WEBVTT

NOTE Sentence-level transcript of https://www.youtube.com/watch?v=RmS5s6Wbin4

NOTE One cue per sentence. Cue ids are the line anchors on /transcripts/RmS5s6Wbin4.html. A cue ends where the next begins, or 2 s after its last word.

s1
00:00:01.309 --> 00:00:03.309
[music]

s2
00:00:23.680 --> 00:00:24.480
Okay.

s3
00:00:24.480 --> 00:00:25.519
Hi.

s4
00:00:25.519 --> 00:00:25.840
All right.

s5
00:00:25.840 --> 00:00:29.439
I've got a lot to talk about, so I'm going to launch right into it here.

s6
00:00:29.439 --> 00:00:35.360
Um, so Swix says that you only get to make one point at every talk, uh, one key takeaway.

s7
00:00:35.360 --> 00:00:37.680
And so I figured I'd just lead with that.

s8
00:00:37.680 --> 00:00:43.120
My, uh, key point is personal AI codegen breaks traditional cloud infrastructure.

s9
00:00:43.120 --> 00:00:49.280
And to clarify what I mean about that, the word personal here is, uh, is is doing a lot of work.

s10
00:00:49.280 --> 00:00:52.000
It's uh, loadbearing as cloud would say.

s11
00:00:52.000 --> 00:01:02.320
Um my point is that um if we want to see this future where um everyone has personal apps and like can personalize uh the apps that they run um the

s12
00:01:02.320 --> 00:01:09.760
infrastructure we're using today um for for software in general is is not the right thing and we need something completely different.

s13
00:01:09.760 --> 00:01:18.400
So to explain what I mean um think about the way that uh uh software is produced and distributed today.

s14
00:01:18.400 --> 00:01:31.600
You have a developer in an ivory tower who builds an app and then sends it down to the the people the users who use the app and many of them are happy with it but some of them are not.

s15
00:01:31.600 --> 00:01:43.520
Some of them uh say this app needs uh some additional features for my use case and so they go to the developer and they say oh great developer will you please grant my feature request

s16
00:01:43.520 --> 00:01:46.799
your app is literally unusable without it.

s17
00:01:46.799 --> 00:01:56.720
And so then the the developer's representative, the product manager takes these feature requests and files them into Jira where they are never seen again.

s18
00:01:56.720 --> 00:02:07.759
Um but sometimes sometimes the product manager sees a feature request and says ah I you know I want that too and then that feature request goes onto the road map and the developer

s19
00:02:07.759 --> 00:02:22.080
um works on it and the developer is implementing all these features features that uh you know each one is only used by a small subset of users and each one is adding all these if statements their code and making things messy

s20
00:02:22.080 --> 00:02:28.239
and uh they don't like it because the codebase is becoming a mess and each of these features which is really kind of boring to implement.

s21
00:02:28.239 --> 00:02:32.879
And so the developer says, "Ah, I know what I need to do.

s22
00:02:32.879 --> 00:02:35.440
We need a rewrite.

s23
00:02:35.440 --> 00:02:40.560
We need to we need a new architecture that has a plug-in system."

s24
00:02:40.560 --> 00:02:48.400
And then every one of these features can be a plug-in and it can be nice and clean and easy to build and the core can stay clean.

s25
00:02:48.400 --> 00:02:53.760
And so the developer goes off and starts working on the the new architecture with the plug-in system.

s26
00:02:53.760 --> 00:03:03.280
and uh there are still feature requests coming in and the developer says,"Well, we can't do those features yet because uh we need the plug-in system.

s27
00:03:03.280 --> 00:03:06.080
This will be so much easier once we have the plug-in system.

s28
00:03:06.080 --> 00:03:09.760
And if we do it now, we're just delaying that and we'll just have to redo it later anyway."

s29
00:03:09.760 --> 00:03:17.157
And so um the years go by and uh the new architecture is not ready yet and

s30
00:03:17.157 --> 00:03:17.599
[snorts]

s31
00:03:17.599 --> 00:03:21.920
none of the features are being implemented and people are saying, "What are they doing?

s32
00:03:21.920 --> 00:03:27.519
this developer has given up their product and uh everybody is sad.

s33
00:03:27.519 --> 00:03:34.560
So AI seems to present a new alternative to this.

s34
00:03:34.560 --> 00:03:45.280
What if uh the developer could create their app, the first version of their app, give it to the users, and the users if they need a new feature could say

s35
00:03:45.280 --> 00:03:51.040
that could ask their AI agent to write that feature just for them, add it to the app.

s36
00:03:51.040 --> 00:03:54.400
Um, then everyone gets the features they need.

s37
00:03:54.400 --> 00:03:57.519
No one is bogged down in everyone else's features.

s38
00:03:57.519 --> 00:04:03.360
Uh, and the developer gets to keep the the core app nice and clean and beautiful.

s39
00:04:03.360 --> 00:04:13.840
But there's a there's a problem with this, which is that none of the the infrastructure we build software on today is like remotely designed for this.

s40
00:04:13.840 --> 00:04:28.160
You've got uh Apple and Google for the past 15 years uh gatekeeping their systems to the point where there's like five companies that can build mobile apps now and uh because everyone else has been banned.

s41
00:04:28.160 --> 00:04:36.320
Um and it's almost like easier to in the United States to buy a gun than it is to like get access to your own phone to install unsigned software.

s42
00:04:36.320 --> 00:04:38.880
You go to Google and you say, "I want to install unsigned software."

s43
00:04:38.880 --> 00:04:42.880
And now they're going to say, "Oh, whoa, hold on, buddy.

s44
00:04:42.880 --> 00:04:44.000
uh you seem upset.

s45
00:04:44.000 --> 00:04:46.880
Uh you should uh go home and think about this.

s46
00:04:46.880 --> 00:04:53.600
Uh if you still want that unsigned software in 24 hours, then you can come back and talk to us.

s47
00:04:54.960 --> 00:04:58.639
Fortunately, we have a workaround for all of that, which is the web.

s48
00:04:58.639 --> 00:05:01.440
On the web, everyone can build whatever they want.

s49
00:05:01.440 --> 00:05:02.880
And it turns out it's fine.

s50
00:05:02.880 --> 00:05:07.600
It's not the security disaster that Apple and Google keep telling us would happen.

s51
00:05:07.600 --> 00:05:21.600
So you can build whatever you want on the web but there's a different problem on the web which is that for the past uh 25 years of uh cloud architecture we've been running in the wrong direction.

s52
00:05:21.680 --> 00:05:37.120
uh when you distribute a web app, you run it on your own server like put it on your server and then users send requests to your server where the one version of your app, the one um you know blessed version runs

s53
00:05:37.120 --> 00:05:39.120
uh for every single user.

s54
00:05:39.120 --> 00:05:41.919
And so that's convenient for developers.

s55
00:05:41.919 --> 00:05:46.400
That's why we've done it is so the developer can make sure things stay updated and everyone's on the same version.

s56
00:05:46.400 --> 00:05:53.440
But um it obviously means that users cannot customize their apps.

s57
00:05:53.919 --> 00:06:10.160
So you know last year uh vibe coding comes along and we have all these vibe coding um platforms out there and the most of them are targeting web apps because that's the easy thing to target but they're all targeting this existing infrastructure

s58
00:06:10.160 --> 00:06:14.800
which is actually like not the right way to do it.

s59
00:06:14.800 --> 00:06:18.080
Um, we need something entirely different.

s60
00:06:18.080 --> 00:06:19.919
And hence my point.

s61
00:06:19.919 --> 00:06:25.680
Do you uh do you like how the word breaks kind of wiggles every now and then?

s62
00:06:25.680 --> 00:06:32.000
That was uh that was something Claude put in there and it was so stupid I just had to keep it.

s63
00:06:32.000 --> 00:06:48.479
Um, I want to know where in Claude's training data it uh it learned that you could make words wiggle to give them emphasis because like I you know I understand the red I understand the underline but uh the wiggle like I don't think that's that's from humans.

s64
00:06:48.479 --> 00:06:51.759
I I think that's an AI original.

s65
00:06:51.999 --> 00:06:53.440
[laughter]

s66
00:06:53.440 --> 00:06:55.039
This this is ASI folks.

s67
00:06:55.039 --> 00:06:59.919
Yeah, it's beyond my puny human brain's ability to comprehend.

s68
00:06:59.919 --> 00:07:14.720
Um anyway, uh so you might be wondering at this point like who is this this guy who hasn't introduced himself up on stage um giving a Richard Stallman-esque rant about how we should have the freedom to modify our own software

s69
00:07:14.720 --> 00:07:17.120
and what does he know about cloud infrastructure.

s70
00:07:17.120 --> 00:07:19.520
So I'm Kenton Varta.

s71
00:07:19.520 --> 00:07:21.599
I created Cloudflare workers.

s72
00:07:21.599 --> 00:07:25.599
I started the project um back in 2017 when I joined Cloudflare.

s73
00:07:25.599 --> 00:07:28.240
I am still the lead engineer today.

s74
00:07:28.240 --> 00:07:32.479
um it now is uh you know it's a serverless application hosting platform.

s75
00:07:32.479 --> 00:07:33.840
We have millions of developers.

s76
00:07:33.840 --> 00:07:36.560
We serve trillions requests per day.

s77
00:07:36.560 --> 00:07:46.000
But what I'm going to talk to you a little bit about today is uh sort of a side project I've been working on on top of workers which is um

s78
00:07:46.319 --> 00:07:52.080
designed to is my exploration in how to uh uh solve this problem.

s79
00:07:52.080 --> 00:07:58.639
So, uh, this thing you're looking at right now is actually a little app that I created in this platform.

s80
00:07:58.639 --> 00:08:04.400
But, um, we're going to the the front page here.

s81
00:08:04.400 --> 00:08:07.599
So, you have your your Vibe Code prompt.

s82
00:08:07.599 --> 00:08:09.199
You know, these things are a diamond dozen.

s83
00:08:09.199 --> 00:08:13.360
Um, we all seen this before, but I'm just going to put in a little prompt to make to show that it works.

s84
00:08:13.360 --> 00:08:17.840
Uh, make a silly counter app.

s85
00:08:17.840 --> 00:08:22.960
Silly Max it silly.

s86
00:08:22.960 --> 00:08:25.440
All right, but I'm not actually gonna sit here and watch it.

s87
00:08:25.440 --> 00:08:28.560
Oh no, it said error.

s88
00:08:29.360 --> 00:08:31.360
Yep, the internet doesn't work.

s89
00:08:31.360 --> 00:08:31.919
That's okay.

s90
00:08:31.919 --> 00:08:34.159
That's not the most important part of my talk.

s91
00:08:34.159 --> 00:08:52.240
So um so what I what I want you to understand about this environment is uh this is not like your typical vibe coding environment where you're deploying apps to a web page.

s92
00:08:52.240 --> 00:08:58.240
This is um uh you need to think about more like uh like an office suite.

s93
00:08:58.240 --> 00:08:59.680
So think about Google Docs.

s94
00:08:59.680 --> 00:09:03.680
You open Google Docs, you have a bunch of documents, hundreds, maybe thousands of documents.

s95
00:09:03.680 --> 00:09:07.600
You open one, you edit it, you share it with people.

s96
00:09:07.600 --> 00:09:11.519
This is the same thing except instead of documents, you have gadgets.

s97
00:09:11.519 --> 00:09:14.320
And each gadget is an application with code.

s98
00:09:14.320 --> 00:09:15.760
They can all be different code.

s99
00:09:15.760 --> 00:09:21.839
I have um I have an app here which is like a collaborative whiteboard app.

s100
00:09:21.839 --> 00:09:24.000
Like this is a oneshot prompt.

s101
00:09:24.000 --> 00:09:29.360
Um, I have a uh an app here which So, I get a lot of email in Spanish.

s102
00:09:29.360 --> 00:09:30.240
It's a long story.

s103
00:09:30.240 --> 00:09:34.160
I don't know Spanish, but I need help like filtering all the Spanish email.

s104
00:09:34.160 --> 00:09:36.480
So, I made a little app to help me do that.

s105
00:09:36.480 --> 00:09:37.360
Uh, a gadget.

s106
00:09:37.360 --> 00:09:44.959
Um, I have a gadget to help me sort uh pull requests that I need to uh review on GitHub.

s107
00:09:44.959 --> 00:09:51.600
And uh but those are, you know, things that I just like vibe coded from scratch.

s108
00:09:51.600 --> 00:09:54.399
But we also have this concept over here of blueprints.

s109
00:09:54.399 --> 00:10:04.160
And um a blueprint is someone made a gadget and they decided that it was useful and they took a a blueprint of it which is just taking the code exporting the code

s110
00:10:04.160 --> 00:10:12.399
without the data which they can then share with someone else and then other people can uh instantiate gadgets from these blueprints.

s111
00:10:12.399 --> 00:10:19.680
So um we have like a you know document editor app here, a combon board and um a slide builder.

s112
00:10:19.680 --> 00:10:36.079
So like you know typical office apps uh I'm going to s so this this slide builder um was built by my colleague Philip here um who's a product manager at Cloudflare and of course these days all product managers are also prolific engineers

s113
00:10:36.079 --> 00:10:48.560
um so he you know he vibed this in an afternoon I believe but uh if I instantiate this gadget I get this nice little slide deck um you know it has things I can edit it and so on.

s114
00:10:48.560 --> 00:10:49.120
Yay.

s115
00:10:49.120 --> 00:10:52.240
And if I shared it, it would well.

s116
00:10:52.240 --> 00:10:59.200
So an important point here is that when I instantiate this app, it is only for one slide deck.

s117
00:10:59.200 --> 00:11:04.720
If I want multiple slide decks, I make multiple instances of the gadget uh one for each.

s118
00:11:04.720 --> 00:11:18.160
And the reason for that is that all gadgets are um sharable and uh you know you can collaborate with other people on them and the sharing model is implemented by the platform instead of by the app itself.

s119
00:11:18.160 --> 00:11:23.360
So if I click up here, I get sort of a a share dialogue kind of like a Google Docs share dialogue.

s120
00:11:23.360 --> 00:11:25.760
I can create a share link and send it to people.

s121
00:11:25.760 --> 00:11:40.079
And uh because each gadget is just the one thing that you want to share, that means that the platform can implement the sharing model and the access control such that the gadget itself can't possibly get that wrong.

s122
00:11:40.079 --> 00:11:44.480
So I'm going to go over to actually another instance of the same slides app.

s123
00:11:44.480 --> 00:11:55.120
This is the um the slides I originally wrote for this talk, which yesterday I decided these slides were trash and I threw them all away and rewrote it.

s124
00:11:55.120 --> 00:11:58.880
Um but the the reason they're bad is is entirely my fault.

s125
00:11:58.880 --> 00:12:00.079
It's not Philip's fault.

s126
00:12:00.079 --> 00:12:01.920
It's uh not the software's fault.

s127
00:12:01.920 --> 00:12:10.000
Um but this this can still serve as an example uh to to demonstrate some of what you can do on this platform.

s128
00:12:10.000 --> 00:12:13.279
So if I uh click on here, I can see the conversation.

s129
00:12:13.279 --> 00:12:16.399
And you know, of course, I didn't edit the slides myself by hand.

s130
00:12:16.399 --> 00:12:19.200
I asked the agent to make them for me, right?

s131
00:12:19.200 --> 00:12:26.560
Um, and every app in this platform automatically integrates with agents so that you can do that.

s132
00:12:26.560 --> 00:12:39.680
And so what I did is I gave Claude a link to this document, this Google doc where I had described all of the gadgets that I wanted or all the the slides that I wanted in my um

s133
00:12:39.680 --> 00:12:41.040
in my presentation.

s134
00:12:41.040 --> 00:12:44.480
And crucially though, this is the interesting point.

s135
00:12:44.480 --> 00:12:54.320
I said, if you need uh if you need to add any new features to the slides app itself to support some of these slides, feel free to do so.

s136
00:12:54.320 --> 00:12:55.600
And it did.

s137
00:12:55.600 --> 00:13:02.079
Um Claude read all the code for the app and read my doc and said, "Yes, actually, let's see.

s138
00:13:02.079 --> 00:13:05.519
Slide three needs a uh strikethrough formatting.

s139
00:13:05.519 --> 00:13:06.800
That's not implemented."

s140
00:13:06.800 --> 00:13:08.399
Um we can add that.

s141
00:13:08.399 --> 00:13:11.440
Um, some of the slides require things to be centered.

s142
00:13:11.440 --> 00:13:16.959
And you know, I guess Philip's design taste is too good for centering text.

s143
00:13:16.959 --> 00:13:20.320
Uh, but my more pedestrian taste called for some centering.

s144
00:13:20.320 --> 00:13:21.360
And that's okay.

s145
00:13:21.360 --> 00:13:23.120
Cloud can add that.

s146
00:13:23.120 --> 00:13:27.680
Um, more interestingly, slides uh five and six here.

s147
00:13:27.680 --> 00:13:32.160
So, I asked for this like really crappy diagram of the cloud, right?

s148
00:13:32.160 --> 00:13:38.160
And the the app um didn't support sort of like arbitrary diagrams.

s149
00:13:38.160 --> 00:13:44.480
It supported, you know, uh box diagrams and arrows and such, but not an arbitrary drawing like this.

s150
00:13:44.480 --> 00:13:46.639
And so Claude said, "Okay, that's okay.

s151
00:13:46.639 --> 00:13:47.920
We can add a feature.

s152
00:13:47.920 --> 00:13:52.480
We'll add a feature that allows uh you to insert a bunch of SVG.

s153
00:13:52.480 --> 00:13:54.720
Just paste it into this box here.

s154
00:13:54.720 --> 00:13:56.639
And now it becomes uh part of the slide."

s155
00:13:56.639 --> 00:14:03.440
And now that's not very useful for any human, but it was perfectly useful for Claude who then generated the SVG.

s156
00:14:03.440 --> 00:14:07.360
Now, at this point, you might be looking at this and saying, "That's a little scary.

s157
00:14:07.360 --> 00:14:10.079
SVG can contain JavaScript.

s158
00:14:10.079 --> 00:14:13.040
Uh, are there XSS bugs here?"

s159
00:14:13.040 --> 00:14:18.079
And the answer to that is, uh, it doesn't really matter because of the way this environment is set up.

s160
00:14:18.079 --> 00:14:35.680
So the UI that you see for the app here is running inside a null origin iframe sandbox um with content security policy set so that it basically cannot talk to anything any of the rest of the world can't access any cookies so on

s161
00:14:35.680 --> 00:14:47.360
um the only thing it can do is post message to the parent frame and through that post message channel we set up a a captain web RPC uh session

s162
00:14:47.360 --> 00:15:01.040
which forwards onto the server and all the way back to the server code for this gadget which is uh this code here which is written as a a durable object on Cloudflare workers

s163
00:15:01.040 --> 00:15:13.199
and uh basically that means so so this this server code runs in a dynamic worker sandbox uh on the server side where it too is prevented from talking to any of the rest of the world.

s164
00:15:13.199 --> 00:15:17.920
So now we've set up this environment where there's a vibecoded client and a vibecoded server.

s165
00:15:17.920 --> 00:15:23.680
They can only talk to each other and produce the UI uh for the user.

s166
00:15:23.680 --> 00:15:29.839
And so if you have an XSS bug, it actually doesn't end up mattering because these can't leak anything.

s167
00:15:29.839 --> 00:15:31.600
Um they're prevented from doing so.

s168
00:15:31.600 --> 00:15:37.920
And it basically there is no security bug you can have in this code that matters.

s169
00:15:37.920 --> 00:15:43.920
Um, and that makes it safe to, you know, go and do things.

s170
00:15:44.240 --> 00:15:53.440
So, uh, I, uh, there's a whole lot that I would like to talk about that I won't have time for here, unfortunately.

s171
00:15:53.440 --> 00:16:11.279
So the um uh so there there like for instance the uh we created a whole system by which these apps can talk to external services in a safe way but I could give you know two more talks about that.

s172
00:16:11.279 --> 00:16:18.399
Um we created um there's a lot of stuff here.

s173
00:16:18.399 --> 00:16:28.560
the the points that I want to make in the time that I have left though is so everything you see here is uh is built on everything except for the LLM

s174
00:16:28.560 --> 00:16:30.880
is built on Cloudflare workers.

s175
00:16:30.880 --> 00:16:35.519
Um a lot of people don't know this but you can actually build complex apps on workers.

s176
00:16:35.519 --> 00:16:37.600
There are no containers involved here.

s177
00:16:37.600 --> 00:16:39.279
There's just dynamic workers.

s178
00:16:39.279 --> 00:16:41.680
There are no there's no database involved.

s179
00:16:41.680 --> 00:16:44.240
It just uses durable objects.

s180
00:16:44.240 --> 00:16:54.880
Um, and furthermore, all of this is actually running locally on my laptop, which is why it doesn't matter that uh the internet didn't work because uh so this is all running on

s181
00:16:54.880 --> 00:16:57.199
workerd, which is our open source runtime.

s182
00:16:57.199 --> 00:16:58.399
A lot of people don't know this.

s183
00:16:58.399 --> 00:17:01.279
The Cloudflare workers runtime is open source.

s184
00:17:01.279 --> 00:17:03.040
You can self-host it.

s185
00:17:03.040 --> 00:17:11.520
And I'm excited about that because we have in here a uh Home Assistant uh connector and a Spotify connector.

s186
00:17:11.520 --> 00:17:17.360
And I want to run this in my basement and uh use it to do home automation tasks.

s187
00:17:17.360 --> 00:17:19.496
Um so

s188
00:17:19.496 --> 00:17:20.559
[sighs]

s189
00:17:20.559 --> 00:17:23.600
this is where though I have to give a little bit of an apology.

s190
00:17:23.600 --> 00:17:30.320
Um so a couple of months ago when I submitted the the uh the proposal for this talk.

s191
00:17:30.320 --> 00:17:39.360
This was like a side project I was working on and the plan was I was going to come here and I was going to present it and then I was just at the end of the talk going to ye it onto GitHub

s192
00:17:39.360 --> 00:17:43.120
so that everyone could go and download and play with it themselves.

s193
00:17:43.120 --> 00:17:50.720
In the last couple of weeks um there's been a lot of excitement inside Cloudflare and this has become a more serious project.

s194
00:17:50.720 --> 00:17:59.520
And so last Thursday Dne our CTO pulled me uh into a room and said Kenton I don't think you should yeet this.

s195
00:17:59.520 --> 00:18:01.840
I don't think this is yeet material.

s196
00:18:01.840 --> 00:18:08.160
I think we need a uh we need to be more careful and disciplined and intentional about how we release this.

s197
00:18:08.160 --> 00:18:09.919
So, let's hold it off for a few weeks.

s198
00:18:09.919 --> 00:18:17.360
And I was pretty upset about that because I promised in the abstract that I was going to open source it, but sorry.

s199
00:18:17.360 --> 00:18:18.880
Uh that's not happening today.

s200
00:18:18.880 --> 00:18:21.440
It will happen soon though.

s201
00:18:21.440 --> 00:18:31.360
Um, and I wish the silly counter worked because GPT makes some silly counters, but um oh well, it's not a big deal.

s202
00:18:31.360 --> 00:18:34.822
And that's uh that's all I got.

s203
00:18:34.822 --> 00:18:36.822
[applause]

s204
00:18:51.852 --> 00:18:53.852
[music]
