Blog
Failures explained, measurements published, and what we learn building Kestro.
When prompt injection arrives through database content
September 1, 2026
A database row can carry an instruction, and an AI agent reads it like any other row. Nothing in the tool result marks one of them as data rather than orders.
Is read-only database access safe for an AI agent?
August 31, 2026
A read-only role stops destruction, not disclosure. Whatever an AI agent can read, it can summarise and carry away in a single answer. Measured on Postgres 16.
An MCP server on your production database: the actual risk
August 27, 2026
An MCP server grants the agent ambient authority: tools are discovered at runtime and their natural language descriptions steer every decision the model makes.
The health check returns 200 but the service is down
August 26, 2026
A 200 from a shallow health check only proves the HTTP process is up. A real check queries every dependency and watches latency, which drifts before the code.
Cloud SQL Proxy: connection refused on 127.0.0.1:5432
August 19, 2026
The proxy is not listening where your app is calling. It died, it took another port, or it bound another address. One command tells you which of the three.
Cloud SQL Proxy 403: Admin API has not been used in project
August 18, 2026
The proxy returns this 403 when the Cloud SQL Admin API is off on the project Google bills, not always the one holding your instance. The message names it.
Connecting to a Memorystore Redis from your local machine
August 15, 2026
A Memorystore Redis has no public address: the path runs through a VM on the same network, two hops in a single gcloud command. Here it is, piece by piece.