Agents, Engineers, and Citizen Developers
Dan and Cory O’Daniel discuss how infrastructure agents gain safe autonomy through modeled context, separate identities, and enforceable permissions. Cory shares Massdriver’s development and testing workflows and argues that engineers should build guardrails for citizen developers.
Show notes
Cory O’Daniel is CEO and co-founder of Massdriver, an internal developer platform and platform orchestrator for governed self-service infrastructure using Terraform, OpenTofu, and Helm. He has spent more than 20 years building teams and startups and working with cloud infrastructure. He created Bonny, an Elixir-based Kubernetes operator framework, and is a co-founder of OpenTofu.
Massdriver gives developers self-service cloud infrastructure through diagrams backed by modules approved by their operations teams. Agents pushed the company to redesign its API around context. Because the platform models the connection between an application and a database, it can answer what depends on what. An agent does not have to reconstruct those relationships from cloud API responses.
Cory starts safe infrastructure changes with the agent’s identity. Giving Claude a person’s credentials hides which actor made a change and gives the agent more access than it needs. He argues for attribute-based permissions that encode business rules. An agent might be allowed to provision databases in staging but blocked from resources that store personally identifiable information. Agents can help draft those classifications. The people who know the business still need to review them.
They then discuss Massdriver’s four-person team and the code that supports its agent-assisted development. Cory credits test-driven development and a consistent domain model with giving Claude useful examples. He recommends assigning agents neglected maintenance, such as flaky tests and linting, while engineers work on features. In one cleanup, an old domain name had to be changed in tables, foreign keys, and variable names. The team had deferred that work repeatedly.
Cory expects more engineering work to focus on reliability, DevOps, and quality controls that let people outside engineering ship software. Automated gates still need a person to review the logic.
For his own coding, Cory runs several Claude Code sessions in Ghostty and gives them small skill files. He favors examples and rules the codebase can enforce over long instruction files or agent memories that may carry irrelevant facts into later work. For marketing work, he provides the company’s actual writing and shared materials. In both cases, the goal is to give agents context that other people can inspect and reuse.
Massdriver Architect applies the same idea to infrastructure changes. Cory can ask for a Postgres module change while limiting the agent to development releases and staging environments. Release channels run plans, compliance scans, and real deployments. Claude connects to the database to check the requested feature, and Cory marks the release stable before it reaches production. An SQS FIFO example covers several configurations and the full provision, reapply, destroy, and rebuild lifecycle. Presets give developers examples and provide test cases. Shared provisioners keep common tooling in one place across modules.
Cory says Terraform is easy compared with satisfying an organization’s requirements. A database request has to meet its security, compliance, spending, and reliability rules. He expects citizen developers to choose services such as Vercel and Supabase, and thinks easier private networking would make those platforms stronger alternatives to the large cloud providers. He gives one warning from a music company with 63 applications spread across Vercel and employees’ laptops. A sales tool stopped working when its creator took the laptop home.
They end by discussing how engineers can support people who understand a business problem but not the software toolchain. Cory says domain experts should be able to iterate without waiting on an engineering backlog. Rejecting their work leaves the business with fewer ways to solve its problems.
Collaboration around back-end changes is still unresolved. Massdriver’s sales employee can publish applications through Architect without installing Git. The code is versioned in an immutable OCI registry and can later move into Git. Cory says engineers should build safe paths that let these new developers deliver useful software.
Chapters
From this episode — Cory O'Daniel
Terraform's easy. Organizations are complex.
Have it do the thing that you wish you had the time to do in your code base and you go work on the feature that the PM's asking you for at the same time.
We spend a lot of human time making sure that even though our quality gates passed, that we're happy with logic, happy with the reasoning there.
They need good ways to get their applications into production safely, not going around your team, which is what they're doing today.
Mentioned
- Massdriver
- Infrastructure platform modeling environments and governing self-service cloud deployments
- Massdriver Architect
- Claude plugin driving context queries and governed infrastructure deployment workflows
- The Citizen Developer
- Cory O'Daniel's article on citizen developers and the guardrails they need
- Cory O'Daniel's personal website
- Cory O'Daniel's personal site
- Terraform
- Infrastructure tooling discussed through modules, configuration, and lifecycle tests
- OpenTofu
- Infrastructure tooling used in Cory's agent-driven module workflow
- Postgres
- Massdriver's data store and the subject of a deployment example
- GraphQL
- API technology exposing resource relationships and expressive infrastructure queries
- Kubernetes
- Container platform used in deployments and infrastructure test environments
- attribute-based access control
- Permission model constraining agents by environment and resource classifications
- test-driven development
- Engineering practice Cory credits with giving agents reliable code examples
- domain-driven design
- Approach shaping codebase terminology and consistent examples for agents
- Ghostty
- Terminal used to run multiple Claude Code sessions in parallel
- Checkov
- Compliance scanner discussed in infrastructure plans and shared provisioners
- Wiz
- Security scanner discussed as part of infrastructure provisioning toolsets
- Snyk
- Security tooling used as an example of replaceable provisioning checks
- GitOps
- Infrastructure workflow Cory critiques for scattering configuration across repositories
- OCI
- Artifact registry standard used to store versioned application source code
- Elixir
- Language used in Massdriver's codebase and Cory's specialized coding agent
- Golang
- Language whose opinionated tooling informs Cory's approach to quality
Transcript
Today, people who aren’t traditional software engineers, or as we’ll call them, citizen developers, can, with an agent and enough patience, create useful software. This creates a new, important job for software Make it possible to take a citizen developer’s software and secure it, deploy it, and make it robust.
In this episode, we discuss how software engineers can think about this new aspect of the job and how this relates to agentic DevOps and infra management. Welcome to Agents and Engineers. I’m your host, Dan Gerlanc. Today’s guest is Cory O’Daniel. Cory is the CEO and co-founder of MassDriver, an internal developer platform and platform orchestrator that helps teams turn Terraform, OpenTofu, and Helm into governed self-service infra.
A software engineer and CloudOps veteran. He has spent more than 20 years building teams and startups working with cloud Infra. In this episode, we also discuss thinking about identities and permissions for agents. Testing cloud infra rollouts in an agentic loop.
and how we’re all citizen developers in one way or another. Enjoy the show.
Yeah, so we’re well, today we’re what’s referred to as a internal development platform. So the idea is give developers self-service to the cloud, make it easy for them to manage infrastructure configurations without them having to learn your ops team’s tooling. So can a developer manage a Kubernetes cluster, put apps in it, manage their databases, keys, et cetera, without them having to learn Terraform? And so the idea is pretty straightforward. Your operations teams takes
the IAC tooling, all the stuff that they already write today, Docker files, Terraform, et cetera. They push it into our registry. And then instead of your developers, you know, hunting down a bunch of different GitHub repos and kind of piecing together miles and miles of YAML, they diagram. So you go to our platform and you diagram what you need from the cloud, and that all gets provisioned based off of the modules that your operations team’s uploaded. So you’ve given developers this autonomy to get what they want, but you’ve also given them
Guarantees that it’s going follow your compliance, security, et cetera, because it’s all using sanctioned models by your ops team. Now, we’re currently in the process of launching. I I’m not sure when this is going to come out, so I’m not sure if like people have launched this, but we’re essentially launching our agentic development platform as well, which is a platform designed for agents and citizen developers to be able to access and manage applications in the cloud as well.
Yeah. I mean it’s changed it in quite a few ways. So we actually went back and did a pretty deep rethinking of almost everything in the product from how like our RBAC permission system works all the way down to our API. And so when we originally built Massdriver, you know, we had a a a fairly like rest feeling GraphQL API. And what became very obvious with agents is like context is important.
And behind the scenes in Massdriver, one of things that’s really interesting, I think that sets us kind of miles apart from a lot of the other things in the space is you actually model your environments. So like your environments are first class resources in Massdriver. And so we spent a lot of time rethinking how to design an API to provide the most amount of like custom context to a caller, whether that’s a person or an agent. agents love context, but believe it or not, humans love it too.
this is one of the things we learned, like while we’re designing for agents for this thing, all of our customers are like, this is just an easier to use API, right? But we’re designing for this new scale of like thousands of ephemeral people, air quotes, interacting with it. And so, you know, one of the things we’re trying to do is make sure that even at the API level, like you can ask a question and get real facts, right? And so if you think about how you do this today, let’s say I’ve got a bunch of stuff in AWS and I ask Claude, like, hey, like where
What’s using this database? Claude literally cannot answer that question. Right? Like, where is this database first? Like it’s got to go hit a bunch of different AWS APIs just to find it, and then it finds it. It’s like, okay, I found the RDS, right? But then how does it know what’s using it? Is it based on subnet rules? Is it based on who’d got the environment variables? Like, there’s no way for it to tell. But in Massdriver, you’re actually modeling this stuff. So like when you’re drawing it on like the canvas, I see the application is attached to the database. You draw that line.
And Massdriver automates the subnet rules, automates the environment variables. We actually know this app is using this database. And so what’s really cool is like one of the things that agents kind of forced us to do is rethink how we deliver information to people. So you can do things in our API now, like find every staging environment that has a database that’s in use that is a T3 micro. And you can ask an extremely expressive question. No AI on the back end there.
And say, hey, here are all of your environments that specifically have T3 micros on a database that’s in use by an application. And you can even say like that is a Lambda or that is in a Kubernetes cluster, right? And so now as an agent, you think about like day two, an agent or a person can now ask extremely detailed questions and get back an extremely small, compact response instead of like 2,000 pages of VPCs and subnets and whatnot that’s coming back from the AWS CLI.
No, it’s actually so dumb on the back end. so like one of the things with Massdriver that’s kind of different is we’re we have a we have a SaaS platform, but we have a very old school business model. We sell you our software. You you buy a license and we give it to you and you run it. and this is important because most of our customers are high compliance, high security operations teams, data centers, and whatnot. so they they don’t want stuff leaving. And so one of the things that’s crucial for us is having the minimal amount of dependencies in Massdriver as possible.
So behind the scenes in Massdriver, it’s just the only data store we have is Postgres. So it’s all built on Postgres’s full text search, et cetera, just doing snowflake type design in the database. So it’s just all good engineering practices for like how you design and organize search and data and relational database. And then we just expose that in a very expressive, directed graph way in our GraphQL API.
So it lets you kind of traverse relations, fetch the data that you need, filter, et cetera.
So one of the things that we we do a bit different, like, and this is what like the heart of Massdriver is, is we’re essentially your state for the cloud, right? And it’s funny, like when most people look at infrastructure operations, it’s like, where is the state? It’s like, well, we do GitOps. Where is the state? It’s like, well, it’s it’s the code that’s in Git. And it’s like, well, that sucks, actually. I mean, I know we’ve been doing it that way for 20 years,
but it sucks, right? Like if I’m like, hey, where is this database? Where is it?
Is it the code or is it the state file or is it what’s in Amazon, right? And so Massdriver is that state storage. It is that configuration storage. So like our database is essentially the source of truth. So anything that one of our users is managing through Massdriver is very easy to kind of tie into the data plane. Like we are the authoritative writer and reader of that configuration. Things that are outside of Massdriver suck because you don’t have means of going about it, right? So
We have tools to like be able to bring in your infrastructure and generate IAC and whatnot to get people up and running quickly. But you know, as long as it’s managed through the platform, it becomes very trivial because it’s just kind of saying like here’s the IAC module, here’s the inputs, here’s the state, and Massdriver keeps track of where all that is and can kind of, you know, fold over that data to, you know, do the querying and whatnot and return it.
So you have said that state tells you what exists and context tells you what it means.
What do you think the minimum context an infra agent needs to be able to make safe infra changes?
A, I think the minimum thing it needs is its own identity. Right. I see that like this is this is the thing I see people I feel like fumbling over in their OpenClaw lives and in their infrastructure agent lives is like like what is my agent, right? And most people see it as an extension of themselves. I see them as I don’t want to say people or things, but like they they have identities to me, right? And it’s funny, like
internally at our company, like I will refer to an agent not by like a name, but I’m like, that’s my Elixir agent versus like that’s my social media content writing agent or tweet writing agent or whatever it is, right? And so it’s like they have different context, they have different data that’s loaded in them. But I think identity is really key and I feel like that’s where a lot of people kind of screw the pooch for lack of a better term, with managing their agents is just saying like, hey, this
is a technical term. Right? They just give it their access, right? And so
In Massdriver, one of the things we do is like the agents have identity. Like they’re they’re effectively a service account, but they have they they have their own thing. So it’s designed so it’s like you give these agents their own accounts and they have their own permission systems, right? And so I think one of the other things that’s very key to making that plausible is I think a lot of companies and a lot of SaaS providers, a lot of SaaS tools are gonna have to rethink how their permission systems work to make this plausible in the future. One of the things that sucks about
agents is they’re ephemeral, but the things that they do can also be ephemeral, right? And so if we think about DevOps and devs trying to access the cloud, right? There was this long time where devs would have to ask an ops person to do something, right? And then we created DevOps. A lot of companies ended up in ticket ops. We’re like, hey, we do DevOps, we just do it through Jira. And we’re still at that same point. I’m an agent and I need to make a database for something. How do I do that? Do I have the rights to make as many databases as I want?
Probably not. That sucks. I don’t want Claude to make a thousand databases. But if I only wanted to be able to manage one database, then I have to make it first, right? In AWS, I have to go make the database and then give it rights. And so one of the things I think that’s going to be really crucial for an agent-centered world in development is many of the tools that we have today are RBAC-based, they’re role-based. And I think that one thing that has to change is I think we’re gonna have to move towards like more classification-based permission systems like ABAC, where you can say, hey,
This agent doesn’t have the ability to create databases. It doesn’t have the ability to manage that database. It has the ability to make non-PII stored Postgres databases in staging environments. Right. And so you’ve given it its permissions based on a classification of what it’s allowed to do. And I think that mixed with identity is one of the things that really gives an infrastructure agent a lot of power and autonomy without necessarily exposing a ton of blast radius.
that’s
a great question. That’s a great question. most companies already do this. They just do it in Jira docs and Slack and you know old documentation that they don’t care about anymore. So one of the key things with this is at Massdriver, we actually have an attribute registration system. So at the org level, you come in and say, here’s all the different attributes that are available on all like the first class resources of Massdriver. So Massdriver has projects, environments, OCI repos.
And you can actually extend the interface of Massdriver and say, OCI repos, they don’t just have a name and they don’t just have source code inside of them, but they might have a class of artifact that’s inside of them, like a Docker image or a Terraform module, or maybe just raw source code. Right. And so you can essentially attach these other fields to any first class object in Massdriver. And when you’re defining those attributes, that lets you as the organization essentially define the rules. So I can come in and say things like,
this is a database type repo. It essentially stores something that provisions a database. It might be Postgres, it might be MySQL, it doesn’t matter. Like this is a database type versus an application workload versus the network, right? And so now I’m classifying the IAC modules or Docker files that manage or that are essentially being provisioned. Right. And so now I can say Claude can make databases. Now it has the ability to use any database module, right? It can make as many as it wants if.
It’s in a staging environment, right? And I say, hey, this environment has a essentially a tier and it’s production or staging or production or dev or whatever it is, right? So you can essentially extend it with your business’s terminology. Maybe you have classifications of like data compliance. This is PII, SOC2, HIPAA, et cetera, right? And so you can say, hey, this database stores this class of information. Claude can never touch anything that stores PII.
Right. And so you already do this today. Like you have these rules. They’re just in lore. You speak you write someplace. You just don’t have them in code for the most part. And these were two of the things that we as we were seeing customers use the platform and starting to see like how agents could run amok, that we went back and kind of redesigned everything from the ground up around these ideas so we could constrain them by default.
Yeah, so I mean we we do internally for sure, but customers definitely do as well. It’s interesting, like there’s there’s enough like there’s enough compliance, like zeitgeist in any of the LLMs where you can actually like expose how our ABAC system works and then say like the type of business that you are. And you’ll actually see that Claude can spit out like a pretty good classification system for you. Right. And so we have a lot of customers when they first
come in they’ll get into like decision paralysis like what should I put in
here? And it’s like, ask Claude what an insurance company or what a healthcare company should classify their data as. And then it comes back and all of a sudden they’re seeing it and they’re like, that makes sense. That makes sense. That makes sense. we don’t do that. And it’s like, great, change that one. Take that one out. Right. Like let it do like the baseline for you. But don’t forget that you’re the expert. Like you know your business more than Claude does, but like it can get through a lot of it for you. So
Yeah, yeah.
So it’s funny. I will say no, not with customers, but internally, yes. So w the reason I say this is we actually have a minimum number of developers that you must have before we’ll work with you. So a and we do this on purpose. Like our our product is designed for developer self service. So it it needs you to have a operations team. It needs you to have enough developers to warrant the effort, right? And the cultural change of like kind of adopting platform engineering. So
You a lot of startups just don’t make sense to use our product. I get there’s some that do on our SaaS platform, but like, you know, where we really see P teams sort of take off is when they have fifty to a hundred plus engineers and you know, they’re kind of struggling to manage stuff. But internally we’re f Yeah.
So they’re already bought into it, they’re doing it, and it’s in
s it’s institutional policy already.
Yeah. But us
internally, we’re four people. And, you know, our you know, I’m I’m CEO, but I’m a operations engineer. I still write code, you know, I not write code. I read PRs twenty hours a week, right? My co-founder’s an engineer. We have one engineer that works on front end, and then our fourth employee is a sales guy. Like we’re it. Like we do customer support and everything. And we’ve leaned into agentic for our development workflows like pretty heavily. I mean, I haven’t written
IAC or code in over a year and a half. What’s happened? Our products gotten more flexible, gotten more stable, gotten faster. And the reason why, and I think this is key is we myself included, like I I’m pretty hardcore about how like anal I am about stuff, right? So I’m a I’m an extreme TDD engineer. I’m super into domain-driven design. And so our code base has always been a very clean
domain oriented code base with tests, right? And so bringing the agent in, it had such a good example base to work from. Now, if I took an agent and I dumped into let’s say one of my last three employers code bases, it’d be a fucking wreck. It would be a wreck and it’d be a lot of hard work, right? And it’s because those guardrails as good examples aren’t there for it to kind of extrapolate from. And I think that is where a lot of not just small companies but even large companies
Really need to spend the effort. Like I see I have friends that, you know, they start playing around with Claude or whatever. And they’re like, what do you mean this is great? Like the code that comes out of this is dog shit. And it’s like, what is your code like in your code base? And they’re like, it’s dog shit. I was expecting this to fix it. And it’s like, you’ve showed it dog shit. And that’s the context that it has is you’re okay with dog shit. Right. So it’s like like you do the work. And what’s crazy is like you can use Claude to do the work. Right. And so, you know, one of the things that we sat down and did.
Massdriver, like we’re we’re very heavy TDD, but there’s like some tests in our test suite that run long because you know they actually boot up a full Kubernetes cluster and like tests actually like running provisioning and like the results and stuff, you know, whatnot. And so there’s places where we have like weird locks and and database stuff, you know. Got like eighteen hundred tests that run in 70 seconds, something like that. And they’re full transactional tests, standing up databases, Postgres, et cetera. But there’s been so some places where we have these like flaky tests.
And it’s just like, man, like I’m doing 50 PRs a day. And then, you know, I’m starting to see, shit, this flaky test that I saw like once a month before, I see seven times a day now, right? And I’m like, hey, Claude, this test is flaky. It’s gonna take me a while to like figure out like what makes it flaky, like go get rid of the flakiness in the test. It’s very good at figuring that stuff out. And so what I’ve been telling a lot of smaller teams and like friends that are starting to experiment is like instead of coming in and like installing this thing and saying, hey, I’m gonna have it do.
my job, like I’m gonna have it write the feature my PM’s asking me for. Have it do the thing that you wish you had the time to do in your code base and you go work on the feature that the PM’s asking you for at the same time. Right. So you have it go and say, hey, you know what? You know, we don’t have a great linting tool. Great. Install it, set up the pre-commit, set up the GitHub actions, get that fucking linter in there, and then have it work through PRs, file by file or lint rule by lint rule, like getting that linter to go green, right?
That is enormously beneficial to you as a human, right? It’s enormously beneficial to the agent going forward. And it’s something that’s like, I don’t know, no PM’s ever gonna give you the time for that in most organizations, right? Like kind of t conquering that level of technical debt. It’s it’s a hard fight to get. And it’s also not super exciting to do. Nobody wants to sit around and make a a thousand changes to a code base to appease a linter. But they know that if they did it, everybody’d have a better time. Great. You know who has all the time in the world?
Claude does. Give it to him. Let him do it. Or it do it.
Too one one of the things like
I said earlier, like we’re extreme. This and this is such a small pedantic thing, but like we’re pretty extreme into domain driven design, terminology and whatnot. And there was some terms that we picked very early on that just absolutely penetrate our code base. Just hundreds of references, files that have the words in it, database tables, et cetera. And these are things that we just started to like mask. And we’re like, we’ll rename the class, but the table underneath and all the variable names, like
We’ll leave that what it was because of the pain in the ass to change it in a thousand tests or whatever. And that was fine until we got to self-hosted. And then all of a sudden customers are like, hey, we’re fiddling around in the Postgres database and like we don’t see an instances table. And we’re like, well, it’s because instances used to be called this, and like we never changed it. We didn’t change the foreign key names either. And so then it’s just like, hey, you know what? Like the surface of our domain is named properly, but like the internals of the code, you’re like, inside the
You know, I I again a DDD person, I’m like, I want a good domain. I don’t give a shit what’s inside the domain. Like if the outside feels good, the inside I can jerk around all I want as long as I’m not breaking that surface area. And so to be able to throw all that renaming at Claude’s like that is something that I would have just never gotten around to do in the next six months, nine months, twelve months because there’s too much feature work. And then just to let Claude just grind on it for three or four hours and get the entire code base like
Every single abbreviation that referenced like the old name changed, right? Like, you know, it’s called instances now, but I think we used to call our instances packages, right? And so like the P, P equals package.get or whatever, right? It’s like change the P too, change it to an I, right? Like it went through and did all that stuff. And like the code’s just so neat and consistent now. And it’s like a person can appreciate that. A person would have never had the time to do it.
And and honestly think like that’s I think that’s gonna be where, you know, and we were kind of talking about this before the show, like I think that five years out from now, there’s only gonna be like three software roles is kind of my my guess. traditional software roles, people that write software. I think there’s gonna be a fourth role of the citizen developer who’s gonna be a person, business expert, et cetera, that does not write software but wills it into existence via Claude.
And of the three roles that I think exist will that will continue to exist in engineering, I think are gonna be SRE quality, making sure the thing is still up DevOps, because they’re more important now than ever with comp compliance and security around this stuff. And then I think the third one where like most of front-end engineers, back-end engineers, like traditional like feature land engineers, I think are gonna end up in like guardrails and quality. Right. And I almost see this world where if you think about like when DevOps came to be, there was ops, there was devs.
We came together, found a way to work together. Ops made it easier for devs to deploy. I think the next iteration of efficiency and autonomy and software development is developers doing the same thing for the citizens. And that is developers building guardrails and code quality pipelines that make it possible for your sales guy to make an SDR app, to make it possible for
the customer experience guy to add a feature that a customer’s been asking for, right? And get that good quality because you as the engineers have been focusing on trying to design this like quality layer that lets other actors deploy ten times a day like we can deploy ten times a day.
No, I I
mean this this is a funny one. I have an answer for it. People are gonna fucking hate it unless unless you’re an Elixir or a Golang engineer and then you’re gonna pick up my vibe pretty quickly. And that is the thing that sucks the most about software developers, and mind you guys, I’m a software developer, I’ve been doing this a while, so I’m talking about myself as well when I say this, is we’re pedantic and we care about shit that the business does not give a single rat’s ass about. Right? Like code quality. Business doesn’t care, CEO doesn’t care.
CEO is there to make money. CEO started company because he had a good idea. He didn’t start company because he was like, I want 40 nerds to like argue about tabs versus spaces. And so I think like when it comes to quality, one of the things that sucks is getting all the engineers to agree on like what is quality? Like, what does quality look like? And the thing that sucked with that is tenures of 18 to 3 months, or sorry, 18 months to three years at a job, like those opinions are changing frequently.
And so it’s funny, like internally at Massdriver, we write in Golang and Elixir. And Golang Elixir has great tooling that’s very opinionated. And we just don’t care. I’m like, I’m going to do it the way the Golang Linter says to do it. And it’s like, I could have an opinion, I could like, I maybe I don’t like the way the code looks, but guess what? The entire programming language community has agreed that this is the way it should look and function. And it’s like, great. I want it to be easy for when I hire any one of those people to come in and be like, this is the way the community does it.
And I think the first thing you have to do is whatever programming language framework you’re in, like are there is there a best practices style guide, open source, awesome Ruby equivalent, right? Of like, hey, this is how you do it well. And starting with that and being like, this is, you know, this is kind of our North Star for like how code quality works. And then working through whether that’s, you know, markdown files, describing your standards or building tooling to enforce those standards, which I think is where the work actually is. I think that’s
That’s the part that people are gonna have to do. And I think, you know, for the most part, writing those in a markdown file is a great way to get started. But we all know that Claude is going to do that or not, right? ChatGPT is going to do that or not. And I think the next step is, okay, well, how do we write, you know, a linter, compiler, you know, tool X that enforces these rules versus just provides guidance. So now Claude can do it at once and then tool can say, uh-uh, that’s not right.
shit, well let me do it again. I didn’t know that we were supposed to use tabs or spaces or you know, whatever pedantic thing people want to argue about. And then instead of Claude having to get it right and then a human going, that’s wrong, let me deny the PR, tooling. That’s what we’re doing now. We’re building tooling to make it easy for people outside of engineering to ship software. Like that is where I see the average developer going from.
Yeah.
Yeah, I mean I you know it’s funny, it’s like I used to be a it’s funny, VS Code, I’m like, what is that? I don’t like I don’t even have an editor on my machines anymore. Like I have I used to use the Claude CLI and I’m like I look at I look at PRs. Like that’s that’s my development flow now. I very very, very rarely like touch code. I look at a lot of code. I read every single PR.
Like I as a CEO, I’m still getting PRs from my team, like and looking over them and I’m sending them my PRs. We spend a lot of human time making sure that even though our quality gates passed, that we’re happy with logic, happy with the reasoning there. I think one of the things that’s important with that is like we’ve gotten so efficient with LLM assisted generation that we’re like, we can go fast, we can go infinity speed. And it’s like, yeah, but you’ve created a lot of time for yourself. Spend half the time it took you that it would have taken you to write that feature just to review the code.
Make sure it does what you want it to do. You’re gonna get more and more confidence. You’re gonna learn more and more things you can build into your tooling that way.
I mean, I think that’s the whole job now. I mean, I think it’s there there’s two platforms to serve. There’s the the the platform that’s providing the like the SaaS and cloud services, and then there’s the platform that’s guaranteeing the code quality. Right. And I think that the DevOps role is gonna be pretty paramount for both of those teams, the citizen devs and your like guardrail developers. But I think the guardrail developers are gonna be building platforms in their own rights, right? Like it’s gonna be a lot of tooling, it’s gonna be a lot of quality controls, but
I mean, that’s that’s what makes businesses move quickly, right? Like your CEOs aren’t super like see your business’s capitalism wants things to go faster. They want things to work efficiently, right? And having a bunch of engineers, like all business logic, having to process through engineers has been a bottleneck that we’ve had for decades, right? Look at how long our backlogs are. Right? Like to be able to get that down to zero, backlog zero. Can I can I quote that?
Back back backlog
zero. Right? Like, I mean, maybe all maybe some of them features are stupid, but you can test that those features are stupid quicker, right? And then say, okay, you what? We’ll cancel that one in the backlog. It was a silly experiment. But you know, that that’s where we need to get to. That’s where organizations want to move. And the funny thing is like it’s not just the CEOs that want this, not just like the executive suite, especially your directors, it’s it’s the other people in the business, right? So I was, you like you we’re four people on our team. Our sales guy this morning was
Talking about, sorry, this is the story of a story. He was talking to his girlfriend about how he was working on the website and he was like struggling with like some like CSS thing, yada yada yada, sales guy. Struggling with some like CSS transition thing. And she’s like, is that annoying that like you know, you work at a small company and like they’re making you do engineering shit when you’re the sales guy? He’s like, No, it’s it’s autonomy that I’ve never had. He’s like, I used to wait for like a month because the engineers were too busy, and I’d be like, I’d see this thing that bugged the shit out of me. He’s like, I can just
Do it now. And like this helps me do my job, but I’m not blocked anymore on stuff. And if you think about the amount of people, like the layer cake of how we write software today, like we’re no longer in waterfall, we’re in a layer cake. People have ideas, they pitch them to PMs, they get in a backlog, PM’s organizing it, they they’re gatekeeping the engineers’ time, right? Engineers need things from like DevOps. DevOps has a bunch of things going on, so people are blocked, right? And
Meanwhile, the top of the business has these ideas, whether it’s a marketing site, a new feature, a new revenue stream, whatever, where people are just waiting for engineering capacity.
Why? Why are they waiting for engineering capacity? Because we don’t have enough engineers. Okay, how do we get more engineers? So we can hire Okay, we won’t have a budget for that. Okay, well can we enable other people into business? Well, we don’t want to do that. Well why? Well because that’s our job. It’s like, okay, well that’s gatekeeping. Right? Like by definition.
so Yeah, so when you look at like the old, you know,
the old like 2006, like the original DevOps video, where like the Flickr team was talking about how they got to deploying 10 times a day. And like half that room was like, you guys deploy I remember seeing this video. I worked at a company, we deployed once a month. We had a build, we built it, we shipped a jar, the ops team would pick it up on the end of the month, they’d push it out to servers.
Shit would break because we hadn’t deployed the month, we’d roll it back, we’d make a new jar, we’d deploy on the second of the month, right? and then when I saw that Flickr video originally, and it was like we deploy 10 times a day, I’m like, that is reckless. Like the amount of people that saw that and were like, that’s reckless. But now, like if somebody says, we deploy 10 times a day, you’re like, why why only 10? Like
Matt Massdriver deploys something like 50, 60 times a day, like everything. We’re just shipping tiny features, tiny changes all day long.
How do we get to the point where I can say the business analyst, Margaret in accounting, Tony in sales, Jana in marketing, why can’t they deploy 10 times a day? Like I want to be able to say she can deploy ten times a day, the marketing team. And people go, That’s safe. That’s our job as DevOps, to make that statement safe. We made it safe for developers. How do we make it safe for citizens? Citizen developers, sorry.
Right.
What does your agentic workflow look like?
Mine is absolutely basic and stupid. And I try to keep it that way. So I I run a fair number of agents in a given day. I typically have so I have Claude Code and just like Ghostty, and I just got a bunch of tabs split. And so I’ll probably like on like the Massdriver core code base, I think like right now I’ve got like seven or eight features in flight. So I’ve got like seven or eight like spin-ups of of my Elixir agent.
Which just like a small skill file that kind of details a few things. But again, like what I try to do is like rather than me collect this like language cruft that like may or may not get processed by Claude, it may or may not be shared with my team. Like, how do I get the things that I want Claude to do in my code base so they’re actionable, so they’re testable, right? I have a test that proves that this is the way that this linter works or this that code should look, right?
And so I I want Claude to be able to make those decisions on like style and how based off of this the subject matter that it’s got, not some additional metadata that I give it. So I purposely keep my coding ones very, very trim. Now when I get over to like, you know, so I hosted the platform engineering podcast. And so right now, you know, I spend a lot of time, you know, episodes are an hour long. I’ll research somebody who’s coming on the show for like an hour or two. I put a lot of care into the episodes.
Now I hate social media. And when I when I have a podcast I want to listen to, I just want to know it exists. I’m not like romanticizing their Twitter post and be like, did they flatter me enough to listen to it? It’s like, no, I like this podcast. There’s a new one. Fantastic. I don’t even read the Twitter. It’s like click, like I’m listening to it, right? And so I’m making a agent now that essentially manages the social calendar for the platform engineering podcast. And so I was kind of going about it the same way. Like I didn’t want to write.
a big markdown file of like how to write a LinkedIn post like me. Right. And so what instead what I do is I have a very similar to my code, I have a directory called marketing language. And there’s content in there that shows like how I talk about technology. Right. And so I’ll use that one for like our you know actual like marketing content. Maybe I’m like polishing something up send an email or something like that. And instead of just having like, hey, here’s a you a a markdown file with a bunch of rules, it’s like here is
An actual one pager where you can see how we talk at a conference environment. And here is we have this thing called the dossier, which is just all of the language of like how we talk about Massdriver or the terms, et cetera. Very domain-driven design, but on like the marketing side. And so it’s like, I want to give it really good content and examples, not like one-off meta instructions where you’re like, hey, never do this. It’s like, I don’t want to tell it necessarily to never do something because, you know, it’s a randomness engine. I get that.
And sometimes the randomness that comes out of it’s intriguing. Sometimes it’s intriguing in a negative way. I’m like, that’s fucking wrong. And I want to make sure that doesn’t happen, right? and sometimes it’s intriguing and I’m like, that’s that’s actually an interesting take on like the way that it’s talking about it. And I want incorporate that. So I don’t want to like give it a bunch of instructions on what to do and not to do. I want to give it really good content that it can base this context off of.
Yeah,
yeah. So we just do, you know, all of the all of the like non engineering docs. sorry, like non-engineering stuff like the marketing materials and whatnot. We just keep in a Google Drive so everybody can just kind of pull it down, we go there. Right, ‘cause then it’s like it for us, it’s like an actual Google Doc, or it’s an actual slideshow, right? And so we just kind of like tie all that stuff together. And so if I locally need like a new version of it, I just you know download that tar or whatever, and then my agent has access to it. I’ve actually started using
Claude in Chrome for a lot of my non-engineering stuff. And now I’m just like, you know where the tab is, dude. Like you got your own, you got your own bookmarks, you go find it. Like you can go figure it out, right? So don’t have to download something. I don’t want to file on my computer. but yeah, so as far as like the the code-based stuff though, it’s like again, like it’s the code. Like we we try to just do it in in the code itself rather than have a big markdown. I think if I were to pop open my agent file for Massdriver itself.
I would be surprised what’s in there. It’s probably just random garbage like that, you know, Claude’s kind of added. You know, like the weird stuff that just it’s like, let me put this weird fucking thing in memory. And then like a month later, you’re like, you’re doing something bizarre. And it’s like, yeah, yeah, I stored this one random transient fact in memory. And it’s like, dude, clear that. Do wh whatever you think, get rid of that, dude. You’ve no idea what you’re talking about. Just look at my code. Don’t don’t worry about memorizing things. This this is the way that you write code. You can see how to do it here from actual examples.
Instead of, you know, text based extrapolations.
Dude,
it is the worst. It is the dude, I have to say there’s so much weird stuff that comes out of memory where it’s just like, like, why did you do that? And it’s like, well, you told me three months ago that your son really liked Star Wars Legos. And I’m like, that has nothing to do with my day job. Like, that’s true. That’s cool. Like he you used an Anakin, you know, example in a test, but it just it’s weird and has does not fit the rest of our test suite. We just call it dev and ops when we’re like doing like user facades or whatever, right? And so
It’s just it’s so weird what ends up in the memory. It’s just like, dude, I don’t I don’t want any of that. I want you to look at my code. Cause then the other thing is nice is anybody else who comes along with Claude, we have the exact same context. The stuff is in the code, right? It might be comments, it might be the actual code itself, it might be linter rules, but it’s just like the examples are there. We have the same working set. We don’t have to worry about like syncing our markdown files. And then I’m like, why is there 10 never do this in here?
Like I’ve never seen it do that. Like did somebody else see it do that? Like I don’t know why this stuff’s in here. So I don’t know. I think I think a lot of that, like the skills engineering, I think is a lot of low value, like undifferentiated heavy lifting that could be put someplace else that you could yield more benefit from.
Yeah, I know a lot of places are working on agent memory and maybe if it’s very specifically defined, like this is the Elixir agent that always does X, that maybe it works better in those cases, but personally I have not really bought into using it for anything I’m doing.
When you’re working with infrarelated changes and agents, is there any kind of specific workflow that you follow?
Yeah, again, super lazy. So super duper lazy, right? And we we run Massdriver on Massdriver. We’re very dog foody, which is weird. The deployment system running on itself is mind-boggling, especially once you start changing the infrastructure under that deployment system that’s managed this deployment system. and so you know, when we issue commands to Massdriver itself, like I tend to just write in very plain English. I tend to be very basic, but here’s the catch.
We have all the controls of Massdriver, right? And so like when I sit down and I’m like, shit, we’re we’re adding a new feature. I need this plugin in Postgres. And I know that we don’t have that in our Postgres module today, right? And so I’ll sit down at our like Terraform repo that like backs our instance of Massdriver. And they’ll say, hey, go add this plugin as an option to the Terraform module. And then I’m done and I walk away.
How can I do this and be confident with it? Well, Massdriver itself has the concept of like non-production environments and development releases. And so when I say that, like, hey, go add this feature, we use we have a tool called the Massdriver Architect, which is like a Claude plugin that works with our context engine. So while that’s a very let’s say I’m adding like you know the UUID plugin or whatever, right? What happens is Claude steers the context engine and
It’s running as Cory’s Terraform Claude bot or whatever. Sorry, OpenTofu. I don’t want to get sued for saying that word. but it’s running as Claude, not as Cory. And so it can only do certain things. And so Claude goes, okay, well, I need to make changes to this Terraform module that happens to be used by the production database. That would be bad if that fucked that up. But I just tell Claude, hey, add this thing to it. And I know it’s comfortable. So Claude looks and goes, the only thing I can change is the staging environment.
And I cannot make a stable release of this OCI repo. I can make a development release. So our OCI repo is immutable, which is great for auditing, and it is semver required. So you can’t do latest, FUBAR, whatever. Like you actually have to give it semver versions. You can do development releases, pre-releases, et cetera. And so in my ABAC rules, I just say, hey, Cory’s IAC bot can only make development releases and he can only put stuff in staging. And so
Massdriver has this concept in it called release channels, which will actually automatically like spawn up and essentially run test grids of like IAC, et cetera. And so as Claude’s working on this, it goes, okay, I’ve added this OI or UUID plugin to Postgres. It’ll publish a development release, and then the staging environment that’s on the development release channel will automatically run all the plans, compliance scans, and then do like a use case apply of it. And so I literally just watch Massdriver. I have the canvas open, so I’ll issue a comment over here.
And then I literally see like a database get added to staging that’s using the development release, turn on the UUID plug-in, like do the whole thing, and then Claude will connect to that Postgres instance, verify that UUID is installed, and then I mark it stable, and then that rolls out to my production environment. It’s like that’s my flow now. I give it a very simple statement. I literally watch it build. So I see it adding things to the canvas, connecting things. I can click on it, interact with it in real time as Claude can as well.
And so, like this is again like we are this is an extreme version because we are a company that builds platform and guardrails and we run on our own platform. But I think this is where most teams are going to need to get to. Like I have a level of confidence that most teams don’t have. Right. And so I issue things pretty willy nilly and pretty I don’t sit around and do like spec kit and think through, you know, a fifty line prompt with it’s like fuck it. Just get it in there.
And I will see if it’s good or not. And usually it’s good, especially when it’s in like the Terraform realm, right? Like it’s you’re just kind of changing the developer experience on like the outside of a module. So it’s not like you’re building like a a net new crazy feature, some sweet UI thing, right? Where it has to have like deep validation or whatnot. It’s just like, hey, does it present this config and does it apply that config? Right. It’s a pretty basic test case.
Yep. And I don’t have to think about it. Like Claude’ll make its own it can make its own environment. So it’ll like, ooh, you know, so it’s very interesting. Like it’ll see things sometimes it’ll like, ooh, this this feature that you’ve requested being added to this module, it’s not so simple as just updating the one that’s there in the staging environment. I need to test a few different use cases. Maybe it’s adding FIFO to your SQS Q module or something like that, right? And it’s like, okay, well, there’s some caveats there with like some other configs in FIFO for
AWS SQS, right? And so I need to spin up three instances so I can do all these combinations of values, right? And Claude will do that. Like a part of our architect plugin tells it to exercise like a multitude of use cases. And so I’ll say, hey, add this, and then I’ll be watching Canvas. And I’ll see, Claude just made a new project. Let me look at it. And I see it, okay, add it a queue, and then I’ll see you add like six of them, spin it up, reapply it, right? Because it has to go through the terror. Like, so like one of the things that’s key with like Terraform is not just that the a
config applies, but you can apply it a second time and you can tear it down and reapply it, right? So I actually go into like the full life cycle of the Terraform to make sure you can destroy the thing, apply the thing, et cetera. And all of a sudden, from me saying, hey, we need to add FIFO support to this SQSQ, Claude will run four use cases, detail the use cases, put the docs in the operator guide or the run book for that module of like how it works and what it’s exercised, run through it, and then I have full logs
Of all four of those use cases going through like our, you know, our Wiz or Checkov scanner, like that the plans all apply cleanly, et cetera. And it’s just like that is while that feature, like adding that like variable to like a Terraform module, might take 10 seconds, all of that manual testing and like QA takes a while, right? And even to think through the use cases takes a while. And then have to set up four different instances of the module. Am I doing that locally? Am I setting up a
you know, a bunch of GitHub actions to test four different versions of this module. Like it’s a pain in the ass. And now I just don’t even think about it. Like
Shit.
So, okay, so if you think about it from like a pure ops perspective, let’s say that you’ve got, let’s say you’ve got like a an A-tier GitOps setup, right? And I’ve got this SQS terraform module. Let’s just keep it real stupid, SQS. So the first question is like, where is it? Right. And like this is this is already a huge struggle for many orgs. Where do you keep your Terraform modules? Do you have a monorepo of all the modules? Do you have a monorepo of like the environment itself? Do you have a repo per
Terraform module, and then you keep the configurations with your apps. What do you do with your shared apps? Like, like that is a bike shed that just sucks in IAC. And I think one of the problems with it is we see infrastructure as code as code. It is not code. It is infrastructure as configuration. It’s actually a database entry. If you think about it, right? Like you think about it. Hey, this SQS queue, I want to configure it. It’s named, you know, emails. That’s a database entry.
That you happen to be storing in Git. Right? Think about it. Think about that, right? Like our configs, like, we want to drive this Terraform module. That’s a database entry that we’re putting into Git. That’s why it feels so shitty. But we look at it and we’re like, well, it’s not a database entry, it’s a JSON or it’s HCL. It’s code. It’s like, no, it’s not code. It is it is a database entry serialized to code that you’ve put into Git. So let’s say you’ve got this great GitOps setup. Okay, I want to add this Terraform module. I gotta find it first.
That’s the that’s a hard part. That’s it’s a stupid hard part for many orgs. But let’s say I know exactly where it is. I go find it. Let’s say, let’s say I do a a Git repo per Terraform module, which is like we’re we’re spending time, we’re doing the Lord’s work. This is a mature team. There’s people probably listening to this. It’s like, yo, we have a repo called Terraform and it’s got seven thousand modules in it. Yes. That sucks. I’m sorry. But let’s say you got this this one you go to. Okay.
So now I want to add this. I want to add this new test case. So I add the variable to Terraform, I make the change to my resource. Let’s say it takes 10 seconds. Now I gotta think through the use cases. What are all the combinations of the FIFO field being turned on that could conflict with other configuration changes of SQS? What I’m doing now is I’m going to the AWS SQS docs and I’m reading, man. I’m doing a ton of reading and I’m
keeping track of the different fields of this field doesn’t work with this field. If you have this value selected from the enum, it can’t be this. The the if you have FIFO on the queue name also has to end with FIFO. shit, I forgot about that. But the queue names can also have a maximum length and you just added five characters to the end of it.FIFO, right? There’s all these like caveats to AWS, right? That I have to go make sure I got all so I figure that all out and then I go back to that Terraform module and I say, okay, I’m gonna make four
tfvars files for each of the 4 use cases, and then I’m going to add a GitHub action that exercises all four of those, runs a test suite, tears them down.
Right? Like that’s a lot of work. Like that’s that’s a feature that takes ten seconds to add the terraform is an hour, two hours, three hours of research and like YAML work that adds value but incrementally, I’d say, versus now I say, Hey, this should exist. Now in Massdriver, the way it works is there are these things that we call presets or examples. They’re essentially common use cases.
So your ops team can say, hey, we we run SQS, and here’s two common use cases. There’s a you know global queue with DLQ, there’s a FIFO queue, and then there’s an unordered queue. These are the three most common use cases, right? And so what’s cool with this
is it presents it to your developers. So when you go to make an SQS queue, it says, hey, your ops team has like three presets that they recommend, and you can pick one.
But you can also say, those don’t matter to me. I want to do some, I want to fill all this out myself. Great. Well with Massdriver, those presets are also.
the things that uses the test, right? So the thing that the use that is helping the developers make a decision faster is also the thing that is driving the test through this test grid, right? And so by me defining what these use cases are, I’ve made it easier for the developer. And now, again, actionable. The thing that makes it easy for the developer is also the thing that drives the test. There is no additional code.
Right. And so now every single time I say, hey, I want to make a change to this module, Claude’s able to say, hey, let me get an environment. I can see that there’s three very common use cases that developers are using this, this, and that. It applies those configs. It walks the full life cycle. There’s no additional code for tests. It’s just a part of the workflow. Right? I don’t have so I’ve made now I’ve made a one line code change instead of a one line code change, four tfvars and a hundred lines of YAML.
It’s a big savings now and and that d that’s not even the end of the pain. Let’s say a couple weeks goes by and all of a sudden somebody goes, Hey, what if we upgraded to Terraform 1.17? And then you go, Okay, we have 700 Terraform Git repos. We just have to go to every single one of those and change the GitHub actions from one point one six to one point one seven and then make sure that works.
In Massdriver, you make that change in one place again. So you have we have this concept called provisioners. Again, like, sorry, I’m not trying to sell, I’m trying to talk through like how like this is the level of like guardrails that we kind of think about. And so in Massdriver, we this concept called a provisioner, which is essentially it’s it’s almost like the underlying like runner in a GitHub action. And so your operations team says, here are the tool sets that Massdriver can provision with. And so you might say, Hey, we use Terraform, and Terraform always runs through Checkov and Snyk.
Or Checkov and Wiz, whatever. So you essentially make this tool set, you push that tool set into Massdriver. And now every Terraform module uses that tool set. And you can say you can have multiple, you can have a Terra Terraform V0 and a Terraform V1 tool set or whatever. But now when you’re like, hey, I want to change the compliance tool that’s in our Terraform tool set. You take that tool set and you say, I’m going to take Snyk out, I’m going to put Wiz in, you push it back up. Everything that is on that V1 Terraform module gets upgraded to the new.
compliance tool. You make change in one place, right? And like that’s the name of the game, right? Like we don’t want to be this proliferation of config all over the place. As soon as you have this proliferation of config, everything is harder. It’s harder for DevOps, it’s harder for the dev, and it’s impossible for the citizen. Right. And so if we can get it down to you have these concrete places where you define like how systems work, it makes it really easy to start to reuse and compose things and have guarantees that you don’t necessarily get when you have
700 GitHub.yaml files trying to provision and test some Terraform.
yeah. I mean and the funny thing is with Terraform, and this this is something that like it absolutely boils my piss when I meet operations or DevOps or platform engineers that say things like developers don’t like writing Terraform or developers can’t write Terraform. I’m like, dude, the average front-end engineer I know knows five fucking programming languages. They have no problem sitting down and learning HCL in about eight minutes. It’s not much of a language.
The hard part is a lot of operations in cloud is not writing Terraform. It is managing all these external stakeholders with non-negotiables. I have to manage the CISO’s desire for security, legal’s desire for compliance, the CFO’s desire for budget, right? Scale for the SRE team. Like there’s all this stuff that is external, right? And so you as a dev, who sits down locally and you’re like, I need Postgres, and you brew install Postgres or you Docker run Postgres and you’re done.
When you get to the cloud, all of a sudden it’s like, well, what about the IAM? What about the credentials? What about AWS Secrets Manager? What’s the scale of this thing? How much should you spend on it? Which compliance tool do you use? And it’s just like, dude, I have no fucking idea. All that’s I need Postgres 16. I got it like that locally. And when I get to the cloud, there’s this abundance of non-engineering stakeholder desires that is what makes Terraform hard. Terraform’s easy. Organizations are complex.
And we’ve spent so much time like as an industry like focusing on like how do we make the Terraform easier? It’s like how do we make the complexity of our organizations easier? Like that’s what’s gonna unlock autonomy and make people go faster, whether it’s the software developer or the citizen developer.
Yeah. Very good. I mean it’s it’s cool. I I’ve I I’m curious where this will go. ‘Cause the thing is interesting is like I think you know, we’re a we’re we’re a tool that works with anything that you can write in IAC. So we have customers that use Vercel, AWS, Superbase, GCP like it literally doesn’t matter to us what you use under the hood. But it’s funny, like when I sit and think about
Like the giants in the space, like the AWSs and GCPs and then the Vercels, right? Vercel obviously runs on, you know, a number of cloud services under the hood, probably AWS, GCP, et cetera. But like thinking about like the way that they’re approaching the world, I feel like AWS, and it’s funny because like AWS, like you build it, you run it, you know, they like they they push so much of like what DevOps is and platform is. I feel like they have missed the boat on like seeing the citizen developer. And what’s gonna be really interesting is
The citizen developers are going to the Vercels and they’re going to the PlanetScales and the Supabases because that’s where it’s easy to get their apps up. Now, what’s gonna happen in the near future, whether that’s a startup or whether that’s a established, you know, company, there’s gonna become a compliance and security requirement where that’s gonna be problematic. And there’s this sucks for two reasons. One, that’s immediately your DevOps team’s problem. Whoops, that sucks. Right? That de
That that citizen developer probably doesn’t even know that DevOps engineer. They went and they’ve built all of this stuff on all of these third party SaaSes. And then all of a sudden somebody’s like, yo, none none of that stuff SOC 2, or like that doesn’t match our whatever requirements. And now all of a sudden, this DevOps engineer who’s drowning and shit to do has to figure out how to get all this stuff over here, right? So like that sucks. The other thing that sucks though is like I think that this is going to be an absolute sleeper cell on
AWS, Azure, and GCP’s markets. I think a lot of these citizen engineers are going to end up on the Vercels, the Railways, like these easier to use, like PaaS-adjacent things. And those companies are probably going to say, hey, you know what? People don’t like that their database traffic is traversing the public internet. Let’s figure out a way to have, you know, a checkbox to turn on private networks between Vercel and Supabase or whatever, right? And as soon as they solve that private networking problem.
A lot of those security and compliance issues are gonna go away. Right. And now that’s not the DevOps engineer’s problem. But now the DevOps engineer is saying, I guess we’re gonna start putting more applications on Vercel. Right. And now you see somebody like Vercel start to invest in hardware, kind of like a Fly.io did, right? and now I think AWS’s GCPs in the citizen developer future are gonna have a problem where they didn’t cater to this new type of developer.
While the PaaSs did. And it’s gonna be much easier for the PaaSs to add additional security tooling than AWS to say, hey, move all your shit back over here. We like you guys now. We’ll help you do your job. Like they they they’re missing the boat on it right now. And it is it is astounding to me that they’re just like, all the all the weird stuff that AWS could Q, all this stupid shit. And it’s like, you guys, like you are you are launching AI tools for engineers that are in the weeds.
Like launch an AI tool for the business people that need autonomy. so I don’t know, man, I think it’s gonna be a real I think it’s gonna be real weird future for the clouds.
Yeah. It’s crazy. It’s crazy. One I mean, yeah, i it is it is maddening. And we have we have a lot of citizen developers that use our platform today. And you know, we’ll have people that like, you know, they’ll ops people come in and they’ll say, Hey, you know, citizens can deploy lambdas and if their application is, you know, of some class, then it’ll become a you know, Kubernetes deployment, right? And that’s great for those people, like they can get going really quickly. But like if you are not a team that’s big enough to like
Product like ours and spend the time like writing Terraform. And you’ve got people in your business that, you know, I I’ve got a buddy right now, works for a music company, and they have 63 applications that are in production that are running on a mix of Vercel and people’s laptops. And nobody had any idea this was happening until all of a sudden, like one of the tools that they’d become critically dependent on.
They have an engineering team too. Like the
engineering team is working on stuff. But the org is like, shit, like we don’t have engineering policies. Did you know this Claude Code thing can just make apps? Right. And they just download it and they just make apps. Like they didn’t know who any of these people are. But then all of a sudden, this you know, this this sales tool that they’ve all become dependent on just stopped working one day. And I was talking to my buddy where we’re going for a walk at Huntington Gardens and he’s just like
He’s like, it stopped working one day. He’s Do you know what happened? And I was like, I have a feeling I know what happened. And he was like, the guy that made it took his laptop home and he usually left it over the weekend.
And they just couldn’t reach. They’d been going to a fucking IP address. They’d slack each other’s IP address. Thinking about domain names or anything like that. Like, I can bookmark this IP. Like, they don’t think like we think. I need a DNS name. They’re like, somebody sent me the thing. I can click on it. I can see it. It works. I bookmarked it.
How do I get back to said site? I go to my bookmarks. These people aren’t type. You what I’m saying? It’s just like they’re a completely different class of people that are in our orgs and they’re shipping software now. And that is amazing. And it’s also terrifying at the same time because people are going to miss it. They’re going to guardrail or sorry, they’re going to gatekeep it, and they’re not going to build guardrails. And that’s what these people need right now. They need good ways to get their applications into production safely, not going around your team, which is what they’re doing today.
That would never happen
on Hacker News. What what are you talking about?
Yeah, I know, right? It’s just like like that’s funny.
but it’s funny, like the the idea that people reject the citizen developer, right? Like you’re rejecting somebody else’s autonomy first, which is kind of fucked up. Especially in like a world where we’re here to make money, we’re here to make products, we’re here to do business. And these are the domain experts. The amount of time I’ve seen a domain expert give something to a PM that gets built and then it comes back to the domain expert and it’s not what they intended is is is very common, especially in like larger orgs, right? The things
Also funny about the citizen developer is every single one of us is also one, right? And so like I’ve got a ton of distributed systems experience. Elixir, Golang, I’m a back-end engineer. My master’s degree is in database information systems and healthcare. I am by far not a React developer. I’m not a node developer. I know HTML and CSS, but I know like the 2006 version of it, right? I am a citizen developer when it comes to doing front-end stuff.
Right. And I think that’s one of the things that we forget as engineers. Like, well, I’m a software engineer. It’s like, yeah, yeah. And you probably know your tool stack very well. The second you step out of that, your company acquires another company and you’re running, you know, Java now and you were running Python before, like you are a citizen developer in Java Land. Like you are not going to be the most effective engineer there.
What does it matter who’s writing the code? Right? Like if I go and write some React and it’s a little shitty, I should have tooling or people reviewing the PRs that are like, hey, it’s a little shitty. It’s fine for me to write that. Why is it fine for me to write that? But it’s not fine for Donna in marketing to write that. Well, Cory, it’s because you know Elixir. It’s like, okay, well, she knows marketing. Domain-wise, me knowing how software works.
I am less qualified to build a website than a person that understands how to market to people. So why can’t she do it? Well, she’s not an engineer. Well, neither are you. We aren’t engineers. We don’t have licenses. That title’s bullshit. Like there’s states that you can’t even be called an engineer. Like we’re not engineers either. We’re we’re hobbyists. Hobbyists that may or may not have a computer. Like when did I become a developer? Was it when I got my first job? Was it when I graduated and got my degree? Was when I got my like when did I become a developer? Like I didn’t take a test and become a developer. I just
was deemed it at some point in time. I deemed Donna a developer. She’s a system developer.
Yeah. And it’s funny too, ‘cause they will they will sit and they will grind in a way that we won’t, right? Like the like just if you’re hearing this and you’re still like resistant to the idea of a citizen developer, just just think through this. How many times have you been given a feature, particularly if you’re a front-end engineer, where somebody man, especially if you go back into the early 2000s
There’s these pixel pushers where man, you were a pixel off and like it would get back to like whoever the designer was and it’s like, yo, this needs to be shifted one pixel to the left. Like this corner needs to be rounded. It’s like there’s no such thing as round corners in two thousand six guy. Like I’m uploading a a JPEG like on the corner of a table or whatever, right? Like So you ship a feature and you do it exactly right and you get it into somebody’s hand, and they’re like, That’s not quite exactly what I wanted. Like I want
this change or it doesn’t feel right. Like it is what I asked you for, but like now that I’m using it, like it’s not right. And you might be thinking, you gotta be MVP, you gotta be a bit more agile. Fuck, I see this happen all
the time with Agile, right? That’s part of Agile, right? Getting that change back to that person. But how many times does this happen? Where you get the change back to the person, they say it’s not quite right, but you’ve blown your story points and you’re like, well, this if the MVP is shipping, we’ll get put that change request on the backlog. Happens all the time, right?
Tell you what citizen developers don’t do. They don’t put shit on the backlog. They Claude it up. It’s not right. They tell Claude it’s wrong. They tell Claude it’s wrong. They tell Claude it’s wrong until it works the way they want. They don’t have a backlog.
Imagine the freedom of that, right? But like that, but that that’s just it. It’s like, man, it’s like we like the the these people behave different, they work different. And I think we gotta support them in businesses. And so I think I mean, I think it’s coming. And I think that if you’re pushing back against the idea of the citizen developer, I think organizations are going to start seeing those developers as dead weight, right? You gotta create paths for these people to move quickly and safely. If you’re gatekeeping them, people are gonna say, Hey, Tony.
He sucks, man. He’s he’s just he’s just slowing the business down. He’s he’s arguing about, you know, transpiling some some node.js code and Donna has a way for us to make ten percent more money next year. But we’re we’re we’re switching to bun or whatever, right? You know what I’m
saying? It’s like we’re doing we’re doing these things that just make no sense to the business, but they feel good to us and I don’t think it matters in the future.
Mm-hmm. We’re we’re
we’re we we were a means to an end for a very long time, software developers. And now everybody has the means. So if we want to continue to have value to business, we got to figure out how to show value to business. And telling people no they can’t do something has never been a way to show value to a business, to slow down the org. Like, yeah, you gotta slow down to go fast, but you don’t slow down and stop.
Right, you slow down, you build guardrails and you get going quicker.
Yeah. I think one of the things that’s gonna be really interesting, like in the in all the talk around like which of our engineering tooling makes sense and doesn’t make sense in the future, right? Like I’ve I haven’t I’ve been checked out on GitOps for since it came out. GitOps has always been foolish to me. It always seemed like a database record and code. But you know, there’s people that are talking about like, is Git the right tool? Good question. Like b i like is Git but I think the thing that
I think there’s genuine opportunity for in the near future. And if you’re a if you’re somebody sitting around like trying to think of a startup idea, the citizen developer is going to take off. And the thing that’s still not solved in the citizen developer space is what collaboration looks like. And when you look at things like GitHub, like they’re very much designed for developer collaboration. They’re not designed for the citizen developer to collaborate. Now tools like Vercel, where like you can go in and you can visually click on things, like, hey.
You know, Donna, like, I don’t like the blue here. And I can click on it and I can tell. Like that is Vercel, like starting to handle it. And they’ve been ho they’ve been doing that for the citizen developer for a while. The designer, the marketing person that wasn’t writing the Node.js or React code that produced that site. So I think that’s going to be important. And tools like Vercel, like frameworks for UI, are solving that. But I think where it’s going to start to become interesting is like when they start designing APIs, when there’s back-end code they’re creating. It’s very hard for
citizen developers to kind of collaborate on changes that need to happen at an API level. And I think that’s one of the places that’s going to be really, really interesting in the near future. I’m curious if like we see GitHub go that direction or if it’s going to take some, you know, new startup who’s just like, hey, you know what? There’s a different type of developer and GitHub’s focusing on the software developer, not the citizen developer. And maybe there’s just like a whole other tool set that kind of boots up around managing our code.
in making it where these people that aren’t necessarily developers can come in and collaborate on stuff.
From my understanding, at Google, their version control systems, they just track commits and make commits essentially as files get changed. And I think there’s tagged, essentially like tagged releases, things like that, but a big part of it is just automated as part of the process, whereas Git is very intentional. What are you? But with agents, it’s
Do you need them be they’re making all these commits, you kind of don’t care about a lot of the things that are happening, so
I’m gonna say something that’s probably gonna sound absolutely I’ve probably said a lot of shit that sounds bonkers to a lot of engineers listening to this, but you know, we have a whole host of vibe coded apps at Massdriver. It’s not a part of like Massdriver core. Like Massdriver Core, I Massdriver Core is now vibe coded, but I mean we have like truly like from scratch vibe coded apps for just different things. sometimes they’re like full proof of concepts for customers.
Their internal tooling, et cetera. And so what’s interesting is our you our sales and marketing guy, he’s allowed to write software. Now, when he set up his machine, we were trying to set him up in the easiest way possible. I didn’t want him to have to download Git, download AWS, download some credentials, make him like 30% of a developer. And so when we developed the Massdriver architect, the our Claude plugin, one of the things we did was we wanted to make it work.
Very well for people that have no idea what any of our shit is as software engineers, right? It’s like, hey, I downloaded Claude, I downloaded this architect thing, my ops team told me I have to use to deploy apps. I’m good to go. And so the architect, what it does by default is if it can’t find a Git repo, like if you don’t have Git and you don’t are in a Git repo, it stores the code in Massdriver’s OCI registry. Like at the heart of Massdriver, we’re an OCI registry, a Docker registry.
Right, Docker registries you can push Docker images to, but Docker registries or OCI, you can also push arbitrary artifacts to. This could be a Terraform module, it can be an actual code base. And so we have a bunch of code bases at Massdriver that are not in Git. They’re stored in the Massdriver OCI registry. Now, again, it it’s an immutable registry, which is really cool. So I can actually see the sales guy working on something.
I can actually go into Massdriver’s registry. I can click on the you know the repo that he made. I can actually browse the code. It feels like a GitHub, but it’s all stored in OCI and it’s immutable. He has different versions of it, et cetera. But what’s cool for him is he didn’t have to think about Git. He didn’t have to think about code. It just appeared up and went into the platform that also does all the provisioning, right? And so, like thinking about like where our tooling goes, like there’s a lot of stuff that’s similar between OCI and Git. Like there’s a lot, I mean there’s a lot of stuff that’s different.
But like the core stuff is very, very similar. And so we were just like, how do we make these people more efficient at delivering software? And what’s cool about this is it’s a citizen dev app. It might only be used by three people. Do you really need like all of Git to do that? Or does it does it really matter, right? Let’s say it gets to the point where you’re like, this is critical. It’s an OCI repo. Docker pull pulls the entire code base down, Git push. And now it’s in Git, right? It’s very easy to like back out to engineering land.
But it gives you this means of I don’t have to have all this tooling around to be able to, you know, get these people. And the cool thing is works without Docker. Literally just it’s like our CLI and Claude, and you are good to start shipping apps to the cloud, like meeting all your compliance and security. And like this is where I think all teams must be going if you want to continue to be a software developer. You have to figure out how to build guardrails and pathways to make these people’s jobs easier.

