frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Hardened OpenClaw on AWS with Terraform

https://github.com/infrahouse/terraform-aws-openclaw
2•aleks2•2h ago
I work on AWS infrastructure (ex-Percona, Box, Dropbox, Pinterest). When OpenClaw blew up, I wanted to run it properly on AWS and was surprised by the default deployment story. The Lightsail blueprint shipped with 31 unpatched CVEs. The standard install guide uses three separate curl-pipe-sh patterns as root. Bitsight found 30,000+ exposed instances in two weeks. OpenClaw's own maintainer said "if you can't understand how to run a command line, this is far too dangerous."

So I built a Terraform module that replaces the defaults with what I'd consider production-grade:

* Cognito + ALB instead of a shared gateway token (per-user identity, MFA) * GPG-verified APT packages instead of curl|bash * systemd with ProtectHome=tmpfs and BindPaths sandboxing * Secrets Manager + KMS instead of plaintext API keys * EFS for persistence across instance replacement * CloudWatch logging with 365-day retention Bedrock is the default LLM provider so it works without any API keys. One terraform apply. Full security writeup: https://infrahouse.com/blog/2026-03-09-deploying-openclaw-on...

I'm sure I've missed things. What would you add or do differently for running an autonomous agent with shell access on a shared server?

We visited "ground zero" for hospice fraud: Los Angeles, California

https://www.cbsnews.com/projects/2026/hospice-fraud/
1•gmays•1m ago•0 comments

Hollywood Hacks OT: Cybersecurity Lessons from the Movies

https://www.emberot.com/resources/blog/ot-cybersecurity-lessons-from-the-movies/
2•TheWiggles•3m ago•0 comments

40 Years of Wireless Evolution Leads to a Smart, Sensing Network

https://spectrum.ieee.org/telecom-history-1g-to-6g
2•Brajeshwar•4m ago•0 comments

"Added 1M context window for Opus 4.6 by default for Max, Team, and Enterprise"

https://raw.githubusercontent.com/anthropics/claude-code/refs/heads/main/CHANGELOG.md
2•taspeotis•6m ago•1 comments

Could a Day Job Be the Foundation of an Artist's Success?

https://3quarksdaily.com/3quarksdaily/2026/03/could-a-day-job-be-the-foundation-of-an-artists-suc...
1•herbertl•8m ago•0 comments

Japanese government makes indie game devs eligible for grants up to $60k USD

https://automaton-media.com/en/news/japanese-government-makes-indie-game-developers-eligible-for-...
2•maenbalja•10m ago•0 comments

Pick one of catastrophic or equitable. Are founder clean breaks possible?

1•mehctothroaway•11m ago•0 comments

How the Strait of Hormuz closure affects global oil supply

https://www.reuters.com/graphics/IRAN-CRISIS/OIL-LNG/mopaokxlypa/
3•aanet•11m ago•1 comments

Iran and Region Monitor of Attacks and Major Events

https://newsfeed-staging.pages.dev/
1•msukhareva•12m ago•0 comments

Smaller Than a Fingernail: Unboxing the Tiniest Books [video]

https://www.youtube.com/watch?v=faN_yEghseo
1•gnabgib•14m ago•0 comments

Electron microscopy shows 'mouse bite' defects in semiconductors

https://news.cornell.edu/stories/2026/03/electron-microscopy-shows-mouse-bite-defects-semiconductors
1•hhs•14m ago•0 comments

Show HN: diz – SSH key exchange in one command each side

https://github.com/noahra/diz
1•noahra•15m ago•0 comments

The Playbook and Play-Engine Site (2003)

https://www.wisdom.weizmann.ac.il/~playbook/
1•turtleyacht•18m ago•1 comments

Digg cuts jobs after facing AI bot surge

https://www.reuters.com/technology/digg-cuts-jobs-after-facing-ai-bot-surge-2026-03-13/
2•geox•20m ago•1 comments

macOS backups with Kopia and Backblaze (2023)

https://hmarr.com/blog/mac-backups-with-kopia/
2•chmaynard•20m ago•0 comments

Dust Outbreak Reaches Europe

https://science.nasa.gov/earth/earth-observatory/dust-outbreak-reaches-europe/
1•gnabgib•21m ago•0 comments

How the Iran War Threatens Big Tech's AI Data Center Buildout in the Middle East [video]

https://www.youtube.com/watch?v=-vhTIkq9-ng
2•mgh2•22m ago•0 comments

Harnessing eDNA to help conserve Australia's oceans

https://phys.org/news/2026-03-harnessing-edna-australia-oceans.html
1•Brajeshwar•24m ago•0 comments

The AI that taught itself: Researchers show how AI can learn what it never knew

https://viterbischool.usc.edu/news/2026/03/the-ai-that-taught-itself-usc-researchers-show-how-art...
1•hhs•28m ago•0 comments

Execwall – firewall to stop ModelScope CVE-2026-2256 (AI agent command injectn)

1•sentra•28m ago•0 comments

Ask HN: Has anyone built an AI agent that spends real money?

1•xodn348•28m ago•0 comments

Waitrose suspends sale of mackerel because of overfishing

https://www.theguardian.com/environment/2026/feb/26/waitrose-suspends-sale-mackerel-overfishing
1•PaulHoule•28m ago•0 comments

High Grow Market Equilibrium After the Singularity

https://www.lesswrong.com/posts/WS3JBPsBGtJvFDEjy/high-grow-market-equilibrium-after-the-singularity
1•gmays•29m ago•0 comments

Stop repeating yourself to Claude Code

https://www.gopeek.ai
5•itsankur•29m ago•1 comments

I beg you to follow Crocker's Rules, even if you will be rude to me

https://lr0.org/blog/p/crocker/
8•ghd_•30m ago•6 comments

Computing in Freedom with GNU Emacs

https://protesilaos.com/codelog/2026-03-13-computing-in-freedom-with-gnu-emacs/
3•birdculture•31m ago•0 comments

Annette Obrestad: The teenage prodigy who won the first WSOP Europe Main Event

https://www.poker.org/latest-news/annette-obrestad-the-teenage-prodigy-who-won-the-first-wsop-eur...
1•indigodaddy•31m ago•0 comments

YC: Need more time to review application

3•bstrama•32m ago•0 comments

Global Flood Hub by Google

https://sites.research.google/floods/
2•teleforce•35m ago•0 comments

Ninth Circuit Guts California's Kids Code Once Again

https://www.techdirt.com/2026/03/13/ninth-circuit-guts-californias-kids-code-once-again/
2•hn_acker•37m ago•0 comments