A coding agent reads untrusted text for a living. Ours runs with permissions bypassed and holds no credentials at all. The reasoning, and the part we haven't solved.
The second agent took an afternoon. The two bugs it surfaced were nowhere near the model.
Job tokens die with their jobs and deploy keys sprawl, so our agents stopped pushing entirely.
Kubernetes already replaces dead pods. Why were we running a manager, with a standing secrets-reader Role, to do it again?