HN user

maxchehab

310 karma

[ my public key: https://keybase.io/maxchehab; my proof: https://keybase.io/maxchehab/sigs/nkOOWJ0aF8uj_MwWO_-2HEHOZ6Dui43_lNkL1kFol2Q ]

Posts6
Comments29
View on HN

We’ve taken a different approach.

Hermes is our harness, and we run it in the sandbox.

Session history is tracked in a Postgres db (small monkey patch to do this)

We built a lightweight skills hub to manage/track skills.

And the file system is backed up on S3 (using the new S3 FS).

But everything else is just running in a k8 pod.

We haven’t ran into any issues yet, but our strategy here is to have the least invasive changes so upstream harness changes don’t get in the way.

Absolutely. We make it obvious to the user when a query/chart is using a non standard metric and have a fast SLA on finding/building the right metric.

It only works because all of the data looks the same between customers (we manage ad platform, email, funnel data).

So if we make an “email open rate” metric, that’ll amortize to other customers.

Trust is the hardest part to scale here.

We're building something similar and found that no matter how good the agent loop is, you still need "canonical metrics" that are human-curated. Otherwise non-technical users (marketing, product managers) are playing a guessing game with high-stakes decisions, and they can't verify the SQL themselves.

Our approach: 1. We control the data pipeline and work with a discrete set of data sources where schemas are consistent across customers 2. We benchmark extensively so the agent uses a verified metric when one exists, falls back to raw SQL when it doesn't, and captures those gaps as "opportunities" for human review

Over time, most queries hit canonical metrics. The agent becomes less of a SQL generator and more of a smart router from user intent -> verified metric.

The "Moving fast without breaking trust" section resonates, their eval system with golden SQL is essentially the same insight: you need ground truth to catch drift.

Wrote about the tradeoffs here: https://www.graphed.com/blog/update-2

How do you handle schema drift?

The data archive serialized the schema of the deleted object representative the schema in that point in time.

But fast-forward some schema changes, now your system has to migrate the archived objects to the current schema?

My partner and I have been playing this almost every morning. We're really enjoying it!

Some feedback: 1) it would be great if the incomplete clues could move to the top. this would avoid having to scroll down towards the end of the puzzle. 2) better collission behavior; it would be nice if we could drag a chunk of words and it would just "move the other words" out of the way. Sometimes we have to spend time to make a path to move chunks of words around.

Thanks for building this!

Just some fast feedback, I can't copy & paste in the connection url input form. On a mac.

Once loaded, I get the error "Table must contain a UUID column for vector visualization."

I'm assuming it's trying to find an ID column for grouping? Can we manually specify this? My ID columns are varchars.

Both Core Weave & Lambda Labs have fairly predatory pricing making it impossible to rent GPUs without a yearly contract.

This doesn't make sense for training models, where a training run is on the scale of days & weeks.

I wished that the techcrunch article mentioned other companies, like sfcompute, which offer hourly compute instead of yearly contracts.

I find the meta implications on this thread quite interesting:

How cheap can you run this cron job, the basics:

- 8,765 invocations a year

- Lambda: $0.20 per 1M requests

- Cloudwatch Events: $1.00 per 1M requests

$1.2 / 1,000,000 * 8,765 = About 1 cent

Is anybody going to host that as a service for this price? Absolutely not.

Rupa Health | Senior Software Engineer, Analytics Engineer | Full-time | Remote or San Francisco | https://www.rupahealth.com Rupa Health is on a mission to make root cause medicine the standard of care. We’re helping doctors get the information they need to get to the root cause of patient disease, so that they can make them healthy. We do that by making lab testing simple. We turn an archaic 15 hour-a-week process into a delightful 15 min task for healthcare practitioners.

We’re still just an 8 person engineering team but are already post-revenue and have strong product market fit (PMF). Our growth rate is through the roof (doubling active users every 6 months) and so we’re looking for talented engineers who want to join us in building the future of lab testing. You’d be working in Django and React with the chance to work cross functionally and own big parts of the product!

If you’re interested, check out our open roles:

* Senior Software Engineer: https://jobs.lever.co/rupa/14b92187-8b55-4830-a555-9b009ad2c...

* Analytics: https://jobs.lever.co/rupa/70f39950-3542-4973-a22b-b5d8629e0...

* Other Roles: https://www.rupahealth.com/careers

Or shoot me an email: careers@rupahealth.com

Rupa Health | Full Stack Engineer, Senior Backend Engineer | Full-time | Remote or San Francisco | https://www.rupahealth.com

Rupa Health is on a mission to make root cause medicine the standard of care. We’re helping doctors get the information they need to get to the root cause of patient disease, so that they can make them healthy. We do that by making lab testing simple. We turn an archaic 15 hour-a-week process into a delightful 15 min task for healthcare practitioners.

We’re still just a 7 person engineering team but are already post-revenue and have strong product market fit (PMF). Our growth rate is through the roof (doubling active users every 6 months) and so we’re looking for talented engineers who want to join us in building the future of lab testing. You’d be working in Django and React with the chance to work cross functionally and own big parts of the product!

If you’re interested, check out our open roles:

* Full-Stack Engineer: https://jobs.lever.co/rupa/f291c87b-97df-4929-9d7d-a9c065d12...

* Senior Backend Engineer: https://jobs.lever.co/rupa/705fede6-a6e5-4fef-aede-f077262ce...

* Other Roles: https://www.rupahealth.com/careers

Or shoot me an email: careers@rupahealth.com

Rupa Health | Full Stack Engineer, Senior Backend Engineer | Full-time | Remote or San Francisco | https://www.rupahealth.com

Rupa Health is on a mission to make root cause medicine the standard of care. We’re helping doctors get the information they need to get to the root cause of patient disease, so that they can make them healthy. We do that by making lab testing simple. We turn an archaic 15 hour-a-week process into a delightful 15 min task for healthcare practitioners.

We’re still just a 7 person engineering team but are already post-revenue and have strong product market fit (PMF). Our growth rate is through the roof (doubling active users every 6 months) and so we’re looking for talented engineers who want to join us in building the future of lab testing. You’d be working in Django and React with the chance to work cross functionally and own big parts of the product!

If you’re interested, check out our open roles:

* Full-Stack Engineer: https://jobs.lever.co/rupa/f291c87b-97df-4929-9d7d-a9c065d12...

* Senior Backend Engineer: https://jobs.lever.co/rupa/705fede6-a6e5-4fef-aede-f077262ce...

* Other Roles: https://www.rupahealth.com/careers

Or shoot me an email: careers@rupahealth.com

I work at WorkOS (we handle Enterprise SSO among other things, https://workos.com). We interface many... should I say "less elegant"... enterprise identity protocols with an OAuth api. There is support for common identity providers such as Azure, AD FS, Okta, VMware, to name a few. If you'd like access to our beta send me an email (max@workos.com) and mention hn.

Hey hn! I was tired of keeping track of Slack's webhook payloads, designing blocks in JSON, and general code fragmentation. So I tried removing the knowledge barrier of storage, state, webhooks, and message publishing as much as possible. Although Phelia won't make you a better developer, I hope it helps you build your Slack applications faster. All you gotta know is React.

It actually can't. Instagram does use this protect java-script injection from extensions, but clearly injecting CSS is allowed.

Javascript can be blocked from chrome extensions. In fact, Instagram does block javascript. However, clearly css is not blocked.

Yes they can. This attack does not have to be carried done through a chrome extension. I simply chose that because it is the easiest to show off. This can be hidden inside of a malicious npm module or injected into a website that has poor input sanitization.

The most important aspect of this attack is that it is carried out through css. It is possible to block remote javascript code from an extension, in fact, if one wanted to inject javascript into https://instagram.com (my example on github), they would fail.

Your background-image url must be an endpoint that can process a request. Simply, requesting a placehold.it/a image is pointless, but sending to l33thacker.com/a, assuming that l33thacker.com knows how to process that request maliciously, will work.

Author here. I believe the injection of the css in the chrome extension will only work in newer versions of chrome. However the "attack" would still work for all browsers. :)