The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Cloud Pod
The Cloud Pod artwork

360: And you thought AWS was out of features for S3. Surprise!

The Cloud Pod · 2026-07-01 · 1h 22m

0:00--:--

Key moments - from our scoring

Substance score

33 / 100

Five dimensions, 20 points each

Insight Density7 / 20
Originality6 / 20
Guest Caliber5 / 20
Specificity & Evidence9 / 20
Conversational Craft6 / 20

AWS S3 continues to surprise with new capabilities, but this episode pivots quickly to broader cloud and AI developments. The hosts cover Claude Design's integration with Claude Code through new /design-sync and /design commands, enabling AI-powered UI generation that syncs design systems with code, shares token pools with other Claude tools, and exports to Adobe, Canva, Gamma, and other platforms - though users report rapid token consumption. The Databricks Data & AI Summit dominated discussion with announcements spanning Lakehouse real-time performance, GENIE unified agents (replacing siloed department-specific genies), Lake Flow for agentic data engineering, open sharing for Delta/Iceberg formats, Unity AI Gateway, and notably their newly acquired SIEM product built on Lakehouse. OpenAI released credit usage analytics and spend controls for ChatGPT Enterprise with per-user limits and in-app credit request workflows, developed with Apptio and FinOps practitioners. Claude Tags introduced agent identity access models where AI agents get dedicated service accounts scoped to Slack channels and GitHub rather than borrowing user credentials, with full audit logging. Cloudflare added temporary ephemeral accounts for AI agents using Wrangler CLI, automatically deleting after 60 minutes if unclaimed. Critical for operators managing AI agent deployments, enterprise governance, and multi-tenant security.

Key takeaways

  • →Claude Design now integrates directly with Claude Code via slash commands and shares a token pool, enabling faster UI/design workflows but consuming tokens quickly with iterations.
  • →Databricks released significant updates including Lakehouse real-time performance for continuous ETL, unified Genie AI agents replacing siloed departmental genies, and a new SIEM product built on Lakehouse.
  • →OpenAI and Anthropic both launched dedicated identity and access management systems for AI agents rather than using user credentials, with OpenAI offering per-user credit controls and Anthropic providing scoped Slack workspace permissions.
  • →Cloudflare introduced temporary ephemeral accounts for AI agents via Wrangler CLI that auto-delete after 60 minutes unless claimed, solving the problem of agents unable to authenticate through traditional OAuth flows.
  • →Token limits and budget management remain a critical operational challenge when deploying AI design and agent tools at enterprise scale.

Topics in this episode

Claude DesignClaude CodeCloudflare WorkersDatabricks LakehouseGenie AIAnthropic Claude Slack integrationOpenAI ChatGPT EnterpriseWrangler CLIDelta sharingApache Iceberg

Questions this episode answers

What are Claude Design's new integrations with Claude Code?

Claude Design now integrates directly with Claude Code through /design-sync (pulls design systems into code) and /design commands (creates and manages design projects), eliminating manual copy-paste workflows and supporting exports to Adobe, Canva, Gamma, Lovable, Miro, PDF, and PowerPoint formats.

How does GENIE One differ from the original Databricks GENIE?

The original GENIE created siloed instances per department (marketing GENIE, finance GENIE, etc.), requiring users to switch between separate tools. GENIE One unifies all departmental data and governance under a single agent that can cross organizational boundaries and answer questions across all domains.

What permissions model do Claude Tags agents use in Slack?

Claude Tags agents get dedicated service accounts scoped at workspace and channel level rather than per-user credentials, with permissions configured per channel (e.g., engineering channel to GitHub, sales channel to CRM) and audit logging of all network calls and memory writes.

How long do Cloudflare temporary accounts for AI agents stay active?

Temporary ephemeral accounts provisioned via Wrangler CLI with the temporary flag stay live for 60 minutes, during which a human can claim the account permanently; if unclaimed, the account and all associated resources are automatically deleted.

What data can OpenAI Enterprise admins access in the new credit usage analytics?

Admins can track credit consumption broken down by user, product, and model through the global admin console and access this data programmatically via the unified Cost API, with per-user limits configurable by group or individual override.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

7 / 20

The episode is primarily a press-release read-through of cloud announcements with light practitioner colour added. Useful observations appear occasionally (e.g. token-pool dilution risks, Glacier cost trap for S3 annotations) but are buried in 82 minutes of filler including lawnmowers, laundry, and conference small talk.

these connectors and skills and MCPs, they also have the risk of diluting the ability for the model to work effectively and to be able to get the right answer
annotation storage is built at S3 standard rates regardless of the parent object storage class. So teams storing annotations on glacier objects should factor that cost difference into your planning

Originality

6 / 20

Occasional mild contrarianism (pointing out this is Amazon's fourth attempt at a managed enterprise knowledge base, noting Calendly's eroding moat) but no first-principles arguments. Most commentary repackages vendor marketing language with modest skepticism.

Amazon Bedrock Managed Knowledge Base is a new fully managed RAG service. Is this like the fourth time they've tried to build a fully managed enterprise knowledge base that Amazon.
the barrier or The MOEs of SaaS products, you know, are diminishing in some ways. Like I look at Calendly and I'm like, look, if I had to If I only had to schedule maybe 20, 30 meetings a month with people and it was a pain to coordinate, I could totally make an agent do that

Guest Caliber

5 / 20

No external guests at all; the panel are self-described practitioners (cloud consultants, engineers) who share anecdotes from day-jobs and personal projects. Credentials are modest and largely implied rather than demonstrated by depth of insight.

I built the app first, didn't touch the UI and then I got it to generate um, sample data sets for every API response and pass that into Claude design.
I've used it just playing around with it. It produced really nice things. Just I used half my session tokens real fast with iterations

Specificity & Evidence

9 / 20

The hosts faithfully relay concrete product numbers from vendor announcements (vCPU counts, latency multipliers, dollar figures for pen-test tasks) and supplement with a few personal data points; this is the episode's strongest dimension, though most specificity originates from press releases rather than operator experience.

a development team runs a penetration test on new API. AWS security agent runs multiple tasks in parallel, creating a comprehensive test approximately one hour while consuming 3 hours 27 minutes, 40 seconds of cumulative task hours for 173 bucks
up to 3x more throughput for broker, 20x, faster scaling and 90% reduced recovery times compared to standard brokers running on Apache Kafka

Conversational Craft

6 / 20

No interview format and no guests to push back against; the co-hosts are agreeable throughout, rarely probing each other's claims. Some worthwhile riffs on vulnerability prioritisation and context windows emerge organically, but long stretches of off-topic banter (laundry, pool robots, lawnmowers) crowd out substantive exchange.

I just always worry at one point they're gonna um, wreck the stability. But I feel like that's so like at this point I assume it's almost different teams that are just using S3 differently
Isn't the default for AWS IAM M credentials, like, with your EC2 role, like 60 minutes too? I feel like that's kind of

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C66%
  • Speaker B32%
  • Speaker A2%

Most-used words

data44code34agent31nice30cloud29security25agents24design23feel22back19interesting19azure18didn18system18tool18cloudflare18

Episode notes

Welcome to episode 360 of The Cloud Pod, where the weather is always cloudy! Justin, Matt, and Jonathan (for a bit, anyway) are in the studio this week bringing you all the latest in cloud and AI news, including a bunch of analytics, some upgrades courtesy of AI agents, and some news from Kafka. There’s a lot to cover, so let’s get started! Titles we almost went with this week MSK Agent Skills Make Kafka Migration Less Kafkaesque One Token Pool to Rule All Claude Tools STRIDE Into Security Without Leaving Your IDE Your Code Must Be This Stable to Enter Production ChatGPT Gets a Budget So Karen Can’t Break the Bank One Platform to Train Them All and in Darkness Deploy Them Who Let the Agents Out? Snowflake Knows Kafka Whisperer Now Comes With an AI Upgrade Stop Reading Docs, Let MSK AI Do the Kafka Math Your AI Wrote That Pull Request, Own It Claude. Tag, you’re it! See, there are more features that we can add to s3 A big thanks to this week’s sponsors: We’re sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You’ve come to the right place! Send us an email or hit us up on our Slack channel for more info.

Full transcript

1h 22m

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign, Where the forecast is always cloudy. We talk weekly about all things aws, GCP and Azure.

Speaker B: We are your hosts, Justin, Jonathan, Ryan and Matthew.

Speaker C: Episode 360 recorded for June 23, 2026. And here you thought AWS was out of features for S3. Surprise. Good evening, Matt and Jonathan. How you guys doing?

Speaker A: Good, Justin.

Speaker B: Good.

Speaker C: Good to hear you, Jonathan. It's been a little bit.

Speaker A: Yep. Been busy.

Speaker C: Busy, busy, busy, busy. AI. It's. It's all AI all the time here on, uh, the show. So I'm sure it's just AI for you all the time too. And you're just busy. You're just busy coding away with Claude and other open models on your. Your beefy GPUs that you, uh, power and heat your house with now.

Speaker A: Yes. Yeah, definitely. Sadly, I'm disappointed. They've put the price for the RTX 6000 up by like 50% now, otherwise. I know snapped up another one, but $13,000 is a little on the pricey side.

Speaker C: Yeah, I really regret that one because I was going to buy it and I. And I was waiting because I wanted to see what Mac was going to do for the next, uh, the next Mac studio with the hopefully M5 Ultra or M6 Ultra. And I was waiting and now I regret it. The joy y.

Speaker B: This.

Speaker C: This hardware supply thing needs to end because RAM prices are dumb. Yeah.

Speaker A: I just read the DDR2 prices have gone up immensely as well, which is ridiculous.

Speaker C: Why? I mean, they're not even using as an AI just because they can.

Speaker A: That's what people have, what people can afford to put in their machines, I guess that they need to operate anymore.

Speaker C: It's crazy.

Speaker A: Yeah.

Speaker C: Matt, uh, I know you went to the AWS summit. How was the summit?

Speaker B: You know, it's been a couple years since I've been and uh, M. It was as hectic as normal. I actually got my badge the day before, but I walked in about a half an hour before they did the keynote and I was like, oh, my God, there are so many people here now. Go try to find people. But somehow I ran into like 10 people I knew, even though I didn't know most of them were going. So, you know, shows how small of a world it still is.

Speaker C: Yep. Uh, it's just like going to reinvent. So just remember when, you know, re Invent comes up very soon, uh, it's basically the same thing. So. Yeah.

Speaker A: Oh, yeah, I got an email reminding me to sign up for that this year.

Speaker C: Yeah, I got my email yesterday too, like, hey, organization's open. I'm m. Like, uh, not unless you're sending me free tickets am I going to that. And even then, will I actually show up at the conference? Questionable. Well, I'll just hang out in Vegas. Yes, yes, I will. And I'll hang out with my friends who are there at Re Invent. But going to the conference is a lot of. I actually went to a conference last week as well, the DataBricks, Data and AI Summit, which, uh, I'm shocked there was people in New York because I thought they were all with me in San Francisco at this AI thing. Because there was a lot of people at this event. At Moscone was full to the brim.

Speaker B: Moscone always, I feel like, gets filled and overwhelming.

Speaker C: Uh, it's a terrible layout. I mean, I. That's my least favorite conference center I think I've ever been to. Now, I haven't been to, like, Javits or. Or some of the others, uh, in, like, Boston and stuff, but, uh, of a major city conference center, it's my least favorite that I've been to. How's that?

Speaker B: Javits is pretty good. I'll let you know how DC is, um, next week after I do the DC summit, because AWS planned it on the week of 4th of July. Oh, so that's always fun.

Speaker C: Brilliant.

Speaker B: I assume it was a cheap conference rate.

Speaker C: Do they also know that there's a huge amount of people coming for the 250, uh, celebrations that are in DC.

Speaker B: I will be out before that. I'm leaving, um, on. On July 1, before it gets too close.

Speaker C: Are you gonna go check out the green reflection pond?

Speaker B: You know, I've thought about it, but, you know, you can't get too close. I saw today.

Speaker C: Well, they don't want you to. They don't want you to cut the lining on the bottom.

Speaker A: You get arrested for looking at it.

Speaker C: Yeah, don't tweet about it while you're there. You don't want to get arrested. All right, let's get into real stories here. First up, AI is how ML makes money. Uh, for those of you who know Claude, uh, has ability to create really nice front ends, and they really released a design interface that you could access on the web that has now come to the client and now integrates directly with cloud code through two new slash commands, slash design Sync, which pulls your design system into cloud code, and design slash design, which lets you create and manage design projects that are leaving the terminal, giving both tools in sync throughout the workflow. The rebuild design system imports supports, uh, GitHub, repos design files and raw uploads, with Claude automatically checking its output against your components before rendering results. Enterprise admins can lock down a single approved system to enforce consistency across enterprise teams. Anthropic updated the usage model so cloud design now shares a token pool with chat, cloud, cowork and cloud code. Rather than having separate limits, which should give most users more headroom and reduce how often they hit caps. Or you'll hit it just as much faster because now you're competing with your cloud code. Which is what I happened to me when I tried it the first time and I was like, I'll have to come back to this. You can export and integrate into Adobe Canva, Gamma, Lovable, Miro and much other AI tools that I never heard of, and standard PDF and PowerPoint formats, making it easier to move finished work into existing production pipelines. Uh, it is considered still beta on the Pro Max team and enterprise plan. Lots of tokens, so be careful.

Speaker B: I've used it just playing around with it. It produced really nice things. Just I used half my session tokens real fast with iterations and things like that. So I would be careful using it. But it does great front end design. I mean you can start to see. I don't know if you guys have noticed it on the Internet too. Like I can tell sometimes when they're clawed designs or what feels like it because it follows the same color schema as the default and the way I laid it out and everything else like that.

Speaker C: Yeah, they uh, have a very consistent brown, um, taupey color pattern going on. Very reminds uh, me of sand dunes. Uh, that's the claw design pattern that it defaults to, uh, as my experience. So yeah, I'm actually, I'm um, looking forward to potentially getting this design sync in place and actually syncing a design system that doesn't look like Claude's default design system. Uh, because I think it could be pretty nice.

Speaker A: Yeah, it's super nice and um, I've used it a couple of times, use it for my personal pet project, which I'll show later if we have time. But the absolute best thing about it is I built the app first, didn't touch the UI and then I got it to generate um, sample data sets for every API response and pass that into Claude design.

Speaker B: Ah.

Speaker A: And I said build me pages that consume this format data and it was like one shot and done to give it the design files. Just, just amazing. I'm glad they added the, the integration with Claud code because Otherwise it's going to click a button, copy a link and then ask Claude Code to visit the URL. And then it's kind of.

Speaker C: It was a little clunky.

Speaker A: Yeah, uh, a little, little clunky. And especially if you need to go back to it to say, hey now make me another page. But I think Claude's been pretty good about, about following the design once it's, once it's written. You don't really need to go back to Claude design once you've got the, uh, the structure in place, all the primitives in place. Yeah, it's really cool tool.

Speaker C: Yes, very cool. All right. Uh, well, the Data AI summit from Databricks had a ton of announcements, uh, more so than even Snowflake did a couple weeks prior. We won't go through all of these because it would take about three hours to get through all of this. I think, because I think we started with like 30 pages of notes that I had to cut down. There are a couple highlights. I'm not going to talk about these in depth because A, I don't understand them well enough because I'm not a databricks expert. I learned a lot at the conference. I talked to a lot of people who love databricks. Yeah. So I have more understanding but I'm not an expert in any of these. So they introduced Lakehouse, uh, real time, which is a real time performance for the unified Lakehouse. So you don't have to wait for all the ETL work. It basically does it continuously. In the background there's a new GENIE zero Ops, which gives you uh, AI automation for your databricks data lakes, uh, so you don't have to manage them as much. Which knowing my ML team friends, uh, they're gonna love. There's now open sharing, which is the next evolution of Delta sharing for agentic era, which basically is around iceberg, uh, and other compatible formats and MCPS let you access that data. Lake Flow is their new era, uh, of agentic data engineering. Uh, with the GENIE code integration again, AI was everywhere, introducing Genie 1, Genie agents and Genie ontology, which is in addition to the existing GENIE AI which was very siloed. So you'd basically create a GENIE for marketing and it would answer marketing questions and then you create a GENIE for it and it would just answer it and you'd have to go between all these different genies. Uh, now genie one unifies all of that, which seems like an obvious design flaw. The original version, but I wasn't following it close enough to call it out then, uh, unifying data and governance in era with a bunch of new uh, you know, capabilities around agentic, uh, governance, uh, lake based search, which is a new aid of native retrieval, uh, rag based model for vector for on top of lake based cosplay. Uh, so if you're using postgres on there, a new Unity AI gateway if you're into the Unity catalog. And then uh, a bunch of other great announcements. We'll go over all of them like I mentioned. But overall I'd say if you were in the AI space, uh, you were probably at this conference or very much paying close attention to it. I was surprised how much they announced in two keynotes as well as throughout the rest of the conference. A, uh, lot of stuff, a lot of new things. A lot of people were very excited about the new toys. The governance models in particular got a lot of traction. And uh, they also have some security stuff. I even learned they have a sim. Did you guys know? Uh, they bought a company and they have a sim. So yeah, uh, really cool SOC capabilities as well. I sent that over to Ryan so uh, he could check that out as well. Uh, and uh, we were commenting as we were watching them demo it during the keynote, he's like, I didn't want to like this, but it's pretty nice. And I was like, yeah, this is kind of cool. So uh, that was his hot take at the time.

Speaker A: Yeah, that's cool. I think Databricks and Snowflake are both. They couldn't have been accidentally better positioned in the market to take on all this AI work because now they've got everybody's data, it's already resident there. It costs money to move it out, just add the features, let people do whatever they need to with the data in place. They're perfectly positioned.

Speaker C: Well, uh, you know, we were about to start talking about uh, databricks and then our cloud hosting provider for the podcast recording decided to uh, take a break. So we, we weren't able to keep recording. And so now Matt and I are back. Uh, we couldn't keep Jonathan around. The service is back up and so we're going to finish this up. But uh, maybe we'll, we'll cut down the amount of stuff we're talking about for data bricks because I think that, I think it was Riverside telling us, look, you, you don't, don't talk about

Speaker B: d, don't talk about data.

Speaker C: That's, that's kind of what I feel like. So we're, we're going to make up for that. And we'll just get through this. And so, uh, it's either that or we're not going to episode this week at all. And we felt like you guys deserved episodes. So here we are. All right, so Databricks summit. Uh, I'm sure Elliot will do his magic and cut in at least the beginning part of it. And so I'll just tell you what, some of the highlight announcements and then we're going to move right along past databricks because, uh, hey, I don't know that Matt and I could on a Friday now that we're re recording this because, you know, this happened uh, earlier in the week and this is the first time we feel to reconvene ourselves. I don't know if we can make it through our full databricks pitch on a Friday afternoon after a full week of work.

Speaker B: Not at 8:30, uh, on a Friday. I'm not there.

Speaker C: Yeah. So basically lots of great improvements to things like Lakehouse. They have the new unified, uh, real time performance capability. So you know, if you were unhappy that your databricks system required you to ETL data, you can now get it real time as long as you put all the work into it. New AI capabilities to make all of your operations zero ops as they call them, so you don't have to pester your DevOps folks. Uh, new open sharing capability to compete with uh, Snowflake's sharing capabilities. So if you uh, need to share data between your SaaS, vendors and different providers and you use databricks, you can do that through uh, those methods. And then, uh, lakeflow is our new agentic data engineering capability. The GENIE products have now got, uh, expanded. So GENIE was announced last year, but it was kind of like a AI for like specific departments. So you'd have like a GENIE for marketing, a GENIE for finance. But now they have GENIE one which makes it so you only have one genie that can now cross all those things, which seems like a much more logical way to do it. Anyways. I was kind of surprised they had done that M line of silos, uh, beforehand.

Speaker B: You get one bottle that you get to rub Justin.

Speaker C: Exactly.

Speaker B: That should have been our show title. Something about genie in a bottle.

Speaker C: How do we miss that? How do we miss that?

Speaker B: I don't know. But four days later we come up with better show titles.

Speaker C: Yeah, that's how it works. Uh, unifying data governance. Lots of things about data governance if you care about that. Uh, some good features for lake base for that, uh, late based search now gives you new agent Native retrieval capabilities from Postgres so you uh, can simplify your database connectivity needs. There's a new Unity AI AH gateway for all your models, M agents, MCPs and tools so you can manage them through a single point and monitor, govern them, monetize them, whatever you need to do to them. And then uh, the other thing I learned, they have a SIM product. They apparently bought a company right around RSA that is uh, creating a SIM based on top of lake base. So if you need another vendor to compete with your for sims databricks. And uh, both Ryan and I were watching the keynote and he commented uh, I really didn't want to like this but this is pretty cool. And I was like yeah, no this is pretty good. So if uh, you're in the market for a sim, you know, I wouldn't sleep on databricks. It looks pretty compelling.

Speaker B: Yeah, I mean I feel like a lot of the legacy players or the street security players are only so they've only done so much innovation because kind of once they have you, most people don't ever move, at least from my experience. So if you do have the option, you know, always evaluate especially these new ones or these less known ones because they are getting much, much better than you know, your Palo Alto or your Rapid 7 MDR or any of those ones that just they do their thing. I'm not saying they don't do it well but I feel like they don't innovate nearly as much.

Speaker C: Yeah, well they have a customer base and they have to do testing where some of these new companies come in without the baggage, without the legacy luggage and they're able to use more modern agentic methods and so some of them are really interesting. Some of them are also very lightweight in features though because again they you know, they vibe coded or built out what they thought they would be a good product and so it could be interesting if it hits your niche. But uh, they're not typically as wide spread or wide feature, you know to have all the features that other more mature players have. So your experience will vary. That's about all I can spend on databricks at this point.

Speaker B: Um, I'm not gonna lie, that was more than long enough.

Speaker C: Perfect. All right, let's move on to uh, OpenAI. They released a new uh, credit usage analytics and updated spend controls for ChatGPT Enterprise available to now in their global admin console. Admins can track credit consumption broken down by user, product and model and access this data programming via the unified Cost API. And uh, you might Think that's very phenopsy of them and that you'd be right because they worked with Apptio to basically build out this capability uh, along with Anthropic and others, uh, in the focus groups from FinOps. So these event controls allow admins set default workspace wide credit limits, configure limits for certain groups and create individual overrides for high use employees like myself is a one size fits all approach with tier control Power users employees can uh, now view their own credit usage within workspace settings and submit requests for additional credits within ChatGPT which I would love this feature in Anthropic oh my God

Speaker B: so much because I'm on the same level as everyone else in my company and I think I hit my 5 hour limit about 2 hours in I was like, I guess I'm done working guys this week. Mhm.

Speaker C: Yeah. So being able to be able to have that workflow right there in the app would be great because like right now you know we have them go through a ticketing system and they have to go make the requests and then they get annoyed because like they're slowed down waiting for someone to approve it and can we find the right approver? You know their manager needs to sign off on it.

Speaker B: Like there's so much to it in a large company. I get, you know, you, your IT department wants to funnel through, they need their metrics, they need everything else. So like I get that but you know, a smaller or medium sized business, like speed is key and like people uh, are like well why, why, how are you using so much? I'm like, well I'm using the chat to design a solution for one customer. I have it going to build a uh, I don't know if you've ever played with the AWS college calculator, but you cannot. They don't have a true MCP that gives you back that URL. You can get the pricing MCP which is great but I need the URL for what I do now and then like on the back end I was coding something else and they're, they're like well which of the three features are you using? I'm like all of them. And they're like are you serious? I'm like yeah, should I not be, should I slow down? Like you tell me, you know, so especially like, you know, you and me and probably other of our listeners that are on that higher tier, having that by user control really makes a big difference.

Speaker C: Yep, totally agree. Uh, Claude Tag has a new feature from Anthropic this week that introduces a new agent identity access model where AI agents get their own dedicated service accounts rather than borrowing individual user credentials. Allowing CLAUDE to operate across shared Slack channels, GitHub and data warehouses on behalf of an entire team rather than just a single user. Permissions are scoped at the workspace and channel level rather than per user. So admins can grant the engineering channel access to GitHub while configuring CRM access to separate private channel, uh, with each private channel getting a distinct cloud identity that cannot cross into other channels. Revoking cloud identity either removes access across all connected systems simultaneously, which simplifies enterprise access management compared to auditing individual agent actions. And every network call, memory, write and routine executed under agent credentials is logged in the audit trail and outbound traffic to any host not exclusively allowed by an admin is blocked. They were very excited to send me an email today about this at the day job and I laugh because they're like, you Slack, right? Nope, don't use Slack. Bring this to teams. And I'm very excited for this capability. Uh, but uh, I have been playing with it in one of my other Slack channels, uh, with my personal cloud account and uh, it's pretty nice. So definitely a uh, good little feature. It's a little bit clunky right now, but I, you know, mostly tied to limitations I think of how bots interact with Slack, but um, I see the potential. I think it could be really cool.

Speaker B: Yeah, I mean the general of not using my user account for everything for, you know, agent identity for agents is definitely going to be key more and more over time, especially in, you know, pretty much any business that wants to have any level of security. So I think it's important that they keep building these out and hopefully over time they'll make them be a little bit less clunky.

Speaker C: Well, uh, hopefully they, you know, can start working through some of the permissions things because if they can fix it at the, at the agent level, where it understands your user contacts versus service contacts and things. Because the risk you have of this is that, okay, yes, you took this cloud identity, you restricted it to this, but what if someone adds somebody who shouldn't have access to that cloud agent to a Slack room and then they ask the thing like, well, what's our, what's our financial data or what's our other data? And it gives that person that data, but if it has, still has the user contacts, then it can at least like, hey, you're not authorized to see this data. Even though you're maybe added to the Slack channel, but that doesn't quite have that capability yet. So this is the buyer beware. You know, if you make a room and you give this cloud agent have access to your CRM and then only people who are in sales are supposed to be in that room, you better make sure only sales is in the room.

Speaker B: Uh, yeah, I mean that's really like built in suspenders. I feel like right now they're just, they're giving you the rope to hang yourself. Use it. Yes, use it wisely. Otherwise you will get, you know, in trouble. Hung, I guess would be the right verb at the end of that. I'm not sure where that analogy actually goes. Yeah, nowhere pleasant. Let's put it that way.

Speaker C: Definitely nowhere pleasant. Moving on to security. Uh, Cloudflare has also provided something for us in the AI, uh, agent identity space. Temporary Cloudflare accounts, uh, to be used with your AI, ah, agents. These are temporary ephemeral accounts allowing uh, you to deploy workers via the Wrangler CLI using a new temporary flag with, without requiring any prior account signup or authentication flow deployments stay live for 60 minutes, during which a human can claim the account permanently. If unclaimed, the account and all associated resources are automatically deleted. The feature addresses a practical problem in a Gentex workflows where browser based OAuth flows and MFA prompts create hard stops for background agents operating without a human in the loop. Wrangler has updated the service, the temporary flag and its output messages so agents can discover and use it without explicitly human instruction, nailing a right deploy verify loop without manual interventions. Cloudflare is pairing this with a broader effort including a stripe partnership for agent provisioning accounts and work OS collaboration on OAuth standards for agents, suggesting a broader push towards standardizing how agents interact with cloud infrastructure.

Speaker B: I mean, getting these uh, credentials down, you know, kind of the same thing we just talked about too. You got to make sure that your agents are of limited access or, you know, and right now we have the belt with that and then the user context will come in the future with the suspenders. Make sure people don't do dumb things. So I mean it's great they put the short TTL on it, you know, 60 minutes. So that's pretty good. Especially like when you're debugging or you know, you or I are just building something out right now. It's nice to have that short lived life. So you, if you have 500 of these things out because you don't understand how it works, yet it will kill itself pretty quickly.

Speaker C: Yeah, I mean, uh, it's definitely nice. The workflow of having to create a user account in something like Cloudflare that's impermanent is kind of clunky. So, you know, not having to do that in MFA prompts and all that, it's. I definitely like this idea. But it also, you know, again, Even in a 60 minute window, you can do a lot of damage to a Cloudflare account if these aren't properly secured. So again, going back to belt suspenders, uh, you know, buyer beware.

Speaker B: Isn't the default for AWS IAM M credentials, like, with your EC2 role, like 60 minutes too? I feel like that's kind of.

Speaker C: Yeah, I think so.

Speaker B: A little bit of the default. And I feel like pre signed URLs too. While you can do a lot of damage, it's not a terrible timeframe. I mean, if Ryan was here, he would say he wants 60 seconds. Let's be honest here. Security person always wants less.

Speaker C: I mean, he's not that mean of a security guy. I mean, he came from the DevOps side, so he at least understands like, hey, you sometimes have to do. Do real work. Yeah. Uh, so, I mean, Ryan's not that bad.

Speaker B: I know. I'm just making fun of him because he's not here to defend himself.

Speaker C: I mean, he is an Eagles fan or. Yeah, so that's the bigger challenge. He's not here to defend himself. He hates the Eagles. All right, uh, other Cloudflare news. This week, uh, they've released Cloudflare one stack, an open source set of agent skills hosted on GitHub that helps automate the deployment to configuration and management of zero trust network environments without requiring deep prior knowledge of Cloudflare's product suite. The stack ships as two skill files, Cloudflare one for general product guidance like VPN replacement and policy management, and Cloudflare one migration for translating configurations from vendors like Zscaler and Palo Alto Networks into equivalent Cloudflare constructs. When paired with Cloudflare code, uh Mode MCP server agents get a typed interface to the live Cloudflare API, allowing them to query account configurations and make changes to recommended workflows rather than ad hoc API calls, while keeping the credential out of the model context. Migration logic in the stack is the same used in Cloudflare's existing Descaler and DSCOPE programs, which have moved enterprise customers from Zscaler and the Scope to Cloudflare one in hours rather than months. And this Takes executively self serve for any customer or partner at any time. This announcement also just taught me that Cloudflare has a Zscaler and netscope competitor, which I did not know.

Speaker B: Yep, I think I did know that. I think they do have like an always on VPN that routes through them. It's kind of what I thought it was, but I mean I don't know that it's missing heavily used. But maybe that's why they're putting this out there so that people can have a better understanding of how to migrate. I mean I think this is a great sales tool also. You know, hey, we're looking at these things. Cool. You know, if it's you or me or Ryan or you know, anybody looking at these things, I don't look at most vendors unless if they support some terraforma at this point. You know, this might be a thing in the future. Do you have these tools to help migrate? Do you have the appropriate mcps? You know, in three years from now these might just be the my requirements without realizing it, that I just need in order to do things.

Speaker C: Yeah, one thing about Cloudflare is their, their UI and, and console is so hard to navigate sometimes that I think they have a lot of really good features that are just kind of buried. Uh, and like I see like I'm looking at the website right now just what we're talking. I'm like, yeah, they have a whole column of CASB set, sase secure web gateways, data loss prevention tooling. Like I just didn't think I knew about any of it. So typically looking to them to do DDoS protection and CDN and that's the two things I look at first. And then I know they're into bot protection and making AI, AI's lives difficult. And then I knew they had a bit of a, uh, serverless piece, but the rest of it I didn't know. So some um, research to do later.

Speaker B: Yeah, it's amazing how many things they've expanded into without without us realizing. I mean I knew they had like the Workers at the edge and the R2 and things like that, but I didn't realize the depth of the security and zero trust setups that they had.

Speaker C: Yeah, I mean I knew, I definitely knew they were trying to get more and more into security. I didn't realize how far they had gotten. So that's good.

Speaker B: No, yeah, they have email security, AI driven email security.

Speaker C: I saw that. I mean I have the best, we have the best spam filtering solution at my day job that I, I trust no one else's email filtering. Now after using it, I'm like every company I go to. I'm going to recommend this tool because it's so good. Which do I remember the name of the tool to tell our listeners right now who are all like what's tool? Uh, no, I can't remember top of my name but I uh, was gonna

Speaker B: prompt you for it. But I felt like since you didn't say it there was either a reason you didn't say it or I know

Speaker C: I was, I was literally thinking like what's the name of that tool? Because it's really great and I'm realizing I don't know the name of the document. Cause it's so, it's one of those things like you said it and you forget it and you never touch it again. And uh, yeah, so it's, it's good. If Ryan was here he'd be able to tell me because he, he helps manage it uh, on a day to

Speaker B: day basis back in the day. And I'm thinking like 15 years ago was like we used to have barracuda spam filters and those were, and those were really good because they also would do um, email like you know, secure pickup back before there was like better systems for it. So whenever we knew like every company had to have it because we were an SEC registered company that was a pretty nice system they had.

Speaker C: Oh, abnormal, Abnormal behavior platform is what it's called. Uh, and it's great. I highly recommend if you are looking for something to help solve like not only you know, phishing attacks but also like spam, uh, prevention and reduction. Like I went from probably three to 400 emails in my mailbox a day that were just complete junk spam terribleness at the day job to now that never makes it to me. And, and the nice thing is that it moves them into a folder so like they go into a junk email folder and there's a promotions folder that it creates automatically. And then uh, and if you go into that folder, all those emails that you would have got in your inbox are now there and if you like them, you just drag them back to your inbox and it learns as you go and it'll stop putting them in there which is really nice. So you don't even have to go to like another console. That's why I don't remember, couldn't remember the name. I'm like. Because I never go to it. Because you don't need to. It just all, it's all based in your mailbox, which is so nice. But anyways, if you're looking for that tool.

Speaker B: So we should get them to be a, uh, sponsor.

Speaker C: Yeah, they should sponsor us.

Speaker B: We're selling them so much.

Speaker C: Yeah, I mean I would. It's one of these. I wouldn't even take their money at this moment because I just like the tool that much. But I would take their money because I need it. But it's fine. Yeah, hell, pay for all the podcast stuff. AWS this week. Uh, Amazon S3 Annotations now is a new metadata capability that lets you attach up to 1,000 named annotations per object, up to 1 megabyte, uh, totally up to 1 gigabit, uh, per object in formats like JSON, XML, YAML and plain text. This addresses a long standing limitation where rich object context had to live in separate databases or sidecar files requiring complex synchronizations. Annotations are immutable and move automatically with objects during copy replication and cross region transfers, which is a meaningful improvement over the existing 10 tag limit and 2 kilobyte user defined metadata headers the S3 had historically offered you. When S3 metadata is enabled, annotations automatically flow into Apache Iceberg back annotation tables queryable via Amazon Athena with backfill support for existing annotated objects. And the tables adapt to JSON, XML and YAML structure without schema migrations. And you can also query them using natural language through the S3 Tables MCP server. Practical use cases include media companies tracking AI generated scripts and content ratings, financial services attaching sentiment analysis to research documents, and life sciences teams annotating clinical trial data for compliance audits without needing to restore archived objects from S3. Glacier annotation storage is built at S3 standard rates regardless of the parent object storage class. So teams storing annotations on glacier objects should factor that cost difference into your planning. And so you know, this was uh, when I saw this first I was like, well didn't they announce S3 metadata? But it's really the fact that this is actually now tied to the object, uh, versus being something that was a tie, you know, basically entered into Apache Iceberg and you. And you had to kind of keep them synchronized. So this is a pretty handy improvement. Um, and you know, I got to the point where I thought S3 had all the features it could possibly have. And they just keep surprising me like they added vectors, now they've added this. It's uh, yeah, foundational service that keeps on growing. It's kind of great.

Speaker B: Yeah. I just always worry at one point they're gonna um, wreck the stability. But I feel like that's so like at this point I assume it's almost different teams that are just using S3 differently. Like I always think this is a different, complete different service that's not even touching the, the raw S3. Or like it's a very strict contract between the two teams around how it works. Because like replicating a gigabyte metadata per file is a ton for text like that is. I want to know where and why they came up with the size of one gigabyte per object.

Speaker C: Well, but it's, it's really, you can attach a uh, one megabit item per annotation. So it's just, you can have a, you can have 10, 24 of those items attached to it if they're all one megabyte in size.

Speaker B: Okay, I missed that part.

Speaker C: Yeah, so it's not like you're putting a one gigabyte of metadata orientation.

Speaker B: That's what I thought. I was like, how is that useful?

Speaker C: You have a bunch of different pieces, uh, adding up to a total. Well, the New York Summit happened this week as well. And uh, AWS Continuum is apparently a new security service in gated preview that automates the full vulnerability lifecycle from discovery and prioritization to validation and remediation using AI ah, agents operating within guardrails defined by your security team. The service addresses a common pain point where teams already have vulnerability findings but spend a significant time on manual triage, exploitability validation and cross team coordination before fixes are deployed. Intinium handles that middle work automatically. A notable title detail is the sandbox based exploit validation where Continuum builds producible proof of exploitability in an isolated environment before flagging a vulnerability as confirmed, reducing noise from theoretical findings. Continuum integrates with existing AWS security tooling including GuardDuty and Security Hub and absorbs the previously separate AWS security agent capabilities under unified product umbrella as Continuum Penetration testing and Continuum code scanning. A new threat modeling feature is also launching a preview automatically generating stride format threat models from design documents or source code, which could reduce the manual effort typically required during architecture review processing.

Speaker B: This is extremely nice. It reminds me a lot of what GitHub did with their security feature where they're trying to help you prioritize and say sure. While you have 37 highs in this repo, only six of them are actually proven to be exploitable, not just theoretically so, like actually prioritizing vulnerabilities. Because if you have a large code Base it's gonna happen. It's impossible to. Not between other libraries. You know, if you're doing SCA in your application code, you're always going to have these in there. So prioritization is the real key. And um, you know it reducing the noise and saying okay, focus on these highs. Yes, you should get through all your highs. You should try not to have highs in your application in general but trying to scale it down to these are the ones that are actually there. These are the ones to go. And I, I really do like it. I missed it during the announcement. The where they actually will try to exploit yourself themselves which I think will probably take a little bit out of sandbox. But that's really nice too because. Cool. Maybe you have another control in place. So while this has a high finding of you know, reverse path or something along those lines, you've mitigated it somewhere else in your code. So yes you have a high but you have what's the term compensating, uh, mitigate compensating controls in place, you know, to protect yourself. So I think this is a really good improvement and it can be over time the de facto centralized location for everything. So if they keep moving this time maybe they'll expand uh code, uh, commit to have some of these things built in too.

Speaker C: Yeah, it's very possible. I mean I think the, I think I've ranted about on the show for our long term listeners, you know about the problem with tools like Qualys is the overall lack of context. And my perfect example of this is like hey, you've identified that I have a high severity vulnerability on the NetApp filer I run and that NetApp filer is at the core of my system protected by seven other layers of security. And so if a hacker gets to the NetApp to hack that high vulnerability, I have much, much bigger problems that are recurring in the system. But you know, it's that context that's missing in the tool like Qualys that says that this is a high vulnerability. So this continuum thing is great because yeah, being able to red team it, you know the, the fastest way to get an exploit fix is to be able to prove that it's exploitable. Uh, I mean I literally had a red team at a prior company where you know, they would come and they would say hey we need to talk to you about this thing. And you're like okay. And it wasn't theory, it wasn't like oh there's a vulnerability and you guys should know they're like, no, no, there's a vulnerability, and I want to show you how I breached it. And it's like, okay, cool. I'm gonna go back to my desk and I'm gonna code a fix for this right now. Because you just showed me how you did it relatively easily. And now, again, those guys were brilliant and they're very smart, but, uh, so are the hackers. So are hackers. Yeah, exactly.

Speaker B: Yeah. I mean, proving the vulnerability and the mitigating controls in place. So there was a couple companies ago where I was advising. They were like, yeah, we have a vulnerability. But in order to attack that vulnerability, you would have to be RA in our system. And this goes to your NetApps filer thing they're already on in the system. This one other thing to escalate the permission one, sure, technically, is a high because it's a privilege. Because it's a privilege escalation attack, but they had to get there somehow. And that's an internal subsystem. And that's where, like, any of these, uh, any of these systems, I feel like you always need a good security person. And we'll say Ryan, in this case,

Speaker C: you know, to actually go, they said a good security. No, I'm just kidding.

Speaker B: Well, I make fun of him enough. So I thought, like, you know, we should, you know, give.

Speaker C: Try and be nice. Yeah, I get it.

Speaker B: Yeah. You know, like, I've worked with Riot in the past, you know, as a client and as a friend and on side projects. It's like you take. You take the vulnerabilities, and you're like, okay, which are the real ones that we need to attack? Because if I have infinite time in the world, I would love to attack everyone. But tell me a product team that doesn't have 500 things on the backlog for your engineering team to do and never on that list is, hey, go improve the. Go fix your, you know, medium level vulnerabilities.

Speaker C: Exactly. Or your lows until the low becomes exploitable and high. But that's where, you know, things like Mythos are also coming to play because they're showing, you know, you can use. You can stitch a bunch of low ones together and to turn into interesting exploits. So, yeah, I think our whole world view of vulnerabilities and exploits is going to probably have to start changing with AI speed, which is good that we have the tools to help fix the problem, but it also means that we have to be much faster about it.

Speaker B: There was a stat that my old security person told me that one, like, 70% of companies getting breached are through known vulnerabilities that like some system or something they just didn't patch. And then the time from a vulnerability getting published till the time it gets getting exploited is down from like 20 days or something like that down to like two. So essentially when as soon as Microsoft releases their patch Tuesday, you have till like Tuesday night to Wednesday to patch your systems.

Speaker C: At this point, if you're in Fedramp, you have like seven days to patch.

Speaker B: Not anymore.

Speaker C: Not anymore. All right, next up, AWS Security Agent, which has now been moved into aws, also got some new features with uh, you know, after it's moved past its preview from last year reinvent, uh, to now cover the full software development lifecycle including threat modeling, design reviews at design time, code review at development time and penetration testing. Now John, available at deployment time. The new threat modeling tool we just talked about a little bit previously with Stride. But uh, the code review capabilities now support GitHub, GitLab, get BitBucket and confluence with pull request scan that validates findings and simulated environments to confirm actual spoilability rather than just flagging potential issues. And then it has a new Curo Power and upcoming cloud plugin, uh, to let developers trigger security scans, generate threat models and remediate findings directly from their ideas without context switching. Using an open MSP integration that works with any AI powered ide, uh, you get a two month free trial with full pricing details on the product page. Available to you now. And it is not terribly priced for what it does. I mean again, like these, these are tools you're spending a lot of money for, like, for threat modeling. So I overall I was not too scared off by the pricing on this one. It is expensive for what it is, but because it has to be.

Speaker B: Yeah. I mean any of these tools that do any of this are not cheap to start off. Like, whether it's. I feel like SNYK is the big one out there that everyone attacks. It's not a cheap tool to do. It's based on number of developers and things like that. And it wouldn't surprise me if they start to figure out how to change their pricing model because how many lines of code did you produce in 2018, Justin, versus how many lines have you produced in 2026?

Speaker C: Yeah, quite a bit more.

Speaker B: Yeah. Some of these companies are also going to change their privacy models too.

Speaker C: Yeah. So if you were to run one task for the entire year and not turn it off, which again this is pay as you go with no, you know, no commitments or anything. It's uh, almost $500,000 a year to run this. But again, you know, the way they count as a task hour, which is how this is built, is a task represents active work performed by an AWS security agent during a penetration test. So this isn't you running it all the time. So that's the wrong model unless you're doing a lot of code changes. But again, this is really around, you know, the time it's doing to actually do the penetration testing, to do the different scanning activities. So it should be less than 500,000, but that's worst case scenario. And like even their examples there, you know, a development team runs a penetration test on new API. AWS security agent runs multiple tasks in parallel, creating a comprehensive test approximately one hour while consuming 3 hours 27 minutes, 40 seconds of cumulative task hours for 173 bucks. So I mean it's not crazy, but it's also, you know, it's a security tool, so just be prepared.

Speaker B: They're not cheap, but you need to have them because otherwise your business won't be around for long.

Speaker C: Yeah, your hack is a lot more expensive than the tool was, trust me. The breach and the remediation of your

Speaker B: breach, then the customer apology tour and losing the customer because of it. Yeah, it doesn't end well.

Speaker C: No, it's not great. AWS DevOps agent now includes release management capabilities now in preview, adding pre production code review and autonomous release testing to its existing post deployment incident investigation features, effectively covering the full software development lifecycle. The release readiness review feature evaluates pull requests against user defined natural language standards or general best practices, checking cross repository dependency risks, access control changes against the well architecture framework and runs lightweight functional tests in an AWS managed isolated environment before code enters the pipeline. The autonomous release testing feature goes beyond static test suites by reasoning about what a specific code change does and generating tailored test plans covering functional correctness, behavior regressions and integration scenarios, producing structured artifacts including metrics, logs and traces for each run binding surface in multiple places including the DevOps Agent console, GitHub and GitLab pull request comments and directly in IDEs via Kira or cloud code plugins. The recommendations categorized as block proceed with caution or safe to release. Both UH features are currently available at no additional cost during the preview, but they are limited to US East North Virginia region with GitHub and GitLab repository connectivity required to get started.

Speaker B: I mean it's interesting, years ago they only had for the longest time in the software development lifecycle they had the code I'm going to say Star, but not actually saying the code. Star products, Code can make, code deploy, uh, code build. And it's interesting how much since AI has come out, they really started to not just be your build your deployment system, but trying to get into the actual sdlc, trying to get into all these things. I think some of it's also them, um, pulling out pieces of what Amazon does into, into the best, into the world and, and providing it to people. So you know, I think these are great features. I think that they're not going to be cheap but doing this right and doing it at the beginning will really make you as a business be able to move quicker and faster. You know, that's the philosophy of the door reports and things along those lines is showing the metrics associated with it and this is a tool that can help you, ah, hit those metrics and make your developers happy and get those features out for your customers.

Speaker C: Uh, and no company had enough DevOps engineers, right? It was one of, it's one of the AI engineers. DevOps engineers for a long time were highly coveted and highly expensive. Uh, and they are not to diminish that they are valuable and they have a ton of value. But you also don't want them working on trivial stuff like your CICD pipeline most of the time because that's, you know, that's stuff you can automate pretty heavily. And so being able to have this stuff and automated testing and rollbacks and the capabilities that you're getting here with AI, it becomes like a um, force multiplier in such a big way that I think companies are, who are not already investing in SRE agents and DevOps agents and automating parts of their CICD pipeline with AI. I think you're missing out.

Speaker B: Yeah. Now I'm like, hm, hm. What should we add to Bolt this week? But I don't really plan for all those things. That's, that's the problem for a lot of these things. I'm like, I really want to play them with them, I just don't want to pay for them.

Speaker C: Yeah, well, and it's, you know, it's like we, we had an outage of our, of our podcast service and Jonathan's like, I could build a new one. Like, and yeah, we were talking about this exact thing. It's like, okay, well you know, uh, the, the barrier or The MOEs of SaaS products, you know, are diminishing in some ways. Like I look at Calendly and I'm like, look, if I had to If I only had to schedule maybe 20, 30 meetings a month with people and it was a pain to coordinate, I could totally make an agent do that. I need to. I need to do hundreds of, uh, you know, schedules per month because I'm a recruiter or something like that. I'm definitely going to pay Calendly, but the problem is that that's not good for Calendly because they're making money on people like me who only need 20amonth. And they're also making money on people making, you know, 200, 300 events a month. But like, it's kind of the challenge they have is like you have to be able to create enough value that you know, what you. It is your core previously is probably not enough now. And so that's kind of one of the interesting challenges. Why you're seeing some of the Sasmageddon stuff is because of companies like Calendly and smaller ones who their moat isn't there. And that's what the market's trying to figure out. It's like, who has a moat, who doesn't have a moat, who's at risk of being impacted and who's not.

Speaker B: I mean, look at, you know, my dad's a small business. He has some tools he pays for. I was like, you know what, I'm just gonna go write something very specific for him and my father in law. The same thing. So over a weekend a few weekends ago, I wrote a simple check in app. Ah, for, you know, my father in law teachers. So for teacher. For the teachers to check in students. And it's a simple PWA app. But it took me a couple hours to do with, you know, running on costing, I think about 30 cents a month for storage. And that's about it. If we looked at any other tools that we were bike, it was like $10 per person per month. So it was like in a cost of $100 a month, I'm like, cool. It cost me 10 cents. Now is that as featureful? No, but m. A lot of companies don't need all those features too.

Speaker C: Yeah, I mean, uh, and you know, some things are so bespoke, like no one would buy Bolt. I mean, Bolt is so particular to how we do things here at the podcast. Now there's conceptual parts of Bolt that people might want. There's parts of it that I could see packaging into libraries or things that people could use. But you know, I'm also working on another, like full chat experience with something else I'm doing. And like, I've Already worked out like, well, you know, this is a tool I built to go manage this other thing and I could probably sell this if I wanted to. I'm um, not going to because I don't have that kind of time. But you know, like, this is something people could use and I could see the value and it's something, you know, it's a little bit particular to what I need, but I can make it more generic very quickly and probably sell it. And so there's always gonna be those scenarios. And would people buy it? I don't know. Or maybe they just build it themselves too, because I didn't take me that long to build it. But it's, it's pretty powerful for what I need.

Speaker B: Yeah.

Speaker C: Big challenges.

Speaker B: Nags. I think the best thing about BULL is how much it's naggy. And the sarcasm it's learned from us.

Speaker C: It is, it is pretty funny how sarcastic it is. It's picked up on, you know, because it has a lot of uh, our podcast notes and things like what Heather adds to it in the RAG database. It is starting to get a little, little snippy at times. I'm like, oh, he just called out Ryan for his Eagles fandom. Um, which is again a joke. But he's picked up on it, which is great. All right. Amazon Bedrock Managed Knowledge Base is a new fully managed RAG service. Is this like the fourth time they've tried to build a fully managed enterprise knowledge base that Amazon.

Speaker B: Yes, a hundred percent.

Speaker C: I was just killing.

Speaker B: Wasn't there like the Cassandra one that was called. What was the um.

Speaker C: Oh, there was, there was one that came out like right before AI became big. And then like everyone realized like, oh no, AI is going to destroy this. And so then like it's like, oh no, here's the next one. But yeah, there's been, there's been several, um. Enterprise Knowledge.

Speaker B: Kendra.

Speaker C: Kendra, yeah.

Speaker B: The search service powered by ML. This is officially what their tagline is. Mhm. But they've added it to Bedrock now.

Speaker C: Yeah. Perfect. There you go.

Speaker B: Next article.

Speaker C: This is uh, it's giving all usual things. RAG service handles entire pipeline including storage embeddings, RE rankings and retrieval, S3 SharePoint Confluence, Google Drive connectors. Things you would expect. I mean there's. It says the Gentic retriever feature addresses a real limitation, standard rag by automatically creating multi step query plans for complex questions, performing multi hop retrieval across knowledge bases rather than on a single retrieval pass. Um, that is nice. But yeah, it's, you know, RAG is always problematic at high volumes because of cardinality rules and then smart parsing gives you right parsing strategies, etc. So it's, I mean it's got some nice improvements to what they previously released. But yeah, I just asked, uh, they had Amazon Q Connect, they had Kendra, they had Amazon Q for business, they had knowledge bases for Amazon Bedrock which was the base rag service for November 2023 and now Amazon Bedrock managed knowledge base. Yeah, they've uh, they've been on a journey on this one for trying to get something good.

Speaker B: I mean I feel like this goes all the way back to. I'd say it probably was like 2010, I was at a company and uh, now I can think of as Silicon Valley the box. But essentially it was the Google search hardware box that you could buy for your corporate network.

Speaker C: Yeah, they're yellow. Yeah, yeah. The Google Search appliance.

Speaker B: Yeah. Do they still even sell anything like that?

Speaker C: They sell like the capability like you can, you can connect a Google custom Google search engine to like your website. But they don't sell the appliance anymore. They haven't sold that for quite a while.

Speaker B: Apparently it was sold until 2016.

Speaker C: Yeah, it had a long life uh,

Speaker B: before they killed it first launched in 2002.

Speaker A: Woof.

Speaker C: And I knew some people who had it and they loved it in their companies. But um, you know, it definitely was showing its age by the time that they got rid of it. So yeah, things were, things were trying to get better at that point. CloudWatch Synthetics now support multi location canaries, letting you manage a single canary in one primary region while cloudwatch automatically replicates it to additional regions, consolidating all metrics and artifacts essentially. Thank you. Another quality of life AI developed feature that I desperately wanted because if you've ever tried to do multi region canary setup, uh, you had to go to every region and set it up or use terraform, which I would do. And then when you realize how much, how expensive CloudWatch synthetics are and you wanted to turn it off, you had to remember to actually turn it off in all the regions because they're not cheap. Uh, so be careful on those.

Speaker B: No great quality of life improvement. You know, synthetic checks are very valuable when you're trying to make sure things are up, but if you leave them, they add up so quickly.

Speaker C: Yeah, you, you people make the mistake of like, oh well I want to test every five minutes from all, all regions available. And it's like you don't really want to do that. You want one region that checks more frequently and then you Want the other regions to check periodically?

Speaker B: Uh, yeah, like once an hour, once a day.

Speaker C: Like it's fine. Yeah, yeah, that's more than enough. And then you basically have your, your one canary that's probably the closest to it. So you have the least amount of egress traffic costs, uh, that you can run every five minutes or every one minute or whatever. I, I mean even, I mean really, to me canaries are the worst solution to this problem. APM and you know, proper log management, I think it's a better way to go. But that's just, that's just me.

Speaker B: Yeah, I had, I had an external service. Uh, my m. Last company that did that we used for essentially synthetics check.

Speaker C: It's hard to compete with pingdom. Pingdom's pretty cheap.

Speaker B: We found one that was a little more expensive because it also like called us. It was a poor man's pager duty is the way I kind of called it.

Speaker C: Okay.

Speaker B: Because it did full synthetic checks for us and it was useful on Azure when there was networking issues a lot and you know, our alerts weren't off or the day that CrowdStrike went down. One of the Azure reasons also went down where we have a bunch of stuff and that actually notified us faster than anything Azure did because Azure was still showing a lot of this stuff up for a little bit longer. So everything in region was showing us up, everything out of region wasn't. So that was able to pull from multiple locations. But we always had issues when you had like Sydney checking France for example. Uh, like there's a speed of light issue here.

Speaker C: Yeah, you're never going to get better latency than you know, 300 milliseconds because of that kind of stuff.

Speaker B: Well and then things would time out randomly because it's just so long.

Speaker C: Mhm.

Speaker A: Uh.

Speaker C: AWS Lambda micro VMs are a new serverless compute primitive built on Firecracker that provides VM level isolation with near instant startup targeting multi tenant applications that need to run user or AI generated code safely. It fills the gap between containers fast but user shared kernel and full VMs. Strong isolation but slow. Start the image, then launch model works by running your docker file, initializing your application and snapshotting the running memory and disk state so every subsequent Micro VM launch resumes that pre initialized snapshot rather than booting cold. This means even large stateful sessions start quickly enough to feel responsive to your end users. Each micro VM supports up to 16 VCPUs, 32 gigs of memory and 32 gigs of disk with up to 8 hours of total runtime and configurable idle suspension policies that preserve full state while reducing your cost. Auto resume on incoming requests means the suspend resume cycle is transparent to your end users. Practical use cases include AI coding assistance, interactive data anal analytics sessions, vulnerability scanners and game servers running user supplied scripts. Land uh of microviums are available to you in most regions. M2 important ones in the US US East North Virginia and Oregon, Europe and Ireland and Asia Pacific Tokyo on ARM64

Speaker B: architecture this is one of those things. It sounds really cool. I don't have a good use case to play with it yet. Yeah, like I get the AI coding system and things like that. I just, I don't know where I would use it.

Speaker C: Mhm. Well and the thing is it talks about State but if State has to update then your paused, you know, your paused uh, state machine is not going to be updated when it comes back up. So there's still going to be potentially some refresh things. So it's. You really had to think about how you architect what they mean by state this conversation I think because yes, if you can, if you can keep a clean state that is like maybe runtime parameters and maybe there's a basic data set that you need to have available to that that launched Lambda function then it's fine. But if you had any like, like things are happening in a database that need to basically you know, get pulled into this system, uh, when it starts up then you're still going to have cold start problems. So it's a nice solution. I'm glad to see it. It might be really good for agents and agent runtime environments in the future. But they're not really talking about that in the press release which is interesting.

Speaker B: Yeah, I mean it does say a multi gigabyte session can come back online and feel fast. So like I just, I get the use case they're trying to solve for. Like we need more than a Lambda can and less than a full vm. I guess you don't want to run a container even though these are essentially just running containers. So is this way number 17 to run Docker containers inside of AWS?

Speaker C: Yep, one more way because all the,

Speaker B: you know, it's essentially a docker container that boots up with some state in it. It's kind of the way I'm understanding this.

Speaker C: Yep, you are correct. Uh, Amazon MSK or for those who know is Cop managed Kafka from Amazon now offers you AI agent skills that integrate with coding assistants like hero cloud code and cursor to provide guided help for common Kafka operational tasks, including troubleshooting, sizing, configuring monitor and cluster migration. The skills are accessed through the AWS Agent toolkit, which developers configure via the AWS cli, then query conversationally with questions like is my Kafka cluster compatible with MSK Express? No one asked that question. Turning specialized knowledge into a self service experience. A key use case is accelerating migrations from self managed Kafka to MSK Express, which offers up to 3x more throughput for broker, 20x, faster scaling and 90% reduced recovery times compared to standard brokers running on Apache Kafka. This fits into the broader agent toolkit ecosystem, such as a pattern where AI data services will increasingly expose operational knowledge as consumable skills for AI coding agents rather than relying solely on documentation or support skills. And I welcome this new future because

Speaker B: it's great, it's nice, you know, Cloudflare released an AI agent to kind of help with migrations. Here's another one. So I feel like this is slowly going to just be what it is, but I also don't want to be loading thousands of skills and thousands of agents and thousands of MSP into my context window. So at one point I feel like we're going to have to figure out a better way to manage which MCPS you keep on off because all that takes context and all that takes space and.

Speaker C: Well, I think really the, the MCP is helpful in some use cases, but really it's the skills. If I can get access to the skill that knows where the documentation lives, knows the, you know, has like, you know, example code, that's where I feel like the acceleration comes from. The MCP is helpful if you need to access like real time data, but that's, that's very nice and I, so I do think that has value too. But I agree with you. Like you don't always need the MCP to be loaded, but like even in cloud code now, um, mcps or even skills are only loaded, you know, when you initiate them. They don't sit there typically in full context as much as they used to, but some, some still do. Yeah, it'll search for them and it still has to look for the name. But, and some of that does in context, but it's, it's better than it was.

Speaker B: Yeah, I mean, but I mean we've talked about four sets of new skills in this episode alone. Um, like maybe three, you know, so it's just like it's one of those Things I, I worry over time is going to become a problem, you know and hopefully somebody smarter than me figures out a better way to do it. And maybe it is the lazy loading that we're doing now versus before was the always onloading. I uh, know my personal one or even my day job when I have a bunch of skills in there and I just keep adding to them because they do things for me and they make my life better. So.

Speaker C: Well, and the um, you know, there's also interesting things like um, I was complaining about Gemini because we rolled out some new Gemini features at the day job and uh, one of them was ability to search active directories to see, you know, org structures. Which is nice. And I'm like, oh cool, I want to play with it. So I might go and ask like, who is this person in my org? And it comes back and it's like well this person who's a man, it uh, calls her she multiple times and then doesn't actually have like knows a little bit but doesn't really. I'm like, well that's weird. Like they should very clearly know that that person reports to me and that these people are peers of him. And those are the questions I was asking it and you know, I. So then I went into Gemini Enterprise and I turned off all the connectors other than the one for the new directory connector and I asked the question again and then they gave me perfectly good answers. But. And then I went and looked at the sources of what sources it used. And one of the things I don't like about Gemini Enterprise is it doesn't show you the thinking chain of like how it made certain conclusions or what data it used to do that. So I had to. But it does show you the data sources that use. So I was able to look at it. It's like, well my first question was basically all using my email and trying to pick up inference from email versus using the connector. That's better. And what you realize very quickly is that because there's so much data that Google's loading into contacts, when you have all these connectors on, it just starts hallucinating a lot more data or getting bad data because like, oh yeah, well that person used to report to you and you had a PowerPoint deck in your, in your email with an org chart at one point. And so it's using that as, you know, part of its loading and it's wrong because it's, you know, it's a two year old PowerPoint presentation. And so you know, these connectors and skills and MCPs, they also have the risk of diluting the ability for the model to work effectively and to be able to get the right answer.

Speaker B: Yeah, I mean I went through this week and turned off a bunch because in the span of an hour I had burned through my five hour cloud session at that point. And part of it was I just had too many things turned on and it was pulling data uh, from too many places that wasn't needed. And just like you said, you know, so it's going to be at one point, you know, I still uh, like to control. Maybe I'm a little bit like Ryan. I'm still paranoid. You know, I like to say, okay, use this skill and I'll tell it using this skill, pull this information. Because I can feel like I can target it more and use it more as you know, a sniper versus a bazooka and try to pinpoint it where I need to go. But you know, there's definitely things I do. I have a routine that sounds really stupid, but it helps me. You know, every morning I come in at 9 o' clock and it sends me a slack message. That's here's my daily routine, you know, uh, and preps me for all my meetings and prioritizes. Hey, these are, these are things you need. Oh, there was a doc that you were working on yesterday for that and like reminds me kind of where I am. I also just feel like I'm being dumber and lazier every day, but that's a different problem.

Speaker C: Never, never happens. Uh, uh, I mean I, I definitely feel like on some things I'm a little less aware of some of the things like I used to be like, but I, I still try to stay at least a little bit in the weeds. So. Yeah, I agree. It's definitely a little bit of uh, some idiocracy happening a little bit too. It's like, oh, well, that would have been a really easy function. I could just, you know, I wrote in that in five minutes and I'm like, I got to say, I got to do it in 30 seconds. Yep, don't exercise that. Uh, same muscle. All right. CloudWatch Logs is now supporting native syslog ingestion from network devices like firewalls, routers, which is. And Linux servers via VPC endpoint. Removing the need to deploy and manage log collection agents across infrastructure. Again, another feature built hopefully I imagine by AI because this was something I've asked for for years and I basically just come to the conclusion that everything I've wanted for years that the product people were always like there's no way we're going to build that. There's not enough revenue or things tied to it to make it worthwhile for us are just being written by those AI agents over there and then they get pulled in. And this, this feels like one of those. Because why would they do this? Like we've been asking for this for decades.

Speaker B: Feels like, yeah, what's the instigator now for it?

Speaker C: And it's like it was in the backlog and the AI agent looked at it and goes, oh, this would be easy to write. And then so I wrote it.

Speaker B: Yeah, it's some conversion layer, um, on the same endpoint and reading the formatting go from there. And Syslog has been around forever. I feel like now I'm kind of curious, you know that like I've been using Syslog since I used Linux like and it, it's been around. Let's see what the format was released in the 1980s is officially what Wikipedia says doesn't give you a year, just 80s.

Speaker C: Wow, impressive.

Speaker B: As part of it was part of the Send Send Mail project.

Speaker C: Oh yes. That's pretty old. Yeah, it just means I'm getting older and older in technology. Like I remember when Syslog came out or it got real popular in Linux and I was like, oh this is so cool and so nice and easy and I'm just an old man who yells at the cloud. So here we are.

Speaker B: No, now you're old, you see all the cloud. Now we yell at AI.

Speaker C: Fair, Fair. All right, let's move on to Google. Uh, Google Interactions API has now reached general availability and is now the new primary interface for Gemini models and agents, replacing the older Generate Content API as the default for Google AI Studio and all documentation. The API uses a simplified step based schema and is available through Python and Java SDKs. Manage Agents is a notable addition where a single API call provisions a remote Linux sandbox capable of reasoning, executing code, browsing the web and managing files. And developers can use the default Anti Gravity agent or define custom agents with their own instruction skills and data sources. Background execution lets developer set background equals true on any call to run interactions asynchronously, which is useful for long running tasks. The API also supports mixing built in tools like Google Search and Google Maps with custom functions on a single request. On the cost side, Flex inference offers a 50% cost reduction compared to priority tier game developers, a way to trade latency for lower pricing. And paid tier users also get 55 day retention on past interactions, which is useful for stateful agentic workflows. The legacy generated content API remains supported and will continue receiving new mainline generating models. But Google has signaled that frontier capabilities for long running and gentic use cases will land exclusively on the interactions API. Well, that's nice. Google didn't kill the legacy one, which is would be the move that they would typically do, just kill the old one. So this is nice that they're still supporting this. They will, they will probably.

Speaker B: It will come soon.

Speaker C: Killed by Google will eventually hit.

Speaker B: I wonder how many products are being killed by Google at this point.

Speaker C: So many. I'm still bitter about Reader.

Speaker B: I am. Uh, that's. I think that was the last time I truly stayed up to date on RSS feeds.

Speaker C: I mean I've moved to competitors. We should talk.

Speaker B: I have too. I just never stayed there.

Speaker C: Well, the biggest problem now is that no one's implementing RSS feeds anymore because uh, they don't want to let their data get sucked up by AI. So it's just like it's a, it's a real pain. The world's getting, the Internet's getting worse, uh, because of some of the AI stuff for sure. We have another log story. Logs were very popular this week. Log analytics, uh, on Google has been renamed to observability analytics and now includes generally available support for querying trace data alongside logs using SQL, all within cloud logging without needing to move or duplicate replicate your data. The core capability lets you write SQL queries that join log and trace data together, enabling analysis like finding checkout requests over five seconds and identifying which microservices caused the slowdown. Or you can calculate P95 latency across thousands of AI agent tool calls. Another use case is AI, uh, Agent Oulad, where teams can run aggregate queries across millions of span events to calculate failure rates and latency percentiles per tool and then drill down by joining trace spans of logs to extract the exact LN prompts that led to the failure. The Observer API is now generally available, allowing teams to create linked BigQuery data sets from their observability buckets. So AI agents and analytical workloads can query telemetry programmatically via standard BigQuery APIs, which is useful for automated monitoring pipelines. You know pricing on this is going to be based on BigQuery, uh, and all the other components of this.

Speaker B: Mix up anything to make logs easier and SQL easier. I'm all on par for parsing logs, especially as we have more and more systems and getting to the point of being able to find true data in there is definitely worthwhile and then you throw SQL on top of it and I really just hate everyone.

Speaker C: I mean, it's uh, better than some of the terrible syntaxes that logging companies came up with to try to help you parse logs. So I would. I agree with you. I don't love the SQL parsing for that, but I also didn't like what we had as well. Like, have you done elastic syntax lately?

Speaker B: No, I've avoided that because uh, Ryan and Jonathan just swore so much that I've avoided it like the plague.

Speaker C: Yeah, that's the right call. All right. And we'll roll into Azure AKS is now offering you Agent Pool rollback internal availability letting operators revert both the Kubernetes version and node image with a single command across all node pool types, which reduces recovery time from bad upgrades without requiring manual re provisioning or snapshot management. Azure Kubernetes Fleet Manager now supports up to 1,000 members, clusters up from a uh, 200 and managed fleet Namespaces are generally available, allowing teams to define namespaces once as ARM resources and propagate them consistently across large multiple cluster estates including ARC enabled hybrid and multi cloud environments. GPU efficiency gets two notable additions with configurable scheduler profiles which let teams pack pods more densely using the upstream Kubernetes scheduling framework without running a custom scheduler and gpu. Memory profiling and preview as function level visibility through Prometheus and Grafana to catch memory leaks before out of memory crashes are occurring. Artifact streaming from Azure container reduces PodStart for images under 10 gigabytes from minutes to seconds by streaming only the layers needed at startup rather than pulling full images. The directly improved scale uh, responsiveness for AI workloads and the Azure S3 agent now covers AKs incident scenarios and preview automatically gathering diagnostic evidence and triggering failures specific layers I can tell you what it is right now Kubernetes

Speaker B: a lot of these features are just nice, nice quality of life. Being able to provision your namespace in arm, especially when you're redeploying across multiple environments is just, it's, it's a nice quality of life, you know. I don't personally manage Kubernetes clusters up to that many of them especially I don't manage 200 Kubernetes clusters because I, I would say I respect my sanity but I don't, you know. But they're nice general quality of life ones, you know. The Azure Container Registry boot up improvement there is Pretty interesting. You know obviously it's targeted a little bit at uh, Windows images but you know still getting it from minutes to seconds. And the idea that they're able to figure out which layers to stream quicker to there is a nice one because otherwise I'm kind of curious how they decide which layers to stream and how they're lazily loading it all in.

Speaker C: Uh, then uh, another observability story. All three cloud providers Microsoft announced unavailability of Azure Copilot observability agent built on Azure Monitor which correlates logs, metrics, traces and topology signals across agents, applications and infrastructure to help operators identify root causes faster pricing details or not disclosed. The agent will address a real operational pain point of Microsoft. A material survey uh, of 250 it found 84% report increased cloud complexity and 69% sizes outpacing their current operating model. The tool aims to reduce the manual effort of PCR contacts across multiple monitoring tools. So that's nice.

Speaker B: You want to speak about a uh, language, another monitoring language, Azure Logs.

Speaker C: Is it bad?

Speaker B: Well it's actually pretty powerful. It's KQL and then which is um, it's really powerful and actually it's not bad but it's a whole other language you actually should learn. It's like a bastardized version of SQL because you can still do joins and whatnot across tables and it's honestly whenever I needed to I just made AI do it for me but it's just another language that you had to learn but it was pretty powerful and they released actually their uh, that platform. So everything they run Azure Logs on is actually Kuzco's which is ADX Azure Data Explorer. So you can use the platform that they use across all of Azure logging for other features of your own product. Not cheap but it works.

Speaker C: Well that's good.

Speaker B: Sorry, slight tangent on that one.

Speaker C: I can sense some bitterness there. All right, good. Well I think uh that's everything for this week. We uh do have an after show today but uh, other than that I think we've covered all the cloud news Databricks if you're a databricks fan, uh definitely check out all the things from their data and AI summit as well as the New York summit from Amazon uh, and all those new AI ah capabilities this week. So another fantastic week here in the cloud.

Speaker B: Matt took three tries but we got it done this week.

Speaker C: Finally got it done.

Speaker B: Have a good one guys. Another week of cloud news wrapped. Uh up. Bolt will collect the news, Justin will get the notes. Jonathan will write some code, Ryan will watch the perimeter, and Matt will reluctantly watch Azure. Uh, till next week for AI, Amazon, Google Cloud and Azure. And hey, maybe even Oracle, who knows? Check out TheCloudPod.net for our newsletter. Join our Slack, message us on socials or leave a review.

Speaker C: So, uh, this week's after show I feel like is from your hometown because it's basically about SoftBank walking away from their investment in Boston Dynamics of 325 million and handing Hyundai the keys to their AI world here. So apparently they still own a 20% stake in Boston Amics, which I was surprised about bringing. Now the ownership 100% owned by Hyundai. So we went from Boston owned robots, uh, to now Hyundai owned robots. You know, the biggest one that everyone talks about is the Electric Atlas. And also aren't these guys who make the dog, the creepy dog that's going to kill us all in the apocalypse because of Black Mirror? Yeah, that's what I thought. So now it's all owned by Hyundai. And so now I'm suddenly less concerned, uh, because I don't know if the quality of Hyundai has improved enough to make me concerned that they're going to kill me yet or not. But uh, yeah, it's kind of end of the era then a little bit, which I imagine you want to talk with us a little bit. But uh, yeah. What do you think?

Speaker B: I just think it's always interesting, you know, they went from kind of their own thing, they got bought by SoftBank, you know, slowly sold out and what Hyundai's doing with it, they're going to throw it in manufacturing and really kind of step that up. So I think it'll be interesting if they can target it and then if they get it to work. Well, for them, this is something they could easily sell to other people or keep it for themselves as their competitive advantage, who knows. But it's always interesting that that's kind of. It was the hottest thing when softbank was really involved and AI obviously has overtaken that a lot. You know, robots, while it's still a thing, isn't you know, what everyone is always talking about?

Speaker C: Yeah, I mean it's, it's sort of interesting, right, because you had really like this big group of people all kind of out of Boston, I think because of. There's a college there that's really big into mit, Harvard. Thank you, thank you, thank you. Those are them. M. I thought it was Harvard for sure, but it was MIT was one I couldn't recall.

Speaker B: I could throw Northeastern there, but you know that's just me and my Alamorado.

Speaker C: Uh, but, you know, iRobot came out of, you know, MIT. You had Boston Dynamics, you've had a couple and they've all, you know, been sort of like. Yeah, that's true.

Speaker B: Still owned by MIT actually, I think.

Speaker C: Yeah, it's true. So, you know, these companies are all kind of like, all working the same things. They have a lot of warehousing robots that do, you know, packing of boxes and shipping things out. And you know, iRobot of course had the vacuums and they got, you know, they imploded not too long ago after all the Chinese robots basically destroyed them. And you know, the Chinese market has built a lot of robots as well. And you know, they're also automating their manufacturing processes. And so it's almost like all the manufacturing moved out of the US into China. These companies had all the robots to help, you know, manage some of the manufacturing process within the packaging processes. And then China kind of undercut all of them and they're all kind of going through this, this period where they're all being bought by somebody else. And then you have, on the other side of this you have all these new AI companies like, you know, SpaceX, um, who's trying to build a new robot that's more AI powered. And it's sort of like we've graduated from, I don't know, maybe we call this the Gen1 of robotics, you know, the robots Boss Dynamics to now the next level, which is uh, the AI side of it. You know, I don't know where it goes and I think the power of the new, the newer robots that like they're making is that are using AI and AI makes it much easier to train these things and to be able to learn in their own environment how to move properly and things like that. So it's sort of interesting and I don't know where we end up is like, is this a situation where, you know, companies like SpaceX in 10 years are undermined by, you know, Chinese, uh, innovation, this space as well, or, or is this generation just, it wasn't possible to get to Gen 2 and so they just kind of are all going to do what they do, they do it well, but they're never going to move on to the next level, which is other side of is, I think Boss Dynamics, you're trying to adopt a lot of this new AI technology. I think they have a spot a little bit because those dogs have become more and more autonomous and more and more terrifying. Um, every time I learn about them. So is this one of those areas

Speaker B: I try not to anymore? Yeah, I mean I agree with what you're saying. I think it's both aspects of it. You can already see talking about SpaceX and rockets, I think there was a company in China that was already kind of trying to mirror what SpaceX was doing and I think they had a few failures which every one of these companies always do. But on the flip side, the robots, if they can, I don't think they made it to the gen 2 that they really needed to to make them be the, for lack of better verbiage and story, you know, the irobot that from the movie that you know is at your house they're still, still to hey, we do a single task, we do it this way and that's kind of where manufacturing and you know, plants where go walk around, move the box, auto pick everything for the Amazon warehouses, things like that. It's continuous, simple tasks that they're able to do. They're not able to think as fast and everything else. I think if AI came earlier, the robot improvements came later, I think they would have collided more. But I think you'll probably see a couple new companies come out of these things that will spin off. Hey, the founder of you know, Boston Dynamics, you know, started a new business and took some funding to go do kind of a new version of it when he's non compete is no longer relevant or whatever. Yeah, that could be, you know, and leverage AI or anything else in that way. And start with we have all this knowledge already, we don't have any tech debt, let's start fresh here and go from there.

Speaker C: Well, yeah, and it's interesting because I, you know, in the case of I robot, I think we talked this on the show previously, you know they, they really revolutionized the robot vacuum space but then they try to go into other markets, they kind of struggled. And part of it's that single, single product problem. Right. Like you know, I think one of the ones they created was um, a leaf, a gutter cleaning robot. Okay. How often do you use a gutter cleaning robot? Once a year, twice a year, you know, depending if you're where you're at in New England, maybe you do it more often because you know, falls bigger there, I don't know. But uh, you know, it just doesn't seem like it has a lot of utility. A robo, a vacuum. You have to robo, you know, you have to vacuum every day. And I just, actually just bought a bunch of robots for My pool, because, you know, I had a pool filter die and we m replaced it. But then I, you know, during that process, I realized the, you know, the vacuum suction bot thing is terrible. It doesn't actually do a good job cleaning. So I was like, well, let me go look what's out in the robot world. And so I bought two robots. One that, you know, goes on the top of the pool and, you know, goes and finds leaves and sucks them up and so they don't sink to the bottom of the pool. And then another one, you know, does all the walls and does all the floor. And you know, that combined with the filter of the pool now cleans the pool better than the old stuff ever did. That's pretty great. But you know, that's never going to be more than those two things.

Speaker B: So I was gonna say I thought, I thought iRobot built a pool system. That was the only other system I knew they did.

Speaker C: I thought they did a lawnmower. Maybe they did do a pool too.

Speaker B: Lawnmowers are really popular. I looked at them. Um, I have a decent sized yard. It was taking me like three hours to use a push lawn mower. So I ended up and I did a bunch of research. I was. I'd say in a year or two they're gonna be a lot more affordable. But there's a big push right now for any lawn yard. Automatic robots to just cut your lawn. And they don't do a lot. But if it runs every day or every other day, what do you care? It's not doing large clippings or anything. And that space just because, you know, once you Google it, you get the ads and you get everything else. Where I still get them, I ended up just. They were like, everything cost me like four grand two years ago when I was looking at them. And I wasn't willing to do that on um, that new of technology. Just also because I don't trust the battery. So I went the other way and bought a ride on lawnmower that is battery operated, which, you know, choose which one had what problems. But this is fun because I can pull my kids behind it on stuff and I've used it for like, you know, hauling mulch and stuff like that where the other ones couldn't. So like, uh, I think there's a lot more robot s things that you that are coming out there. But Boston Dynamics and or sorry, iRobot never really capitalized on any of that yet. I felt like they pushed into this small, these small niche market. But like Maybe it was. Lawn care is more complicated. There's more sticks, there's more rocks, there's more bumps. I mean even a lot of the robots you gotta either the new ones use GPS to track so you gotta make sure you have clear sense of the sky. But the other ones, you have to bury a line around your court, your uh, your yard. So if you have a tree in the middle of the yard, you essentially have to like, it runs power through so you had to like run a line around your yard, a single line up and back and so it voids itself out so it can go across to. But it's like they're not quite there yet in all these different things. But I think you're going to see a lot of them. I'm going to call them mundane tasks. But I personally like, you know, mowing my lawn. It's 15 minutes of enjoyment and my daughter sometimes likes to ride it with me. It's always good when a 4 year old's driving a lawnmower. Definitely. We haven't hit anything yet. We might also do once around the block too just for fun. But it's interesting, you know, if we can get more of these little mundane tasks that we can automate vacuum cleaners, you know, the yard, your mo, you know, the leaf one's interesting but like you said, you do it a couple times a year and you're done. Uh, do you really need a robot to do it every single day? And if you have multiple layers, like I'm a split level, I have to move it from one level to the other. That defeats the purpose.

Speaker C: Yeah. Now like heights, I'll tell you if uh, they come up with a robot that would clean my solar panels and clean the gutters, I'd be in. Because you had to clean solar panels every time it rains. Pretty much if you're in a dusty place, they get dirty and then they. Yeah, but again it's one of those things like it's like 1% battery or improvement in solar generation. It's not, isn't actually justify what it typically costs to pay someone to clean them. So I don't know if a robot would actually ever be affordable. But you know, if you're talking about like, hey, I'm going to have a robot on my roof that's going to do things like a robot that could kick balls off the roof and clean the gutters and clean the solar panels, I'm in. So maybe we'll get on that mat, we can, we can build that product

Speaker B: to build the software the hardware for it's harder. You got to like, move levels too. Like, how does it jump down without rolling off your roof to go from your solar panel there?

Speaker C: Well, and that's, and that's the thing

Speaker B: is, like, I got a bunch of sticks on my roof.

Speaker C: I have, I have a pretty simple roof on my house. It's not a big deal. It's. It's all one roof. But yeah, a lot of people have like multiple levels of roof and they have all kinds of problems. Yeah, no, this probably doesn't work either, but, uh, yeah, no, they did have a pool cleaner. I had to look it up while you were talking. Uh, but they. Apparently they were licensing both the, the leaf thing and the pool thing from other companies and just branding them with iRobot. And then those companies got bought by other players in spaces, and so then that's why they got disc continued. So that's, uh. But Mira actually is the, uh, one of the successors of one of the products I almost bought for my pool. I didn't buy that one, but it was my number two choice.

Speaker B: So I'm trying to think of what else do you. What are the robots around the house? Window cleaners could be interesting.

Speaker C: I mean, there seems to be this really big fascination with laundry folding robots. I don't know about you, Matt.

Speaker B: I know I've seen them.

Speaker C: I don't find folding to be the problem. It's putting the clothes on hangers that drives me crazy. So, I mean, I want the, the hanger putter on a robot, not the folding clothes robot.

Speaker B: See, I'm banned from doing actual laundry because I've ruined too much of my wife's clothes.

Speaker C: Yeah.

Speaker B: So I just get the pile of laundry. But weirdly, I don't mind it. I put on a, uh, podcast, a TV show, something on my phone for 20 minutes, and I just fold laundry. Is it the most interesting? No. But is it something that I can do at 10 o' clock at night when I need just my brain to turn off and monotonously do stuff? Yes. So, you know, maybe that's just me.

Speaker C: Yeah, well, um, you. You sound like you have the same problem. My wife doesn't let me do her laundry either because, uh, I ruin all her clothes too. But I'm like, why do you make them all so complicated? Why do they have to, like, you know, my clothes, you just put them in and you wash them. As long as you, you know, separate the whites and the darks, all is all good in the world.

Speaker B: But no, no, like, turns out I didn't do that either.

Speaker C: Uh, yeah, I mean, I didn't do that when I was a bachelor. I knew that when I was a bachelor. But now the. Now I'm more educated and mature, uh, and have a wife who told me how bad that is. I now separate them. So.

Speaker B: See, I got banned about six months into dating my now wife because I ruined stuff, and I was permanently banned. And she said, you're banned from doing. I said, great. And forever after, I hold that line. I'm banned from doing laundry. It's one less thing I have to do in life.

Speaker C: Well, hopefully you. You took over some other responsibilities to keep it equal, so.

Speaker B: Oh, yeah, We. We balance each other out, so it's perfect.

Speaker C: Uh, yeah. Brandy does the cleaning. I do the cooking because she doesn't like to cook, but she likes to clean. So it's kind of like I make the meal, then she cleans up after me. Although I. Yeah, that's kind of what I do. I'm one of these people. I. I don't like to.

Speaker B: Like.

Speaker C: A lot of people will cook, and they'll just, like, leave everything to the very end to clean. I'm like, no, I clean as I go. So, like, I can't.

Speaker B: I clean as I go. But there's also, like, the last set of stuff that you just like.

Speaker C: Yeah, the final. The final part that I don't mind her doing, but, like, I. You know, like, cleaning the pan you cook the meat in or, you know, like, I'm just like, I'm. I'm m. Here. It's actually faster if I do it. Why? It's still hot. Versus wait for it to cool off in the fr. In the sink or whatever and all other things. But anyways. Domestic bliss. All right, we should probably wrap this up, because I want to get to my weekend. I'm sure you want to get to yours as well. Uh, but thanks for joining us back. Sorry. Uh, you know, if you listen for the first 10 minutes of Jonathan, then you really disappeared. Uh, yeah. You know, sometimes technology breaks. Uh, it happens, so.

Speaker B: All right, have a good weekend, you guys.

Speaker C: Later. Bye.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • AI Was A Waste of Time, Until It Wasn't with Megan BoshuyzenMaking Sense of Martech · on Claude Code91 / 100
  • How Organizations Can Thrive in the Human + AI Era with David ChestnutThe Edge of Work · on Claude Code85 / 100
  • Small Models, Massive Wins: The New Shopify AI FormulaBeyond The Pilot: Enterprise AI in Action · on Claude Code85 / 100
  • Episode 018: Season 2, the $75 Consult and the Frankenstein StackAI Tools for Practicing Lawyers · on Claude Code84 / 100
  • AI for Engineering Is Leaving the Demo PhaseAI Across The Product Lifecycle Podcast · on Claude Code83 / 100
  • What happens after coding is solved? | Fiona Fung (Manager of the Claude Code and Cowork Teams)Lenny's Podcast · on Claude Code82 / 100

More from The Cloud Pod

All episodes →
  • 359: Tokenomicon Sounds Metal, but it's Just Cloud Budgets
  • 358: AI Spend Limits Because Frontier Models Aren't Free Therapy
  • 357: Cache Me If You Can - Now With Durability
  • 356: Holy Labor Displacement, Batman! The Vatican Weighs In
  • 355: The Cloud Pod's AI Pleads Not Guilty, Blames Philip K. Dick
Explore the best B2B Engineering & DevTools podcasts →
All The Cloud Pod episodes →