Sign in

Agent IO

@agent.io
28 followers 26 following 98 posts

Fetching and serving by @babu.dev. Application superpowers on the Envoy proxy.

PostsRepliesMedia
Agent IO @agent.io · 04/09/2026
This week we took our gRPC-compatible networking library to the annual gRPC conference. agent.io/posts/grpcon...
agent.io
gRPConf26: A Lightweight gRPC-Compatible Implementation for Sidecars
Here's what I said about Sidecar at the the annual gRPC conference.
000
Agent IO @agent.io · 06/08/2026
If you run your app with Podman, you can easily require all of its network traffic to go through an IO where you can control and review it. agent.io/posts/sandbox/
agent.io
Sandbox with Podman and IO
Control and monitor all of your application's network traffic.
011
Agent IO @agent.io · 06/08/2026
Here's how I use Podman Quadlets to keep an IO running on every Ubuntu system that I use. agent.io/posts/podman/
agent.io
Run IO with Podman
Keep your IOs running with Podman Quadlets
010
Agent IO @agent.io · 06/08/2026
After spending some time evaluating Podman, I've decided to embrace it and move on from Docker, Nomad, and Kubernetes (which I'd already personally deprecated) agent.io/decisions/po...
agent.io
Embrace Podman
Prefer Podman as an alternative to Docker, Nomad, and Kubernetes.
000
Agent IO @agent.io · 14/07/2026
Every official gRPC implementation has a demonstration API called "Route Guide". Here we've implemented it with Sidecar: agent.io/posts/routeg...
agent.io
A Route Guide for Sidecar
Implementing the gRPC Route Guide example with Sidecar
000
Agent IO @agent.io · 10/07/2026
This week we replaced SQLite with Bolt and IO's data storage got a lot simpler. agent.io/decisions/bo...
agent.io
Replace SQLite with Bolt
Use Bolt for IO internal storage and general data persistence.
000
Agent IO @agent.io · 25/06/2026
Is there a lexicon for release binaries? We want one, and sketched a draft here: agent.io/decisions/re...
agent.io
Release IO binaries
Build and distribute IO binaries.
000
Agent IO @agent.io · 24/06/2026
MacOS builds of IO (currently ARM-only) are available from a Homebrew Custom Tap. agent.io/decisions/ho...
agent.io
Distribute MacOS builds with Homebrew
Distribute IO builds for MacOS using Homebrew.
010
Agent IO @agent.io · 19/06/2026
Last year I replaced grpc-go and connect-go with a thin layer of code that I use to write gRPC clients and servers on the Go standard library. Details are here: agent.io/posts/sidecar
agent.io
Lightweight gRPC on the Go Standard Library
Sidecar is a tiny Go package that can be used to make clients and servers that use the gRPC wire protocol.
012
Agent IO @agent.io · 13/06/2026
Hugo was a great way to get started building web sites, but now it's time for something different. agent.io/decisions/dr...
agent.io
Drop Hugo
Replace Hugo with a custom site builder.
010
Agent IO @agent.io · 14/05/2026
I went native and built ACME support directly into IO. Here are some things that I learned: agent.io/posts/acme/
agent.io
Building an ACME Client
RFC8555 is revolutionary, but it has some rough edges.
000
Agent IO @agent.io · 09/05/2026
"You've already used Envoy today. You probably didn't know it." From this beautiful overview by Erica Hughberg: a-decade-of-envoy.netlify.app
a-decade-of-envoy.netlify.app
A decade of Envoy
A decade of Envoy: from Lyft's debugging nightmare to the AI infrastructure era.
000
Agent IO @agent.io · 05/05/2026
Recently I added support for proxying "raw" TCP ports so that IO could proxy SSH and other non-HTTP services. Here's an updated start screen that describes all of IO's modes.
000
Reposted by Agent IO
Tim Burks (legacy did:plc) @timburks.me · 01/05/2026
Today I added local service discovery to IO and OMG it's so nice... I didn't realize how good it would feel to write zero-configuration API clients like this example that calls the Google Cloud Translate API...
141
Agent IO @agent.io · 28/04/2026
Is it an agent that you want, or just agency? agent.io/posts/agency/
agent.io
Agency over Agents
A lot of people are trying to sell you agents. What you really want is agency.
000
Reposted by Agent IO
Tim Burks (legacy did:plc) @timburks.me · 09/04/2026
"By leveraging Envoy as an agent gateway, organizations can decouple security and policy enforcement from agent development code." Google (partially) gets @agent.io -- they understand the potential but, as usual, miss the importance of simplicity! cloud.google.com/blog/product...
cloud.google.com
111
Agent IO @agent.io · 09/04/2026
People at Google really like Envoy (so do we) cloud.google.com/blog/product...
cloud.google.com
The case for Envoy networking in the agentic AI era | Google Cloud Blog
In the world of AI agents, the Envoy networking proxy consistently enforces governance and security across all agentic paths, and at scale.
000
Agent IO @agent.io · 04/04/2026
Slink is infrastructure code that generates infrastructure code. To facilitate usage, it's now available under the most permissive OSS license.
000
Agent IO @agent.io · 04/04/2026
The slink CLI and code generator is now MIT-licensed. github.com/agentio/slin...
github.com
GitHub - agentio/slink at v0.2.0
A tool for calling XRPC APIs, automatically generated from Lexicon. - agentio/slink
150
Agent IO @agent.io · 02/04/2026
Software Licenses and Workers' Rights agent.io/posts/softwa...
agent.io
Software Licenses and Workers' Rights
The open source ladder is leaning on the wrong wall.
050
Agent IO @agent.io · 02/04/2026
On the decision to write a PDS agent.io/decisions/pds/
agent.io
Build an ATProto PDS
Build an AT Protocol PDS the hard way (from scratch).
000
Agent IO @agent.io · 27/03/2026
Managing a Beta with Bluesky agent.io/posts/managi...
agent.io
Managing a Beta with Bluesky
How I use Bluesky to easily and securely preview a software product to users.
010
Agent IO @agent.io · 19/03/2026
Building a PDS the Hard Way agent.io/posts/buildi...
agent.io
Building a PDS the Hard Way
Commits that could get me committed.
031
Agent IO @agent.io · 18/03/2026
I've been building a new service that, like IO, uses an SSH port to take commands and display a TUI. When I deployed it to one of my Nomad-based servers, I realized that I needed a way to proxy the SSH port from my internal Nomad port to a public port on my server. Thus the new "tcp_port" config.
001
Agent IO @agent.io · 18/03/2026
New in IO: Direct TCP port configuration agent.io/io/config/#t...
agent.io
IO Configuration Reference
Here’s how you can configure IO using its HCL-based configuration language.
100
Agent IO @agent.io · 10/03/2026
Are you worried about DID:PLC? There are reasons to be, but they can be fixed agent.io/posts/risks-...
agent.io
Risks of DID:PLC
It’s the cornerstone of identity on Bluesky. What could possibly go wrong?
022
Agent IO @agent.io · 09/03/2026
Finally! The treatise about slink that no one was asking for but everyone needed agent.io/posts/slink
agent.io
Better Go clients for ATProto
Easily call XRPC APIs from your Go code and the command line.
020
Agent IO @agent.io · 28/01/2026
Finally (for now), here's our Statusphere app updated to use Slink. github.com/agentio/stat...
github.com
GitHub - agentio/statusphere: The ATProtocol Statusphere demo application on IO.
The ATProtocol Statusphere demo application on IO. - agentio/statusphere
000
Agent IO @agent.io · 28/01/2026
Slink also generates a Go client library that powers the CLI. We can use that in other Go programs like this tool that sends chat messages like the one above. github.com/agentio/chat...
github.com
GitHub - agentio/chatter: A command-line tool that sends messages using the Bluesky Chat API.
A command-line tool that sends messages using the Bluesky Chat API. - agentio/chatter
100
Agent IO @agent.io · 28/01/2026
Among many other things, you can use it to send Bluesky chat messages.
# izakaya:~/Desktop/agentio/slink
$ CONVOID=$(SLINK_ATPROTOPROXY=did:web:api.bsky.chat#bsky_chat slink call chat.bsky.convo get-convo-for-members --members $(slink resolve did timburks.me) --members $(slink resolve did agent.io) | jq .convo.id -r)
# izakaya:~/Desktop/agentio/slink
$ echo $CONVOID
3md2h2kakjk22
# izakaya:~/Desktop/agentio/slink
$ vi message.json
# izakaya:~/Desktop/agentio/slink
$ cat message.json
{"text":"Here's your CLI-generated Bluesky chat message! I built a mechanically-generated CLI that calls XRPC functions. I'm using it to send you this with chat.bsky.convo.sendMessage"}
# izakaya:~/Desktop/agentio/slink
$ SLINK_ATPROTOPROXY=did:web:api.bsky.chat#bsky_chat slink call chat.bsky.convo send-message --convo-id $CONVOID --message message.json
{
  "id": "3mdjbt5flrc26",
  "rev": "2222224a7rehk",
  "sender": {
    "did": "did:plc:ahr5yhciwadehhwm7fotyfju"
  },
  "sentAt": "2026-01-28T22:06:03.745Z",
  "text": "Here's your CLI-generated Bluesky chat message! I built a mechanically-generated CLI that calls XRPC functions. I'm using it to send you this with chat.bsky.convo.sendMessage"
}A chat view showing the message that I just sent.
100
Agent IO @agent.io · 28/01/2026
Here's a little CLI that generates itself from Lexicon and calls XRPC APIs. github.com/agentio/slink
github.com
GitHub - agentio/slink: A tool for calling XRPC APIs, automatically generated from Lexicon.
A tool for calling XRPC APIs, automatically generated from Lexicon. - agentio/slink
111
Agent IO @agent.io · 09/01/2026
Another thing that auth scopes don't provide is visibility into how auth tokens are used. So IO allows traffic histories to be exported as HAR files that show us all the approved and blocked requests.
$ ssh localhost -p 2200 -- get traffic -m calling -a digitaloceandns -l 1
{
  "log": {
    "version": "1.2",
    "creator": {
      "name": "IO",
      "version": "v0.1.75-f45f06b2*"
    },
    "entries": [
      {
        "startedDateTime": "2026-01-09T14:53:54-08:00",
        "time": 0,
        "request": {
          "method": "DELETE",
          "url": "/v2/domains/agent.io/records/1781875673",
          "headers": [
            {
              "name": ":authority",
              "value": "localhost:5000"
            },
            {
              "name": ":path",
              "value": "/v2/domains/agent.io/records/1781875673"
            },
            {
              "name": ":method",
              "value": "DELETE"
            },
            {
              "name": ":scheme",
              "value": "http"
            },
            {
              "name": "user-agent",
              "value": "curl/8.12.1"
            },
            {
              "name": "accept",
              "value": "*/*"
            },
            {
              "name": "x-forwarded-for",
              "value": "192.168.4.172"
            },
            {
              "name": "x-forwarded-proto",
              "value": "http"
            },Here we see that the disallowed request was blocked by IO, which returned a 403 (Forbidden) error
000
Agent IO @agent.io · 09/01/2026
Auth scopes are great but they don't always restrict access as much as we want. Here's an IO configuration that *only* allows a couple of authorized API key users to call a few named methods of the Digital Ocean DNS API using a token that it gets from Hashicorp Vault.
calling "digitaloceandns" {
  name   = "Digital Ocean DNS"
  target = "api.digitalocean.com"
  port   = 5000
  require_apikey {
    users = <<END
fury:{SHA}czqgP91Ev45QGKCokt/+mBIHgn8=
hulk:{SHA}Mf6CeupM9fas594sId4LX2t4OFg=
END
  }
  apply_header "authorization" {
    secret = "vault:default/io/digitalocean-dns"
  }
  operation "retrieve-domain" {
    method = "GET"
    path = "/v2/domains/{domain}"
  }
  operation "retrieve-domain-records" {
    method = "GET"
    path = "/v2/domains/{domain}/records"
  }
  operation "retrieve-domain-record" {
    method = "GET"
    path = "/v2/domains/{domain}/records/{recordid}"
  }
}
110
Agent IO @agent.io · 06/01/2026
Here's IO running on MacOS agent.io/decisions/ma...
011
Agent IO @agent.io · 06/01/2026
Are you familiar with the XDG Base Directory Specification? Here's how we used it to improve IO: agent.io/decisions/xdg/
agent.io
Conform to the XDG Base Directory Specification
Store IO state and temporary files in a standard location.
000
Agent IO @agent.io · 03/12/2025
Recently we started building our own Envoy binaries and IO container images. agent.io/decisions/co...
agent.io
Build Envoy and IO containers directly
Use gcr.io/distroless and self-built Envoys to have more control and to reduce dependencies, vulnerabilites, and image size.
000
Agent IO @agent.io · 10/11/2025
Envoy requires libc, so it doesn't make sense for IO to make performance sacrifices to avoid depending on libc itself. That lets us build IO with CGO and use the native SQLite library, which has big performance benefits. agent.io/decisions/cgo/
agent.io
Use CGO, libc, and pure SQLite.
Since Envoy will always depend on libc, it seems reasonable for IO to also.
000
Agent IO @agent.io · 31/10/2025
This week IO's configuration language got a revamp and a reference agent.io/io/config/
agent.io
IO Configuration Reference
Here’s how you can configure IO using its HCL-based configuration language.
100
Agent IO @agent.io · 20/10/2025
Tempted by Alpine Linux: agent.io/decisions/al...
agent.io
Hold on Alpine Linux
I love the ideas behind this lightweight distribution, but it’s challenging in practice.
000
Agent IO @agent.io · 03/10/2025
In September we created Sidecar, a new Go gRPC implementation that focuses on clarity, simplicity, and security for apps that run with sidecars. It's now how IO does gRPC. Here's a discussion of our decision to switch. agent.io/decisions/si...
agent.io
Build and Use Sidecar
Replace Connect with a new, simple, transparent Go gRPC library.
000
Agent IO @agent.io · 03/10/2025
Is it an SDK... or a monster infesting your app? agent.io/posts/sdks/
agent.io
Out-of-Process SDKs
Do you really want to put that vendor code in your app?
000
Reposted by Agent IO
Tim Burks (legacy did:plc) @timburks.me · 24/09/2025
If you use Go, gRPC, and sidecar proxies, I wrote this for you github.com/agentio/sidecar
github.com
GitHub - agentio/sidecar: Baggage-free gRPC for Go.
Baggage-free gRPC for Go. . Contribute to agentio/sidecar development by creating an account on GitHub.
021
Agent IO @agent.io · 09/09/2025
Echo is a simple gRPC service that we wrote to test and experiment with gRPC and ConnectRPC agent.io/posts/echo/
agent.io
What can we learn with a simple gRPC service?
Exploring gRPC and connectrpc with a simple echo service.
000
Agent IO @agent.io · 25/08/2025
How IO uses gRPC: agent.io/posts/grpc/
agent.io
How IO runs on gRPC
IO doesn’t just manage gRPC APIs, gRPC makes IO go.
000
Agent IO @agent.io · 20/08/2025
IO was created to work with a set of API management APIs from Google called Service Infrastructure, but now we think we've outgrown it. agent.io/decisions/dr...
agent.io
Drop Service Infrastructure
Remove integration with Google’s Service Infrastructure APIs.
000
Agent IO @agent.io · 07/08/2025
What's it like to run an application with Nomad and IO? Here's an example with bonus info about gRPC: agent.io/posts/memos/
agent.io
These are my Memos on IO
Here’s how I self-host a gRPC-based web application with IO.
000
Agent IO @agent.io · 01/08/2025
Here's a practical benefit of our exploration of @hashicorp.com's Nomad and Vault: all of the configuration for this Nomad-hosted ATProto PDS is now read from secrets in Vault.
Here we are in the Nomad console looking at the configuration for our PDS. The job description contains a template that puts secrets from Vault into our job's environment.The Vault console shows the secret that contains our PDS configuration. Here is the index page for our running PDS!
010
Agent IO @agent.io · 31/07/2025
I'm getting more and more hooked on Nomad. With the raw_exec driver, I can run pretty much anything on my Nomad-running laptop. Here's how I use it to automatically unseal Vault. agent.io/posts/laptop...
agent.io
Nomad+Vault to Go
How I set up my Ubuntu laptops to run Nomad and Vault.
000
Agent IO @agent.io · 30/07/2025
"The caller never sees this secret." IO can read and apply API keys so that applications can securely use secrets without ever directly possessing them. agent.io/posts/vault
agent.io
Let IO Handle your Vault Secrets
If you’re protecting your secrets with Vault, why are you handing them out to your applications? Let IO handle them instead.
000
Agent IO @agent.io · 29/07/2025
Here's IO using an API key that it read from Vault using its Nomad workload identity.
The IO console showing the configuration of the Wordnik API above a curl call to the API.The Vault entry for the Wordnik secret.The Nomad configuration for IO showing its workload identity configuration.
020