The escape hatch that turned out to be french doors
I wanted an FFmpeg that couldn't touch my disk. Building the interface to get one accidentally produced something considerably more useful.

I wanted an FFmpeg that couldn't touch my disk. Building the interface to get one accidentally produced something considerably more useful.

Eleven variants of one shell script, on hundreds of laptops, launching pods into production. The language was never the problem, and it wasn't the fix either.

One of them was from me, testing it. I'd still publish the key, and the reason isn't cryptographic.

I set out to add a config writer and keep Viper. I ended up keeping the writer and deleting Viper, and I didn't notice until it was already gone.

A security review read "safely process untrusted media" and asked the harder question. A sandbox stops escape; it does not stop exhaustion.

Three HIGH advisories deep in a Rust dependency tree, a one-line fix that changed nothing, and eleven minor bumps that were never mine to make.

rust-tool-base needed go-tool-base's control over which commands an AI agent may call. Closing the gap meant doing the opposite of what Go did.

If the platform hosting your code also hands out the key that verifies it, the signature proves nothing. Where to publish a public key instead.

Launching sigillum, a standalone artefact signing and verification CLI, and the Rust signing problem that made it necessary.

Where a signing key lives is the most provider-specific decision in the whole business, so the framework deliberately refuses to have an opinion.
