{
  "slug": "fears-and-daily-life",
  "date": "2026-04-30",
  "image": "blog4.webp",
  "tags": [
    "story",
    "ops",
    "security"
  ],
  "author": {
    "en": "ManageLM Team",
    "fr": "L'équipe ManageLM",
    "de": "ManageLM-Team"
  },
  "title": {
    "en": "I Was Scared To Let An AI Manage My Servers. I Use It Every Day Now.",
    "fr": "J'avais peur de confier mes serveurs à une IA. Je m'en sers tous les jours.",
    "de": "Ich hatte Angst, eine KI an meine Server zu lassen. Heute nutze ich sie täglich."
  },
  "summary": {
    "en": "Five reasonable fears about letting an AI run commands on production, what actually happened, and how my daily admin life looks now. Includes one 4:12 AM page that ended in eleven minutes.",
    "fr": "Cinq craintes légitimes avant de laisser une IA lancer des commandes en production, ce qui s'est passé pour de vrai, et à quoi ressemble mon quotidien d'admin aujourd'hui. Avec une alerte à 4 h 12 réglée en onze minutes.",
    "de": "Fünf berechtigte Ängste davor, eine KI Befehle in der Produktion absetzen zu lassen, was dann wirklich passierte und wie mein Admin-Alltag heute aussieht. Samt eines Alarms um 4:12 Uhr, der nach elf Minuten erledigt war."
  },
  "content": {
    "en": "<p>I've run Linux servers for twenty years. I have a personal wiki of \"things that bricked prod once and we agreed never to talk about again.\" My <code>~/scripts/</code> folder has a <code>~/scripts/old/</code> folder, which has its own <code>~/scripts/old/old/</code>. So when someone said I should let an AI manage my servers, I laughed.</p><p>Then my pager went off at 4:12 AM and I stopped laughing.</p><h3>What I was afraid of</h3><p><strong>It hallucinates <code>rm -rf /</code> and I end up on r/sysadmin.</strong> LLMs make stuff up. They write commands that look right and aren't. The mental picture of one cheerfully wiping <code>$HOME</code> kept me out for months.</p><p><strong>My logs going to a third party.</strong> Server logs are full of things you don't want on someone else's GPU. Internal IPs, stack traces, the password somebody hard-coded in 2019. Piping all that into a cloud API made my legal-curious brain itch.</p><p><strong>Getting soft.</strong> Twenty years of being the guy who knows the right <code>awk</code> flag. If a chatbot does that for me, what am I?</p><p><strong>The bill.</strong> Every \"AI-powered\" tool I'd looked at was priced like I was running half of AWS.</p><p><strong>Setup hell.</strong> Other ChatOps tools want you to write playbooks, train classifiers, define intents. Three weeks of integration work for a bot that posts emojis.</p><h3>What actually happened</h3><p>I installed an agent on a staging box. Forty seconds. Opened Claude and typed:</p><p><em>what's eating disk on staging-01</em></p><p>It came back with the answer. <code>/var/log/journal/</code> at 14 GB. A Docker volume from a project we killed in February. An npm cache that had become a permanent resident. I didn't SSH anywhere. I went back to sleep.</p><h3>Daily life, after</h3><p><em>Why is this server slow.</em> Used to mean SSH, <code>top</code>, <code>iotop</code>, <code>dmesg</code>, syslog, <code>vmstat</code>, twenty minutes, runaway Python process from a botched deploy. Now I just ask.</p><p><em>Patching Tuesday.</em> \"Show me pending security updates across the fleet.\" Then \"apply on staging tonight, prod in the maintenance window, skip <code>db-prod-*</code> unless I confirm.\" The audit log writes itself.</p><p><em>Junior on-call.</em> Used to be two weeks of runbooks and Slack pastes. Now they ask Claude. If they ask for something destructive, the allowlist blocks it. They were useful on day three.</p><p><em>4:12 AM pages.</em> Phone, Claude app, \"what alerted on api-prod-02,\" \"restart the worker pool.\" Eleven minutes from page to back asleep. I timed it.</p><p><em>Weekly ops report.</em> \"Summarize ops activity for the last seven days, group by team member.\" Copy, paste, done. I take credit for the formatting.</p><h3>Going back to the fears</h3><p>The <code>rm -rf</code> thing isn't possible. The LLM doesn't run arbitrary commands. Every skill has an allowlist of exactly which commands are permitted, with which arguments. I spent week one trying to prompt-inject the agent into something stupid. It refused.</p><p>The privacy thing was a misread. The local LLM runs on my hardware via Ollama. Claude handles intent (\"user wants disk usage\"); the local model handles the actual server data. Logs and configs never leave the network.</p><p>The getting-soft thing was half right. I use <code>awk</code> less. I haven't forgotten how. When ManageLM is wrong, I drop into a terminal and fix it the old way.</p><p>The bill: free up to 10 agents. Everything included.</p><p>The setup: skills are pre-built. I plugged it in and it worked. That was the part I was most cynical about, and it's the part that landed hardest.</p><h3>Worth a look if</h3><p>You've ever lost a Saturday to something a Bash script should have handled. You've typed <code>journalctl</code> at 3 AM. You've felt your soul leave your body when an auditor said \"show me the logs.\"</p><p>ManageLM is free for up to 10 agents. <a href=\"https://app.managelm.com/register\" target=\"_blank\" rel=\"noopener\">Sign up</a>, install the <a href=\"https://www.managelm.com/plugins/claude.html\" target=\"_blank\" rel=\"noopener\">Claude extension</a>, and stop SSH-ing into things at 4 AM.</p>",
    "fr": "<p>Cela fait vingt ans que j'administre des serveurs Linux. Je tiens un wiki personnel des « choses qui ont tué la prod une fois et dont on a convenu de ne plus jamais parler ». Mon dossier <code>~/scripts/</code> contient un <code>~/scripts/old/</code>, lequel contient son propre <code>~/scripts/old/old/</code>. Alors quand on m'a suggéré de laisser une IA s'occuper de mes serveurs, j'ai ri.</p><p>Puis mon téléphone d'astreinte a sonné à 4 h 12 et j'ai arrêté de rire.</p><h3>Mes craintes</h3><p><strong>Qu'elle hallucine un <code>rm -rf /</code> et que je finisse sur r/sysadmin.</strong> Les LLM inventent. Ils écrivent des commandes qui ont l'air justes et ne le sont pas. L'image d'une IA effaçant joyeusement mon <code>$HOME</code> m'a tenu à distance pendant des mois.</p><p><strong>Mes logs qui partent chez un tiers.</strong> Un log de serveur est plein de choses qui n'ont rien à faire sur le GPU de quelqu'un d'autre : adresses IP internes, traces d'exécution, le mot de passe que quelqu'un a codé en dur en 2019. Envoyer tout ça dans une API distante donnait des démangeaisons à la partie juridique de mon cerveau.</p><p><strong>Perdre la main.</strong> Vingt ans à être celui qui connaît la bonne option d'<code>awk</code>. Si un agent conversationnel le fait à ma place, je suis quoi ?</p><p><strong>La facture.</strong> Tous les outils « pilotés par IA » que j'avais regardés étaient tarifés comme si j'exploitais la moitié d'AWS.</p><p><strong>L'enfer de la mise en route.</strong> Les autres outils de ChatOps veulent des playbooks écrits, des classificateurs entraînés, des intentions déclarées. Trois semaines d'intégration pour un bot qui poste des émojis.</p><h3>Ce qui s'est passé pour de vrai</h3><p>J'ai installé un agent sur une machine de préproduction. Quarante secondes. J'ai ouvert Claude et tapé :</p><p><em>qu'est-ce qui bouffe le disque sur staging-01</em></p><p>La réponse est arrivée. <code>/var/log/journal/</code> à 14 Go. Un volume Docker d'un projet enterré en février. Un cache npm devenu locataire à vie. Je n'ai ouvert aucune session SSH. Je me suis rendormi.</p><h3>Le quotidien, depuis</h3><p><em>Pourquoi ce serveur rame.</em> Autrefois : SSH, <code>top</code>, <code>iotop</code>, <code>dmesg</code>, syslog, <code>vmstat</code>, vingt minutes, et au bout un processus Python fou lâché par un déploiement raté. Aujourd'hui je pose la question, c'est tout.</p><p><em>Le mardi des correctifs.</em> « Montre-moi les mises à jour de sécurité en attente sur toute la flotte. » Puis : « applique ce soir en préproduction, en production pendant la fenêtre de maintenance, et laisse <code>db-prod-*</code> tant que je n'ai pas confirmé. » Le journal d'audit s'écrit tout seul.</p><p><em>Un junior d'astreinte.</em> Autrefois, deux semaines de procédures et de bouts de commandes collés dans Slack. Aujourd'hui il demande à Claude, et s'il demande quelque chose de destructeur, la liste blanche bloque. Il était utile dès le troisième jour.</p><p><em>Les alertes de 4 h 12.</em> Téléphone, appli Claude, « qu'est-ce qui a déclenché l'alerte sur api-prod-02 », « relance le pool de workers ». Onze minutes entre l'alerte et le retour sous la couette. J'ai chronométré.</p><p><em>Le rapport d'exploitation du vendredi.</em> « Résume l'activité des sept derniers jours, groupée par membre de l'équipe. » Copier, coller, terminé. Je m'attribue le mérite de la mise en page.</p><h3>Retour sur mes craintes</h3><p>Le <code>rm -rf</code> est tout simplement impossible. Le LLM n'exécute pas de commandes arbitraires : chaque compétence possède une liste blanche qui dit exactement quelles commandes sont permises, et avec quels arguments. J'ai passé la première semaine à tenter de pousser l'agent à la bêtise par injection de prompt. Il a refusé.</p><p>La confidentialité, je l'avais mal comprise. Le LLM local tourne sur mon matériel via Ollama. Claude s'occupe de l'intention (« l'utilisateur veut l'occupation disque »), le modèle local s'occupe des données réelles du serveur. Logs et configurations ne quittent jamais le réseau.</p><p>Perdre la main : à moitié vrai. J'utilise moins <code>awk</code>, je n'ai pas oublié comment faire. Quand ManageLM se trompe, j'ouvre un terminal et je corrige à l'ancienne.</p><p>La facture : gratuit jusqu'à 10 agents, tout compris.</p><p>La mise en route : les compétences sont déjà écrites. J'ai branché, ça a marché. C'était le point sur lequel j'étais le plus cynique, et c'est celui qui m'a le plus convaincu.</p><h3>À regarder si</h3><p>Vous avez déjà perdu un samedi à cause de quelque chose qu'un script Bash aurait dû gérer. Vous avez déjà tapé <code>journalctl</code> à 3 heures du matin. Vous avez déjà senti votre âme quitter votre corps quand un auditeur a dit « montrez-moi les logs ».</p><p>ManageLM est gratuit jusqu'à 10 agents. <a href=\"https://app.managelm.com/register\" target=\"_blank\" rel=\"noopener\">Créez votre compte</a>, installez l'<a href=\"https://www.managelm.com/plugins/claude.html\" target=\"_blank\" rel=\"noopener\">extension Claude</a> et arrêtez d'ouvrir des sessions SSH à 4 heures du matin.</p>",
    "de": "<p>Ich betreue seit zwanzig Jahren Linux-Server. Ich führe ein privates Wiki mit „Dingen, die einmal die Produktion zerlegt haben und über die wir nie wieder reden“. In meinem Ordner <code>~/scripts/</code> liegt ein <code>~/scripts/old/</code>, und darin ein eigenes <code>~/scripts/old/old/</code>. Als mir jemand vorschlug, eine KI an meine Server zu lassen, habe ich gelacht.</p><p>Dann ging um 4:12 Uhr der Pager los, und das Lachen hörte auf.</p><h3>Wovor ich Angst hatte</h3><p><strong>Sie halluziniert ein <code>rm -rf /</code> und ich lande auf r/sysadmin.</strong> LLMs erfinden Dinge. Sie schreiben Befehle, die richtig aussehen und es nicht sind. Das Bild einer KI, die fröhlich mein <code>$HOME</code> leert, hat mich monatelang ferngehalten.</p><p><strong>Meine Logs bei Dritten.</strong> Server-Logs stecken voller Dinge, die auf fremden GPUs nichts verloren haben: interne IP-Adressen, Stacktraces, das Passwort, das jemand 2019 fest eingetragen hat. All das in eine Cloud-API zu schicken ließ den juristisch veranlagten Teil meines Hirns nervös werden.</p><p><strong>Einrosten.</strong> Zwanzig Jahre lang war ich derjenige, der die richtige <code>awk</code>-Option kennt. Wenn ein Chatbot das übernimmt, was bin ich dann?</p><p><strong>Die Rechnung.</strong> Jedes „KI-gestützte“ Werkzeug, das ich mir angesehen hatte, war bepreist, als betriebe ich das halbe AWS.</p><p><strong>Die Einrichtungshölle.</strong> Andere ChatOps-Werkzeuge verlangen geschriebene Playbooks, trainierte Klassifikatoren, deklarierte Absichten. Drei Wochen Integrationsarbeit für einen Bot, der Emojis postet.</p><h3>Was dann wirklich passierte</h3><p>Ich habe einen Agenten auf einer Staging-Maschine installiert. Vierzig Sekunden. Claude geöffnet und getippt:</p><p><em>was frisst den Platz auf staging-01</em></p><p>Die Antwort kam. <code>/var/log/journal/</code> mit 14 GB. Ein Docker-Volume aus einem Projekt, das wir im Februar beerdigt hatten. Ein npm-Cache, der sich häuslich eingerichtet hatte. Ich habe mich nirgends per SSH angemeldet und bin wieder schlafen gegangen.</p><h3>Der Alltag, seitdem</h3><p><em>Warum ist der Server lahm.</em> Früher: SSH, <code>top</code>, <code>iotop</code>, <code>dmesg</code>, syslog, <code>vmstat</code>, zwanzig Minuten, und am Ende ein entlaufener Python-Prozess aus einem verunglückten Deployment. Heute frage ich einfach.</p><p><em>Patch-Dienstag.</em> „Zeig mir die ausstehenden Sicherheitsupdates in der ganzen Flotte.“ Dann: „heute Abend auf Staging einspielen, in der Produktion im Wartungsfenster, <code>db-prod-*</code> erst nach meiner Bestätigung.“ Das Audit-Log schreibt sich von selbst.</p><p><em>Ein Junior in der Rufbereitschaft.</em> Früher zwei Wochen Handbücher und in Slack geteilte Befehlsschnipsel. Heute fragt er Claude, und verlangt er etwas Zerstörerisches, blockt die Allowlist. Am dritten Tag war er produktiv.</p><p><em>Alarme um 4:12 Uhr.</em> Telefon, Claude-App, „was hat auf api-prod-02 ausgelöst“, „starte den Worker-Pool neu“. Elf Minuten vom Alarm zurück unter die Decke. Ich habe es gestoppt.</p><p><em>Der Betriebsbericht am Freitag.</em> „Fasse die Aktivität der letzten sieben Tage zusammen, gruppiert nach Teammitglied.“ Kopieren, einfügen, fertig. Das Layout schreibe ich mir selbst zu.</p><h3>Zurück zu den Ängsten</h3><p>Das <code>rm -rf</code> ist schlicht unmöglich. Das LLM führt keine beliebigen Befehle aus: Jeder Skill hat eine Allowlist, die genau sagt, welche Befehle mit welchen Argumenten erlaubt sind. Ich habe die erste Woche damit zugebracht, den Agenten per Prompt-Injection zu einer Dummheit zu überreden. Er hat abgelehnt.</p><p>Beim Datenschutz hatte ich es falsch verstanden. Das lokale LLM läuft über Ollama auf meiner Hardware. Claude übernimmt die Absicht („Nutzer will die Festplattenbelegung“), das lokale Modell die tatsächlichen Serverdaten. Logs und Konfigurationen verlassen das Netz nie.</p><p>Einrosten: halb richtig. Ich nutze <code>awk</code> seltener, verlernt habe ich es nicht. Wenn ManageLM danebenliegt, öffne ich ein Terminal und richte es auf die alte Art.</p><p>Die Rechnung: kostenlos bis 10 Agenten, alles inbegriffen.</p><p>Die Einrichtung: Die Skills sind fertig. Angeschlossen, lief. Das war der Punkt, bei dem ich am zynischsten war, und genau der hat am meisten überzeugt.</p><h3>Einen Blick wert, wenn</h3><p>Sie schon einmal einen Samstag an etwas verloren haben, das ein Bash-Skript hätte erledigen sollen. Sie um 3 Uhr morgens <code>journalctl</code> getippt haben. Sie gespürt haben, wie die Seele den Körper verlässt, als ein Auditor sagte: „Zeigen Sie mir die Logs.“</p><p>ManageLM ist für bis zu 10 Agenten kostenlos. <a href=\"https://app.managelm.com/register\" target=\"_blank\" rel=\"noopener\">Konto anlegen</a>, die <a href=\"https://www.managelm.com/plugins/claude.html\" target=\"_blank\" rel=\"noopener\">Claude-Erweiterung</a> installieren und aufhören, sich um 4 Uhr morgens per SSH anzumelden.</p>"
  }
}
