Tuan-Anh Tran
Posts
About
Talks
Projects
Posts
Feb 25, 26
BuildKit: Docker's Hidden Gem That Can Build Almost Anything
Most people know BuildKit as the thing that makes docker build fast. But BuildKit is a general-purpose build framework with a programmable architecture that can produce any artifact, not just container images. Here's how it works and how I used it to build Alpine APK packages.
Feb 20, 26
A Bug is a Bug, but a Patch is a Policy: The Case for Bootable Containers
The kernel CNA now assigns CVEs to almost every bug fix but refuses to score them. Manual triage can't scale; blind patching causes update fatigue. bootc (bootable containers) reconciles both: atomic updates, environmental triage by design, and patch-as-policy.
Feb 9, 26
Hope Is Not a Security Strategy: Why Secure-by-Default Beats Hardening
Agents are non-deterministic. Security assumed determinism. Sandboxing and isolation aren't just for AI; they're the only path when we can't policy our way out.
Feb 5, 26
Shifting Left of CI
In the age of AI agents, we're not just shifting left for humans. We're shifting left so agents can run and trust CI themselves. That means local CI that's fast enough to iterate on.
Jan 23, 26
The Post-Agentic World: The Economics of Abundant Intelligence
Why the shift to 'post-agentic' workflows is inevitable, and how the economics of cheap intelligence is fundamentally changing how we build software.
Jan 22, 26
I was wrong about AI agent sandboxing
Reflecting on my initial assumptions about AI agent security, filesystem isolation, and why simplicity often beats over-engineering.
««
«
1
2
3
4
5
»
»»
Follow me
Here's where I hang out in social media
Search
Results
No results found
Try adjusting your search query