employee recognition graphic assets. The script overlays custom employee text onto the visual using Pillow, then posts the finished banner to corporate LinkedIn accounts via API. Python 3.10+OpenAI API (DALL-E 3)LinkedIn REST APIPillow 1. Initialize a Python virtual environment and install the required utility dependencies. python3 -m venv env && source env/bin/activate pip install openai requests pillow 2. Set your mandatory API credentials as environment access variables. export OPENAI_API_KEY="sk-proj-YOUR_API_KEY" export LINKEDIN_ACCESS_TOKEN="YOUR_LINKEDIN_TOKEN" 3. Run a script generating a corporate background asset with DALL-E 3, overlay custom text, and post to social channels via API. from openai import OpenAI import requests from PIL import Image, ImageDraw client = OpenAI() res = client.images.generate(model="dall-e-3", prompt="Minimalist enterprise employee recognition banner", size="1024x1024") img_url = res.data[0].url img = Image.open(requests.get(img_url, stream=True).raw) draw = ImageDraw.Draw(img) draw.text((50, 50), "Congratulations!", fill="white") img.save("milestone.png") **Sources:** Joshua Fluke ## Videos Covered Today * Joshua Fluke — COMPANIES WILL DO ANYTHING EXCEPT PAY YOU MORE MONEY! * Dave Ebbelaar — How to Build a Company Knowledge Base (Full Tutorial) * Fireship — Meta is pivoting again... everything you missed from Connect 2026 * AI News & Strategy Daily | Nate B Jones — Is your AI smart? Use this simple trick to find out #AI #ChatGPT #taxes #money #personalfinance * AI News & Strategy Daily | Nate B Jones — How To Use ChatGPT Work: The Complete Beginner's Guide (2026) * Nate Herk | AI Automation — Opus 5.5 Just Changed Video Editing Forever (free skills) * The AI Advantage — Claude Opus 5.5 - 5 Real Uses and One BIG Website Showdown! Generated and deployed by Hiro Digest Engine v2.3.8
www.headlesshiro.com
September 26, 2026 at 12:04 PM
📝 Summary:

Coder is a self-hosted platform for cloud development environments and AI coding agents, using Terraform-defined workspaces, secure WireGuard connections, and AI agents on your infrastructure with centralized governance and cost controls. It offers quickstart setup, extensive (1/2)
September 21, 2026 at 5:17 PM
Coder is the self-hosted platform for cloud development environments — reproducible workspaces defined in Terraform, running on Kubernetes, EC2, or Docker, connected through WireGuard tunnels. Coder Agents delegate coding to Claude Code in governed workspaces. AGPL-3.0, 14k stars.
Coder: Self-Hosted Cloud Dev Environments Where the Workspace Is Infrastructure
Coder (coder.com) is a self-hosted platform for cloud development environments. **Go** , **AGPL-3.0** , **13,900+ GitHub stars**. Community edition free. Premium contact sales. ## Core concept Workspaces are defined in Terraform — infrastructure, startup scripts, resource quotas, idle shutdown. A coderd control plane manages lifecycle. Workspaces run on Kubernetes, EC2, Docker, or bare metal. Developers connect through WireGuard tunnels — no VPN, no exposed ports. ## IDE support VS Code, JetBrains Gateway, Cursor, Jupyter, code-server, SSH — any IDE that works over SSH works with Coder. ## Coder Agents Delegate coding tasks to Claude Code, Codex CLI, or OpenCode running inside isolated Coder workspaces on your own infrastructure. Each agent run has defined resources, audit logs, and lifecycle control. AI Gateway centralizes model provider config with unified auth and cost tracking. ## Deployment Quickstart via Docker. Production via Helm chart at helm.coder.com/v2. Requires PostgreSQL and ingress. Supports air-gapped deployment. ## vs Codespaces vs Gitpod Codespaces: managed on GitHub Azure, zero ops, no infrastructure control. Gitpod: better out-of-box DX, self-hosted option, less flexibility. Coder: full infrastructure control, data residency, requires platform engineering — right for regulated industries and enterprises. ## Who it is for Good fit: teams of 20+ with environment consistency problems; data residency or air-gap requirements; regulated industries needing audit logs; teams replacing VDI; organizations running AI agents with compliance controls. Not ideal: small teams without platform engineering; teams wanting zero ops overhead. ## My take Environment drift is cheap at three developers and catastrophic at three hundred. Terraform templates turn environments into version-controlled infrastructure code. Coder Agents running Claude Code in isolated, governed workspaces on your own infra is the architecture that makes AI coding compatible with enterprise compliance. The operational cost is real — someone owns the server, database, and templates. If you have the capacity, it pays for itself. * * * PIPOLINE · DEVOPS CONSULTING ### Need help deploying Coder for your team? Helm on Kubernetes, PostgreSQL, Terraform workspace templates, Coder Agents with AI Gateway — I can design and deploy the full platform. Get in touch at pipoline.com
devopspack.com
September 17, 2026 at 9:55 AM
Hackers exploit exposed Vite dev servers to snatch AWS and Azure secrets. This shows the importance of protecting dev environments to stop data theft. #CyberSecurityAlert
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.
www.bleepingcomputer.com
September 15, 2026 at 10:05 AM
Mass scanning of exposed Vite dev servers is exploiting CVE-2026-39364 to read .env files, AWS creds, Azure tokens, and Terraform data. F5 saw hundreds of attacks. #Vite #AWS #Azure
Hackers Target Exposed Vite Dev Servers To Steal AWS, Azure Secrets
A mass-scanning campaign is exploiting CVE-2026-39364 in exposed Vite development servers to steal cloud credentials, configuration files, and other secrets from AWS and Azure environments. F5 observed hundreds of attacks and thousands of events, with activity linked to traversal tricks, multiple Vite access-control flaws, and source IPs that should be blocklisted. #Vite #CVE-2026-39364 #AWS #Azure
www.hendryadrian.com
September 14, 2026 at 7:30 PM
AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs www.csoonline.com/article/4217...
AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs
The attack exploited exposed credentials and trust relationships spanning development and cloud environments, showing how access in one system can enable more privileged actions in another.
www.csoonline.com
September 10, 2026 at 11:42 PM
My workplace (Renaissance Computing Institute at the Univ of North Carolina at Chapel Hill) is hiring a Senior Research Software Developer -- come work with me! unc.peopleadmin.com/postings/325...
Senior Research Software Developer
The Senior Research Software Developer will lead and contribute to the design, development, deployment, and operation of cloud-native computing environments that support research and data-driven proje...
unc.peopleadmin.com
September 9, 2026 at 6:52 PM
A Day in My Setup: Building Full-Stack Apps on a Phone with Docker, Redis, and Codespaces
_How I run and test a full-stack automation system with headless Chromium, message queues, and databases—entirely from a phone-based development workflow._ ## Working Within the Constraints When people think of software engineering, they often picture dual 4K monitors, mechanical keyboards, and powerful workstations. But with cloud development environments and the right tooling, the workstation doesn't always have to be where the heavy work happens. Today, I was contributing to **Replex** —an open-source video automation tool that uses **Playwright** , **BullMQ** , **Redis** , **MongoDB** , **Express** , and **Next.js** to autonomously browse websites and record demo reels across different viewports. Here's a look at my development setup, how I optimize my cloud resources, and how I run the different services from a phone. ## The Architecture at a Glance [ My Phone / Local Environment ] ├── Local Git Repo (Editing & quick checks without burning Codespace quota) └── Mobile Browser (http://localhost:3000) │ ▼ (gh cs ports forward 3000:3000 5000:5000) [ GitHub Codespaces Cloud Container ] ├── 🐳 Docker (Redis:6379 & MongoDB:27017) ├── 🖥️ screen: Next.js Frontend (:3000) ├── 🖥️ screen: Express API Server (:5000) ├── 🖥️ screen: BullMQ Worker + Headless Chromium └── ☁️ Cloudinary Video Pipeline ## The Workflow: Step by Step ### 1. Conserving Cloud Quota (Local-First Editing) GitHub Codespaces gives me a monthly pool of compute time. To make the most of it: 1. I write code and perform initial lint and syntax checks locally on my device. 2. Commit and push the branch to GitHub. 3. SSH into my Codespaces environment and pull the latest changes. # Pull the latest changes into the Codespace git pull origin improve-mobile-recording Sometimes I code directly inside Codespaces, but when I don't need the cloud environment yet, doing the lightweight work locally saves those minutes for when I actually need them. ### 2. Spinning Up Data Stores with Docker For Redis and MongoDB, Docker saves me from installing and configuring each service directly in the Codespace. Instead of setting up each database separately and managing additional services, I can spin both of them up in a couple of commands: # 1. Start Redis in the background for BullMQ task queues docker run -d --name redis-local -p 6379:6379 redis:alpine # 2. Start MongoDB in the background for persistent video history docker run -d --name mongo-local -p 27017:27017 mongo:latest That's it. Both services are running and ready for the application to connect to them. ### 3. Setting Up Headless Automation The worker needs a Chromium browser environment to automate and record web interactions, so I install the required dependencies: cd backend && npm install npx playwright install --with-deps chromium cd ../frontend && npm install ### 4. Running Services with GNU `screen` The frontend, API, and worker all need to run simultaneously. Rather than keeping multiple terminal sessions open, I use GNU `screen` to run them as detached sessions: # Session 1: Next.js Frontend screen -dmS frontend bash -c "cd frontend && npm run dev" # Session 2: Express Backend Server screen -dmS backend-server bash -c "cd backend && npm run dev" # Session 3: BullMQ Playwright Worker screen -dmS backend-worker bash -c "cd backend && npm run worker" I can inspect the worker logs whenever I need to: screen -r backend-worker And detach again with `Ctrl+A`, then `D`. This lets all the services continue running while I use another terminal session for the next part of the setup. ### 5. The Magic Link: Port Forwarding At this point, the application is running inside Codespaces. I still need to interact with it from my phone's browser. That's where GitHub CLI port forwarding comes in. I initially forgot to forward the backend's port too, assuming the frontend could reach it directly in Codespaces. The API calls wouldn't resolve from my phone, so I added `5000:5000` to the forward command: gh cs ports forward 3000:3000 5000:5000 Forwarding: • Local port 3000 ──▶ Codespaces Next.js UI (:3000) • Local port 5000 ──▶ Codespaces Express API (:5000) Now I can open `http://localhost:3000` in my phone's browser and interact with the application running in the Codespace. The frontend can then dispatch background jobs to the API, which communicates with Redis and the worker running Playwright and Chromium. ### 6. Verification & End-to-End Testing Once everything is running, I verify that the pieces are actually communicating. # Test API connectivity through the tunnel curl http://localhost:5000/api/history # Output: [] (Healthy 200 response!) Then I can trigger an actual recording job and inspect the worker's output from its detached `screen` session: screen -r backend-worker The worker then processes the job: [Job 1] Started for URL: https://example.com on mobile [Recorder] Warming up cache... [Recorder] Found menu button via: button[aria-label*="menu" i]. Clicking... [Recorder] Clicking visible menu link (Pricing)... [Job 1] Streaming video upload to Cloudinary... [Job 1] Saved to MongoDB! [Job 1] Completed successfully! At that point, the entire chain—from the frontend on my phone to the backend, queue, worker, browser automation, video pipeline, and database—is working together. ## What This Setup Shows 1. **Resource Optimization:** I don't have to run the application's resource-intensive environment on my phone. Codespaces handles the databases, worker, Chromium, and application servers, while my phone is mainly used for editing, terminal access, and interacting with the running application. 2. **Less Environment Management:** Without Docker and `screen`, I'd have to install and manage each service individually and keep separate terminal sessions open for the frontend, backend, worker, Redis, and MongoDB. Docker handles the data stores, while `screen` keeps the application processes running independently. 3. **The Constraint Changes the Workflow, Not Necessarily the Work:** A phone obviously isn't as comfortable as a full workstation, but with the right tooling, it doesn't prevent me from working on a multi-service application. The setup isn't conventional, but it works, and this is what a few hours of software engineering looked like for me today.
dev.to
September 9, 2026 at 3:28 PM
CVE-2026-79696 - Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
CVE ID : CVE-2026-79696

Published : Sept. 9, 2026, 9:17 a.m. | 16 minutes ago

Description : A Code Injection vulnerability in adk web in Google Cloud Agent Developmen...
CVE-2026-79696 - Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
cvefeed.io
September 9, 2026 at 11:10 AM
Attackers Exploit TeamCity Flaw to Breach JetBrains Cadence #AWSCredentials #CICDSecurity #CloudSecurity
Attackers Exploit TeamCity Flaw to Breach JetBrains Cadence
JetBrains has revealed a security incident involving its Cadence cloud development service after attackers gained access through an unpatched TeamCity server. The compromise exposed sensitive credentials, source code, and service information, causing concerns regarding the security of development environments connected to cloud computing resources.  During this incident, CVE-2026-63077, a critical TeamCity On-Premises vulnerability, was exploited by an unauthenticated attacker, allowing him to execute operating system commands on an affected server without any authentication.  A flaw disclosed by JetBrains on July 27 was exploited soon after by vulnerable TeamCity installations. In the case of Cadence, it was api.cadence.jetbrains.com, the infrastructure used to support JetBrains' cloud computing service for PyCharm, which was vulnerable.  A malicious attacker is believed to have begun attacking on August 8 JetBrains discovered the intrusion on August 23 and taken the affected server offline the following day, putting the confirmed incident window between August 8 and August 24. Cadence integrates with PyCharm through an optional plugin that provides access to cloud-based computing resources for development projects.  As TeamCity managed those workloads behind the service, the compromised system was part of a closely related environment involving software development and execution. JetBrains acknowledged that the server should have been patched immediately following the disclosure of the TeamCity vulnerability, but remained unpatched.  Following the discovery of the critical vulnerability in TeamCity, the company has previously advised organizations to update vulnerable TeamCity deployments. In addition, the breach became more significant because attackers obtained a complete backup of Cadence server data from 2024. In addition, JetBrains confirmed that several Amazon Web Services IAM users and their credentials were compromised, including those belonging to Cadence employees.  The backup may contain credentials, configuration data, artifacts, and logs. A compromised backup contained more than routine service data. It also contained configuration information and credentials associated with cloud and development resources. Researchers also discovered that JetBrains customers' own buckets were accessed through S3 buckets within JetBrains' Amazon Web Services environment.  The extent of customer access to these buckets is unknown. There were several aspects of the development infrastructure exposed, including access to AWS IAM accounts, source-control access, package and container registry credentials, API tokens, SSH and deployment keys, service accounts and signing credentials, among others.  In the event of valid credentials remaining after the compromise, such access could provide a path into connected systems. JetBrains has not identified a specific threat actor as responsible for the activity, and no custom malware has been identified. Instead of exploiting a TeamCity vulnerability, the attacker used legitimate credentials and cloud services to conduct the intrusion. This method can make it difficult to distinguish malicious activity from normal administrative activity. This incident demonstrates the security implications of continuous integration and continuous delivery.  Using TeamCity environments, you can access source repositories, build artifacts, deployment systems, package registries, and cloud resources. Thus, a compromise on this level can lead to credential theft, unauthorized changes, and software supply chain attacks beyond the affected server. According to JetBrains, access tokens for the Cadence plugin in PyCharm have been invalidated, and users are encouraged to revoke or rotate credentials and secrets that were potentially used during Cadence executions.  In addition, Cadence inputs and outputs derived from this period should be viewed as potentially untrusted. As a result of the TeamCity vulnerability, a CVSS score of 9.8 has been assigned to it; it affects on-premises installations not updated to the latest version. The JetBrains patch version 2025.11.7 and version 2026.1.3, along with a security patch plugin, are available for environments in which immediate upgrades are not possible.  After exploitation was observed in the wild, CISA added the flaw to its catalog of Known Exploited Vulnerabilities. JetBrains has begun to assess the impact of the Cadence breach and has prompted a broader review of the affected environment. Upon completing the investigation, the company will contact affected users if further information is discovered that requires action.  According to the company, the incident is limited to the data associated with the Cadence host identified. It illustrates how critical it is to keep the CI/CD infrastructure patched, particularly when development systems are connected to the cloud and sensitive credentials.
dlvr.it
September 8, 2026 at 12:44 PM
Two new frontier models just landed on Diploi 🚀
You can now build with GPT-6 Astra and Claude Fable 5.1 straight in your browser. No API keys, no extra logins, prompt to production in a single tab.
👉 https://diploi.com/
#AI #devtools #GPT6Astra #Claude
Diploi
Diploi is a platform that lets you build apps using cloud development environments and host them online with a single click, without configuring servers manually.
diploi.com
September 8, 2026 at 6:03 AM
LiteLLM and the New Stakes of Software Supply-Chain Security
The LiteLLM supply-chain attack shows how quickly a trusted software tool can become a security risk. The attack shines a spotlight on a growing challenge as AI tools become more common across development, cloud and production environments. As organizations adopt more AI-powered tools, they are also relying on more open-source software, automated workflows and third-party dependencies. That means a compromise in one space can have wider consequences across the software ecosystem. The perspectives below from cybersecurity leaders highlight what the LiteLLM incident reveals about the importance of software supply-chain security in the AI era: Pascal Geenens, VP of Cyber Threat Intelligence, Radware “Developers are rapidly adopting local AI agents at scale to streamline their workflows, but this automation also introduces severe risks to the software supply chain. These coding agents, with or without heartbeat, are designed to resolve missing packages and routinely rely on package managers, such as npm, to automatically import and install any dependencies required to complete their assigned tasks. This high level of autonomy effectively transforms these helpful assistants into powerful amplifiers for supply chain attacks. The core issue is that the agent itself does not need to be inherently malicious, explicitly hacked or manipulated via prompt...
www.cybersecurity-insiders.com
September 6, 2026 at 12:49 PM
PPO-STGNN: A Proximal Policy Optimization Approach with Spatio-Temporal Graph Neural Networks for DAG Task Scheduling in Cloud-Edge-End Computing

Yangshuo Qi et al.

#arXiv #cs.AI
PPO-STGNN: A Proximal Policy Optimization Approach with Spatio-Temporal Graph Neural Networks for DAG Task Scheduling in Cloud-Edge-End Computing
With the rapid development of the Internet of Things, computation intensive directed acyclic graph (DAG) tasks have become increasingly common in cloud-edge-end collaborative environments. However, cloud, edge, and end nodes are highly heterogeneous in computing capacity, network bandwidth, and ene…
arxiv.org
September 5, 2026 at 5:14 PM
PPO-STGNN: A Proximal Policy Optimization Approach with Spatio-Temporal Graph Neural Networks for DAG Task Scheduling in Cloud-Edge-End Computing

Yangshuo Qi et al.

#arXiv #cs.AI
PPO-STGNN: A Proximal Policy Optimization Approach with Spatio-Temporal Graph Neural Networks for DAG Task Scheduling in Cloud-Edge-End Computing
With the rapid development of the Internet of Things, computation intensive directed acyclic graph (DAG) tasks have become increasingly common in cloud-edge-end collaborative environments. However, cloud, edge, and end nodes are highly heterogeneous in computing capacity, network bandwidth, and ene…
arxiv.org
September 4, 2026 at 4:50 PM
@liorbela.bsky.social

🎥 Reduce onboarding time simplifies environment setup for developers experience across Cloud PC #w365
🎥 Organizations can now provision Development-ready Environments with Minimal configuration
www.youtube.com/watch?v=2rKG...
September 3, 2026 at 6:05 AM
Containerization means packaging an application together with the code, libraries, and dependencies it needs to run. This allows the same application to work consistently across development, testing, on-premise servers, and cloud environments.

#Containerization #CloudComputing
September 2, 2026 at 1:30 PM
Catalyst by Zoho Solves The Shortfalls of Moving from Coding to Production With an Agent-Ready, Full-Stack Cloud and Built-In Governance

Zoho Corporation, a global technology company, today announced major enhancements to Catalyst by Zoho, its Platform-as-a-Service (PaaS), now weaving agentic…
Catalyst by Zoho Solves The Shortfalls of Moving from Coding to Production With an Agent-Ready, Full-Stack Cloud and Built-In Governance
Zoho Corporation, a global technology company, today announced major enhancements to Catalyst by Zoho, its Platform-as-a-Service (PaaS), now weaving agentic development capabilities directly into the coding environments developers already use. Additions include Agent Skills, a non-interactive command-line interface (CLI), and Model Context Protocol (MCP) support to Catalyst's platform, along with new integrations for agentic AI coding assistants including Anthropic's Claude Code and OpenAI's Codex.
itnerd.blog
September 2, 2026 at 12:23 PM
Kyndryl, Broadcom expand partnership to push private clouds for AI work
Kyndryl and Broadcom on Thursday rolled out new consulting services for VMware Cloud Foundation (VCF), tweaking the initiative to be an AI program and pledging to invest in the skills development of several thousand certified Kyndryl consultants, architects, and delivery specialists to enable agentic workflows. “Against the backdrop of rising sovereignty demands, enterprises are rationalizing their hybrid and private cloud environments, and they require a pragmatic, outcome-driven approach,” said Giovanni Carraro, global strategic alliances leader at Kyndryl, in a news release. “By expanding our partnership with Broadcom and investing in VCF skills, we will help customers build modern, resilient, private clouds that enable AI adoption, support data modernization, address the risk of AI-identified vulnerabilities and deliver real business value.” Analysts and consultants said the partnership expansion was fairly mundane in itself, but they did think there was meaningful potential in the consultant program. Mike Leone, a VP/principal analyst at Moor Insights & Strategy, thought that the significant part of the partnership is in the skills investment. “Enterprises moved onto VCF pretty quickly, and now they’re at the harder stage of actually modernizing it,” he said. “More companies than you think have lost their deep VMware talent, so that work stalls out. Broadcom putting real money behind training a few thousand Kyndryl consultants is a direct answer to that.” He noted that it isn’t glamorous, but delivery capacity is usually what decides whether a platform gets used well. “Kyndryl’s a logical partner for it too,” he said. “They already run a huge amount of VMware for customers, so this resources a relationship that was already there.” But Sanchit Vir Gogia, chief analyst at Greyhound Research, questioned how much is really new with this announcement. “This is neither a new alliance nor a new platform. Kyndryl and VMware expanded their partnership in November 2021, and managed-services status followed in August 2023, so the relationship is old and the packaging is new,” Gogia pointed out. “What has been announced is scaffolding: consulting, certification, and managed operations built around VMware Cloud Foundation 9.1, with no disclosed financial commitment, no exclusivity, and no named launch customer.” Gogia said this shows strong interest in private clouds from these two vendors, but he questioned how much enterprise interest exists today in private clouds. “No broad enterprise migration from public cloud back to private cloud is visible, and this announcement does not establish that one is needed,” Gogia said. “The defensible reading is selective workload placement. The announcement does not prove that enterprises must shift to private cloud, it proves that Broadcom and Kyndryl want a larger role when enterprises decide where workloads run.” Justin Greis, CEO of consulting firm Acceligence, disagreed, and said that he found the announcement interesting, “because they are trying to make that private portion of the equation behave more like cloud rather than simply resurrecting the old corporate data center. Automation, policy as code, container support, developer experience, AI inference and agent governance are all part of that proposition.” However, he said that the boost in personnel is potentially significant. “I think the investment in thousands of trained Kyndryl people may ultimately be more consequential than some of the technology language in the announcement,” Greis noted. “Enterprise infrastructure is already incredibly complicated. Add AI agents, multiple models, new governance requirements and hybrid infrastructure, and the skills required to operate all of it become a major constraint. Technology vendors can build increasingly sophisticated platforms, but enterprises still need people capable of turning those platforms into reliable operating environments.” Shashi Bellamkonda, a principal research director at Info-Tech Research Group, added he saw another element in the statement. “I see a double-edged irony in this. Broadcom’s post-acquisition VMware pricing is itself what pushed many tech leaders into pain and dependency, and the product it now sells is the antidote,” Bellamkonda said. “VCF, marketed as the route to sovereignty from governments and hyperscalers, leaves buyers just as dependent on Broadcom commercially as they were before. Sovereignty from a jurisdiction is not the same as independence from a vendor.” _This article originally appeared on NetworkWorld._
www.cio.com
August 28, 2026 at 4:48 AM