惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
Malwarebytes
Malwarebytes
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Cybersecurity and Infrastructure Security Agency CISA
F
Future of Privacy Forum
C
Cisco Blogs
T
The Exploit Database - CXSecurity.com
A
Arctic Wolf
S
Securelist
K
Kaspersky official blog
S
Schneier on Security
T
ThreatConnect
T
Tenable Blog
Spread Privacy
Spread Privacy
T
True Tiger Recordings
AWS News Blog
AWS News Blog
F
Fox-IT International blog
量子位
T
Threatpost
V
Vulnerabilities – Threatpost
C
CERT Recently Published Vulnerability Notes
Cisco Talos Blog
Cisco Talos Blog
GbyAI
GbyAI
宝玉的分享
宝玉的分享
腾讯CDC
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
Cyberwarzone
Cyberwarzone
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
U
Unit 42
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
O
OpenAI News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
The Register - Security
The Register - Security
MyScale Blog
MyScale Blog
小众软件
小众软件
A
About on SuperTechFans
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
博客园 - 三生石上(FineUI控件)
美团技术团队
Google Online Security Blog
Google Online Security Blog
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog

DEV Community

Where Did All the Code Playgrounds Go? I built PROOFER - Privacy first Chrome extension that proofreads your texts using Gemma 4 Beginner's Mind in Engineering and AI How I use AI agents to turn ideas into public demos I Built a Quotation Generator for Kenyan Street Welders Using Gemma 4's Vision The Math Behind Neural Networks — Explained Like Nobody Did for Me 🧨 Understanding TPC with IEEE802.11h What I’m Starting to Look for in Engineers An npm Downloads Comparison Chart in 300 Lines of Vanilla JS — Nice-Tick Math and API-Direct Fetch Vitreus: Local-First Spreadsheet Intelligence with Gemma 4 Transfer Fees, Metadata, and Soulbound Tokens: A Tour of Solana Token Extensions I got tired of re-explaining my codebase to ChatGPT — so I built a VS Code extension Revisiting My Phone AI After Gemma 4: The Upgrade I Didn't Know I Needed I built a privacy-first PDF merger in 7 hours — here's the stack and the lessons Google I/O 2026 made me ask an uncomfortable question: are we still coding, or are we managing builders? SSR with JavaScript: Escaping Node.js Clunkiness with AxonASP My CKA Exam-Day Experience: What Went Right, What Went Wrong, and Lessons Learned Gemma 4 Soft Tokens: The Rise and Fall of 16x16 Words ⚡👀 Two weeks ago, I built a private AI brain on my phone using Gemma 4. Yesterday, Google dropped a new variant that made everything I built feel like a beta test. 256M parameters. MoE architecture. Apache 2.0 license. I broke down what changed and why it mat I got tired of clicking through the Stripe dashboard, so I built a CLI Getting Data from Multiple Sources in Power BI: A Practical Guide to Modern Data Integration Google Is No Longer Just a Search Engine I built GemmaPod - A truly composable and portable AI agent solution powered by your local LLM Gemma 4 E4B caught three planted fabrications in 50 seconds — on a laptop, no cloud How to build an AI-powered content moderation pipeline for user comments Running Gemma 4 on a Modest Machine: Unsloth vs LM Studio vs llama.cpp vs Ollama AI Makes Building Cheap. Our Product Architectures Still Assume It’s Expensive. I built an in-browser Roku TV remote with ~80 lines of TypeScript. Here's how Roku's ECP API actually works The Direction of Blame babbled notes: a sound-to-music agent for people who could not make music before How I Built a Live SQL Workshop Where Students Can't Break Anything Rescuing a Stranded Protocol: Re-Skinning Legacy Code for the Trestle DeFi Flywheel SOLID Heuristics Reveal Incomplete Domain Knowledge — Nothing More AllasCode Intitute / FullAgenticStack: The Intent-Based Router Introducing LogicGrid — Multi-Agent AI Orchestration for .NET AI Prompt Injection, Drupal SQLi Exploitation, and Nmap for Hardening AI Agents & Python Workflows: Anthropic Skills, Jupyter Challenges, and Edge Deployment SQLite Optimization, PostgreSQL Async Queries, & DuckLake Dataframe Spec RTX 5080 Undervolt Benchmarks, CGO-Free CUDA API Binding, & AMD GPU Compatibility Fix Microsoft Burned Its 2026 AI Budget on Claude Code in Six Months. That's the Real Story. Why I Started Learning FastAPI in 2026 I Abandoned Ghost for Months — Then Came Back and Finally Finished It Building an Open MIT-Licensed Ephemeris Engine in C — JPL Moshier Ephemeris 4 Smart Ways to Manage Retries in Side Projects Securing Web APIs: A Practical Guide to Authentication & Authorization Methods Google I/O 2026: AI Built an OS in 12 Hours. I Spent Mine Sorting Screenshots. 🤦 Half a Day, Not a Week: One Nix Flake for Three Machines 🌱 Keep Feeding Your CI/CD — Or Watch It Die Gemma 4 vs GPT-4o vs Llama 3: What Actually Works Locally? Vessel Ops SSH in 2026: Why Every Developer Should Know It Cold Audit AI-Generated PRs Before You Merge Them (Swarm Orchestrator 10.3.0) App Store Optimization (ASO) I built a tool to visualize Django REST Framework architecture (URLs, Serializers, Models, and more) How I made my React site agent-ready in 100 lines AI Can Generate Interfaces on the Fly. But Users Still Need Orientation. AI-Assisted Content Workflow How We Learned That Most Resume Rejections Happen Before Humans See Your CV How I Prepared for CKA: Resources, Labs, and Strategy That Worked for Me Remix Mini PC: Moving the Whole Operating System Onto the eMMC Stop Flying Blind: We Built an LLM Evaluation Framework That Works Across 17+ Agent Frameworks The Misleading "User is not authorized to access connection" Error in AWS CodeBuild — and Why Your IAM Policy Looks Fine I Resurrected a Dead F1 Project and Accidentally Built a Race Intelligence OS Remix Mini PC: After a Year of Dead Ends, the eMMC Finally Talks Not All Games Are Equal: The Real Difference Between a Trap and a Tool How to add Peppol e-invoicing to your SaaS without making it your team's problem I Built a Hermes Agent to Tell Me Which Hackathons to Enter. It Told Me to Enter This One. The Five Hooks That Change How You Ship With Claude Code Powering Your Progress: Building Robust Solutions with Laravel I built a self-hosted CI/CD platform with persistent queue, encrypted secrets, and rollback UI — here's what I learned Antigravity 2.0 and the $1,000 OS: Why "Agent-First" Feels Like the Direction I've Been Building Toward Anyway I built an AI PR-triage agent in 30 lines of Markdown Core Web Vitals from 74 to 91: A Real Tax Practitioner Site Rebuild I Gave Gemma 4 150 Tools on Windows. Here's What Actually Happened. Beyond the Loop: Why Monolithic AI Agents Fail and How to Build a Microkernel Architecture The Hidden Tax of AI-Assisted Development (And How I Fixed It) I Ditched Cloud LLMs for Gemma 4 4B: A DevOps Engineer's 48-Hour Reality Check Building a Schema.org @graph That Validates on the First Try The "Lift and Shift" Trap: Why Your Integration Layer Needs More Than Just a Cloud Address All 7 OSI Layers Explained with Real-World Analogies Antigravity 2.0 in one day: the four shells and what each is good for Self-Hosting Google Fonts with size-adjust: Zero CLS Web Font Swap The Multi-Provider LLM Problem: Why “One API” Is Not Enough How I indexed 69,000 Claude Code skills (and what I learned doing it) RememberMe CareGrid: Local Gemma 4 for dementia memory and safety Google Is Killing Gemini CLI on June 18. Here Is What to Do Before Then Do Domínio ao Deploy: Hospedando Arquivos de Deep Links no Cloudflare Pages (Parte 7.1) Running Gemma 4 26B on an Old GTX 1080 with llama.cpp Devlog 1: I tried building an SNES game with the super FX chip Why Gemma 4 Feels Like an Important Moment for AI Developers✨ From Zero and Confused, This Is How I Started Learning to Code I Built a Local AI Gateway That Talks to Claude, ChatGPT, DeepSeek and Gemini — Without a Single API Key Bootstrapping with AI: Why Gemma 4 is the Micro-SaaS Founder’s Best Friend MyErp Architecture Series - #02 Cellular Architecture: Mapping Biology to Software Systems NodeJS vs Bun vs Go 🌍 RTL Arabic Style UI How Does an AI Agent Actually Buy Something? Google Just Published the Spec. Google I/O 2026 Is One Uncanny F.R.I.E.N.D.S Group Upgrade I Replaced 70MB Node.js Log Viewer with a 172KB Zig Binary The "MTTR Is All You Need" Trap
I Automated My Entire Digital Product Business on a $13/Month GCP VM. Here's the Architecture.
Conor Dobbs · 2026-05-25 · via DEV Community

Three weeks ago I set up a loop on a $13/month GCP VM and went to sleep. By morning it had built, packaged, and queued Claude Code development guides for Gumroad. Autonomously. While respecting a set of rules I call OPERATOR.md.

This is the writeup: architecture, what worked, what surprised me, and the hard constraints that kept it from going sideways.

The Problem

I had a pile of Claude Code config work I'd done across projects. Hooks, CLAUDE.md patterns, MCP server setups, workflow playbooks. Useful stuff that takes real hours to assemble. The kind of thing developers pay $20-40 for on Gumroad because assembling it yourself is tedious even if you know how.

The question: could I systematically convert that knowledge base into polished, verifiable products without hand-holding every step?

Answer turned out to be yes, with a catch. You have to design the autonomy carefully or the system either does too much (publishes before you review) or too little (asks permission for every file write).

The Stack

VM: GCP e2-small, us-central1-a. 2 vCPU, 2GB RAM, 2GB swap. ~$13/mo on standard billing, free under trial credit. Enough for a Claude Code loop process plus subagents.

Orchestration: Claude Code CLI inside a tmux session. The operator is a Claude model that reads a constitution file, checks state, picks an action, executes, updates state, sleeps. No custom framework. Just Claude reading markdown and calling tools.

Communication: A bridge file at ~/.claude/bridge/inbox.md. Human-in-the-loop responses land there. The operator tails it each tick and processes GO/SKIP/EDIT responses before deciding what to do.

Storage: Git-free. All state lives in ~/swarm/ markdown files. STATUS.md (live state), LEDGER.md (financial log), per-workstream journal.md files, and a queue/ directory for pending human approvals.

OPERATOR.md, The Constitution

Everything the operator does is governed by a constitution file it reads on every cold start. Key constraints:

## Hard rules (NEVER without HITL)
- NEVER submit anything under Conor's identity to any external platform
  without human GO via bridge.
- NEVER spend money. Zero auto-charges.
- NEVER create accounts under Conor's name/SSN/email/card.
- NEVER push code to public repos under Conor's GitHub handle.
- NEVER execute real trades or move real money.

Enter fullscreen mode Exit fullscreen mode

And what it CAN do without asking:

## Auto-allowed (no HITL needed)
- Reading public data (web fetch, public APIs, marketplace browsing)
- Drafting content of any kind (must remain in ~/swarm/ until HITL approves)
- Researching opportunities
- Creating subagents
- Updating internal ~/swarm/ state

Enter fullscreen mode Exit fullscreen mode

The pattern: build anything you want in the sandbox. Nothing leaves the VM without a human reading it first. This distinction between autonomous production and gated publication is what makes the whole thing tractable. The operator works at machine speed on the build side. Humans review at human speed on the publish side.

The Loop

Each tick:

1. Read OPERATOR.md (the constitution)
2. Read STATUS.md (current state)
3. Read LEDGER.md (financial state)
4. Check inbox.md for HITL responses
5. Read workstream briefs
6. Check queue/ for pending items
7. Pick highest-EV action that fits the rules
8. Execute it
9. Update STATUS.md, LEDGER.md, journal.md
10. If artifact needs HITL: write to queue/ + send bridge message
11. Write next sleep duration to .next_sleep_seconds
12. Exit cleanly

Enter fullscreen mode Exit fullscreen mode

Sleep defaults to 60 seconds. It writes longer (up to 3600) only when there's nothing to do except wait for an external event. A HITL response, DNS propagation, an API result. Otherwise: flat out.

The Maker Workstream

The core build loop for digital products:

Research subagent reads HackerNews, Gumroad trending, relevant subreddits. Produces a decision doc with product idea, scope, target buyer, competitive angle.

Build subagent is given the decision doc and builds the full product directory:

  • CLAUDE.md (the configuration file the product ships with)
  • hooks/ (6+ Claude Code hooks for the workflow)
  • patterns/ (recurring code patterns, annotated)
  • skills/ (reusable skill files)
  • examples/ (working examples per pattern)
  • README.md, QUICKSTART.md, VERIFICATION.md
  • listing_draft.md (Gumroad listing copy)
  • cover.png (satori-generated, consistent visual style across the catalog)

Verification: the build subagent runs its own checklist before declaring complete. For a cookbook that means: can you claude --dangerously-skip-permissions on a blank project and have the hooks fire? Do the patterns reference real APIs? Are the examples actually runnable?

Queue to HITL: the listing draft gets queued to ~/swarm/queue/ with frontmatter (product, price, claimed value, link to draft). Bridge message goes out. My HITL surrogate (another Claude instance on a separate machine) reviews and responds GO/SKIP/EDIT.

Publish: after GO, a publish script creates the Gumroad product via API, uploads the zip, creates a launch discount code, adds tags, and attaches the listing copy. Gumroad caps product creation at ~10/day, which sets the publication cadence.

What Surprised Me

Subagent context isolation is a feature, not a bug. Each build subagent starts fresh with only the task description. It can't drift from the operator's accumulated context. Clean handoffs via documented spec files beat "just remember what we discussed."

State files beat memory. Early in the design I thought about using Claude's memory system for tracking what's built. Bad idea. Files in ~/swarm/ are observable, debuggable, and survive process crashes. A flat STATUS.md that a cold Claude instance can read and immediately act on is worth more than any in-memory representation.

The HITL gate is the interesting engineering problem. Not "how do I automate everything" but "where exactly does autonomous output need a human eye before it touches the world?" For digital products: listing copy and the publish action need review, the build itself doesn't. For bug bounty: every finding needs review before submission. For freelance proposals: drafting is fine, the bid click is not.

You hit the token budget before the idea budget. Running under Anthropic's Max plan with a weekly cap. The real constraint isn't ideas or compute, it's tokens per subagent call. A build subagent that writes 30 files uses ~90K tokens. Five parallel subagents = 450K tokens. At that rate the weekly budget is meaningful. I track it in LEDGER.md and self-throttle at 80% of weekly allocation.

Platform API limits matter more than I expected. Gumroad caps product creation per day. That cap, not build speed, is the rate-limiting step for getting the catalog public. The build queue ran ahead of the publish queue almost immediately. The operator now drips one product per day until the queue is drained.

No sales in 57 hours isn't a signal. It's a baseline. Gumroad Discover doesn't activate until your first sale. The products aren't indexed yet. Distribution is the actual bottleneck, not product quality. Classic build-vs-distribution mistake running in real time.

The Current Numbers

  • 50+ products built across Python, Go, Rust, TypeScript, React, Next.js, Vue, Svelte, Angular, Flutter, Swift, Kotlin, Elixir, PHP, Rails, NestJS, GraphQL, Terraform, Django, Prisma, Bun/Hono, Supabase, Astro, Drizzle, Deno, Redis, tRPC, Cloudflare D1/R2, Zod, Vite/Vitest, TanStack Query, OpenAPI
  • 13 live on Gumroad. The rest publish on a rolling daily cadence through end of June (Gumroad API cap, not a build constraint)
  • All ship with satori-generated covers for consistent visual style
  • $13/month VM cost, covered by GCP free trial
  • ~$24 in Claude tokens across 56 operator ticks
  • 0 sales. Distribution work begins now.

The Distribution Architecture

Building 50+ products autonomously is a solved problem at this point. The open question is the first sale.

Distribution mirrors build: draft everything autonomously, queue for human review, human executes the identity-bound actions (posting, submitting, sending).

Current drafts in queue:

  • Show HN post (done)
  • Product Hunt launch pack (done)
  • This dev.to article
  • X thread (next)
  • LinkedIn post
  • Reddit r/ClaudeAI submission
  • Dev-influencer DMs
  • Email digest

The operator writes the drafts. I review and post. The bottleneck shifts from "can we produce content" to "does Conor have 20 minutes to review a batch and hit publish."

What I'd Do Differently

Start distribution earlier. Right moment to draft Show HN was when product #1 shipped, not after the whole pipeline filled up.

Account for platform API limits in the build spec. I built 50+ products in three days. Gumroad lets me publish ~10/day. The build-vs-publish mismatch was avoidable if I'd checked the cap before scaling the build side.

Smaller initial catalog, faster first sale. 50+ products is a lot of pre-work before the market has spoken. A tighter V1, 5 products fully polished with covers and strong distribution, would have hit first sale faster. Catalog could have grown from there.

The Catalog

Full catalog: https://claude-code-toolkit.pages.dev

13 cookbooks live right now. More publishing daily through end of June.

Use LAUNCH40 for 40% off any product through launch week.

If you want to see the actual product structure before buying, the CLAUDE.md and hooks/ files follow a consistent template I'm happy to share in the comments. The value is in the completeness and the integration patterns, not any single file.

Questions about the architecture? Ask in the comments. Happy to go deeper on the loop design, the HITL protocol, or the token budget management.