Agentic DevOps : AI Engineering for Infrastructure

Where LLMs, AI Agents, and MCP tools meet DevOps and platform engineering. How can we humans use non-deterministic, often hallucinating LLMs to automate our infrastructure and help us with the job of software lifecycle management? I’m Bret Fisher, and this is the Agentic DevOps podcast. After the invention of AI Agents and the MCP standard in late 2024, I started this podcast in early '25 with a narrow topic focus… to document and advise how AI Agents, MCP tools, and large language models can be used in the real world for assisting with DevOps automation, platform engineering, and day to day systems operations… a podcast series hopefully without the hand-wavy AI hype or dreams of a pure AI workforce. I'm joined by expert guests trying to make use of crazy texting robots.

  1. 3 days ago ·  Video

    Rogue AI or Just Sloppy Ops?

    The OpenAI Hugging Face hack. The Anthropic testing failures. Listen to the security and ops experts, not lab researchers. I walk you through the production failures that allowed OpenAI’s models to access the internet, and what we can learn from the last few months on how to protect our systems and data. Let’s stop debating imaginary outcomes and start working through that security backlog in our infrastructure. I agree with the labs needing to slow down, but not because I believe AI will do uncontrollable harm on humans, but because the labs clearly need better production security and ops teams and more advanced lab infrastructure that’s been properly hardened. They also need to become a production ops security innovator and share that knowledge far and wide. Watch the video of this episode. Thanks to SpeechifyAI for sponsoring this podcast. Get started for free. Check the benchmarks for Best Provider Text-to-Speech. 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. ★Articles★ The Hugging Face Incident Is Not an AI Story - Marius HoratauFrom Frenzy to Freakout - Ciaran Martin & Professor Alan WoodwardStop Freaking Out and Start Fixing Things - SANS InstituteFragments: September 8th - Martin FowlerWhen AI can do more than we can check - Christian CataliniI'm sorry, you're not going to die from an AI-engineered supervirus - Claus WilkeThis Week in Security - Zack Whittaker★Other stuff★ 'Big Short' investor Steve Eisman on AI: The companies are trying to manufacture a crisis - CNBCxkcd: Dependency - so much of our systems are this.xkcd: Python Environment - and also this.Defense Factory - OpenAIInvestigating three real-world incidents in our cybersecurity evaluations - AnthropicAnatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident - Hugging FaceMy recommended podspec, with seccomp enabled - Bret Fisher Creators & Guests Bret Fisher - Host Beth Fisher - Producer You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news! Grab the best coupons for my Docker and Kubernetes courses on Udemy. Join my cloud native DevOps community on Discord.Grab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - Start (01:51) - Speechify AI (03:04) - The Hugging Face Incident: Facts (07:07) - Attack Timeline & Escalation (15:33) - Root Cause: Infrastructure Failure (21:15) - Expert Analysis: From Frenzy to Freak Out (23:41) - Martin's Key Points (28:13) - Expert Analysis: Alan Woodward (34:47) - SANS Institute Takeaways (37:47) - Other Good Resources ★ Support this podcast on Patreon ★

    Rogue AI or Just Sloppy Ops?
  2. 21 Aug ·  Video

    AI Agent Sandboxing with Nono

    Luke Hinds, co-founder of nolabs Inc. and the nono project, joins me to dig into AI agent sandboxing with the nono CLI. It's been my go-to sandboxing tool for local agent use, but I know there are more features I should be using, like secure secrets injection and egress URL path control. Watch the video of this episode. Thanks to SpeechifyAI for sponsoring this podcast. Get started for free. Check the benchmarks for Best Provider Text-to-Speech. 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. ★Show Links★ nono websitenono repo on GitHubnolabs websiteOpenSSF SLSACreators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Luke Hinds - Guest You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news! Grab the best coupons for my Docker and Kubernetes courses on Udemy. Join my cloud native DevOps community on Discord.Grab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - Introduction (04:40) - SLSA (07:38) - Nono Origin and Quickstart (12:19) - Nono Elevator Pitch (22:22) - How Nono Works in Practice (46:42) - DEMO (50:35) - What's Next for Nono? ★ Support this podcast on Patreon ★

    AI Agent Sandboxing with Nono
  3. 1 Aug ·  Video

    AI-Native Engineering Culture from a CTO

    My friend Mike Rollins joins me for a chat about what it’s like leading a software engineering team that doesn’t read code anymore. Click here to watch a video of this episode. Thanks to SpeechifyAI for sponsoring this podcast. Get started for free. Check the benchmarks for Best Provider Text-to-Speech 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. ★Show Links★ https://github.com/rollinsio/delta-v-dev-container-boilerplatehttps://github.com/rollinsio/beyond-test-coverage (expand your testing strength)https://rollins.io/https://www.instagram.com/rollins.ioCreators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Mike Rollins - Guest You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news! Grab the best coupons for my Docker and Kubernetes courses on Udemy. Join my cloud native DevOps community on Discord.Grab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - MAIN - Video Podcast (02:14) - Welcome Mike (02:23) - Mike Rollins AI First Journey (06:55) - Speechify.AI (07:57) - Agentic Delivery and Safety Nets (17:50) - PR to Production (35:10) - Testing and PR Chaos (47:49) - Harness Safety and Cost (54:25) - Maturity Milestones and Wrap ★ Support this podcast on Patreon ★

    AI-Native Engineering Culture from a CTO
  4. 17 Jun ·  Video

    Safer Agent Automation with GitHub Agentic Workflows

    A deep dive into GitHub’s Agentic Workflows feature, with Don Syme of GitHub Next & Peli de Halleux of Microsoft Research.  Check out the video podcast version here: https://youtu.be/zmM8VISTOwo 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. ★Show Links★https://githubnext.com/projects/agentic-workflows/https://github.github.com/gh-aw/https://githubnext.com/projects/continuous-ai/https://github.com/githubnext/repo-assist-impact/blob/main/report.mdhttps://github.com/microsoft/apm Creators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Don Syme - Guest Peli de Halleux - Guest You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news! Grab the best coupons for my Docker and Kubernetes courses on Udemy. Join my cloud native DevOps community on Discord.Grab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - MAIN - Video Podcast (10:42) - Agentic Workflows Explained (17:43) - Toil, Repo Assist, and Guardrails (36:44) - Why Agents Need Guardrails (38:45) - Deterministic Security Box (57:16) - Repo Assist in Action (01:04:51) - Async Agent Workflow (01:10:16) - Workflow Optimization Tricks (01:12:03) - Agentic Enterprise Future ★ Support this podcast on Patreon ★

    Safer Agent Automation with GitHub Agentic Workflows
  5. 6 May ·  Video

    AI SREs, Chat With Your Infrastructure with Anyshift

    Bret’s joined by the Anyshift.io co-founders, Roxane Fischer and Stephane Jourdan to discuss how an always-on SRE agent can help you proactively find risks and avoid incidents. 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. This edited version is from my live stream show Apr 9, 2026: https://www.youtube.com/live/-DHZwxXigYI?si=9JnQYp8UZG27Bp2X&t=232  ★Show Links★ Anyshift websiteAnnie CLIBlog post: Agentic Context Engineering in Production: How AI Agents Build Institutional ExpertiseCreators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Roxane Fischer - Guest Stephane Jourdan - Guest You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news! Grab the best coupons for my Docker and Kubernetes courses on Udemy. Join my cloud native DevOps community on Discord.Grab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - Introduction (03:09) - Meet Anyshift and the big idea (03:29) - When Was Anyshift Created? (07:13) - Context graphs and agent workflows (24:31) - Permissions and Auditing (28:16) - Memory and Context Graph (47:07) - Roadmap and Wrap Up ★ Support this podcast on Patreon ★

    AI SREs, Chat With Your Infrastructure with Anyshift
  6. 14 Apr

    Our Favorite Agent Setups

    My friend Brian Christner (Docker Captain alum) and I go through our AI harnesses, agents, models, and what we’re playing with right now. OpenClaw, OpenCode, Claude Code, Copilot, and all of it. Check out the video podcast version here: https://youtu.be/8AFE0kxaY2k 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. ★Show Links★ Brian’s Newsletter Agents & Claude Code Setup Awesome Claude Code SubagentsAgency AgentsClaude Code CourseOpenClaw alternativeBrian’s OpenClaw Projects OpenClaw Security ChecklistGarmin Connect SkillOpenClaw Security Dashboard SkillCreators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Brian Christner - Guest You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news! Grab the best coupons for my Docker and Kubernetes courses on Udemy. Join my cloud native DevOps community on Discord.Grab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - Introduction (03:01) - AI Tools and Skills Deep Dive (30:52) - Securing OpenClaw Servers (36:58) - Safe Use Cases and Token Control (47:43) - OpenClaw DOs and DON'Ts (53:11) - NanoClaw and Container Future ★ Support this podcast on Patreon ★

    Our Favorite Agent Setups
  7. 26 Mar

    Four Months Felt Like Four Years

    It’s been 6 months since the last episode, and it feels like everything has changed. Bret and Nirmal catch you up on the increasing pace of AI change, how it will likely affect DevOps engineers and platform builders, and what’s coming on the podcast. Check out the video podcast version here: https://youtu.be/NkqAMAIW5ks 😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs. ★Show Links★ Agent Harness Skills https://agentskills.ioVideo of Gradel CEO "You can write code faster, can you deliver it faster?" https://www.youtube.com/watch?v=VOXNJ9_sHuMIs your team still hand-chiseling code? https://www.geocod.io/code-and-coordinates/2026-01-21-hand-chiseling-code/Creators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Nirmal Mehta - Host You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news! Grab the best coupons for my Docker and Kubernetes courses on Udemy. Join my cloud native DevOps community on Discord.Grab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - ADOP - Feb 26, 2026 (02:23) - Introduction (03:00) - Season Two Kickoff (04:34) - Productivity Debate and Two AI Camps (06:48) - Ops View from Dev Retreats (10:05) - Automation Debt and App Tsunami (14:12) - Frontier Models Changed Everything (20:12) - Red Pill vs Blue Pill Skepticism (23:14) - Three Focus Areas for DevOps (25:34) - GitHub Copilot and Agentic Workflows (29:00) - Harnesses That Run Longer (29:34) - Skills As SOPs (32:13) - Guardrails For App Tsunami (34:13) - Agent Orchestration a nd Kubernetes (35:33) - Shadow IT Goes AI (36:13) - Inner Loop Diagram Breakdown (38:37) - AI Code Review Councils (40:52) - Context Layer And Docs Debt (47:06) - Career Waves to Agent Ops (55:12) - Future Guests and Episodes (58:28) - ★ Support this podcast on Patreon ★

    Four Months Felt Like Four Years

About

Where LLMs, AI Agents, and MCP tools meet DevOps and platform engineering. How can we humans use non-deterministic, often hallucinating LLMs to automate our infrastructure and help us with the job of software lifecycle management? I’m Bret Fisher, and this is the Agentic DevOps podcast. After the invention of AI Agents and the MCP standard in late 2024, I started this podcast in early '25 with a narrow topic focus… to document and advise how AI Agents, MCP tools, and large language models can be used in the real world for assisting with DevOps automation, platform engineering, and day to day systems operations… a podcast series hopefully without the hand-wavy AI hype or dreams of a pure AI workforce. I'm joined by expert guests trying to make use of crazy texting robots.

More From Bret Fisher