frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Would you trust an AI coworker with shell access to your infrastructure?

1•doctornemesis•1h ago
Hi HN,

I’ve been experimenting with an idea that I’m honestly not sure is brilliant or completely reckless.

Tools like Claude, Cursor, and Copilot can already:

read files

run terminal commands

edit code

And they’re incredibly useful for development work.

It made me wonder: what would the equivalent look like for infrastructure engineers?

I’m prototyping an “AI coworker” that can:

read logs

run shell commands

inspect system state

check Kubernetes

read/edit config files

query internal APIs

The goal isn’t a chatbot. The goal is this:

You say: “The API is failing. Find out why and fix it.”

And the agent goes through the same loop an SRE would:

observe → hypothesize → run commands → verify → fix.

But this raises a lot of uncomfortable questions.

Cursor/Claude can technically already run commands if you let them — so why is this a bad idea? Or is it?

I’m trying to understand the boundary between:

“This would be insanely useful for debugging and ops”

and

“This is how you take down production at 3am”

Before I go too far building this, I’d really like to hear from people who run real systems:

Would you ever try something like this?

Where would this be useful vs unacceptable?

What safeguards would you absolutely require?

What tasks would you want this for?

What makes this fundamentally different from just giving Cursor terminal access?

I’m early, testing this only on a local docker-compose setup with a few services. Just trying to sanity-check the idea with people who’ve been on call.

Comments

Bender•1h ago
Would you trust an AI coworker with shell access to your infrastructure?

I would not, most legal departments would not, all CSO's and compliance officers would not if someone explained it to them honestly. I have no doubt some will be tricked into approving such a thing and will try to back-peddle when it backfires on them.

Would you ever try something like this?

No I would not but I have only worked for companies with highly sensitive data, financial data, credit card data, proprietary code and data.

What safeguards would you absolutely require?

The entire AI stack would need to be written and maintained by the same company it is running in and all of the data must be stored in that companies data-centers. The interface must be behind multi-factor authentication and a corporate VPN running in the data-center. It would need to be audited by internal auditors, red team pen testers, external 3rd party code and infrastructure pen-testers and would have to go through the strictest change control. Every action by the AI must be highly audited real time and every action must be predictable and reproducible. No third party connections whatsoever. Any attempts to connect outbound must trigger and immediate mandatory all hands on deck response. The entire stack both client, agent and servers must run entirely within the data-center and not someones laptop regardless of how locked down their workstation or laptop is.

And that is even before factoring risks such as hallucinations, confidently accepting its own incorrect decisions. Blaming the AI for downtime, leaking customer data, leaking intellectual property would not be acceptable.

Having said all that, I am certain there will be some interested that could get it approved. Some companies give Okta root access via an agent to all their server fleets with no local guardrails. Should they ever get hacked that is insta-root on a lot of servers. My opinions on that matter are not suitable for public forums.

What These Cockpit Lights Mean – ATR Simulator Walkthrough – Dark Cockpit

https://www.youtube.com/watch?v=Q7_PB6f2pqY
1•starkparker•3m ago•0 comments

Fuel Economy Fraud: Closing Loopholes That Increase U.S. Oil Dependence (2005) [pdf]

https://www.ucs.org/sites/default/files/2019-09/executive_summary_final.pdf
1•CGMthrowaway•5m ago•0 comments

Altman, Bezos and Zuckerberg donate to Trump's inauguration fund (2024)

https://www.npr.org/2024/12/13/nx-s1-5227874/trump-bezos-zuckerberg-amazon-facebook-open-ai-meta-...
5•pera•6m ago•0 comments

Bio-Theory Lab Notes: Growth Rates and Worm Brains

https://chillphysicsenjoyer.substack.com/p/bio-theory-lab-notes
1•crescit_eundo•8m ago•0 comments

Grainrad: Browser ASCII/Dithering Tool

https://grainrad.com/
2•smusamashah•16m ago•0 comments

Markdown Viewer – Get This Extension for Firefox (En-US)

https://addons.mozilla.org/en-US/firefox/addon/markdown-viewer-extension/
1•dp-hackernews•17m ago•0 comments

Using Information Entropy to Make Choices / Choose Experiments

https://blog.demofox.org/2025/10/05/using-information-entropy-to-make-choices-choose-experiments/
2•deadbishop•17m ago•0 comments

Daxfs Proposed as Newest Linux File-System

https://www.phoronix.com/news/DAXFS-Linux-File-System
1•Bender•18m ago•0 comments

CachyOS Starts 2026 by Switching to Plasma Login Manager, Live ISO Using Wayland

https://www.phoronix.com/news/CachyOS-January-2026
3•Bender•19m ago•0 comments

OptiMind: Research Model Designed for Optimization

https://huggingface.co/blog/microsoft/optimind
1•gmays•19m ago•0 comments

Almost 12,000 flights canceled as major winter storm bears down across US

https://ktla.com/news/nationworld/ap-over-8000-flights-canceled-as-major-winter-storm-bears-down-...
2•Bender•19m ago•0 comments

Man is shot and killed during Minneapolis immigration crackdown

https://apnews.com/article/immigration-enforcement-minnesota-4d1499fc5962ab880f3816259e04bdbf
10•DiscourseFan•23m ago•2 comments

Dorodango: the hobby that took over Japan in 1999

https://www.youtube.com/watch?v=2H0r81kv5GA
1•n1b0m•23m ago•0 comments

Announcing winapp, the Windows App Development CLI

https://blogs.windows.com/windowsdeveloper/2026/01/22/announcing-winapp-the-windows-app-developme...
2•CharlesW•23m ago•0 comments

I don't write code anymore – I sculpt it

https://www.jerpint.io/blog/2026-01-24-i-dont-write-code-anymore-i-sculpt-it/
3•jerpint•23m ago•0 comments

We didn't ask for 'smart' cars – so why are we getting them?

https://www.autocar.co.uk/opinion/new-cars/we-didn%E2%80%99t-ask-smart-cars-so-why-are-we-getting...
5•breve•24m ago•3 comments

Policy-Based Routing on an OpenWrt Router

https://dariusz.wieckiewicz.org/en/policy-based-routing-openwrt
4•idarek•24m ago•1 comments

Writing a Go SQL Driver

https://www.dolthub.com/blog/2026-01-23-golang-sql-drivers/
1•ingve•24m ago•0 comments

Terraform Actions: Deep-Dive

https://mattias.engineer/blog/2025/terraform-actions-deep-dive/
1•based2•24m ago•0 comments

The chronically online will become a new underclass [video]

https://www.youtube.com/watch?v=Bm2Q9HkbLsQ
2•nanfinitum•26m ago•0 comments

Isolating Claude Code

https://yieldcode.blog/post/isolating-claude-code/
1•ingve•26m ago•0 comments

Hybrid and electric semi truck sales topped 231,000 units 2025 – in China alone

https://electrek.co/2026/01/24/hybrid-and-electric-semi-truck-sales-topped-231000-units-2025-in-c...
2•breve•27m ago•0 comments

Seat-back psychology helped a WA business build a dynasty

https://www.seattletimes.com/business/boeing-aerospace/how-seat-back-psychology-helped-a-wa-busin...
1•CharlesW•27m ago•0 comments

Divergent creativity in humans and large language models

https://www.nature.com/articles/s41598-025-25157-3
2•geox•27m ago•0 comments

Im fucking serious, you can just do things

https://vibe.devpost.com
3•abdibrokhim•30m ago•0 comments

Lennart Poettering and the Cause of Civility

https://www.linux-magazine.com/Online/Blogs/Off-the-Beat-Bruce-Byfield-s-Blog/Lennart-Poettering-...
2•written-beyond•31m ago•0 comments

Continental Power, Maritime Power, and the Fight for a New World Order

https://www.foreignaffairs.com/united-states/land-or-sea-paine
2•mooreds•37m ago•1 comments

Ten Ways to Fool the Masses When Presenting Battery Research (2021)

https://chemistry-europe.onlinelibrary.wiley.com/doi/10.1002/batt.202100154
2•johlo•37m ago•0 comments

Why AI Mentions Brands More Than It Recommends Them, and What That Means for SEO

https://www.flygen.ai/
2•AaronMeslin•38m ago•1 comments

The case for active management when so few outperform the S&P 500

https://www.startribune.com/s-and-p-500-index-stock-market-outperform-active-managed-fund-tech-ai...
3•mooreds•38m ago•0 comments