Every time I see these posts I encourage people to follow everyone in the replies.
There’s definitely people on here doing this, we have to build our circle of followings so we can share with each other!
I’m doing two techniques for this:
1- Test homelab box (no private data) where I just give AI direct access (currently grok bot) so I can see all the mistakes and problems this can cause (like grok bot using my PAW for a Tailscale relay - see image…), plus how fast it can work without constraints.
2- At work, where I build systems around CNI, I’m using Infrastructure as Code (Terraform, Ansible) with security gates/tiering via pipelines (GitLab).
Two extremely important components of this:
- No AI agent has access to privileged credentials - these are gated behind GitLab protected branches and human review.
- Indeterministic AI actions are converted into deterministic instructions by writing the IaC - it will do *exactly* what is in the runbook/Ansible role/Terraform plan.
This solves the risks at a fundamental level whilst granting the productivity gains from AI. I can deploy and manage stuff super fast because the AI can do all the research on syntax and write the IaC in minutes. But I still have total control, and any changes to infrastructure are because I said “yes”.
It’s actually beautiful because we get to ride the coattails of how good AI is at coding…
Screenshot examples of both below (note, all on my test lab, I use both techniques here for experimentation)