<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: dinesh chandika</title>
    <description>The latest articles on DEV Community by dinesh chandika (@dinesh1111111).</description>
    <link>https://dev.to/dinesh1111111</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4149649%2F9fa1b982-af07-4967-a81b-4cec769fc223.png</url>
      <title>DEV Community: dinesh chandika</title>
      <link>https://dev.to/dinesh1111111</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/dinesh1111111"/>
    <language>en</language>
    <item>
      <title>Running a Hindsight Agent on a Free Host, Read-Only</title>
      <dc:creator>dinesh chandika</dc:creator>
      <pubDate>Tue, 29 Sep 2026 12:29:19 +0000</pubDate>
      <link>https://dev.to/dinesh1111111/running-a-hindsight-agent-on-a-free-host-read-only-14gn</link>
      <guid>https://dev.to/dinesh1111111/running-a-hindsight-agent-on-a-free-host-read-only-14gn</guid>
      <description>&lt;p&gt;If you put an LLM agent on a public link, every visitor can spend your API quota. My review agent uses Groq for the model and &lt;a href="https://github.com/vectorize-io/hindsight" rel="noopener noreferrer"&gt;Hindsight&lt;/a&gt; for memory, so I wanted a public link that shows the results and cannot be used to run reviews. This article covers how I did that, what I hardened, and what I did not cover.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two modes, one codebase
&lt;/h2&gt;

&lt;p&gt;The Review Desk is a FastAPI app. On localhost, everything works: you can review a demo pull request, accept or reject comments, and paste a GitHub PR link. On the public link, I turn writes off. That split is controlled by environment variables:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;READ_ONLY=1&lt;/code&gt; blocks &lt;code&gt;/review&lt;/code&gt;, &lt;code&gt;/feedback&lt;/code&gt; and &lt;code&gt;/github-pr&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;PUBLIC_MODE=1&lt;/code&gt; hides the &lt;code&gt;/docs&lt;/code&gt; page.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;BANK_ID=review-agent-public&lt;/code&gt; points the public deployment at its own Hindsight memory bank, so it does not share memory with the local one.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;ALLOWED_ORIGINS&lt;/code&gt; sets which origins may call the API. There is no wildcard CORS.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The switch lives in &lt;code&gt;main.py&lt;/code&gt;. This is the real code:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="n"&gt;READ_ONLY&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;os&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;getenv&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;READ_ONLY&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;1&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;
&lt;span class="n"&gt;PUBLIC_MODE&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;os&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;getenv&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;PUBLIC_MODE&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;1&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;
&lt;span class="c1"&gt;# ...
&lt;/span&gt;&lt;span class="n"&gt;app&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;FastAPI&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;title&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Code Review Agent with Memory&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;lifespan&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;lifespan&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;docs_url&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;None&lt;/span&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;PUBLIC_MODE&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;/docs&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;redoc_url&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;None&lt;/span&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;PUBLIC_MODE&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;/redoc&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;openapi_url&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;None&lt;/span&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;PUBLIC_MODE&lt;/span&gt; &lt;span class="k"&gt;else&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;/openapi.json&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="c1"&gt;# ...
&lt;/span&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;block_if_read_only&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;READ_ONLY&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="k"&gt;raise&lt;/span&gt; &lt;span class="nc"&gt;HTTPException&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;403&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Live reviews are turned off on this deployment.&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;


&lt;span class="nd"&gt;@app.post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;/review&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;review&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;body&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;ReviewIn&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Request&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="nf"&gt;block_if_read_only&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The public link still serves the pages that do not cost anything to show: the Conventions, Results, Replay and How it works pages, and the measured results.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftdgf5c4atpjspo5k0o25.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftdgf5c4atpjspo5k0o25.png" alt="The Replay page as it appears on the public link" width="800" height="671"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The deployment
&lt;/h2&gt;

&lt;p&gt;The public copy runs on Render as a free web service. The build command is &lt;code&gt;pip install -r requirements.txt&lt;/code&gt;. The start command is &lt;code&gt;python -m uvicorn main:app --host 0.0.0.0 --port $PORT&lt;/code&gt;. The environment variables are &lt;code&gt;HINDSIGHT_API_URL&lt;/code&gt;, &lt;code&gt;HINDSIGHT_API_KEY&lt;/code&gt;, &lt;code&gt;GROQ_API_KEY&lt;/code&gt;, &lt;code&gt;READ_ONLY=1&lt;/code&gt;, &lt;code&gt;PUBLIC_MODE=1&lt;/code&gt;, &lt;code&gt;BANK_ID=review-agent-public&lt;/code&gt; and &lt;code&gt;PYTHON_VERSION=3.11.9&lt;/code&gt;. The &lt;code&gt;.env&lt;/code&gt; file is never committed. Pushing to the repository redeploys the site automatically.&lt;/p&gt;

&lt;p&gt;A free Render service sleeps when idle, so the first load can take 30 to 90 seconds. I would rather say that in the article than have someone think the link is broken.&lt;/p&gt;

&lt;p&gt;The decision I would defend hardest is the separate memory bank. While building the app I accepted and rejected plenty of comments just to test the interface, and none of those clicks should shape what a visitor sees on the public copy. Giving the public deployment its own &lt;code&gt;BANK_ID&lt;/code&gt; in &lt;code&gt;render.yaml&lt;/code&gt; means my test decisions can never leak into it. The trade-off I accepted is the slow first load. A free host that sleeps is a fair price for a link that costs nothing to leave online, and a warning line in the article is cheaper than paying to keep it awake.&lt;/p&gt;

&lt;h2&gt;
  
  
  Before and after
&lt;/h2&gt;

&lt;p&gt;Here is the difference between the two modes in practice.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Localhost&lt;/th&gt;
&lt;th&gt;Public link&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Run a review&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Blocked by &lt;code&gt;READ_ONLY&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Accept or reject a comment&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Blocked by &lt;code&gt;READ_ONLY&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Paste a GitHub PR link&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Blocked by &lt;code&gt;READ_ONLY&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;code&gt;/docs&lt;/code&gt; page&lt;/td&gt;
&lt;td&gt;Visible&lt;/td&gt;
&lt;td&gt;Hidden by &lt;code&gt;PUBLIC_MODE&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hindsight bank&lt;/td&gt;
&lt;td&gt;Local bank&lt;/td&gt;
&lt;td&gt;&lt;code&gt;review-agent-public&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Results and Replay pages&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The design goal is that a stranger with the link can look at the measured results and cannot cause a model call or a memory write.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3a4yn73gr4jy3wqcvtj5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3a4yn73gr4jy3wqcvtj5.png" alt="The Results page on the public link" width="800" height="653"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Hardening inside the app
&lt;/h2&gt;

&lt;p&gt;Even on localhost, the app should not trust its input. What I added:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A limit on diff size (200,000 characters).&lt;/li&gt;
&lt;li&gt;Rejection reasons limited to three allowed values.&lt;/li&gt;
&lt;li&gt;Categories sanitized to lowercase letters, digits and underscores.&lt;/li&gt;
&lt;li&gt;Comment text flattened and capped at 500 characters.&lt;/li&gt;
&lt;li&gt;Per-IP rate limits.&lt;/li&gt;
&lt;li&gt;Duplicate votes on a comment return a 409.&lt;/li&gt;
&lt;li&gt;Writes to &lt;code&gt;decisions.json&lt;/code&gt; are atomic, and a corrupt file is moved aside to a &lt;code&gt;.bad&lt;/code&gt; file.&lt;/li&gt;
&lt;li&gt;The in-memory list of comments is capped at 1,000.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;/github-pr&lt;/code&gt; accepts only a link shaped like &lt;code&gt;https://github.com/owner/repo/pull/N&lt;/code&gt;, and only ever calls &lt;code&gt;api.github.com&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There is no database, so there is no SQL to inject into.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this does not cover
&lt;/h2&gt;

&lt;p&gt;This is not a security audit, and I want to be specific about the gaps.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A diff can contain instructions aimed at the model, and prompt injection cannot be fully prevented. It only matters where live review is on, which means localhost.&lt;/li&gt;
&lt;li&gt;There is no login.&lt;/li&gt;
&lt;li&gt;The rate limiter is coarse behind Render's proxy, and the GET routes have no limit.&lt;/li&gt;
&lt;li&gt;There is no Content Security Policy and no integrity hashes on the CDN scripts.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;line&lt;/code&gt; field the model returns is not cleaned in &lt;code&gt;/review&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;decisions.json&lt;/code&gt; is stored as plain text with no encryption at rest. The public link uses HTTPS through Render, which protects data in transit only.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There are three checks I still want to run: confirm that &lt;code&gt;.env&lt;/code&gt; never entered the git history, confirm that the write routes return 403 on the live link and &lt;code&gt;/docs&lt;/code&gt; returns 404, and run &lt;code&gt;pip-audit&lt;/code&gt; on &lt;code&gt;requirements.txt&lt;/code&gt;. I will update this article with the results.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I would add next
&lt;/h2&gt;

&lt;p&gt;The order I would work through the gaps is the order of how much damage each one can do. First, cap and clean the &lt;code&gt;line&lt;/code&gt; field the model returns, because it is a small change. Second, read the real client address behind the proxy, so the per-IP rate limit means something on Render, and put a limit on the GET routes. Third, add a Content Security Policy and integrity hashes for the&lt;/p&gt;

</description>
      <category>ai</category>
      <category>python</category>
      <category>llm</category>
      <category>agents</category>
    </item>
  </channel>
</rss>
