<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Agents on Marcus Pichler</title>
    <link>https://pichler.dev/tags/agents/</link>
    <description>Recent content in Agents on Marcus Pichler</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <managingEditor>marcus@pichler.dev (Marcus Pichler)</managingEditor>
    <webMaster>marcus@pichler.dev (Marcus Pichler)</webMaster>
    <lastBuildDate>Sat, 25 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://pichler.dev/tags/agents/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Meet Konrad: The AI SRE That Runs My Infrastructure - and Can Never Act Alone</title>
      <link>https://pichler.dev/blog/alois-sre-konrad/</link>
      <pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><author>marcus@pichler.dev (Marcus Pichler)</author>
      <guid>https://pichler.dev/blog/alois-sre-konrad/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Konrad&lt;/strong&gt; is a self-hosted AI Site Reliability Engineer. He lives inside &lt;em&gt;Alois&lt;/em&gt;, my LangGraph-based agent platform, and he has &lt;strong&gt;88 tools&lt;/strong&gt; - Prometheus, Loki, kubectl, ArgoCD, Proxmox, Wazuh, OPNsense - wired directly into my homelab. He can query metrics, read logs, correlate alerts, and, when something is actually broken, restart a deployment, delete a crash-looping pod, drain a node, or patch a host.&lt;/p&gt;&#xA;&lt;p&gt;The interesting part is not that an LLM can call &lt;code&gt;kubectl&lt;/code&gt;. That is easy, and mostly a bad idea. The interesting part is the gate: &lt;strong&gt;17 of those 88 tools are destructive, and no language model decides whether they run.&lt;/strong&gt; A deterministic, pattern-matched quarantine intercepts every mutating call and holds it until a human taps &lt;strong&gt;[Erlauben]&lt;/strong&gt; (&amp;ldquo;Allow&amp;rdquo;) in Telegram. The model proposes; a human disposes; the cluster only changes after a single-use, target-bound approval token is consumed.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
