Welcome to episode 366 of The Cloud Pod, where the forecast is always cloudy! Ryan is back from “vacation,” aka his other job (moonlighting as the admin of the Eagles’ biggest fan Facebook group), and this week we’re talking a lot about security, how orgs are managing threats, and whose turn it is to release a new hoard of patches. Plus, we’ve got news from BigQuery, JWT, MCP, and Cloudflare – and so much more, so let’s get started!
Titles we almost went with this week
- 🫗 GitHub’s New Stack Overflow: PRs Edition
- 🪲 North Korea Debugs Its Way Into Your NPM Packages
- 👫 Amazon Bedrock Googles Itself, Skips the Middleman
- 🗺️ Kiro, Claude, and the Quest for Sane Code Review
- 📈 Bezos Bucks: AWS Revenue Growth Defies Gravity
- 🧱 Google Tears Down Data Walls with Borderless Lakehouse
- 🛂 BigQuery Goes Full Nomad, Crosses Clouds Without a Passport
- 🥳 Chollima Chaos: DPRK Hackers Crash the NPM Party
- 🌐 Bedrock Bets Big on Bing-Free Web Search
- 🕹️ Microsoft’s Azure Hits Triple Digits, Xbox Hits Snooze
- 🧖 Google Automates the DBA Out of Day 0
- 📊 MCP Servers Turn Data Chaos Into Actual Answers
- 💻 Cloudflare Gives Agents a Computer, Not Containers
- 200 OK, Zero Trust: Cloudflare Traces Agent Fails
- 🔢 Amazon is all about the Quota
A big thanks to this week’s sponsors:
We’re sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You’ve come to the right place! Send us an email or hit us up on our Slack channel for more info.
General News
It’s Earnings Time!
01:12 Google (GOOG) Q2 2026 earnings report: Live updates
- Google Cloud revenue grew 82% year over year to $24.8 billion, the standout number in an otherwise mixed earnings report, and beat Wall Street’s overall revenue expectations of $116.93 billion with $119.80 billion.
- Alphabet raised its 2026 capex guidance to $195-205 billion, up from the $180-190 billion forecast given just last quarter, with Q2 capex alone up 100% year over year to $44.9 billion. CFO Anat Ashkenazi cited continued supply constraints and strong demand from both external cloud customers and internal AI workloads.
- Despite the cloud growth and revenue beat, stock dropped in after-hours trading, suggesting investors are more focused on the scale of AI infrastructure spending than current cloud performance gains.
- Google’s Antigravity AI coding tool reported 2.4 million weekly active users, and the Gemini App has scaled to 950 million monthly active users processing 22 billion tokens per minute, indicating substantial adoption of Google’s AI products.
- Competitive pressure is mounting from Chinese open-weight models pushing token costs down, prompting Google to release three cheaper Gemini models this week.
- Gemini 3.5 Pro remains in testing after reported delays, while compute is already being allocated toward Gemini 4 to compete with Anthropic and OpenAI’s frontier models.
04:19 AWS earnings Q2 2026
- AWS posted 37% revenue growth to $42.23 billion in Q2, beating analyst estimates of $40.54 billion and accelerating from 28% growth in Q1, its strongest quarter since 2021.
- AI and chip products each surpassed $25 billion in annualized revenue, more than doubling year over year, showing customer demand is translating into concrete revenue rather than just capacity buildout.
- All three major cloud providers reported accelerating growth: Azure at 43%, Google Cloud at 82%, and AWS at 37%, though AWS remains the largest by absolute revenue at $148.4 billion trailing twelve months versus Azure’s $100 billion and Google Cloud’s $78 billion.
- AWS operating margin came in at 36.8%, slightly ahead of Google Cloud’s 35.6%, and the segment now accounts for nearly 61% of Amazon’s total operating profit, underscoring how central cloud has become to Amazon’s overall profitability.
- Capital expenditures jumped 68% to $54.21 billion for the quarter, reflecting continued heavy investment in AI data center capacity and chip infrastructure to meet demand, including new customer commitments from OpenAI and Meta’s Graviton chip deal.
06:22 Microsoft (MSFT) Q4 earnings report 2026
- Microsoft beat Q4 expectations with $90.01 billion revenue (up 18% year over year) and $4.74 adjusted EPS versus $4.24 expected, sending shares up 8% in after-hours trading. Net income of $35.77 billion was boosted by a $3.2 billion gain from the Anthropic investment.
- Azure revenue growth accelerated to 43% year over year, up from 40% the prior quarter, and Azure surpassed $100 billion in annual revenue for the first time, up 41% for the fiscal year. This keeps Azure behind AWS but ahead of Google Cloud in overall scale.
- Capital expenditures and finance leases jumped 69% to $41 billion for the quarter, with CFO Amy Hood extending the useful life of data center and office buildings from 15 to 25 years and shifting more future leases to operating lease treatment. This accounting change contributes to a projected $175 billion in capex and finance leases for 2026, with further growth expected in fiscal 2027.
- Microsoft 365 Copilot reached over 30 million paid seats, up from 20 million in April, and GitHub Copilot now has 50 million users, indicating continued enterprise adoption of AI-assisted productivity tools.
- Analysts flagged concentration risk tied to the OpenAI relationship, with 45% of Microsoft’s $625 billion commercial remaining performance obligations linked to OpenAI as of January. Commercial RPO grew 8% sequentially to $678 billion, driven primarily by non-AI model developer clients, suggesting diversification in the customer base.
- Xbox revenue declined 10% following job cuts and the spinout of four studios, while the broader More Personal Computing segment fell 4.4% amid a 7% drop in device and Windows licensing sales to OEMs.
06:22 📢 Justin – “So overall, no one is buying hardware right now, because it’s way too expensive.”
AI Is Going Great – or How ML Makes Money
09:53 With a stateless makeover, new MCP spec targets enterprise scale
- MCP has moved from a stateful, bidirectional protocol to a stateless, request/response core, removing the requirement that requests be tied to a specific server instance session. This is the largest spec update since MCP launched and directly targets enterprise scalability concerns.
- The stateless design addresses reliability and scaling issues that developers had flagged as high priority, since server instances no longer need to maintain session state for individual clients, simplifying load balancing and horizontal scaling.
- Additional updates include Multi Round-Trip Requests, header-based routing, cacheable list results, authorization hardening, a formal extensions framework, and updated Tier 1 SDKs, expanding both security posture and developer tooling.
- For teams building AI agents or tool integrations, the shift to stateless architecture should make MCP servers easier to deploy behind standard load balancers and in serverless or containerized environments, similar to typical stateless API design patterns.
- The update is maintained by Anthropic engineers David Soria Parra and Den Delimarsky, reflecting continued investment in MCP as infrastructure for AI tool-calling standards across the industry, not just within Anthropic’s own products.
12:56 📢 Ryan – “It is interesting how big of a change this is; if you already have an application out there, this is a big rewrite. You cannot just drop this in.”
13:23 Amazon accidentally spent $1.8 million using Claude for menial coding task, went 860% over budget — ‘catastrophically expensive’ coding
blunders discovered in internal Amazon AI usage metrics
- Amazon’s internal reports revealed a Claude Sonnet deployment for matching author details to product listings went 860 percent over its allocated budget, resulting in a 1.8 million dollar overrun that took five months to detect.
- Additional cost overruns included 541,000 dollars on a financial auditing tool project and 134,000 dollars on a logistics delivery-time optimization system, both attributed to unexpected AI token consumption.
- The core issue stems from agentic AI workflows consuming tokens at a much higher rate than traditional coding methods, turning previously low-cost tasks into significant expenses when left unmonitored.
- Amazon’s response characterized these as isolated learning examples rather than systemic problems, and in context, the overruns represent a small fraction of the company’s monthly revenue, though the story highlights the need for cost monitoring and guardrails when deploying AI agents at scale.
- This raises a broader discussion point for cloud and AI teams: token-based pricing models require the same kind of budget alerting and anomaly detection typically applied to cloud infrastructure spend, since cost visibility gaps can persist for months without proper tracking.
14:21 📢 Justin – “If Amazon can’t get this right, how am I going to do it right?”
Security
17:04 Apple caps security bug reports amid surge in AI-generated findings
- Apple has capped the number of open bug bounty submissions per researcher and added a 30-day cool-off period, implemented in June, in response to a surge of AI-generated vulnerability reports; researchers can request quota increases for critical findings.
- The change reflects an industry-wide problem: LLMs are now capable of finding, chaining, and exploiting vulnerabilities at a volume that outpaces manual review teams, forcing companies to rate-limit submissions rather than review capacity.
- Apple recently accelerated security patches (iOS 26.5.2 and related updates) specifically due to AI-assisted vulnerability discovery, and has credited researchers using tools from OpenAI, Anthropic, and Z.ai in its security release notes.
- The policy has trade-offs: Bynario, a small security firm, had legitimate submissions blocked under the new cap, including a privilege-escalation exploit chain with full Mac takeover potential; Apple is now reviewing those findings after press scrutiny.
- GitHub introduced a similar tiered bug bounty system days before this report, suggesting the industry is converging on verification-based triage to distinguish credentialed researchers from high-volume AI-assisted or low-quality submissions.
18:54 📢 Justin – “To totally cap getting them at all seems like a really silly way to try and control this problem.”
20:23 Amazon identifies North Korean hacker group behind open-source supply chain attacks
- Amazon Threat Intelligence linked four separate NPM package compromises (axios, debug, chalk, typo-crypto) to a single DPRK-linked threat actor tracked as SAPPHIRE SLEET/STARDUST CHOLLIMA/BlueNoroff, marking the first public connection between these incidents.
- The axios package alone has over 100 million weekly downloads, illustrating the scale of potential exposure.
- Attackers gained access primarily through social engineering of trusted package maintainers, then pushed malicious updates that were automatically pulled by downstream organizations.
- Wiz Research found that roughly 1 in 10 cloud environments were affected by the debug and chalk compromise within a two-hour window.
- Attacker tradecraft is evolving beyond single malicious packages toward fragment-level attacks, where malicious behavior is split across multiple benign-looking packages, and toward decoupled behavior where a clean package fetches malicious logic from an attacker-controlled server post-install, evading static code scans.
- Generative AI is reshaping the threat landscape on both sides: attackers are using AI to generate convincing documentation and code with no stable signature for pattern matching, and are beginning to embed prompt injection content in packages designed to trick AI-based code reviewers into approving malicious code. A related technique called slopsquatting involves attackers pre-registering package names hallucinated by AI coding assistants.
- AWS’s response includes sharing indicators through Amazon GuardDuty, reporting malware to the OSV database (tracked as MAL-2026-3400), and refining Amazon Inspector detection logic.
- AWS also joined the Linux Foundation’s Akrites initiative and contributed to a $12.5 million joint investment defending open source against AI-driven attacks.
Cloud Tools
23:03 Stacked pull requests are now in public preview
-
- GitHub’s stacked pull requests, now in public preview, let developers break large changes into an ordered series of small, focused PRs that each build on the layer below, addressing the common problem of oversized PRs that are difficult and slow to review.
- Each layer can be reviewed independently and in parallel by different teammates, with a stack map showing how individual PRs fit into the larger change, while existing branch protections and required checks still apply.
- Merging is flexible: teams can land the entire stack in one operation, or merge only lower layers while upper layers automatically rebase and retarget, reducing manual branch management overhead.
- The feature integrates with existing GitHub tooling including the CLI (via the gh-stack extension), the mobile app, merge queue, and coding agents like GitHub Copilot through a dedicated skill.
- Early adopters (Vercel, TED, WHOOP, jQuery’s creator) report the feature helps manage PR volume increases from AI-assisted development and improves review speed and accuracy; merge queue support for stacks is still rolling out progressively.
- Do you have a really great use case for this one? We’d love to hear about it. Pod@TheCloudPod.net
AWS
26:57 A bigger role for Swami: Amazon’s agentic AI chief gets broader mandate to shape emerging tech
- Swami Sivasubramanian’s org is renamed “Agentic AI & Emerging Technologies,” expanding his mandate beyond agentic AI to include neurosymbolic AI and AWS Context, a service that builds knowledge graphs from company data for AI agents to query.
- He continues leading Kiro, Amazon Quick, and AWS Transform, while his team has operated as a startup-style test case within Amazon, shipping products in months rather than the typical year-long cycle.
- This move is separate from Amazon’s AGI reorganization, which included layoffs, the closure of its San Francisco AGI site, and a reported wind-down of most in-house Nova models (including Premier and Omni) as the company consolidates around fewer frontier model efforts.
- The expansion follows the May hire of former Microsoft exec Shawn Bice to lead AWS’s Automated Reasoning Group, which uses mathematical verification techniques to confirm AI agents behave as intended, signaling AWS’s continued investment in agent reliability and governance.
- For AWS customers, this signals more concentrated leadership over emerging AI tooling and infrastructure decisions, worth watching for how AWS Context and neurosymbolic AI initiatives eventually surface in the product lineup.
27:57 📢 Ryan – “I’m still stuck on trying to figure out what Neurosymbolic AI is.”
29:38 Authenticate with Private Key JWT using Amazon Bedrock AgentCore Identity
- Amazon Bedrock AgentCore Identity now supports Private Key JWT client authentication, letting agents authenticate to identity providers using a signed JWT instead of a shared OAuth 2.0 client secret, removing a common credential-leakage risk.
- The private key never leaves AWS KMS; AgentCore Identity calls kms:Sign to generate the assertion, and only the public key is registered with the identity provider, supporting RS256, PS256, or ES256 algorithms.
- The feature works across all three major grant flows: machine-to-machine (client_credentials), on-behalf-of (token exchange for user-delegated calls), and user-delegated access (authorization code flow), covering most enterprise agent-to-API scenarios.
- Every signing operation and token request is logged in AWS CloudTrail (GetWorkloadAccessToken, GetResourceOauth2Token, and KMS Sign events), giving teams an audit trail for compliance and security review without exposing token contents.
- Setup requires creating an asymmetric KMS signing key, registering the public key with providers like Okta or Microsoft Entra ID, and configuring a credential provider through the AgentCore console; sample end-to-end implementations are available on the AWS GitHub samples repo.
- Costs follow standard KMS asymmetric key pricing (about $1/month per key plus per-request signing charges) plus existing AgentCore usage fees.
30:41 📢 Ryan – “So while MCP is moving towards OAuth and client secrets, this is moving away.”
32:15 Balancing speed and safety: A control framework for AI coding agents
- AWS Security Blog outlines a two-pillar control framework for AI coding agents like Kiro and Claude Code, addressing seven key risks including prompt injection, data disclosure, and supply chain vulnerabilities—relevant as agents now open dozens of PRs autonomously via MCP integrations.
- The framework splits controls into author-time (IDE-based steering documents, specs, MCP scoping) and build-time (pipeline scanning, quality gates, AI-assisted review), using AWS services like Kiro, CodeBuild, and CodePipeline as reference implementations.
- Key technical distinction: deterministic controls (SAST, secrets detection, policy-as-code) enforce hard rules consistently, while non-deterministic controls (LLM-as-judge review, specification compliance checks) catch context-dependent issues that pattern matching misses—AWS recommends layering both since AI-generated code can pass all deterministic checks yet remain functionallyd wrong.
- Notable guidance on human review: AWS explicitly warns against routing every change to human reviewers, citing “consent fatigue” where reviewers approve by reflex; instead, they recommend scaling review depth to risk level and reserving human judgment for security-sensitive or high-blast-radius changes.
- Practical implementation tools mentioned include the open-source Automated Security Helper (bundles secrets, SAST, SCA, and IaC scanning behind one command) and Project CodeGuard (published steering rule templates for common risk classes); both are free and available now for teams to adopt without waiting on new AWS service releases.
35:36 AWS WAF adds pre-parse text transformations and new text transformations
- AWS WAF now normalizes raw query strings before parsing, closing HTTP parameter pollution and parser differential evasion gaps that attackers use to bypass detection rules.
- Ten new text transformations add standard options like Uppercase, Trim, Remove Whitespace, and SHA256, plus OS-aware command line and JavaScript decoding functions built by the Amazon Threat Research Team.
- Rules can chain up to ten pre-parse transformations, including URL decode and combining duplicate query arguments, then layer standard post-parse transformations within the same rule statement for more precise inspection logic.
- Each new transformation consumes 10 WCUs with no added fee beyond standard AWS WAF pricing, and the feature is available in all AWS Regions at launch.
- This addresses a common security gap where WAF inspection logic doesn’t match how backend applications actually parse requests, reducing false negatives from evasion techniques.
36:371 📢 Ryan – “Cloud native WAFs – actually all WAFs – are becoming VERY complicated.”
39:51 AWS Organizations now provides maximum account quota visibility in Service Quotas
- AWS Organizations customers can now check their maximum account quota and current usage directly in the Service Quotas console, eliminating the need to contact AWS Support or account teams for this basic information.
- The feature supports proactive capacity planning, letting organizations monitor quota utilization and request increases before hitting limits that could block new account creation.
- Access is available in two ways: through the Service Quotas console when logged into the management account, or programmatically via the GetServiceQuota API for automation and monitoring workflows.
- This is currently limited to US East (N. Virginia), so multi-region organizations will need to check documentation for their specific setup until wider availability rolls out.
- This is a small but practical operational improvement, particularly useful for large enterprises or managed service providers running many AWS accounts under one organization who need visibility into scaling limits.
41:55 Introducing Web Search on Amazon Bedrock for foundation model grounding
- AWS launched Web Search on Amazon Bedrock as a native, server-side tool that grounds foundation model responses in current web knowledge, eliminating the need to integrate and maintain third-party search providers.
- The feature combines a continually refreshed web index (billions of documents) with a built-in knowledge graph to improve factual accuracy on things like dates, authorship, and events, while using semantic snippet extraction to keep token usage efficient.
- Enablement is a single parameter added to an existing OpenAI-compatible API call through Bedrock’s Responses API, with authentication handled via existing AWS IAM credentials rather than separate API keys.
- Compliance-focused design includes zero data egress by default, in-region processing, and CloudTrail integration that logs calling identity and access decisions without recording query text, URLs, or page content, which should appeal to regulated industries needing audit trails.
- Availability is currently limited to the US, with in-region query handling in us-east-1, us-east-2, and us-west-2, and only indexed-web retrieval is supported at launch, with live-web fetching planned for a future update.
- Pricing details are on the Amazon Bedrock pricing page.
42:52 📢 Justin – “So I’m very happy this exists, because one of the problems you have with Bedrock Agents is that they don’t know anything about the web. They don’t know what the date is, and you had to provide it with a bunch of updated information and context if you need it to be anything current; and so the fact that it has some ability to do this, maybe not completely what you need, but at least it’s heading in the right direction.”
GCP
44:31 Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline
- Google Cloud’s Office of the CISO is pushing AI Threat Defense (AITD) as a board-level governance topic, framing security as a business enabler rather than a cost center, arguing that AI adoption requires automated, machine-speed defense rather than manual processes.
- The piece outlines five governance questions for boards to ask leadership, covering business enablement, remediation cycle speed (MTTR), tool consolidation, contextual prioritization of vulnerabilities, and AI safety policies for shadow AI and internal pipelines.
- CodeMender, Google’s AI code security agent, is now in preview through Agent Platform and AI Threat Defense, allowing automated scanning and fixing of software vulnerabilities.
- Cloud KMS is expanding its post-quantum cryptography digital signature support to include ML-DSA and SLH-DSA algorithms, relevant for organizations planning long-term data integrity strategies against future quantum threats.
- AlloyDB added IAM group authentication in preview, giving enterprises identity-driven access control for database workloads and AI agents, which is useful for teams managing access at scale without manual user provisioning.
45:41 📢 Justin – “Thanks, Google, for scaring the board, and then giving us some new tools.”
46:55 Introducing the borderless Lakehouse
- Google announced borderless Lakehouse enhancements at Next Tokyo, using catalog federation via Iceberg REST to connect BigQuery with AWS Glue, Databricks Unity, and Snowflake Horizon in preview, allowing queries across clouds without data movement or ETL pipelines.
- Cross-Cloud Interconnect now offers zero variable egress costs when pulling data from AWS, with Partner Cross-Cloud Interconnect pricing providing flat, subscription-based rates from 1G to 100G instead of unpredictable per-GB egress fees; note that customers still pay an hourly interconnection service fee.
- Knowledge Catalog acts as the governance and context layer, automatically syncing metadata from AWS Glue, Databricks Unity Catalog, and Snowflake Horizon to translate schemas into business terms and lineage, aiming to reduce AI agent hallucinations and enforce access controls at the table level.
- Zero-copy integrations extend to SaaS platforms like SAP, Salesforce, and Workday, letting BigQuery query live application data directly and letting those platforms run BigQuery AI functions in place, which Google says has driven up to a 230x reduction in token consumption for some customers.
- Spanner Omni and Lakehouse Federation for AlloyDB extend this model to transactional databases, letting operational systems query lakehouse data directly, while the Data Agent Kit plus Conversational Analytics API let developers build custom agents in Gemini Enterprise using natural language over this federated data estate.
50:42 Deep dive on new AI-powered database agents
- Google announced two new AI agents under the Agentic Data Cloud umbrella at Cloud Next 26: the Database Onboarding Agent for initial setup and configuration, and the Database Observability Agent for ongoing monitoring and troubleshooting, both powered by Gemini.
- The Observability Agent correlates telemetry from Database Insights, Cloud Monitoring, Cloud Logging, and Cloud Trace to produce root cause analysis in minutes, and can suggest or execute remediation actions like enabling connection pooling, pending user approval.
- Coverage spans Cloud SQL, Spanner, AlloyDB, Bigtable, Firestore, and Memorystore, with access available through Gemini Chat, Cloud Assist, the Cloud console, IDEs, and MCP servers, letting teams query fleet-wide metrics like top CPU consumers across databases.
- The Onboarding Agent lets users describe application requirements in natural language and receive database service recommendations along with provisioning commands, aiming to reduce manual documentation review during Day 0 planning.
- Some capabilities, including in-product investigations and validated remediations, are still in preview with select customers, so full availability and pricing details are not yet finalized; access is currently through Gemini Cloud Assist.
Azure
52:23 Public Preview: Route-Maps for Azure Route Server
- Route-maps for Azure Route Server enter public preview, giving admins granular control over BGP route advertisements between on-premises networks, NVAs, ExpressRoute gateways, and VPN gateways within a virtual network.
- Four core capabilities: route summarization for simplifying on-premises to Azure connections, route control for filtering traffic direction, path selection via AS-PATH manipulation, and route tagging using BGP Community attributes.
- Targets enterprises with complex hybrid networking setups involving multiple connection types (ExpressRoute, VPN, NVAs) that need to manage routing policy without manual intervention at each peering point.
- This addresses a long-standing gap in Azure Route Server, which previously offered limited routing policy controls compared to on-premises BGP implementations, bringing it closer to feature parity with traditional network appliances.
- Preview is free to test, though standard Azure Route Server pricing still applies; the listed target timeframe is July 2026, so general availability timing remains unclear.
54:10 Generally Available: Trusted Launch as Default
- Trusted Launch as Default is now generally available, automatically enabling Secure Boot and vTPM on new Gen2 VMs and virtual machine scale sets at no additional cost, establishing a stronger baseline security posture out of the box.
- Deployments via Azure Portal, CLI, and PowerShell get Trusted Launch automatically, while ARM templates, Bicep, Terraform, and SDK users need a one-time subscription registration to get the same default behavior.
- Existing VMs are unaffected by this change, and any previously configured security settings will continue to be honored, so there’s no risk of unexpected behavior changes for current workloads.
- Availability spans both x64 and Arm64 Gen2 VM sizes across Azure public, Azure Government, and Azure China regions, giving broad coverage for customers with compliance or sovereignty requirements.
- This is a notable move toward secure-by-default infrastructure, reducing the burden on customers to manually configure security features like Secure Boot and vTPM for new deployments.
54:46 📢 Justin – “That this isn’t required in 2026 is kind of blowing my mind…”
Oracle
55:30 Oracle to Make Gemini Models Available to Thousands of Enterprise Applications Customers
- Oracle is expanding its Google Cloud partnership to embed Gemini models directly into Fusion Applications, NetSuite, and the new AI Agent Studio, following on from existing Gemini access via OCI Enterprise AI.
- This is Oracle continuing its multi-model, multi-vendor AI strategy rather than betting on a single provider.
- Specific models mentioned include Gemini 3.1 Flash Lite for price-performance and Gemini 3.5 Flash for more complex reasoning tasks like video and presentation generation, positioned alongside models from other providers in AI Agent Studio. No pricing details were provided in the release, so cost impact to customers remains unclear.
- The embedded AI use cases in Fusion Applications and NetSuite suggest Oracle is choosing models on a per-scenario basis for optimal price-performance, rather than standardizing on one model across the application suite, which could mean inconsistent AI behavior across different modules.
- This is a partnership expansion announcement with no GA date or technical specifics beyond model names, so listeners should treat this as a roadmap disclosure rather than a shipped feature. Oracle’s own disclaimer notes the timing and functionality could change at Oracle’s discretion.
- The practical impact for Oracle’s enterprise applications customers (ERP, HCM, SCM, CX, NetSuite) is broader model choice for agentic workflows, but actual differentiation versus existing OCI Gemini access or competitors embedding Gemini elsewhere isn’t clearly established in this release.
55:51 📢 Justin – “That’s nice. Can’t wait to get Gemini terribleness in my fusion apps.”
Emerging Clouds
56:45 Your agent needs a computer, not a container — introducing @cloudflare/computer
- Cloudflare released an open-source preview of @cloudflare/computer, an agent runtime that abstracts away whether code runs in an isolate, a container sandbox, or a browser, letting agents choose the right execution environment automatically.
- The core problem being addressed is scale: giving every agent its own dedicated container is not sustainable given projected demand for hundreds of millions or billions of concurrent agents, so Cloudflare is pushing isolates as a more efficient default compute primitive.
- The architecture separates a durable, SQLite-backed virtual filesystem from the execution runtime, allowing agents to run lightweight operations in isolates via just-bash and dynamic workers, while falling back to full Linux containers (accessed via FUSE) only when native binaries or heavier tooling are required.
- Cloudflare reports that in testing, frontier models were able to correctly choose between the isolate and container backends based on task requirements, with the stated goal of limiting container use to under 10% of total agent workload.
- This approach builds on Cloudflare’s existing bets on Workers and Durable Objects, and reflects a broader industry trend of separating the agent “brain” (the loop) from the “hands” (sandboxed execution), which is relevant for any team building or scaling agentic systems on top of cloud infrastructure.
59:15 Introducing: Cloudflare Agents
- Cloudflare is positioning agents as a first-class workload on its developer platform, leveraging existing building blocks like Durable Objects, Workflows, R2, and AI Gateway rather than introducing entirely new infrastructure.
- Agent tracing addresses a specific observability gap: an agent can return HTTP 200 while still failing due to wrong tool selection, stale context, or retry loops that traditional infrastructure telemetry won’t surface.
- The new Agents dashboard provides two debugging views: session replay for reviewing full conversation context across turns, and trace waterfalls for inspecting execution timing across model calls, tool executions, and subagent delegation, all correlated with Workers infrastructure like D1 and KV.
- Support launches with OpenTelemetry-compatible harnesses (Think, Flue, AI SDK), with plans to accept standard OpenTelemetry Generative AI semantic convention spans directly, reducing dependency on Cloudflare-specific adapters and allowing export to any OTLP-compatible destination.
- Pricing is tied to existing Workers Observability spans, with tracing free during beta and billing starting October 1, 2026 – worth noting for teams evaluating long-term cost as trace volume scales with agent activity.
1:00:4 Introducing the Billable Usage API: programmatic cost visibility for Cloudflare
- Cloudflare launched a Billable Usage API for self-serve accounts, giving programmatic access to cost and usage data across Workers, R2, D1, Workers AI, Vectorize, Images, and Stream in a single API call, rather than relying on dashboard exports or screenshots.
- The API format aligns with the FinOps FOCUS specification, using familiar column names like ServiceName, ContractedCost, and ChargePeriodStart, though Cloudflare notes it does not yet have full FOCUS conformance.
- Data updates daily rather than in real time currently, though Cloudflare has stated finer-grained time windows and forecasting capabilities are on the roadmap.
- Cloudflare partnered with Vantage to enable native integration, allowing Cloudflare spend to appear alongside other cloud providers in cost reports, budgets, and anomaly alerts, supporting cross-provider cost allocation via a read-only Billing Read API token.
- This release targets self-serve accounts only, with an Enterprise equivalent still in development, and reflects a broader trend of building cost visibility tooling to support agent-driven infrastructure provisioning where automated systems now deploy resources and incur costs without direct human oversight.
Closing
And that is the week in the cloud! Visit our website, the home of the Cloud Pod, where you can join our newsletter, Slack team, send feedback, or ask questions at theCloudPod.net or tweet at us with the hashtag #theCloudPod

Leave a Reply