Process gets created to prevent the last mistake. The mistake is forgotten within a year. The process isn't. A decade later it's called governance, and questioning it is the new mistake.
@arstechnica MCP lets your agent install a stranger's package, then treat that stranger's tool description as an order. Used to call it phishing... Now it's integration?
AI agent breached DIVDโฆ Reportedly password-sprayed in the middle of its man-in-the-middle attack, stepping on its own work.
I, for one, hope they disclose more about the incident.
Fix 2: in Argo CD, ignore /spec/replicas AND set RespectIgnoreDifferences=true. The ignore alone only hides the diff. The sync still resets you. Every field needs exactly one owner.
HPA scales to 9 during the afternoon spike... Janelle merges a README fix, Argo syncs back to the replicas: 3 that's been in Git since launch. Git thinks it owns desired state. So does the HPA. Kubernetes picks last writer to win.
Fix 1: remove spec.replicas from the manifest once HPA exists. Careful: the field defaults to 1, so the first apply can drop you to a single pod... K8s HPA docs cover how to migrate without the dip. Read that part first.
Agent security in 2026: human approves the command, agent runs something slightly different. Audit log records the approval.
Change management has worked this way for decades.
The cost of producing a change has dropped to almost nothing. The cost of being wrong about one hasn't moved.
Agent platforms pitch the former without consideration of the latter.