More Dev Interrupted episodes

Retrofit or reimagine? Developer environments for humans and agents | Onas Matt Boyle thumbnail

Retrofit or reimagine? Developer environments for humans and agents | Onas Matt Boyle

Published 31 Mar 2026

Duration: 00:37:03

Agentic AI platforms prioritize secure, ephemeral enterprise workspaces with pre-configured environments, emphasizing Onas' optimized workflows, security measures like kernel-level controls, and future integration with project management systems to enhance productivity and scalability.

Episode Description

AI agents have officially arrived on an internet that simply wasn't built for them. So how do we build the infrastructure to keep them safe, productiv...

Overview

The podcast explores the development and challenges of agentic AI, emphasizing the critical role of secure, scalable, and configurable workspace environments in enabling these systems. Ona, a platform previously known as Gitpod, is highlighted for its focus on creating ephemeral, pre-configured cloud environments that streamline agentic AI workflows. Key challenges include aligning cloud environments with enterprise needs, ensuring security and audibility of agent operations, and supporting configurable integration with existing infrastructure. The concept of an "agent jail" is introduced to securely contain agentic systems, while Onas featuressuch as optimized time-to-first commit, context sharing with external tools, and run-loop testingaim to enhance developer productivity and agent efficiency. The platforms evolution from Gitpod reflects a shift toward enterprise-scale agentic AI, balancing developer-centric design with robust security and scalability requirements.

Agent security and runtime controls are central to the discussion, with a focus on preventing unauthorized actions through kernel-level monitoring, rule-based configurations, and addressing bypass tactics like tool renaming. Enterprises require guarantees that agents cannot compromise systems, especially when handling sensitive data. Infrastructure design prioritizes standardized environments to enforce security policies, though flexibility remains a trade-off. The conversation extends to broader implications, including the need for legacy system adaptation, avoiding vendor lock-in, and scaling agentic capabilities across complex workflows in large organizations. Security initiatives like Project Vito and "defense in depth" strategies are outlined as critical for mitigating risks.

The discussion also highlights future directions for agentic tools, including expanding accessibility to non-technical users and redefining engineering workflows. Traditional IDEs are increasingly being replaced by agentic, mobile-first development practices, with tools like Ona enabling code generation, pull request-like workflows, and reduced reliance on complex software. The APEX framework is introduced as a model for measuring AI impact in engineering productivity, emphasizing predictability, efficiency, and developer experience. Long-term goals include autonomous software factories and reimagining SDLC processes to accommodate both fast-moving teams and highly regulated enterprises, while balancing innovation with compliance and security requirements.

Recent Episodes of Dev Interrupted

24 Mar 2026 Why AI-assisted PRs merge at half the rate of human code | LinearBs 2026 Benchmarks

The 2026 Engineering Benchmark Report reveals that while 88.3% of developers use AI regularly, AI-generated pull requests face low merge rates (32.7%), larger sizes, and prolonged reviews due to systemic issues like poor data quality, inadequate policies, and organizational gaps, emphasizing the need for governance, smaller focused PRs, and foundational practices to optimize AI's potential in engineering workflows.

More Dev Interrupted episodes