Vladimir Mikhalev

@valdemar.ai

Docker Captain · IBM Champion · AWS Community Builder Technical Editor: "Docker & Kubernetes Security" 8+ articles on Docker's official blog · 1M+ Docker Hub pulls I test what the industry ships — and publish what I find. ↓ valdemar.ai

Three agents finish in parallel. Main takes one landing at a time. METR's RCT: devs ran 19% slower with AI and estimated 20% faster. Now run that error three ways at once. Writing code got parallel. Landing stayed serial. heyvaldemar.com/merge-debt-2...

Merge Debt: The 2026 Bill Your Parallel AI Agents Are Running Up | VALDEMAR

Three agents finish in parallel. Main takes one landing at a time. METR's perception gap, the rebase tax, and why Merge Debt is the number nobody plots.

heyvaldemar.com

The blast radius of an agentic Terraform apply isn't one workspace. It's every workspace the token can reach, times every team that flips the flag without recording why. Scope the token before you debate the flag.

The Terraform MCP server went GA June 11. One flag — ENABLE_TF_OPERATIONS — lets an AI agent run apply against a production workspace. The agent's code is clean. What's missing is the record of which named human approved the apply. That's the SOC 2 finding. heyvaldemar.com/terraform-mc...

Terraform MCP server GA: the Apply Gate your auditor will ask about | VALDEMAR

HashiCorp's Terraform MCP server is GA and IBM Bob can write production IaC. ENABLE_TF_OPERATIONS separates a safe assistant from autonomous apply.

heyvaldemar.com

Docker Captain, renewed for 2026. Three years in. Most container security tooling is built for the demo. The audit log doesn't care how the dashboard looks. Ship what survives review.

Docker Captain 2026 announcement card. Vladimir Mikhalev in a black turtleneck wearing a white Docker captain's hat with the whale logo, on a blue background with the Docker logo. Text reads "Docker Captain 2026 — Vladimir Mikhalev, sailing strong since 2023. Awarded another year as a Docker Captain for continued impact, expertise, and community engagement."

New on Docker's blog: I let Claude Code rewrite my entire blog — 146 posts, 6,024 images. It worked. I also stopped understanding my own codebase. That feeling is exactly why @docker.com had to build Sandboxes. www.docker.com/blog/untrust... #DockerSandboxes #AIAgents

The Untrusted Autonomous Workload and AI Sandboxes | Docker

Learn why AI coding agents need stronger isolation, how Docker Sandboxes use microVMs, and what secure autonomous workloads require.

docker.com

Renewed for year two as an AWS Community Builder. After editing a Packt book on container security last year, I keep coming back to one thing: most tooling in this space is theater. Audit logs don't lie. Dashboards do. Year two: less theater.

Official AWS Community Builder Year 2 badge: a large orange numeral 2 centered inside a hexagonal frame, encircled by a dark teal ring on a black background.

Execution lives in the terminal. Architecture requires the graph. Cognitive load is a liability. You don’t need more terminal aliases - you need absolute visibility over your blast radius. @devops.pink breaking down the visual control plane we mandate.

GitKraken@gitkraken.com · 5mo ago

@devops.pink jumps between multiple repos daily - cloud automation, content, testing, teaching. "The visual graph instantly tells me exactly where all my branches are." How she removes the chaos → gitkraken.com/blog/two-developers-two-continents-one-philosophy-build-systems-that-work-for-you

Everyone on Instagram is selling you the same dream: Buy a Mac Mini. Install an AI agent. Connect it to your CRM. Walk away. I spent the weekend stress-testing this architecture. Here is what the 7-million-view reels don't tell you about the blast radius. youtu.be/A1mioASn3-w

A sleek, matte black Mac Mini centered on a dark, reflective corporate boardroom table. A glowing crimson radar grid radiates outward from the device, symbolizing the unmanaged blast radius, cyber exposure, and enterprise architecture risks associated with deploying unsupervised autonomous AI agents. Dark, cyberpunk noir aesthetic with deep shadows.

AI can now write and heal Cypress tests. But green checkmarks don't mean correct—they mean unchallenged. The bot that ships the wrong build doesn't get fired. You do. My new playbook on architecting trust is out today on the official Cypress blog: dev.to/heyvaldemar/...

A cinematic photograph of a lone silhouette figure standing before a massive, weathered industrial concrete wall in a dark environment. A large, glowing orange neon sign centered on the wall reads "TRUST BOUNDARY". The atmosphere is gritty, futuristic, and oppressive, symbolizing the hard lines required for AI governance.