I build the infrastructure other engineers deploy on.
AWS, Kubernetes, Terraform — and production AI tooling that helps engineers operate it without giving agents direct access to production.
Safety model read / write split
The assistant reaches the read server, which queries Prometheus, Kubernetes state, and bounded logs using a read-only service account. Separately, the assistant reaches the action server, which holds no cluster credentials and can only open a GitHub pull request. A human reviews and merges that pull request, and only then does the delivery pipeline apply the change to the cluster. There is no path from the agent directly to the cluster.
no direct path to the cluster
Engineer
+ assistant
read server
read-only identity · 4 tools
action server
no cluster access · 1 tool
Prometheus · K8s
bounded logs
pull request
capped diff, reviewed
cluster
pipeline applies
The safety model behind the AI ops layer: the agent reads production, but the only way it can change anything is a pull request a human merges.How it works →