Skip to content

Instantly share code, notes, and snippets.

View rhuss's full-sized avatar

Roland Huss rhuss

View GitHub Profile
@rhuss
rhuss / agent-security-resources.md
Last active September 15, 2026 07:27
Securing AI Agents on Kubernetes: resources (Code Europe 2026, Warsaw)

Securing AI Agents on Kubernetes: Resources

Companion links for the talk Securing AI Agents on Kubernetes: Identity, Sandboxes, and MCP Tool Governance Code Europe 2026, Warsaw · Dr. Roland Huß, Red Hat

The one-sentence version: put the controls in the environment, not in the prompt, and start at the bottom, because everything above the sandbox is advisory if the sandbox leaks.


Slides and demo

Audience Q&A: Code Europe, 2026-09-14

Questions from the session chat for "Spec-Driven Development: Making AI Coding Assistants Build What You Actually Want". Some were answered live, the rest afterwards. Names are omitted.

Questions are grouped by theme rather than by the order they arrived, because several people were circling the same thing from different directions.

Specs over time

After a spec is merged and the requirement changes, do we update the existing spec or create a new one?

@rhuss
rhuss / sdk-proto-drift-issue-draft.md
Last active August 19, 2026 15:27
Draft upstream issue: SDK proto drift detection and sync notifications

Upstream Issue Draft: SDK Proto Drift Detection

Issue Title

feat(ci): automated proto drift detection and SDK sync notifications

Issue Body

User Story

@rhuss
rhuss / openshell-dev
Created June 26, 2026 16:02
openshell-dev: Manage a dev OpenShell environment built from source (gateway, supervisor image, CLI)
#!/usr/bin/env python3
"""Manage a dev OpenShell environment built from source.
Unified tool for gateway lifecycle, supervisor image builds,
CLI symlinks, log management, and brew service coordination.
"""
import argparse
import os
import platform
@rhuss
rhuss / voice-transcribe.sh
Created June 11, 2026 09:16
Local mic-to-text transcription using ffmpeg + whisper-cli (macOS)
#!/usr/bin/env bash
#
# voice-transcribe.sh - Local microphone-to-text transcription
#
# Captures audio from the default microphone using ffmpeg (avfoundation),
# detects speech segments via energy-based VAD, and transcribes each
# utterance with whisper-cli. Transcripts are printed to stdout and
# optionally appended to a file.
#
# Dependencies: ffmpeg, whisper-cli (brew install ffmpeg whisper-cpp)
@rhuss
rhuss / gist:56079081688ae1b54433542d446ce529
Last active May 22, 2026 12:04
Claude Code in OpenShell 0.0.46 on macOS/Podman (libkrun): complete working setup

Claude Code in OpenShell 0.0.46 on macOS/Podman (libkrun)

Environment

  • macOS 26.5, arm64
  • Podman 5.8.2 (VM type: libkrun)
  • OpenShell 0.0.46 (Homebrew)
  • Claude Code v2.1.148
  • Auth: Google Vertex AI (Application Default Credentials)
@rhuss
rhuss / Containerfile
Created May 20, 2026 08:31
OpenShell sandbox Containerfile for Claude Code (cc-deck) - reproduces getifaddrs issue with Vertex AI auth
# GENERATED BY cc-deck.build --target openshell - DO NOT EDIT MANUALLY
# Regenerate with: claude /cc-deck.build --target openshell
FROM ghcr.io/nvidia/openshell-community/sandboxes/base:latest
ARG TARGETARCH
# Layer: System packages (Ubuntu 24.04, apt-get)
# Pre-installed: git, node v22, npm, python3, curl, make, claude, gh, uv
USER root
@rhuss
rhuss / migrate_influx_db.pl
Last active January 5, 2021 20:18
Migration script for migration from a very old InfluxDB installation to a recent version (e.g. 0.7.0 to 1.8.3)
use InfluxDB;
use Data::Dumper;
use REST::Client;
use strict;
# Script for migrating data from an outdated InfluxDB to one of the
# latsest version.
# Developed for migrating from an InfluxDB 0.7.0 to a 1.8.3 version in one go
# ------------------------------------------------------------------------
@rhuss
rhuss / Dockerfile
Last active June 22, 2020 21:33
Restic + Rclone for ARM
FROM golang:1.13.10-buster AS builder
ARG VERSION_RESTIC=v0.9.6
ARG VERSION_RCLONE=v1.51.0
WORKDIR /opt
RUN apt-get update \
&& apt-get install -y \
git \