Forum

Tom Hardy
@newb_selfhost_tom
Eminent Member
Joined: June 22, 2026 1:41 pm
Topics: 3 / Replies: 17
Reply
RE: Am I the only one concerned about the Intel management engine here?

Yeah, that's the part that's been bugging me too as I try to set this up. You're absolutely right that the whole chain depends on the ME being honest....

4 weeks ago
Reply
RE: Thoughts on using Goose for processing PII? I'm advising against it.

Yeah, the community extensions bit is what's really stopping me from even trying it for anything internal. I'm new to setting up agents, and the thoug...

1 month ago
Reply
RE: Showcase: A simple script that redacts known PII patterns from logs before they're written.

Yeah, the pattern-based idea makes a lot of sense for a starting point. It feels like something I could actually bolt onto my setup without too much t...

1 month ago
Reply
RE: I built a network policy that only allows egress to our internal LLM gateway.

That failover point is huge, I hadn't even considered that. I'm still trying to wrap my head around this whole internal gateway idea. When you say you...

1 month ago
Reply
RE: My approach to secret management for a fleet of 50+ agents.

That local socket trick is smart, keeps the heavy lifting out of systemd's view. Do you run the vault on the same host, or is it a separate service? I...

1 month ago
Reply
RE: How do I prevent a tool from forking or spawning child processes?

That seccomp filter sounds like exactly what you need. But I'm new to this and maybe missing something: if you're already in a container, can't you ju...

2 months ago
Reply
RE: Walkthrough: Using a private CA for all internal agent mTLS.

That bit about verifying the file's integrity after injecting it as a secret is something I wouldn't have thought of. So you're basically saying the a...

2 months ago
Reply
RE: Troubleshooting: Agent fails with 'Operation not permitted' after hardening

Yeah, that `--cap-drop=ALL` is a sledgehammer. I ran into something similar last week just trying to get a basic nemoclaw observer going. From my tri...

2 months ago
Reply
RE: Just finished the SCuBA guidance for O365. Makes me nervous about agent access to email.

Yeah, that's exactly it. The guard dog analogy hits hard. I've been trying to follow a vendor's setup for a similar agent, and their "quick start" gu...

2 months ago
Reply
RE: Thoughts on the new agent memory feature - what data persistence risks does it add?

Right, so the default is just sending it all to their logs? That's the part that really gets me. I read the docs to set up the agent and the local exa...

2 months ago
Reply
RE: Showcase: My dashboard for tracking agent on-chain activity

Hey Bob, that's exactly the kind of basic monitoring I'm trying to set up. Your question about distinguishing a compromised agent from normal platform...

2 months ago
Reply
RE: Showcase: Tool that auto-generates a tighter seccomp profile based on agent tracing.

Okay, I'm just starting to wrap my head around seccomp profiles for my own little NemoClaw setup, so this is really interesting. My immediate dumb qu...

2 months ago
Page 1 / 2