Ordinary Abundance | Build or Be Replaced
Today: Ordinary Abundance | Single log line is 49KB+ (ext4) / 110KB+ (btrfs) of systemd-journald disk writes | Hello, me. It's been a while Episode date: 2026-08-14.
Download MP3 →
Build or Replaced
Today: Ordinary Abundance | Single log line is 49KB+ (ext4) / 110KB+ (btrfs) of systemd-journald disk writes | Hello, me. It's been a while Episode date: 2026-08-14.
Download MP3 →JOSH: It's Friday, August 14. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson. ERIK: Today's theme is simple. The model can write code now. The bottleneck is whether you understand what it wrote before it burns your house down. JOSH: Stick around — Erik's got an AI pro tip at the end about forcing agents to explain their blast radius before they touch prod. [pause] JOSH: First headline. Hacker News is talking about "Understanding is the new bottleneck." Erik, that sounds like your kind of problem. ERIK: It is. Code generation is cheap now. Understanding the system, the constraints, the weird little edge cases from 2014 that still matter, that's the expensive part. JOSH: And that's where engineers still matter? ERIK: Good engineers, yes. Button clickers, no. [beat] JOSH: Next one. Gemini 3.7 Flash is showing higher coding and web dev performance, and the cost is getting cut hard. ERIK: That matters because fast cheap models become plumbing. You don't use them for the final answer. You use them to scan logs, write tests, classify failures, and do the boring work at 3 AM. JOSH: So not every task needs the giant model. ERIK: Exactly. Stop sending everything to the biggest brain in the room. Sometimes you need the intern who reads fast and doesn't complain. [beat] JOSH: Third headline. One log line can cause massive journald disk writes. That feels both boring and terrifying. ERIK: Boring technology will ruin your weekend faster than frontier AI. A single noisy log line can turn into disk pressure, service weirdness, and then somebody is blaming Kubernetes because that's tradition now. [pause] JOSH: Let's start with that one. The log line story. Why did that catch your eye? ERIK: Because it's the exact kind of thing people miss when they're busy chasing model benchmarks. A single application emits a huge line. systemd-journald writes more than you expect. ext4 behaves one way, btrfs another way. Then your disk IO starts getting weird. Then the node gets sad. Then alerts fire. Then humans wake up. JOSH: Wait, really? One log line can do that much damage? ERIK: Yeah. Logs are not free. Metrics are not free. Traces are not free. Everybody says observability like it's magic dust. It's not. It's a write path. It's storage. It's retention. It's indexes. It's CPU. It's money. JOSH: That hits differently when you say it like that. ERIK: In my world, this is why PrimeBus exists. I don't want every service screaming into the void. I want structured events on NATS with sane fields, sane sizes, and consumers that know what to do. Today I've got 148 services running on the production server right now. If those services all decide to write a novel into journald, that's not observability. That's a denial of service with timestamps. JOSH: So the fix isn't just "log less"? ERIK: No. "Log less" is lazy. The fix is log correctly. Put a size cap on messages. Put correlation IDs in there. Put the error code in a field, not buried in a paragraph. Don't dump the whole HTTP payload unless you're in a controlled debug window. And if you do turn on debug logging, make it expire. JOSH: Expire automatically? ERIK: Yes. Debug flags should have a timer. I don't care if it's an environment variable, a config row, a feature flag, whatever. It needs a death date. Otherwise somebody turns it on during an incident, the incident ends, and six months later you're paying to store stack traces from a problem nobody remembers. [beat] JOSH: How does AI fit into that? ERIK: AI is great at reading logs, but only if you don't feed it garbage. If you give Claude a clean event stream, it can group failures, find the first bad event, compare it to the last good deploy, and propose a fix. If you give it 49 kilobyte log lines full of random dumps, you're paying tokens to make a model squint. JOSH: That's a painful sentence. ERIK: PrimeBus has had 2,295 auto-merger attempts since June 5. 1,507 merged, 788 blocked by Gandalf, 0 escalated to me. That only works because the events are structured enough for agents to reason about them. Gandalf doesn't read vibes. It reads tests, diffs, telemetry, and guardrail results. JOSH: The blocked number is the important part there, right? ERIK: Exactly. People hear blocked and think failure. Wrong. Blocked means the system caught something before it became my problem. That's the entire point. I want agents moving fast, but I want the guardrails to be mean. JOSH: Mean guardrails. ERIK: Yeah. Friendly guardrails are how you get a surprise outage. [pause] JOSH: Second deep dive. "Understanding is the new bottleneck." This one sounds less like a news item and more like a warning label. ERIK: It is a warning label. The old bottleneck was typing code. Then it was knowing syntax. Then it was knowing frameworks. Now the model handles a lot of that. The new bottleneck is knowing what should exist, what should never exist, and what breaks when you change it. JOSH: Give me an example. ERIK: Network automation is a perfect example. Claude can write Python that calls NSO. Cool. Can it know that this one customer has a weird service template because a router migration in 2019 left a naming convention half dead? Not unless that knowledge is captured somewhere. The code is the easy part. The context is the job. JOSH: So docs matter again? ERIK: Docs, tests, runbooks, telemetry, examples. All of it. But not giant wiki pages nobody reads. You need machine-readable truth. Schemas. contracts. fixtures. golden configs. Real command output. Failure examples. The stuff an agent can use without guessing. JOSH: That's different from normal documentation. ERIK: Normal documentation is often theater. Somebody writes a page after the project is done so a manager feels warm. Useful documentation is part of the control plane. It tells the human and the agent what the system believes is true. [beat] JOSH: You said earlier that button clickers are in trouble. Is this what you mean? ERIK: Yeah. If your job is waiting for a ticket, copying commands, pasting output, and saying "completed," AI is coming for that. Honestly, I am the guy trying to make that happen. But if you understand the system deeply, AI makes you ridiculous. JOSH: Ridiculous how? ERIK: You become the person who can run ten investigations at once. One Claude session checks the failing test. Another looks at the deploy diff. Hermes on my Mac M3 can chew through local code with qwen3-coder without sending every little thing out. PrimeBus routes the event. Gandalf reviews the merge. I'm not sitting there babysitting a terminal like it's 2009. JOSH: That's the fleet idea. ERIK: Right. The fleet matters. Today 12 agents are in the Bobaverse fleet. Neo, Homer, Bill, Echo, Gandalf, Claude plus GPT. That's not a cute lab trick. That's how I split work. One agent should not do everything. That's how you get a very confident mess. JOSH: How should a normal builder start? ERIK: Start with one workflow. Don't build a whole agent city because you watched a demo. Pick one annoying thing. Failed build. Incoming email. New RFP. Broken Selenium test. Feed the event into a queue. Have one agent classify it. Have another agent propose an action. Then force a check before anything writes. JOSH: What's the check? ERIK: Depends on the work. Tests for code. Dry run for Terraform. Diff review for NSO templates. Human approval for anything with money or customer impact. For PrimeTrader, webhooks don't get to just do whatever they want because a chart got excited. You need hard boundaries. JOSH: That's the part people skip. ERIK: Because the demo looks better without boundaries. Real systems need boring things. Idempotency keys. retries. audit logs. timeouts. rollback paths. Access controls. A model can be smart and still be wrong. Same as humans, except the model can be wrong faster. [pause] JOSH: Third deep dive. Gemini 3.7 Flash. The headline says better coding, better web dev, lower cost. What do you actually do with a model like that? ERIK: You put it in the places where latency and cost matter more than genius. First pass triage. Test generation. HTML cleanup. log grouping. Feed scoring. It doesn't need to solve the hardest problem. It needs to handle thousands of small ones without making the bill look cursed. JOSH: ScanBrief is a good example? ERIK: Perfect example. ScanBrief scored 101 items across 56 sources today. The job isn't "write a Pulitzer." The job is pull items, dedupe them, score relevance, summarize cleanly, and surface what matters before coffee. A fast cheaper model is good at a lot of that. Then a stronger model can handle the final judgment or rewrite. JOSH: So model routing is the skill. ERIK: That's the whole thing. Stop asking "which model is best." Wrong question. Ask "which model should do this exact step." OCR might be one model. extraction another. planning another. code repair another. final review another. That's how you build systems instead of prompts. JOSH: That sounds more like network design than prompt engineering. ERIK: Duuude, yes. That's why network engineers should be eating this space alive. We already understand routing, policy, queues, retries, failure domains, and blast radius. Agent systems are distributed systems with a chat box on the front. [beat] JOSH: What's the trap with cheap models? ERIK: People trust them because they look competent. Cheap and fast is great until it quietly makes a bad call 400 times. You need sampling. You need audits. You need a stronger model checking a percentage of outputs. You need canaries. JOSH: Canaries for AI output. ERIK: Absolutely. If a small model is classifying support tickets, have a stronger model review a slice. If it's writing tests, run the tests and check mutation quality if you can. If it's summarizing news, compare sources. If it's touching code, no green tests, no merge. I don't care how polite the answer sounded. JOSH: This is where Gandalf comes back. ERIK: Gandalf is the bouncer. PrimeBus can move fast because Gandalf can say no. That architecture matters more than the model brand. Today it's Gemini Flash, Claude, GPT, GLM, DeepSeek, whatever. Tomorrow it changes. The bus, the contracts, the checks, those survive. JOSH: You're not loyal to a model. ERIK: I'm loyal to working systems. Models are engines. Swap them when the numbers say swap them. Don't tattoo a vendor logo on your forehead. Bad look. Hard to explain at Thanksgiving. [pause] JOSH: One more headline we didn't go deep on. GLM-5.3 showing frontier coding and cyber capability. Does that worry you? ERIK: It should worry everybody a little. Coding ability and exploit ability are cousins. If a model can reason through a complex codebase, it can also reason through weak spots. The answer isn't panic. The answer is patch faster, test harder, and stop leaving secrets in places where a bored intern or a model can find them. JOSH: So defenders get the same tools. ERIK: Exactly. Use them. Have agents scan dependencies. Have them read auth flows. Have them write negative tests. Have them explain why an input should fail. Offense is getting cheaper. Defense has to get less sleepy. [pause] ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com [pause] JOSH: Alright, what's the AI pro tip today? ERIK: Before you let an agent change anything, make it produce a blast radius note. Not a novel. Five fields. Files touched. Services affected. Commands it plans to run. Rollback path. Confidence with evidence. JOSH: Evidence, not vibes. ERIK: Exactly. Bad prompt: "fix this bug." Better prompt: "inspect the failure, identify likely cause, propose the smallest change, list affected files and rollback steps, then wait." That one word matters. Wait. JOSH: Make the agent pause before acting. ERIK: Yep. Then you can choose where to remove the pause later. Maybe unit test fixes can run automatically. Maybe Terraform changes need approval. Maybe NSO changes need dry run plus human approval. The point is you separate thinking from acting. JOSH: That's usable today. ERIK: Today. Add a required blast radius section to your coding agent prompt. Make it fail the task if that section is missing. Then log those notes. After a week, you'll see which agents understand your system and which ones are just typing confidently. That's your tip. Use it. [pause] JOSH: Binge all five episodes this weekend plus our YouTube shorts — links at buildorbereplaced.dev. [pause] JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev. ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff. [pause] ERIK: Build or be replaced. JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.