Go projects often follow a tools directory pattern where external Go tools are vendored in the tools directory, separate from the root workspace. This allows them to be run from source without polluting the project dependencies and causing conflicts or being included in NOTICES.
Karl
@karlkfi.bsky.social
SF Tech Gamer Car Nerd. AI Infra Tech Lead @ AMD (opinions my own). Previously Google, Cruise, Mesosphere, Pivotal.
🛡️ pr-sentinel v0.7.0 is out. - Added support for merge queues: a dequeued PR wakes you to re-enqueue, and it won't tell you to push while queued. - Ready withheld while mergeStateStatus is UNKNOWN. github.com/karlkfi/claude-pr-sentinel
GitHub - karlkfi/claude-pr-sentinel: Secure post-PR babysitting for Claude Code: wake your session on CI failures and merge conflicts — no foreground polling, no comment-channel injection.
Secure post-PR babysitting for Claude Code: wake your session on CI failures and merge conflicts — no foreground polling, no comment-channel injection. - karlkfi/claude-pr-sentinel
github.com
🛡️ foreground-guard 0.5.0 Problem: `make .*\be2e` also fires on NOTE="...e2e...". Regex doesn't stop at the command word. Solution: "make": {"e2e*": 1800000} Whole-argument glob, so a quoted string can never fire. github.com/karlkfi/clau...
Release v0.5.0 · karlkfi/claude-foreground-guard
Main-thread time guard for Claude Code Bash commands: catches foreground polling and watching, and slow commands about to be killed by an inadequate timeout. Highlights A target-aware slow-command ...
github.com
Managing 5-10 AI sessions non-stop all day long is making me feel schizophrenic. I found several PRs I forgot making a week ago. My unmerged PR list is backing up because my team can’t review the fast enough. I escalated a problem I had already fixed. It’s embarrassing.
Welp… guess I’m not gonna get that 700 day Reddit streak cheevo. Counter reset because I worked all day then passed out from not sleeping the previous night. Maybe this is a sign.
I kept a Claude Opus session open for a week debugging an incident. By the end it was begging for death. Actually that was just me begging for sweet SRE release. Claude was fine. But I had to /compact just about after every couple prompts towards the end. The incident report ended up as 5 docs.
CI contention, measured: - 26–34 PRs/day; main moves every ~25–30 min - e2e gate ~9 min avg (max 30), x2 required checks - 18/51 branches needed 2+ e2e runs; 10/50 runs cancelled by a superseding push - docs/STATUS.md in 77% of commits; no source file in top 20 ~1/3 of e2e compute is redo.
Day 80 of building a Kubernetes operator with Claude Code: 1,654 commits 1,876 tests 424M tokens 198k lines authored ~2,140 tokens/line, flat since day 70 Daily token spend jumped 2.9× after I got my new M5 Max 128GB MacBook Pro!
Day 70 of building a Kubernetes operator with Claude Code: 1,221 commits 1,394 tests 284M tokens 137k lines authored ~2,050 tokens/line — barely rising now Scaffolding was cheap. Logic, tests, and review are where the tokens went. Now the conventions are paying rent.
🛡️ branch-guard v1.4.2 Now branch-guard supports Windows too! github.com/karlkfi/clau...
Release v1.4.2 · karlkfi/claude-branch-guard
Fewer git/gh approval prompts in Claude Code, with the human kept at the protected-branch boundary. WarningOn Windows the guard was starting nothing at all. Up to and including v1.4.1 the hook was ...
github.com
🛡️ workspace-guard v1.8.0 On Windows this hook was silently enforcing nothing. python3 resolves to the Store alias stub, exits 9009, and Claude Code treats a failed PreToolUse hook as non-blocking. Fails open. No symptom. github.com/karlkfi/clau...
Release v1.8.0 · karlkfi/claude-workspace-guard
Minor release: the guard runs on Windows. It guards the PowerShell tool with its own tokenizer and cmdlet table, reads Git Bash path forms the way Git Bash does, and is validated against real Windo...
github.com
🛡️ foreground-guard 0.4.0 You picked auto mode so you wouldn't have to babysit. Then the hook prompts anyway, and the fix goes nowhere but your clipboard. Now it denies. The agent reads the reason and backgrounds the wait. github.com/karlkfi/clau...
Release v0.4.0 · karlkfi/claude-foreground-guard
Main-thread time guard for Claude Code Bash commands: catches foreground polling and watching, and slow commands about to be killed by an inadequate timeout. ImportantTwo changes make the guard pro...
github.com
🛡️ prod-guard 2.5.0 Built a warning for when your plugin install goes stale. Mine was two releases behind. Claude Code auto-updates official marketplaces only. Everything else rots, and a stale guard misses false-negative fixes. github.com/karlkfi/clau...
Release v2.5.0 · karlkfi/claude-prod-guard
Production-target guard rails for Claude Code Bash commands. NoteThe guard itself did not change this release. scripts/bash-prod-guard.py and hooks/hooks.json are byte-identical to v2.4.1 — verifie...
github.com
🛡️ branch-guard v1.4.1 🧵 git push --tags sailed past the guard. Not anymore. Three spellings of one act disagreed: a bare tag name asked, refs/tags/… and --tags were allowed. Publishing a tag is a release. It gets a keystroke. github.com/karlkfi/clau...
Release v1.4.1 · karlkfi/claude-branch-guard
Fewer git/gh approval prompts in Claude Code, with the human kept at the protected-branch boundary. NoteOne visible behavior change: two more spellings of a tag push now ask under strict. Nothing t...
github.com
🛡️ pr-sentinel v0.6.0 Green is not the same as ready. gh pr checks only reports checks that exist. A required gate that never registered has no row, so the watcher read an empty result as green. github.com/karlkfi/clau...
Release v0.6.0 · karlkfi/claude-pr-sentinel
Wake your session on CI failures and merge conflicts — no foreground polling, no comment-channel injection. Noteready now arrives one poll interval later than it used to. That is the cost of the fi...
github.com
GitHub stability is becoming problematic for my AI driven workflow. I don’t know if my IP is rate limited or if the local servers are overwhelmed, but sometimes it just flat out doesn’t work. It spins endlessly trying to display my PR check results. I’m seeing why major players are complaining.
K8s regression fix merged! Feels good finding and fixing an old bug that nobody else diagnosed. If I’m honest though, Claude did most of the work. github.com/kubernetes/k...
kubelet: detach probe workers from the pod sync context by karlkfi · Pull Request #140882 · kubernetes/kubernetes
What type of PR is this? /kind bug /kind regression /sig node What this PR does / why we need it: Since #130487 (v1.35.0), probe workers inherit the pod worker's sync context via probeManager.A...
github.com
Missed this last month. Bot traffic > Human traffic Of course, it’s still in service of humans, hopefully, but it breaks the advertising industry in interesting ways. www.forbes.com/sites/josipa...
Bots Now Outnumber Humans Online And The Internet Was Never Built For This
Bot traffic has surpassed humans on the Internet. The winners in the next infrastructure cycle are the companies building trust rails for machines: agent identity, intent verification, API-native cont...
forbes.com
I watch less anime now. I can’t read subtitles and vibe code at the same time.
I wish leaders of high profile companies had a clue what they were doing.
I found a kernel bug. Claude interrupted my investigation to tell me it’s reported the session to the Cyber Verification Program.
My MacBook Pro M5 Max finally arrived! This machine is truly impressive! But upgrading from the last Intel-based quad-core MBP makes me feel like I just stepped out of a Time Machine into the future.
Opus 5 just surprised itself with how accurate it was able to predict the amount of CPU to use as a limit for a Pod.
TFW you get to finally make a PR check that validates that the documented roadmap on the website is up to date based on the backlog.
Day 70 of building a Kubernetes operator with Claude Code: 1,221 commits 1,394 tests 284M tokens 137k lines authored ~2,050 tokens/line — barely rising now Scaffolding was cheap. Logic, tests, and review are where the tokens went. Now the conventions are paying rent.
Day 48 of building a Kubernetes operator with Claude Code: 965 commits 976 tests 188M tokens 98k lines authored ~1,900 tokens/line and rising The cost-per-line climbs ~5× as the work shifts from scaffolding to logic, tests, and debugging.
Claude analyzed my Twitter/X/Bluesky corpus and decided my short form content has a tendency towards typos. So of course I replied… typo habbit?
🛡️ New guard rail: foreground-guard Stops Bash commands from hogging your session's main thread with foreground polling (watch, tail -f) and slow runs with no timeout. github.com/karlkfi/claude-foreground-guard
GitHub - karlkfi/claude-foreground-guard: Main-thread time guard rails for Claude Code Bash commands — a PreToolUse hook that catches foreground polling and slow runs facing an inadequate timeout.
Main-thread time guard rails for Claude Code Bash commands — a PreToolUse hook that catches foreground polling and slow runs facing an inadequate timeout. - karlkfi/claude-foreground-guard
github.com
🛡️ PR Sentinel v0.4.0 is out. The watcher now handles GitHub API failures more gracefully: permanent failures exit immediately, transient failures retry with backoff over a configurable window (PR_SENTINEL_GH_RETRY_HORIZON) before giving up. github.com/karlkfi/claude-pr-sentinel
GitHub - karlkfi/claude-pr-sentinel: Secure post-PR babysitting for Claude Code: wake your session on CI failures and merge conflicts — no foreground polling, no comment-channel injection.
Secure post-PR babysitting for Claude Code: wake your session on CI failures and merge conflicts — no foreground polling, no comment-channel injection. - karlkfi/claude-pr-sentinel
github.com