[Dev]olution

Coder

The development world is cluttered with buzzwords and distractions. Speed, focus, and freedom? Gone. I’m Nicky Pike. And it’s time for a reset. [Dev]olution is here to help you get back to what matters: creating, solving, and making an impact. No trend chasing, just asking better questions. What do devs really want? How can platform teams drive flow, not friction? How does AI actually help? Join me every two weeks for straight talk with the people shaping the future of dev. This is the [Dev]olution.

  1. 3d ago

    AI Didn't Break Your Platform, Your Mess Did

    If you have to do your taxes, do you trust the whiz kid from MIT or the accountant with 30 years of experience? Marc Cluet opens this episode with that question, setting the stage for a candid exploration of modern platform engineering and enterprise AI integration. Drawing from his experience at Canonical, Rackspace, HashiCorp, and leading AI-driven migrations at a major global bank, Marc sits down with Nicky Pike to confront the core realities of modern software infrastructure. Together, they unpack what actually happens when AI is introduced to legacy systems riddled with fragmented standards and accumulated technical debt. Marc reveals why line-by-line code translation fails and advocates for translating business intent instead. He details his "Michelin-star menu" strategy to balance developer enablement with strict architectural guardrails, while warning of the unavoidable 16-month productivity valley during AI adoption. Rather than accelerating messy code, Marc emphasizes standardizing systems first or knowing when legacy shell scripts are better off retired than migrated. This episode is an essential guide for engineering leaders navigating the intersection of enterprise AI hype, platform governance, and legacy modernization. In this episode, you'll learn: Why AI acts as an accelerator for existing technical debt rather than a fix for messy architectureHow to implement a "Michelin-star menu" that balances developer empowerment with curated platform choicesThe realities of the 16-month productivity dip and why translating underlying intent beats line-by-line code migration Things to listen for:  (00:00) Meet Marc Cluet (01:34) How platform engineering became everything (02:53) From gatekeeper to enabler of development (06:15) The three buckets for every vendor pitch (10:14) Making developers maintainers too (12:00) The ten-year contract test for bad ideas (14:05) Why 95% of AI pilots fail (16:45) AI hype versus the old cloud hype (23:02) Modernizing mainframes and COBOL with AI (29:00) Why AI is not the new Stack Overflow (34:21) Building the Michelin star menu (41:00) The first MCP server worth building (44:01) The mixing board every IT org is tuning (48:05) Rapid fire questions (50:00) Predictions: AI ops roles three years out (52:09) Defining a Coder: The double-edged sword Resources Marc Cluet's LinkedIn: https://uk.linkedin.com/in/marccluet

    AI Didn't Break Your Platform, Your Mess Did
  2. Sep 30

    How an AI Agent Broke Into Hugging Face During an OpenAI Test

    An AI model broke into Hugging Face to cheat on a test. Not to make a point, not out of anger, just to win. Nicky Pike walks through two incidents from this summer that read like a heist movie until you strip away the sci-fi. In July, an OpenAI research agent found a zero-day nobody knew existed. It escaped the sandbox it was supposed to be sealed inside and spent four and a half days inside Hugging Face's production systems stealing credentials and minting itself access. A few weeks later, the UK's AI Security Institute ran its own evaluation and watched an agent fabricate fake identities and try to talk a real open-source maintainer into approving malicious code. Nicky borrows a detective's toolkit to make sense of both. Means, motive, opportunity, the usual three, minus the fourth thing every crime show assumes is there: malice. What's left is a mental model for how much of the real world an optimizing system will reach for once you hand it a goal, and a four-letter framework for actually containing it before it happens to you. If your company is standing up agents this quarter and calling it a productivity win, watch this episode first. In this episode, you'll learn: Why commercial AI tools refused to help Hugging Face investigate its own breachThe four-letter framework Nicky uses to actually contain an agentWhy a nicely worded prompt is not a security control Things to listen for:  (00:00) An AI agent breaks out to cheat (00:54) Why the safety filters got switched off (01:45) It stole the answer key from Hugging Face (02:43) The detective framework means motive and opportunity (03:41) Climbing the ladder inside Hugging Face (04:35) Minting itself access to source code (05:40) The boring plumbing that saved Hugging Face (06:41) Why AI safety tools refused to help (07:41) A second lab runs the same test (08:36) Fake identities and a human who said no (10:28) What saved the day both times (11:24) The one leg you can actually attack (12:26) Building the CAGE: Contain, Access, Guard, Exhaustive (14:18) Three questions to ask before trusting an agent (15:19) The scary part was never the malice Resources: Nicky Pike's LinkedInOpenAI and Hugging Face partner to address security incident during model evaluationThe Hugging Face incident and the road ahead | OpenAIThe OpenAI-Hugging Face ExploitGym Incident: A Complete Technical TimelineOpenAI Hugging Face Hack, What the ExploitGym Incident Actually ProvesThe Benchmark That Broke Containment: An OpenAI Evaluation Model Escaped Its Sandbox and Breached Hugging FaceIncident Report: unsanctioned agent behaviour during cyber testing | AISI Work

    How an AI Agent Broke Into Hugging Face During an OpenAI Test
  3. Sep 23

    95% of the World Is Clueless About Platform Engineering

    Everyone said AI would reduce the need for developers. Instead, it made one kind of engineer more important than ever. Luca Galante runs the largest platform engineering community on the planet. Besides hosting PlatformCon, he has also spent years watching real enterprises turn flashy AI demos into systems that hold up in production. Currently, he serves as managing director at Weave Intelligence, the analyst firm tracking how the platform model is reshaping enterprise technology. In this conversation with Nicky Pike, Luca explains why most companies now run an internal developer platform without agreeing on what it's for. He also expounds on why a platform built to serve a thousand engineers suddenly has to support an entire company once agents show up, and why he still thinks 95% of the world is clueless about the discipline that's about to decide whether AI gets deployed safely or not at all. They also get into Luca's new book, Thinking in Platforms, and his thoughts on why demos get applause they don't deserve. He also mentions the one prediction he's willing to put a number on: how many platform teams will actually survive this year? If your platform team just got handed a pile of agents and told to make it safe, this is the conversation that tells you what happens next. In this episode, you'll learn: Why automating yourself out of a task usually means getting handed a bigger oneHow a good platform works like a paved road, not a rulebookWhy product managers are becoming the missing link between platform teams and everyone else Things to listen for: (00:00) Meet Luca Galante (02:10) Why platform engineering never had a name (04:15) The relief of finally having a name (07:35) Why AI debates are really about platforms (09:15) Inside the new book Thinking in Platforms (11:10) Why the media team dogfoods platform engineering (18:35) Why AgenticCon needed its own event (20:15) Behind the 90% platform stat (28:50) Rebuilding platforms for machine scale (31:25) Luca's 3-layer agentic development stack (37:40) Why product managers bridge platform teams (43:40) Moving from writing code to setting constraints (49:05) Rapid fire on demos and paved roads (54:45) Predictions: How many platforms will survive Day 100 (57:00) Defining a Coder: Being able to help Resources: Luca Galante's LinkedIn: https://www.linkedin.com/in/luca-galante/ Weave Intelligence website: https://weaveintelligence.io/

    95% of the World Is Clueless About Platform Engineering
  4. Sep 9

    Are You Really Learning to Code If AI Does It for You?

    John Crickett spent 30 years teaching himself to build software the hard way, and he thinks that's exactly why he's still employable. Long before anyone typed a sentence and watched an app appear, John Crickett was writing Quake bots downloaded by millions, chasing a bed and breakfast search engine years before Airbnb existed, and getting laughed out of a VC pitch for an idea he called takeaways online. Today he runs Coding Challenges, where thousands of engineers go to relearn a skill AI is quietly letting them skip. In this episode, John sits down with Nicky Pike to make an argument a lot of the industry won't like. Cranking out code has never been easier. Building the right software, for the right people, for the right reasons, is exactly as hard as it's always been. They get into what's actually driving the record number of AI projects getting scrapped before launch, why John still thinks coding and software engineering are two different jobs, and why he's calling the entire AI industry a bubble, on record, with names attached. If you've ever handed AI a one-line prompt, gotten back exactly what you expected, and wondered why that felt hollow, this conversation is for you. In this episode, you'll learn: The CEO of You, Inc. mindset he uses to justify learning outside of workWhy test-driven development is about thinking, not testingThe one prompt trick that turns any AI into a real coding mentor Things to listen for: (00:00) Meet John Crickett (01:20) Studying AI decades before it was cool (06:00) From Quake bots to startup rejections (12:25) Why AI projects are getting scrapped before shipping (17:15) Can AI write the blueprint too (20:25) What teams skip when AI makes coding easy (25:50) Why fewer engineers are learning to code deeply (31:05) Why you can't learn coding from YouTube alone (37:50) How to prompt AI to actually mentor you (41:30) Why you're the CEO of your own career (48:05) Getting the customer back into the process (50:40) One skill every engineer should learn by hand (53:45) Predictions: Who survives the AI bubble and who doesn't (56:30) Defining a Coder: To actually code (57:15) Final thoughts: Challenge John’s ideas Resources: John Crickett's LinkedIn: https://www.linkedin.com/in/johncrickett/Coding Challenges website: https://codingchallenges.fyi

    Are You Really Learning to Code If AI Does It for You?
  5. Aug 26

    Open Source Security: The Eyeballs Were Never Enough

    6,000 vulnerabilities but only 97 fixed. Nicky Pike can't stop thinking about a stat that a machine found in the open-source code your company almost certainly runs. It all started with 90 seconds of a much longer conversation. A few weeks back, Nicky sat down with Gene Kim for a full episode on citizen developers and the outer loop. Near the end, Gene described a moment from an Erik Meijer talk that stuck with them both: the suggestion that running open source at all might be crazy, that it's coupled to code nobody's actually accountable for. In this minisode, Nicky goes back through 25 years of the open source eyeballs promise and tests it against what happened this year. An AI model was pointed at open-source code and returned thousands of vulnerabilities. Maintainers, already buried, received more bug reports and barely any hands to fix them. Nicky lays out why the gap between finding a problem and fixing it, not the finding itself, has been the real issue the whole time. If your team runs open source and you've never asked who actually fixes it when something breaks, this one will change how you look at that dependency list. In this episode, you'll learn:1. Why cURL went from weekly bug reports to one every 18 hours2. How a stolen npm credential targeted the exact AI coding tools you use3. Why a signed, verified package still shipped malicious code untouched Things to listen for: (00:00) The stats that proved the risks of running open source (00:53) The 90 seconds with Gene Kim that changed everything (01:37) What this episode is not saying (02:23) Linus's law and Gene’s law (03:16) How the XZ Utils backdoor got in (04:14) An npm attack aimed at AI configs (05:09) An AI model gets pointed at open source (06:12) The wolfSSL bug nobody explained (07:06) A 27-year-old claim no one can verify (07:58) Why the fix counter stopped moving (08:50) The maintainer drowning in bug reports (09:41) Why more eyeballs never meant safer code (10:30) What to actually check this Monday (11:22) Why rewriting your own code has a cost (12:17) Closing thought and a question for you Resources:  Nicky Pike's LinkedIn: https://www.linkedin.com/in/nicky-pike/Coder website: https://coder.com/Gene Kim's Episode: Coding Isn't the Bottleneck Anymore. Gene Kim Explains What's NextLinus's LawOne engineer’s curiosity may have saved us from a devastating cyber-attack | John Naughton | The GuardianJscrambler npm Package Compromised: Why It Matters – ReflectizProject Glasswing: Securing critical software for the AI era \ AnthropicCybersecurity Insights with Contrast CISO David Lindner | 04/18/25Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Security Blog

    Open Source Security: The Eyeballs Were Never Enough
  6. Aug 19

    The Thing You Tested Isn't The Thing That's Running feat. Rick Clark

    For 15 years, enterprises have signed off on a promise: the thing we tested is the thing that's running. Rick Clark, Global Head of Cloud Advisory at UST, says that promise dies the moment an agent starts making its own decisions in production. Rick helped build the cloud era himself, from Ubuntu Server to OpenStack to the Four Opens framework that still governs the OpenInfra community today. Now he's telling enterprise leaders that agentic AI is the biggest wave he's seen, bigger than cloud, bigger than open source, and it's compressing a decade of hard lessons into eighteen months. In this episode, Rick and Nicky Pike dig into why most enterprise leaders running agents in production can't fully trace what those agents are doing, why audit is the first promise to break, and why testing something yesterday tells you nothing about what it does today. If your company is racing agents into production before anyone's decided who signs off when it goes wrong, this conversation will change how you think about what "tested" and "deployed" actually mean. In this episode, you'll learn: Why the behavioral envelope replaces the pass or fail test for goodHow one company's 57 secret managers became a warning storyWhy the AI developer scares Rick more than any 2am coder ever did Things to listen for: (00:00) Meet Rick Clark (01:45) The cloud moment that changed everything for Rick (07:20) Is enterprise AI skipping the usual hype cycle (08:30) The stat that says agents can't be traced (13:45) Three promises about production that just broke (18:00) Why production is a promise, not a place (24:45) What a behavioral envelope actually replaces (29:00) How to test something you can't fully trust (32:45) The first thing a CTO should measure now (38:00) The 57 secret manager mess AI will amplify (48:00) Charred bodies and the cost of moving fast (51:00) Rapid fire on banks, AI, and observability (55:15) Predictions: when the tested artifact stops being a promise (58:50) Defining a Coder: promises a machine can keep (01:00:12) Final thoughts: getting this right instead of fast Resources: Rick Clark's LinkedIn: https://www.linkedin.com/in/dendrobates/ UST website: https://www.ust.com

    The Thing You Tested Isn't The Thing That's Running feat. Rick Clark
  7. Aug 5

    If You Wake Up Hoping the Model Got Dumber, Get Out of That Business

    Wave one was everyone grabbing a shovel and vibe-coding as fast as possible. Wave two is the bill showing up. Rob Whiteley has watched this movie before as he ran NGINX through the last major platform shift, and now as CEO of Coder, he's watching companies rack up token bills and security holes from software nobody thought to govern. In this episode, Rob sits down with Nicky Pike (full disclosure, Coder sponsors this show, and Rob signs Nicky's paychecks) to talk about what actually comes after the AI gold rush. They get into why the model layer is the one thing you should never lock yourself into, how to think about tiered model strategy using a tenured employee analogy, and why governance and rules are not the same thing. Rob also breaks down the real difference between a sandbox, a workspace, and a harness, and makes the case for why an engineer driving an agent will always beat a product manager doing the same. If your team is already sitting on a token bill nobody budgeted for, this conversation is your map for wave two. In this episode, you’ll learn: Why letting a product manager drive an agent alone puts your company at riskWhy there will be just as many developers, only far fewer software engineersWhy Rob expects two or three more Anthropic-style upsets before the year is out Things to listen for: (00:00) Meet Rob Whiteley (01:20) Why this wave feels different from cloud (06:59) Betting on infrastructure, not the tools (11:34) The Excel analogy for your job (15:39) One customer went from 800 apps to 10,000 (17:04) Your token bill is AWS all over again (21:40) Rating AI models like tenured employees (24:12) Why nobody saw the token bill coming (31:05) Governance and rules are not the same (36:20) Why an engineer beats a PM (40:47) Sandbox, workspace, or harness, know the difference (46:52) Why Coder refuses to bet on one model (56:48) Should you go vertical or horizontal (1:04:47) Predictions: who gets usurped and who wins (1:07:56) Defining a Coder: what it means to build Resources: Rob Whiteley's LinkedIn: https://www.linkedin.com/in/rwhiteley/ Coder website: https://coder.com/

    If You Wake Up Hoping the Model Got Dumber, Get Out of That Business
  8. Jul 29

    AI Is Writing More Code Than Humans Can Review

    What happens when the AI coder moves faster than the review process can handle? Nnenna Ndukwe has spent 8+ years as a software engineer and now works at the intersection of AI, developer relations, and enterprise engineering strategy. As AI developer relations lead at Qodo, she spends her time helping teams separate useful AI adoption from expensive chaos. In this episode of [Dev]olution, Nnenna joins Nicky Pike to talk about the part of AI coding most teams skip: review, verification, governance, and the outer loop where AI-generated code either gets controlled or breaks production. They dig into why AI does not fix broken engineering systems, how rework rate exposes the truth behind AI productivity, and why better code review needs more than another stream of AI comments. What it needs, instead, are deterministic gates, developer trust, and a clear view of where AI belongs in the software delivery process. If your team is shipping faster but fixing more, this episode will make you rethink what “AI productivity” actually means. In this episode, you’ll learn: Why rework rate may expose AI productivity better than velocityHow deterministic gates keep AI review from becoming noiseWhere engineering leaders should introduce AI firstThings to listen for: (00:00) Meet Nnenna Ndukwe(01:52) From writing code to advising leaders(04:09) Why AI made the work more interesting(07:02) Paying it forward in women in tech(09:23) AI speed is breaking production(10:30) Where the delivery jam really happens(12:32) Why rework rate tells the truth(15:42) Can AI review AI code(17:21) AI amplifies your current process(20:34) The risk of AI review slop(23:19) Why acceptance rate matters(26:27) Human-agent work needs better rules(29:23) More tokens is not discipline(36:44) Where leaders should start(41:25) Predictions: More managing systems(45:49) Defining a Coder: A problem-solver (47:08) Final thoughts: Cut the noise of AI hype Resources: Nnenna Ndukwe’s LinkedIn: https://www.linkedin.com/in/nnenna-ndukwe/Qodo website: https://www.qodo.ai/

    AI Is Writing More Code Than Humans Can Review

Ratings & Reviews

5
out of 5
2 Ratings

About

The development world is cluttered with buzzwords and distractions. Speed, focus, and freedom? Gone. I’m Nicky Pike. And it’s time for a reset. [Dev]olution is here to help you get back to what matters: creating, solving, and making an impact. No trend chasing, just asking better questions. What do devs really want? How can platform teams drive flow, not friction? How does AI actually help? Join me every two weeks for straight talk with the people shaping the future of dev. This is the [Dev]olution.