October 2026 Summaries
8 posts from Harness
Filter
Month:
Year:
Post Summaries
Back to Blog
No summary generated yet.
Oct 08, 2026
1,392 words in the original blog post.
No summary generated yet.
Oct 08, 2026
956 words in the original blog post.
Harness’s walkthrough shows how a developer can use its AI-assisted onboarding to create a CI pipeline for a GitHub-hosted Java Maven project without manually writing pipeline YAML. After connecting GitHub through OAuth and selecting a repository, the Harness agent analyzed the codebase, detected Java and Maven, generated build, test, caching, test-reporting, and runtime configurations, and stored the resulting pipeline definition in the repository’s .harness directory. The initial pipeline ran 42 unit tests successfully in 2 minutes and 34 seconds, after which the author added a Docker build-and-push step using a DockerHub connector, pipeline sequence and latest image tags, and Docker layer caching. The expanded workflow built, tested, and pushed the container image to DockerHub in 3 minutes and 6 seconds, with the Docker step taking 47 seconds. The post argues that generated pipelines can provide a usable baseline faster than manual configuration, while still allowing developers to extend them, and notes Harness features such as Test Intelligence and Cache Intelligence for potentially reducing build time.
Oct 08, 2026
1,745 words in the original blog post.
No summary generated yet.
Oct 08, 2026
1,768 words in the original blog post.
Software delivery knowledge graphs address fragmented engineering data by representing services, builds, artifacts, deployments, security scans, infrastructure, and other SDLC entities through shared definitions and explicit, typed relationships. The proposed architecture combines version-controlled schema-as-code contracts, a unified synchronization layer that validates and links source data, and declarative queries that allow people and AI systems to retrieve consistent cross-domain answers without manually stitching together multiple tools. Its reliability depends on shared semantics, data contracts, completeness and freshness monitoring, provenance metadata, and automated governance for schema changes. The authors identify practical challenges including reconciling inconsistent entity names across platforms, coordinating changes among independent domains, detecting silent data degradation, and evaluating whether graph-based retrieval improves AI task success. When operated with application-level observability, testing, and continuous evaluation, such graphs can support real-time DORA metrics, faster vulnerability response, root-cause analysis, and cloud cost attribution, with the recommended approach being to begin with a few high-value relationships and expand gradually.
Oct 05, 2026
2,831 words in the original blog post.
Harness describes rebuilding its API-classification pipeline for identifying endpoints that interact with large language models, a security-relevant task because such endpoints may expose organizations to prompt injection, sensitive-data leakage, and unreviewed third-party vendors. The original system used multiple generative LLM calls to summarize traffic spans and classify each endpoint, costing about $176 per thousand endpoints, while a simplified one-call LLM approach reduced that to roughly $22 per thousand but retained high latency and self-reported confidence labels. A hybrid alternative used Jev, a purpose-built decision model, for binary classification and calibrated probabilities, while reserving LLM generation for human-readable explanations on positive or uncertain cases; it was estimated to cost about $0.14 per thousand endpoints and achieved median latency of 0.80 seconds. On a human-verified set of 500 endpoints, Jev reached 98.6% accuracy for identifying AI APIs, with all seven errors concentrated in a 0.3–0.8 uncertainty range covering only 3.4% of examples, enabling targeted LLM fallback or human review. The post argues that maintaining a fixed four-field output contract allowed the decision engine to be replaced without altering downstream dashboards, enrichment workflows, or product interfaces.
Oct 05, 2026
3,007 words in the original blog post.
Engineers may overlook cloud cost governance when conventional FinOps processes rely on delayed billing reports, disconnected dashboards, and manual reviews that do not fit into development workflows or engineering performance metrics. The post argues that cost accountability improves when real-time spending data and policy controls are integrated into infrastructure-as-code reviews and CI/CD pipelines, enabling teams to identify costly configurations, enforce budget or instance-type rules, and attribute shared cloud and Kubernetes costs to services, environments, teams, and business units. It presents Harness Cost Management Agent as a tool for AWS, Azure, and GCP that provides cost allocation, anomaly detection, automated budget tracking, idle-resource shutdowns, rightsizing, and natural-language governance policies operating in recommendation, approval, or autonomous modes. The broader argument is that treating cloud spending as a continuous engineering constraint rather than a monthly financial audit can reduce waste while preserving development speed and can extend to AI cost and engineering-efficiency management.
Oct 02, 2026
1,409 words in the original blog post.
Harness reported 102 product updates in September 2026 aimed at accelerating secure software delivery as AI-generated code increases development speed. Major additions include access to Harness through ChatGPT and expanded MCP Server capabilities, Homebrew installation for the Harness CLI, merge queues for code repositories, and support for importing existing AI agents from Google Agent Runtime and AWS Agent Core for pipeline-based management. Deployment and GitOps enhancements added improved Kubernetes pod diagnostics, AI verification fail-fast criteria, CloudWatch OIDC authentication, ECS cost cleanup, and broader release-management controls. Infrastructure-as-code workflows gained reusable Ansible configurations, richer variable types, automated workspace pipelines, and native Gitleaks and SonarQube scans, while API security improvements connected repository-based API discovery directly to testing and expanded inventory, policy, and DAST capabilities. The release also introduced AI-assisted remediation for Bitbucket Data Center, stronger threat-scoring controls, more reliable cost-data ingestion, and new feature-management and resilience-testing tools, reflecting a broader effort to integrate building, testing, governance, security, deployment, and cost management into faster but controlled delivery processes.
Oct 01, 2026
2,699 words in the original blog post.