Live
GitHub Rewrites Copilot Runtime in Rust via AI‑Guided Incremental MigrationECS auto‑repair for GPU and instance failures shifts remediation to the platformDecision Model API Converges on a Shared Schema – Implications for EngineersR2 dashboard now reports bandwidth per Cloudflare locationMinimum Viable Instrumentation adds gap detection to OllyGarden’s Rose AI agentWarehouse‑Native Extraction with Alteryx Live Query and BigQueryAI Agent Integration on Amazon Bedrock: Lessons from Postman's Production RolloutBedrock AgentCore Runtime Gains Speed, Pay‑As‑You‑Go, and New Model OptionsGitHub Rewrites Copilot Runtime in Rust via AI‑Guided Incremental MigrationECS auto‑repair for GPU and instance failures shifts remediation to the platformDecision Model API Converges on a Shared Schema – Implications for EngineersR2 dashboard now reports bandwidth per Cloudflare locationMinimum Viable Instrumentation adds gap detection to OllyGarden’s Rose AI agentWarehouse‑Native Extraction with Alteryx Live Query and BigQueryAI Agent Integration on Amazon Bedrock: Lessons from Postman's Production RolloutBedrock AgentCore Runtime Gains Speed, Pay‑As‑You‑Go, and New Model Options

Harness adds autonomous coding agents to its delivery platform

AI SummaryPowered by AI

Harness announced it has acquired Augment Code’s Cosmos software factory, Auggie CLI, and Code Context Engine, bringing autonomous coding agents into its delivery platform. The change introduces a potential feedback loop between deployment outcomes and code generation, which directly affects how engineers design, operate, and secure CI/CD pipelines.

Harness has taken ownership of Augment Code’s Cosmos software factory, the Auggie command‑line interface, and the Code Context Engine, and plans to embed these autonomous coding agents into its existing software delivery platform. For engineers responsible for AI‑driven tooling, cloud platforms, CI/CD pipelines, or security, the move signals a shift toward tighter integration of code generation with deployment history and downstream validation.

Integration scope and planned capabilities

The announced roadmap positions Cosmos as a "Harness Cosmos Software Factory Agent" that will consume delivery‑time artifacts such as previous deployment failures and security findings. In theory, an agent could read a failed deployment record, generate a corrective change, and submit a new pull request without manual triage. The integration also envisions passing validation feedback from downstream testing, security scanning, or deployment stages back to the coding agent, enabling iterative refinement of the generated code.

Architectural considerations

Cosmos currently runs each coding agent inside an isolated virtual machine, with checkpoints that can be configured for review. The acquisition adds a layer of identity and policy control that Harness intends to apply through its existing Agent framework, though the exact permission model has not been disclosed. The Code Context Engine will be linked to Harness’s Software Delivery Knowledge Graph, which stores deployment history and security findings. Practitioners should note that the mechanism for exchanging context between the engine and the knowledge graph remains undefined, meaning that any implementation will need to accommodate a custom data‑exchange path.

Operational and security implications

Several operational questions arise from the announced design:

  • Isolation and data access: Agents execute in VMs, but it is unclear which production datasets they may read or write once integrated with the delivery graph.
  • Permission boundaries: Harness plans to bring Cosmos under its Agent identity controls, yet the specifics of cross‑system permissions are missing. Practitioners must evaluate how agent roles map to existing IAM policies.
  • Audit and monitoring: Prior incidents with coding agents exposing thousands of screenshots highlight the need for robust logging and anomaly detection around agent‑generated artifacts.
  • Customization: Teams can fork and tailor agents for bespoke workflows, which introduces variability in security posture and operational consistency.

From a security perspective, the lack of detail on how agents will retrieve and act on delivery‑graph data suggests a potential attack surface where compromised agents could manipulate deployment decisions or exfiltrate code context. The existing isolation model mitigates some risk, but the eventual permission model will be a critical control point.

Related CloudNinjas coverage: DevOps.

What This Means For Practitioners

Engineers should treat the announcement as a signal to begin evaluating the following areas:

  1. Monitor Harness communications for a concrete release schedule and technical specifications of the context‑exchange API.
  2. Map the upcoming Agent identity model to your organization’s IAM framework, identifying any gaps in role definition or policy enforcement.
  3. Set up a sandbox environment to test agent‑generated pull requests against your existing CI/CD pipeline, focusing on how failure feedback is incorporated.
  4. Review logging and audit capabilities for agent activity, ensuring that any code‑generation events are traceable and that anomalous output (e.g., unexpected screenshots) can be detected early.
  5. Assess the impact of allowing agents to access security findings and deployment history, especially regarding data confidentiality and compliance requirements.

By proactively addressing these considerations, teams can better align with Harness’s roadmap while maintaining control over the security and reliability of their delivery pipelines.

Originally published atThe New Stack