Treating an AI like an employee: what actually changes
The framing has become a cliché. The actual mechanics, onboarding, scope of work, performance review, termination, change in interesting ways once you take the metaphor literally.
The framing has become a cliché. The actual mechanics, onboarding, scope of work, performance review, termination, change in interesting ways once you take the metaphor literally.
The workflow-orchestration tools of the early 2010s tried to solve a problem the LLM agents of the mid-2020s are now taking another swing at. The problem is the same. The substrate is different. Worth being honest about which parts of the previous attempt to bring forward and which to leave.
MCP is the standard the integration layer of the AI stack converged on faster than anyone expected. Worth knowing what it actually is before you wire one in.
Thirty days of letting an agent actually drive, write the code, run the tests, fix the failures, and then noticing the patterns in what changed. Not the productivity story. The discipline story.
A coding agent shipped by the model maker, built around the terminal rather than the editor. Worth working through what's actually different about that shape, and what it implies for the IDE category.
Most cloud-bill surprises were visible at PR time. The plan output knows the resource shape, the region, the size, and what the cloud charges for it, and you can read that out of the plan-json before anything ships. Here's the pattern, what it catches, and what it can't.
IBM announced a $6.4B acquisition of HashiCorp on April 24. The honest read is that this confirms the BSL-era trajectory more than it changes it. Here's what's likely, what's uncertain, what stays the same for current Terraform users in the short term, and what to actually watch.
Most GKE-via-Terraform modules expose every knob the API has, then bury the few that matter. Here's the split I've landed on after a year of customer demos, what to parameterize per environment, what to hardcode and forget, and the regional-vs-zonal trade-off nobody likes to talk about.
Provider version pinning is one of those Terraform topics nobody thinks about until the CI runner picks up a new minor release at 2 a.m. and a hundred plans go red. Here's the audit pattern I run for customers, the trap on both sides, and the constraint style I land on by default.
Lifecycle hooks are the part of Terraform that looks trivial in the docs and saves you from a six-figure outage in practice. Here's how prevent_destroy and ignore_changes actually get used in production, what to put them on, what not to, and the operations cost of getting it right.
Most Terraform pipelines treat plan output as text, paste it in a PR, hope the reviewer reads it. The JSON form is structured data, and once you treat it that way, cost preview, policy gates, drift attribution, and change-risk scoring become engineering problems.
Long-lived AWS access keys in GitHub Actions secrets are the wrong default. OIDC federation gives every workflow a scoped, short-lived role assumption with no secret to leak. The trust-policy shape, the GitHub Actions wiring, and the gotchas that make it harder than the blog posts suggest.