
AI-generated infrastructure code needs a different review queue
Dockerfiles, pipelines, and Terraform are not just another diff. When AI generates code with access to the production path, review must follow the risk of the file.
Term

Dockerfiles, pipelines, and Terraform are not just another diff. When AI generates code with access to the production path, review must follow the risk of the file.

When an agent is allowed to act too broadly, the risk is not only leakage or abuse. It also becomes hard to operate: it works outside scope, repeats actions, burns budget, and fails without a clean way back.

It is common for people to argue that hashing is not cryptography; they do it so vehemently that they ridicule things like "I encrypted it with MD5." Is it really that wrong to say...