<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Notes on mrls.xyz</title><link>https://mrls.xyz/projects/noj/notes/</link><description>Recent content in Notes on mrls.xyz</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 02 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://mrls.xyz/projects/noj/notes/index.xml" rel="self" type="application/rss+xml"/><item><title>Week 9: Noj Got Faster Than Its Human Gate</title><link>https://mrls.xyz/projects/noj/notes/noj-got-faster-than-its-human-gate/</link><pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/noj-got-faster-than-its-human-gate/</guid><description>&lt;p&gt;&lt;a href="https://mrls.xyz/projects/noj/"&gt;Noj&lt;/a&gt; is the control room I write about here, which I used to call Mission Control and describe as a software factory. Every morning Noj files a standup issue for me, and one of its sections is &amp;ldquo;Blocked on you&amp;rdquo;. On 26 September it listed 19 tickets. On 2 October it listed 27. It went up on all but one day in between, and the standup on 3 October showed 33.&lt;/p&gt;</description></item><item><title>Week 8 of Building a Software Factory: Looking at Another Factory</title><link>https://mrls.xyz/projects/noj/notes/looking-at-another-factory/</link><pubDate>Fri, 25 Sep 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/looking-at-another-factory/</guid><description>&lt;p&gt;This is week 8 of building my own software factory, and it&amp;rsquo;s a good moment to evaluate how things are going. I have used a third of the Max 20x subscription I got for open source work, and before I spend the rest I want to be sure whether to continue in the same direction or pivot.&lt;/p&gt;&#10;&lt;p&gt;I believe in synchronicities, so I don&amp;rsquo;t think it&amp;rsquo;s a coincidence that this week I also sat down with Vlad Mocanu from Metaminds for a tour of uzi, his dark factory. I&amp;rsquo;ve started playing with it, which raises a question: what does that mean for Mission Control, my own factory?&lt;/p&gt;</description></item><item><title>Week 7 of Building a Software Factory: Capable Enough to Break Things</title><link>https://mrls.xyz/projects/noj/notes/capable-enough-to-break-things/</link><pubDate>Fri, 18 Sep 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/capable-enough-to-break-things/</guid><description>&lt;p&gt;On Thursday morning I merged a security fix from the agent after 71 CI checks passed (&lt;a href="https://github.com/kairos-io/kairos/pull/4569"&gt;kairos#4569&lt;/a&gt;). Before noon, every pull request that ran CI after it was red, and so was the post-merge run on master.&lt;/p&gt;&#10;&lt;p&gt;The change narrowed the permissions our CI workflows hand out, which a security scanner had flagged. It had sat in draft for eight days. On the morning of the merge the agent brought it up to date with master, the run came back green, and I approved it. Six jobs that the old, wider grant had been covering were left with less than they needed, and nothing in the pull request&amp;rsquo;s own run showed it.&lt;/p&gt;</description></item><item><title>Week 6 of Building a Software Factory: Hands on the Hardware</title><link>https://mrls.xyz/projects/noj/notes/hands-on-the-hardware/</link><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/hands-on-the-hardware/</guid><description>&lt;p&gt;The netboot server for my lab moved from my Mac to a Linux box this week. The agents did the migration, with a few back-and-forths, and the one thing I did myself was point DNS at the new machine. Then I opened the dashboard and everything was already there: my data, my login, the same certificate. Realizing I had not had to interact with either machine directly was a little crazy.&lt;/p&gt;</description></item><item><title>Week 5 of Building a Software Factory: Running It Without SSH</title><link>https://mrls.xyz/projects/noj/notes/running-it-without-ssh/</link><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/running-it-without-ssh/</guid><description>&lt;p&gt;Kairos is at 100% on the &lt;a href="https://www.bestpractices.dev/en/projects/9100"&gt;OpenSSF Best Practices badge&lt;/a&gt;, at the passing level. I checked the project page directly rather than take an internal report&amp;rsquo;s word for it: &lt;code&gt;badge_percentage_0: 100&lt;/code&gt;, &lt;code&gt;badge_level: passing&lt;/code&gt;. The rest of the week went to supply chain fixes, maintainer lifecycle documentation, and closing out the monorepo consolidation.&lt;/p&gt;&#10;&lt;h2 id="what-shipped"&gt;What shipped&lt;/h2&gt;&#10;&lt;p&gt;&lt;strong&gt;OpenSSF badge.&lt;/strong&gt; Two code changes helped close the last of it. yamllint is now strict, which is what the badge&amp;rsquo;s &lt;code&gt;warnings_strict&lt;/code&gt; criterion asks for (&lt;a href="https://github.com/kairos-io/kairos/pull/4440"&gt;kairos#4440&lt;/a&gt;), and generated release notes carry a &amp;ldquo;Security fixes&amp;rdquo; section (&lt;a href="https://github.com/kairos-io/kairos/pull/4436"&gt;kairos#4436&lt;/a&gt;). Both merged on 1 September. Most of the work was not code: an audit of the remaining criteria found 11 answers that had gone stale since the repositories were reorganized into one, and those are corrected. The audit&amp;rsquo;s tracking issue (&lt;a href="https://github.com/kairos-io/kairos/issues/4243"&gt;kairos#4243&lt;/a&gt;) is still open.&lt;/p&gt;</description></item><item><title>Week 4 of Building a Software Factory: Opening RISC-V to the Community</title><link>https://mrls.xyz/projects/noj/notes/opening-riscv-to-the-community/</link><pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/opening-riscv-to-the-community/</guid><description>&lt;p&gt;&lt;a href="https://mrls.xyz/projects/noj/notes/shipping-kairos-4-2-0/"&gt;Last week&lt;/a&gt; ended on 4.2.0 shipped and a reviewer agent reading every change before I do. Both held. riscv64 moved the most this week: it now builds on every push instead of only at release time, and there is a public invitation out asking anyone with real RISC-V hardware to test it.&lt;/p&gt;&#10;&lt;h2 id="what-shipped"&gt;What shipped&lt;/h2&gt;&#10;&lt;p&gt;&lt;strong&gt;RISC-V.&lt;/strong&gt; &lt;a href="https://kairos.io/blog/2026/08/28/kairos-riscv64-open-invitation/"&gt;The invitation is public&lt;/a&gt;: an unofficial image, verified only under QEMU so far, and I am asking anyone with real RISC-V hardware to run it and tell me what breaks. Two things changed underneath that ask. The architecture now builds on every push to &lt;code&gt;main&lt;/code&gt; instead of only at release time (&lt;a href="https://github.com/kairos-io/kairos/pull/4377"&gt;kairos#4377&lt;/a&gt;), so it stops silently rotting between releases. And AuroraBoot&amp;rsquo;s raw disk generation no longer hard-fails on an architecture with no signed-shim convention, which riscv64 doesn&amp;rsquo;t have (&lt;a href="https://github.com/kairos-io/AuroraBoot/pull/752"&gt;AuroraBoot#752&lt;/a&gt;). It was treating &amp;ldquo;nothing to chain from&amp;rdquo; as fatal instead of expected.&lt;/p&gt;</description></item><item><title>Week 3 of Building a Software Factory: Shipping Kairos 4.2.0</title><link>https://mrls.xyz/projects/noj/notes/shipping-kairos-4-2-0/</link><pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/shipping-kairos-4-2-0/</guid><description>&lt;p&gt;&lt;a href="https://mrls.xyz/projects/noj/notes/putting-the-agents-on-kairos/"&gt;Last week&lt;/a&gt; ended on a version that had shipped but not released, and a review load I was not keeping up with. Both moved. 4.2.0 is out, reset works again on non-UKI installs, fork pull requests finally get CI, and there is now a reviewer agent reading every change before I do. 34 changes landed against Kairos this week, up from 19.&lt;/p&gt;&#10;&lt;h2 id="what-shipped"&gt;What shipped&lt;/h2&gt;&#10;&lt;p&gt;&lt;strong&gt;&lt;a href="https://github.com/kairos-io/kairos/releases/tag/v4.2.0"&gt;v4.2.0&lt;/a&gt;, on 18 August.&lt;/strong&gt; The last thing holding it was two advisories the release scan was still ignoring (&lt;a href="https://github.com/kairos-io/kairos/pull/4332"&gt;kairos#4332&lt;/a&gt;). Cleared, tagged, &lt;a href="https://github.com/kairos-io/kairos-docs/pull/671"&gt;announced&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Week 2 of Building a Software Factory: Putting the Agents on Kairos</title><link>https://mrls.xyz/projects/noj/notes/putting-the-agents-on-kairos/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/putting-the-agents-on-kairos/</guid><description>&lt;p&gt;Last week I wrote that I wanted to get the agents working on actual Kairos tickets, and that the next post would either have results or another pile of postmortems. I&amp;rsquo;m happy to say it has results. It has a few postmortems too, but the results came first this time.&lt;/p&gt;&#10;&lt;h2 id="what-actually-landed"&gt;What actually landed&lt;/h2&gt;&#10;&lt;p&gt;The one I care about most is a release gate.&lt;/p&gt;&#10;&lt;p&gt;Kairos releases were not gated on a vulnerability scan of the bundle we actually ship. It is fiddlier than it sounds, it touches release CI, and it is exactly the kind of ticket I put off until it hurts enough to force my hand.&lt;/p&gt;</description></item><item><title>Week 1 of Building a Software Factory: From Pair Programming to Delegation</title><link>https://mrls.xyz/projects/noj/notes/from-pair-programming-to-delegation/</link><pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate><guid>https://mrls.xyz/projects/noj/notes/from-pair-programming-to-delegation/</guid><description>&lt;p&gt;The email landed on Friday, 17 July 2026, three days before I was due to leave for vacation. The sensible thing would have been to file it away and deal with it when I got back. Instead I spent the next two evenings standing up a system so I could start a small agent factory before I disappeared for a couple of weeks.&lt;/p&gt;&#10;&lt;p&gt;The agents have been running since Monday 20 July, the day I flew out, so that is two and a half weeks ago. This post is the first report back, and I want to be precise about what it is and is not. Nothing from this experiment has shipped to Kairos yet. Not one line. Everything the system has produced so far has gone into the scaffolding that runs it, plus my own homelab. So this is not a success story, and it is definitely not a &amp;ldquo;look what AI did for me&amp;rdquo; post. It is a write-up of what it took to get the thing running, and of the five separate ways it went wrong while I was doing that.&lt;/p&gt;</description></item></channel></rss>