Infrastructure & agent systems for teams that outgrew the defaults.
Reduced a 66,000-line platform to its durable core and shipped semantic retrieval the next day.
max@ronner.devWhat I run
-
JobFilter.ai retired
Built twice, for two audiences that never arrived.
A hosted career platform, then a public-job corpus API for agents. The corpus-truth layer — deduplication, staleness reconciliation, verification — survives as code; the service, its postgres cluster and the domain are gone.
-
RentFree.site live
Single-tenant static hosting where ownership is your pubkey.
Deploys are git push over SSH, no signup form, and the key is the owner. Losing it orphans the Site; deleting is one irreversible command.
-
Agent permission model running
Replaced runtime approval dialogs with a build-time proof.
Permissions for AI agents as a build-time proof: capabilities → scopes → profiles in home-manager;
nixos-rebuildfails naming an unknown capability before anything runs — the sandbox profile gets a read-only project and four tools. -
Cluster & build farm running
Self-hosted deploy pipeline that publishes this page from real hardware.
One mini-PC running k3s, a Nix build farm across it, Flux image automation, everything versioned. Three nodes until September; the HA version passed a node-loss drill and still lost to the power bill. Parallel rolls once hit memory pressure mid-deploy; rolls are sequential now — slower, deliberately.
I take on senior infrastructure contracts, agent system architecture, and platform engineering — and make the result boring to operate: one command to deploy, builds that fail closed, a rollback somebody has actually run.
Deploys nobody wants to run, an estate nobody can enumerate, an agent holding a credential it shouldn't have: describe the failure mode, not the stack. Send the repo, or the incident that keeps repeating, and the first reply is a written read of the real system — what breaks, how often, what I'd delete first.
max@ronner.dev