Seroter's Daily Reading — #875 (September 25, 2026)

Follow into
Save into
Follow into

Source: https://seroter.com/2026/09/25/daily-reading-list-september-25-2026-875/
Episode 875, September 25, 2026. Seroter wrapped up today a bit sooner to sneak out for a weekend getaway. Inbox is at zero, the sun is shining, and next week’s problems are next week’s problems. The reading list this time spans eight pieces about agent plugins, showing up, GKE agentic migration, Netflix AI adoption, vibe coding revenue, CI/CD hardening, and BigQuery AI functions.
First up is Equip your agent with Google Cloud best practices using google-cloud-developer plugin. Seroter notes that a good agent plugin is useful whether you are new to a platform or an expert, and he likes how this post calls out the value of built-in best practices and always-accurate references. The title points to a plugin for developer agents that brings Google Cloud guidance into the workflow, so the agent does not have to guess at platform conventions or rely on stale general knowledge.
Next is Stop watching your agent work. Seroter flips the premise in his commentary: instead of constantly monitoring an agent, he has the opposite problem. He forgets that he asked the agent to do something and then needs to catch up on what happened. The title suggests that people should stop hovering and let agents run, but Seroter is usually on the other side, wondering what the agent actually did while he was away. It is a practical tension worth naming.
Third is An Ode to Showing Up by Brad Stulberg. Seroter’s commentary cuts to the heart: it is not about intensity, it is about consistency. Show up and do the work, regardless of how you are feeling. The article expands on that with a rhythm: show up on good days and bad days, when energetic and when tired, when confident and when doubtful. Stulberg argues that most top performers are not always motivated but they have built the skill of showing up. Progress often comes quickly at first and then flattens, and the honeymoon phase ends. At that point you stop relying on motivation and start laying bricks. He shares his own writing career, rejected by journalism schools and by twenty-five publishers, and reaching the bestseller list twenty years after his first published piece. The core message is that success is about not stopping and about giving yourself a chance: how I feel in the moment does not determine how this will go. Seroter’s commentary lands on exactly that consistency.
Fourth is Introducing GKE agentic migration for AI-assisted EKS-to-GKE migrations with built-in governance from the Google Cloud blog. Seroter says it is nice, noting it offers an open source agent plugin to translate Amazon EKS configurations into a GKE-ready landing zone. The article explains that generic LLMs are of no use for infrastructure migration: they pull false resource properties, drop network or identity configuration, and lose context across files. This plugin calls in a compilation of agent skills and a local Model Context Protocol server, combining an LLM with deterministic guardrails. It translates EKS Terraform and JavaScript Kubernetes manifests into GKE via pull requests rather than direct cluster changes. It does not move stateful data but instead generates runbooks, and it preserves a separation of platform and application workspaces so large teams can collaborate. The lifecycle covers repository discovery, architectural readiness and blocker governance, landing zone scaffolder, AI-assisted translation of R light and Gradle constructs, Terraform validate style offline validation, and opening at pull request for human review. It is a compiler committee-grade pattern for turning migration from a collection of ad hoc poses into a systematic, human-in-the-loop GitOps process.
Fifth is Parsing “Can” from “Should”: How Netflix’s Product Team Got Thousands of Creatives to Trust an AI Overhaul from First Round Review. Seroter says there is plenty of generic advice out there for inserting and scaling A I inside teams, but he liked some of the specific examples called out here. The article features McKenzie Lock, who spent seven years at Netflix as a general manager of product, operations, and creative. Netflix spans the creative and technical world, where two co-C.E.O.s represent different relationships to automation. Lock’s team did not start with what models could do; she asked what end member experience to create and where workflows genuinely under-serve them. The vision-building process included writing ideal customer scenarios, shadowing creative workers, running surveys and structured debates, and creating today versus tomorrow tables that made the future feel manageable and not just technical. She framed the change with storytelling and imaginary press releases so that creatives could see themselves in the future. Once the vision was formed, her team wrote strategy as explicit bets with genuine tradeoffs, not as process documents full of and not or. They intentionally started with lower-stakes titles, rather than writing on Stranger Things, and they invested in measurement upfront. The core is that an AI strategy fails when it is built around what AI can do instead of what humans should do.
Next is Lovable’s annualized revenue crosses $600M as vibe coding takes off from TechCrunch. Seroter’s commentary is simply that vibe coding is far from dead, and builders have voted with their wallets. The article reports that Lovable crossed annual run-rate revenue of six hundred million dollars, up from around five hundred million in June. Ference Headin made the announcement at the HumanX summit in Amsterdam, claiming that people at two-thirds of Fortune 500 companies are now using the product, including customers like Microsoft, NVIDIA, and Deutsche Telekom. Apps created by users on the platform are attracting nearly a billion visits a month. Hedin made a key point: unlike a raw coding assistant that outputs code, Lovable outputs a product, increasingly a business, with hosting, deployment, and scaling. The existence around revenue and enterprise adoption show that client coding is not just an experiment phase, but a real tool builder treats like infrastructure.
Seventh is Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure from Google Cloud. Seroter warns that the path to production is essential, but also a giant source of risk. Are you actively working to bolster your defenses. This is a Mandiant-authored blueprint for securing the software development lifecycle across five pillars: endpoint, electrical repository, artifact management, CI/CD, and deployment. The threat model is explicit: complainers target under scanner, hierarchical utility libraries, IDEs, and waitress utilities via social media and poisoned packages. They use GitHub Actions cache poisoning, OIDC token extraction, mutable action tags. The defense begins with developer workspaces: pre-commit secret scanning, VDA monitoring, vetted IDE plugins, and sandbox work for isolating hostile dependencies. Repositories far universal identity with phishing-resistant MFA, branch production, one-time permission tokens. Artifact management introduces a seven-day cooldown for new public packages, internal proxies and quarantine, digest pinning instead of mutable tags, and continuation scanning of stored images. CI/CD hardens ephemeral runners, OIDC tokenized least-privilege identities, and gates for secret scanning, static application security testing, software composition analysis, container image scanning, dynamic application testing, and cloud security for infrastructure as code. Finally, deployment guardrails block containers without valid signatures or root privileges. It is a very detailed defense-in-depth checklist for a modern pipeline.
The final article is Jev and BigQuery AI functions, from one row to ten million. Seroter describes this as a good evaluation of how Jev compares to the built-in AI functions in BigQuery, from a cost and performance dimension. The title suggests an experiment that scales from a single row of data to ten million rows, comparing Jev’s experience and economics against BigQuery’s native options. The original remains cut off, but Serotec’s take is that the evaluation is good.
Across what today’s list, agent expectations come up repeatedly: Google Cloud guidance higher-agent plugin, GKE migration, agent control and security. Almost every post returns to the practical question of when to trust an agent and when to insist on human review. Isolation is common, with an ode to showing up because AI is not a substitute for consistency. It is an expectations loop through the infrastructure and multi-modality.
That’s the day’s reading. Enjoy the weekend and ion-dust inbox.
- Equip your agent with Google Cloud best practices using google-cloud-developer plugin
- Stop watching your agent work
- An Ode to Showing Up
- Introducing GKE agentic migration for AI-assisted EKS-to-GKE migrations with built-in governance
- Parsing “Can” from “Should”: How Netflix’s Product Team Got Thousands of Creatives to Trust an AI Overhaul
- Lovable’s annualized revenue crosses $600M as vibe coding takes off.
- Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure
- Jev and BigQuery AI functions, from one row to ten million