<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Amir Amiri</title>
    <description>The latest articles on DEV Community by Amir Amiri (@amiri83).</description>
    <link>https://dev.to/amiri83</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F875965%2F3bece42c-7e6f-4cca-8cb3-62d7c809935a.png</url>
      <title>DEV Community: Amir Amiri</title>
      <link>https://dev.to/amiri83</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/amiri83"/>
    <language>en</language>
    <item>
      <title>How I Built a 24/7 AI DevOps Coding Agent for About CAD 200</title>
      <dc:creator>Amir Amiri</dc:creator>
      <pubDate>Fri, 02 Oct 2026 05:20:49 +0000</pubDate>
      <link>https://dev.to/amiri83/how-i-built-a-247-ai-devops-coding-agent-for-about-cad-200-4fgf</link>
      <guid>https://dev.to/amiri83/how-i-built-a-247-ai-devops-coding-agent-for-about-cad-200-4fgf</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fizo9q2e5655yv1oxzhbj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fizo9q2e5655yv1oxzhbj.png" alt="My 24/7 AI DevOps Coding Agent Setup" width="800" height="1067"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Hermes + Claude Code + Telegram on a cheap always-on thin client.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Hi, I'm Amir 👋
&lt;/h2&gt;

&lt;p&gt;I'm a DevOps engineer, and a surprising amount of my time goes into work that is important but repetitive.&lt;/p&gt;

&lt;p&gt;A server needs patching. A CI/CD pipeline fails. A script needs a small change. A Terraform module needs an update. A tool I built needs one more feature. Tests need to be run, branches need to be checked, and somebody still has to make sure the generated code actually works.&lt;/p&gt;

&lt;p&gt;None of those jobs is necessarily difficult on its own. The annoying part is the &lt;strong&gt;constant context switching&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I kept thinking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What if I had a small AI worker that was always online, understood my repositories, could call a real coding agent, verify the result, manage Git, and report back to me on my phone?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is what this setup became.&lt;/p&gt;

&lt;p&gt;I use &lt;strong&gt;Hermes&lt;/strong&gt; as the agentic AI harness and orchestrator. Hermes is connected to &lt;strong&gt;OpenRouter&lt;/strong&gt;, where I use a low-cost &lt;strong&gt;DeepSeek Flash v4&lt;/strong&gt; model for the orchestration layer. When real coding work is needed, Hermes delegates that work to the &lt;strong&gt;Claude Code CLI&lt;/strong&gt;, which is my main coding agent.&lt;/p&gt;

&lt;p&gt;The split is intentional:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Claude helps me think through the problem. Claude Code does the main coding. Hermes runs the workflow, performs QA, manages Git, pushes the repo, and keeps me updated through Telegram.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This is not meant to replace me as an engineer. It is meant to remove the repetitive overhead around the work.&lt;/p&gt;




&lt;h2&gt;
  
  
  How I divide the work between Claude, Hermes and Claude Code
&lt;/h2&gt;

&lt;p&gt;I deliberately &lt;strong&gt;do not ask one AI agent to do everything&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;When I have a new idea, bug, or feature, I normally start by talking it through with &lt;strong&gt;Claude&lt;/strong&gt;. I explain what I want, what is currently broken, what constraints matter, and what I do &lt;em&gt;not&lt;/em&gt; want changed.&lt;/p&gt;

&lt;p&gt;Claude helps me turn that into a clear, compact prompt for Hermes.&lt;/p&gt;

&lt;p&gt;Then I hand the task over.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claude: planning and shaping the task
&lt;/h3&gt;

&lt;p&gt;Claude is where I usually work through questions like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What exactly should change?&lt;/li&gt;
&lt;li&gt;What should stay untouched?&lt;/li&gt;
&lt;li&gt;What edge case am I forgetting?&lt;/li&gt;
&lt;li&gt;What is the smallest useful test?&lt;/li&gt;
&lt;li&gt;What should count as PASS?&lt;/li&gt;
&lt;li&gt;What instructions does Hermes actually need?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I don't want a giant five-page prompt. By the time I send the task to Hermes, the thinking should already be distilled into something actionable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Hermes: orchestration, QA and Git management
&lt;/h3&gt;

&lt;p&gt;Hermes is my &lt;strong&gt;manager layer&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Its job is not to out-code Claude Code. Its job is to keep the job moving.&lt;/p&gt;

&lt;p&gt;In my workflow Hermes is responsible for things like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;checking the current repo and branch&lt;/li&gt;
&lt;li&gt;launching the coding agent&lt;/li&gt;
&lt;li&gt;monitoring the task&lt;/li&gt;
&lt;li&gt;running the relevant tests itself&lt;/li&gt;
&lt;li&gt;verifying that the result actually matches the request&lt;/li&gt;
&lt;li&gt;checking Git status&lt;/li&gt;
&lt;li&gt;committing only after the task passes&lt;/li&gt;
&lt;li&gt;pushing the branch&lt;/li&gt;
&lt;li&gt;reporting PASS / FAIL, issues and next steps back to Telegram&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That separation matters to me:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The agent that writes the code is not the same layer that decides the job is finished.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  Claude Code: the main coding agent
&lt;/h3&gt;

&lt;p&gt;When the work gets into the actual codebase, &lt;strong&gt;Claude Code CLI&lt;/strong&gt; is my primary coding agent.&lt;/p&gt;

&lt;p&gt;That is where I want the heavier coding intelligence spent:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;reading the codebase&lt;/li&gt;
&lt;li&gt;implementing features&lt;/li&gt;
&lt;li&gt;fixing bugs&lt;/li&gt;
&lt;li&gt;changing tests&lt;/li&gt;
&lt;li&gt;debugging failures&lt;/li&gt;
&lt;li&gt;reasoning about implementation details&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Hermes stays relatively lightweight and cheap. Claude Code does the expensive coding work only when I actually need it.&lt;/p&gt;




&lt;h2&gt;
  
  
  A real prompt from my workflow
&lt;/h2&gt;

&lt;p&gt;Here is a real example.&lt;/p&gt;

&lt;p&gt;After discussing the issue with Claude, this was the kind of short prompt I sent to Hermes:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fddwg5bi0jad8mfqhvzi8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fddwg5bi0jad8mfqhvzi8.png" alt="Claude to Hermes implementation prompt" width="800" height="171"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In text form:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;On feature/patch-all: after app restart, an analysis left RUNNING is not
marked INTERRUPTED and Analyze/Patch stay disabled. Startup recovery from
faa2ae6 isn't working on a real DB (schema v7, existing runs). Fix + test
with a DB containing a RUNNING analysis before startup.
Full suite + ruff. Commit after PASS, push. Report PASS/FAIL | issues | next.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I like this kind of prompt because it is short but still gives Hermes everything it needs:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;where the problem is → what the failure looks like → what must be tested → when Git operations are allowed → what I want reported back.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Hermes does not just trust the coding agent
&lt;/h2&gt;

&lt;p&gt;This is the part that made the setup useful for me rather than just interesting.&lt;/p&gt;

&lt;p&gt;After Claude Code finishes, Hermes still has work to do.&lt;/p&gt;

&lt;p&gt;Here is a real result from my Telegram workflow:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F85ma5fu3zwtiikpkafh4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F85ma5fu3zwtiikpkafh4.png" alt="Hermes QA and Git management" width="555" height="549"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In this example Hermes exercised the fallback path, brought up the required containers, reran the integration test against the real environment, cleaned things up, and then handled the Git commit.&lt;/p&gt;

&lt;p&gt;That is exactly the kind of repetitive workflow I want the orchestrator doing for me.&lt;/p&gt;

&lt;p&gt;I want Claude Code focused on implementation.&lt;/p&gt;

&lt;p&gt;I want Hermes focused on:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;implement
   ↓
verify
   ↓
test
   ↓
inspect
   ↓
commit
   ↓
push
   ↓
report
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Telegram is my remote control
&lt;/h2&gt;

&lt;p&gt;Telegram is what makes the whole setup feel different from simply running an AI coding tool on my laptop.&lt;/p&gt;

&lt;p&gt;I can be somewhere else and send something like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Check the latest branch.

Have Claude fix the regression.

Run the targeted tests.

If everything passes, commit and push.

Report PASS/FAIL, issues, and next.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then I can put my phone away.&lt;/p&gt;

&lt;p&gt;The actual work is happening on the thin client at home.&lt;/p&gt;

&lt;p&gt;I don't need a remote desktop session. I don't need VS Code open. I don't need my laptop to stay awake.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Telegram is just the control surface.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  The hardware cost me about CAD 200
&lt;/h2&gt;

&lt;p&gt;I deliberately did &lt;strong&gt;not&lt;/strong&gt; build an expensive home server for this.&lt;/p&gt;

&lt;p&gt;The machine only needs enough resources to run Linux, Hermes, Git, development tools, containers when needed, and the local Claude Code CLI. The heavy LLM computation happens remotely.&lt;/p&gt;

&lt;p&gt;I bought a used &lt;strong&gt;Dell Wyse 5070 thin client for about CAD 120&lt;/strong&gt;.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Part&lt;/th&gt;
&lt;th&gt;My setup&lt;/th&gt;
&lt;th&gt;Approx. cost&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Thin client&lt;/td&gt;
&lt;td&gt;Dell Wyse 5070&lt;/td&gt;
&lt;td&gt;CAD 120&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CPU&lt;/td&gt;
&lt;td&gt;Intel Celeron J4105, 4 cores&lt;/td&gt;
&lt;td&gt;included&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;RAM&lt;/td&gt;
&lt;td&gt;4 GB physical RAM&lt;/td&gt;
&lt;td&gt;included&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Internal storage&lt;/td&gt;
&lt;td&gt;32 GB&lt;/td&gt;
&lt;td&gt;included&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Wireless&lt;/td&gt;
&lt;td&gt;Linux-compatible USB Wi-Fi adapter&lt;/td&gt;
&lt;td&gt;CAD 20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;External storage&lt;/td&gt;
&lt;td&gt;256 GB external SSD&lt;/td&gt;
&lt;td&gt;CAD 60&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Approx. total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;CAD 200&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The original 32 GB storage was too small once Docker, repositories, package caches and development tools entered the picture.&lt;/p&gt;

&lt;p&gt;I mounted the external SSD at:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/data
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;and moved the storage-heavy workloads there:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/data
├── docker
├── containerd
├── projects
└── swapfile
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;My project path points to the SSD:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;~/projects -&amp;gt; /data/projects
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The Wyse has &lt;strong&gt;4 GB of physical RAM&lt;/strong&gt;, so I also added a &lt;strong&gt;4 GB swap file&lt;/strong&gt; on the external SSD.&lt;/p&gt;

&lt;p&gt;That gives the OS 4 GB RAM + 4 GB swap to work with.&lt;/p&gt;

&lt;p&gt;Swap is obviously &lt;strong&gt;not the same as real RAM&lt;/strong&gt;, but for a cheap orchestration box it gives me useful headroom during temporary spikes.&lt;/p&gt;




&lt;h2&gt;
  
  
  Installing Hermes on Ubuntu 26.04
&lt;/h2&gt;

&lt;p&gt;I run the box on &lt;strong&gt;Ubuntu 26.04&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;For Hermes itself, I followed the official installation method from the &lt;a href="https://hermes-agent.nousresearch.com/" rel="noopener noreferrer"&gt;Hermes Agent website&lt;/a&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-fsSL&lt;/span&gt; https://hermes-agent.nousresearch.com/install.sh | bash
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;After installation, the important pieces in my setup are:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Hermes Agent&lt;/strong&gt; running on the thin client.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;OpenRouter&lt;/strong&gt; as the model provider for Hermes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DeepSeek Flash v4&lt;/strong&gt; as my low-cost orchestration model.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Telegram&lt;/strong&gt; connected so I can talk to Hermes remotely.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Claude Code CLI&lt;/strong&gt; installed and authenticated as the main coding agent.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Git / GitHub access&lt;/strong&gt; configured so Hermes can manage the repository workflow.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The main idea is simple:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Spend the expensive model on the coding problem. Keep orchestration lightweight.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  What happens when the first coding attempt fails?
&lt;/h2&gt;

&lt;p&gt;One thing I did not want was this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Claude Code says "done"
        ↓
Hermes trusts it
        ↓
bad code gets pushed
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That defeats the point of having an orchestration layer.&lt;/p&gt;

&lt;p&gt;My preferred flow looks like this:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff9vey8vpitqbbqtsmwno.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff9vey8vpitqbbqtsmwno.png" alt="Hermes failure and retry flow" width="800" height="320"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If QA fails, Hermes has evidence it can hand back to the coding agent:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;failing tests&lt;/li&gt;
&lt;li&gt;command output&lt;/li&gt;
&lt;li&gt;wrong behavior&lt;/li&gt;
&lt;li&gt;dirty Git state&lt;/li&gt;
&lt;li&gt;integration failure&lt;/li&gt;
&lt;li&gt;missing expected changes&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The coding agent gets another chance to fix the actual failure.&lt;/p&gt;

&lt;p&gt;Only after Hermes can reproduce a passing result does the workflow move to commit and push.&lt;/p&gt;

&lt;p&gt;I find that much more useful than simply asking the coding model:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Are you sure it works?"&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  How I keep the running cost under control
&lt;/h2&gt;

&lt;p&gt;The hardware cost is only one part of the story.&lt;/p&gt;

&lt;p&gt;What matters more over time is &lt;strong&gt;where I spend model tokens&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Hermes mainly needs to do things like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;inspect the current state&lt;/li&gt;
&lt;li&gt;decide which tool or agent should run next&lt;/li&gt;
&lt;li&gt;wait for a result&lt;/li&gt;
&lt;li&gt;run tests&lt;/li&gt;
&lt;li&gt;check Git status&lt;/li&gt;
&lt;li&gt;retry when something fails&lt;/li&gt;
&lt;li&gt;report back to me&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For that layer I use a cheaper model through OpenRouter.&lt;/p&gt;

&lt;p&gt;I save Claude Code for the part where the extra intelligence actually matters: &lt;strong&gt;understanding and changing the codebase&lt;/strong&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Cheap model
    ↓
orchestration / routing / checking

Expensive coding model
    ↓
used only when real coding is required
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I also don't need to pay for a cloud VM just to keep the agent online because the Wyse is doing that job at home.&lt;/p&gt;

&lt;p&gt;My ongoing cost is therefore mostly whatever I spend on Claude/Claude Code and OpenRouter usage rather than another always-on server bill.&lt;/p&gt;




&lt;h2&gt;
  
  
  Guardrails I use before code gets pushed
&lt;/h2&gt;

&lt;p&gt;I want this system to save time, not create a faster way to break things.&lt;/p&gt;

&lt;p&gt;Some rules I like are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;No commit before QA passes.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No push before the working tree is in the expected state.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Test the changed behavior, not just whether the code imports.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prefer a small targeted regression test first.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Use the existing full test suite when appropriate before finalizing.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Report failures instead of hiding or working around them.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Keep production credentials and private keys outside prompts and public repos.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Do not let the coding agent silently change unrelated parts of the project.&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For my personal projects, I also try not to turn every small change into a giant enterprise QA exercise.&lt;/p&gt;

&lt;p&gt;The goal is enough verification to catch the mistake &lt;strong&gt;without spending more time testing than the original task was worth&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Where this setup works well — and where it doesn't
&lt;/h2&gt;

&lt;p&gt;This setup is a good fit for work that is:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;repetitive&lt;/li&gt;
&lt;li&gt;repository-based&lt;/li&gt;
&lt;li&gt;testable&lt;/li&gt;
&lt;li&gt;scriptable&lt;/li&gt;
&lt;li&gt;safe to perform from a development machine&lt;/li&gt;
&lt;li&gt;easy to describe with a clear PASS/FAIL condition&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Examples include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;small internal tools&lt;/li&gt;
&lt;li&gt;bug fixes&lt;/li&gt;
&lt;li&gt;repetitive patching utilities&lt;/li&gt;
&lt;li&gt;CI/CD helper scripts&lt;/li&gt;
&lt;li&gt;Terraform changes in non-production environments&lt;/li&gt;
&lt;li&gt;report generators&lt;/li&gt;
&lt;li&gt;automation around Git and testing&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It is &lt;strong&gt;not&lt;/strong&gt; something I would blindly point at production and tell:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Do whatever you think is best."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For high-risk production changes, security-sensitive operations, destructive database work, or anything with a large blast radius, I still want explicit human review and normal change controls.&lt;/p&gt;

&lt;p&gt;The agent is useful because it removes repetitive work.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It does not remove engineering judgment.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  A few things I learned while building it
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. The orchestration machine does not need to be powerful
&lt;/h3&gt;

&lt;p&gt;At first it is easy to think "AI agent" means "expensive AI hardware."&lt;/p&gt;

&lt;p&gt;In this design, it doesn't.&lt;/p&gt;

&lt;p&gt;The thin client mostly needs to stay online, run tools reliably, and have enough storage.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Separating coding from verification is valuable
&lt;/h3&gt;

&lt;p&gt;Claude Code is very good at coding.&lt;/p&gt;

&lt;p&gt;That does not mean I should automatically accept its own definition of "finished."&lt;/p&gt;

&lt;p&gt;Having Hermes independently run the checks gives the workflow a much cleaner boundary.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. A short prompt can be better than a huge prompt
&lt;/h3&gt;

&lt;p&gt;Because I discuss the idea first, the prompt I send to Hermes can stay focused.&lt;/p&gt;

&lt;p&gt;That reduces noise and makes failures easier to understand.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Reliability matters more than raw speed
&lt;/h3&gt;

&lt;p&gt;The Wyse is not fast.&lt;/p&gt;

&lt;p&gt;But it is always there.&lt;/p&gt;

&lt;p&gt;For this use case, &lt;strong&gt;always available + predictable&lt;/strong&gt; is more valuable to me than having a much faster machine that disappears when I close my laptop.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. The best automation is the one I actually use
&lt;/h3&gt;

&lt;p&gt;The biggest win is not that the architecture looks clever.&lt;/p&gt;

&lt;p&gt;It is that I can send a task from Telegram, walk away, and come back to a tested branch instead of spending another hour doing repetitive setup and Git work.&lt;/p&gt;




&lt;h2&gt;
  
  
  Final thoughts
&lt;/h2&gt;

&lt;p&gt;I did not build this because I wanted an AI experiment sitting in a corner of my house.&lt;/p&gt;

&lt;p&gt;I built it because I'm a DevOps engineer and I have repetitive work.&lt;/p&gt;

&lt;p&gt;Sometimes the right answer to a repetitive task is a Bash script.&lt;/p&gt;

&lt;p&gt;Sometimes it is Terraform.&lt;/p&gt;

&lt;p&gt;Sometimes it is a small Python tool.&lt;/p&gt;

&lt;p&gt;And now, sometimes I can simply describe the problem, let my agent workflow build or fix the tool, verify the result, and give me the branch when it is ready.&lt;/p&gt;

&lt;p&gt;My setup has a very simple division of responsibility:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;I bring the problem. Claude helps shape the solution. Claude Code writes the code. Hermes manages the job, verifies it, handles Git, and reports back to me.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The Wyse provides the always-on home.&lt;/p&gt;

&lt;p&gt;Telegram gives me access from anywhere.&lt;/p&gt;

&lt;p&gt;The cloud models provide the intelligence.&lt;/p&gt;

&lt;p&gt;A cheap little thin client became my &lt;strong&gt;24/7 AI DevOps coding worker&lt;/strong&gt;. 🤖&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Source / setup files:&lt;/strong&gt; &lt;a href="https://github.com/Amiri83/hermis" rel="noopener noreferrer"&gt;Amiri83/hermis on GitHub&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Original Gist:&lt;/strong&gt; &lt;a href="https://gist.github.com/Amiri83/cc2d4f619da3096bfc299e2fec68d984" rel="noopener noreferrer"&gt;My 24/7 AI DevOps Coding Agent&lt;/a&gt;&lt;/p&gt;

</description>
      <category>devops</category>
      <category>ai</category>
      <category>automation</category>
      <category>productivity</category>
    </item>
    <item>
      <title>🛡️ Real-World Security + Automation = IPloader 🔧</title>
      <dc:creator>Amir Amiri</dc:creator>
      <pubDate>Thu, 10 Apr 2025 18:10:15 +0000</pubDate>
      <link>https://dev.to/amiri83/real-world-security-automation-iploader-15kf</link>
      <guid>https://dev.to/amiri83/real-world-security-automation-iploader-15kf</guid>
      <description>&lt;p&gt;A few years ago, while working at a fintech company, I faced a tough challenge.&lt;/p&gt;

&lt;p&gt;Every day, our security team sent us a list of hundreds of IPs to be blocked on our FortiGate firewalls — attackers constantly trying to breach our edge.&lt;/p&gt;

&lt;p&gt;💡 The problem?&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;We couldn’t be sure every IP was 100% malicious — some might have even belonged to customers&lt;/li&gt;
&lt;li&gt;We didn’t want to block them permanently&lt;/li&gt;
&lt;li&gt;And manually managing these lists was a nightmare&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;So I built a tool: IPloader&lt;/p&gt;

&lt;p&gt;✨ What it does:&lt;br&gt;
✔️ Verifies each IP against AbuseIPDB to assess threat level&lt;br&gt;
🗃 Stores IPs in SQLite with expiration dates (for temporary blocks)&lt;br&gt;
🔁 Removes duplicates and keeps the list clean&lt;br&gt;
🌐 Generates a local file that can be served to FortiGate as a dynamic block list&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxq3xfdc90e3uadlh19pn.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxq3xfdc90e3uadlh19pn.png" alt=" " width="657" height="476"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This tool helped automate the entire process — giving our security team confidence in what was being blocked with no guesswork.&lt;/p&gt;

&lt;p&gt;👉 The code is here: &lt;a href="https://github.com/Amiri83/IPloader" rel="noopener noreferrer"&gt;https://github.com/Amiri83/IPloader&lt;/a&gt;&lt;br&gt;
I hope it helps someone else as much as it helped me.&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
