All posts

What Open Plugins gets right, and what it still needs

Every MCP server I’ve added to my Goose setup has been its own small project. Some are a git clone and a config path. Some need pip install and the right virtual environment. A ...

opinionopen pluginsmcpsupply chainplatform engineeringgoose

The supply chain questions nobody is asking about MCP yet

I spent a big part of the last year integrating supply chain security into SDLC pipelines - provenance with SLSA, attestation with in-toto, SBOMs with CycloneDX, signing with Si...

opinionmcpsupply chaindevsecopsgoose

Scoping Goose for production-adjacent ops work

There’s a pattern I keep seeing in tutorials for Goose: the author installs it, gives it their default kubeconfig or shell, and runs a demo. In my first post I framed agents as ...

tutorialgoosekubernetesdevsecopsplatform engineering

Agents as workloads: notes from the platform side

I’ve spent twenty years designing and evolving large-scale, business-critical systems. Mostly platform engineering, DevSecOps, IAM, and lately software supply chain security. Th...

platform engineeringagentic aidevsecopsiamsupply chainmcpa2aharness engineering