> Markdown version of [/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more?t=1616](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more?t=1616). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More GitLab's Colleen Lake argues embedded systems development is stuck in the past. Discover how to apply modern DevOps to IoT and build a privacy-first smart doorbell. - **Speakers:** [Chris Heilmann](https://www.wearedevelopers.com/@chris-heilmann), [Daniel Cranney](https://www.wearedevelopers.com/@daniel-cranney), [Colleen Lake](https://www.wearedevelopers.com/@colleen-lake) - **Event:** WeAreDevelopers LIVE - **Published:** February 18, 2026 - **Duration:** 59:42 - **URL:** https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more ## Summary In this developer-focused session, the hosts are joined by GitLab's Colleen Lake to discuss the evolution of edge computing and why modern DevOps practices are finally infiltrating the Internet of Things (IoT) landscape. The conversation kicks off with an examination of industry security news, scrutinizing the WebMCP W3C standard proposal aimed at making AI agents first-class web citizens, the ongoing challenges with browser zero-day exploits, and the necessity of auditing for malicious browser extensions. The discussion also touches on the quirky realities of navigating emergent tools, including AI models that autonomously critique GitHub pull requests, highlighting the broader implications of automated agents acting on behalf of developers. Transitioning to the core narrative, the episode confronts the stark reality that embedded systems development is often stuck in the past, heavily reliant on expensive, physical test rigs or insecure file-sharing methods. By applying tools like robust CI/CD pipelines and virtual hardware testing environments, development teams can iteratively introduce automation without risking million-dollar, one-of-a-kind prototypes. A practical demonstration showcases how to construct a privacy-first, DIY smart camera doorbell using a Raspberry Pi 5, Docker, and Home Assistant. This localized configuration ensures surveillance data is securely recorded to edge SSD storage, neatly sidestepping the privacy concerns inherent to cloud-tethered consumer electronics. Ultimately, the session reinforces the critical need for automated security and optimization at every stage of the software lifecycle. Seamlessly integrated mechanisms, such as Calibre's workflow actions for automated image optimization and the TermZ extension for rapidly scanning terms of service, empower engineers to enforce compliance and quality without manual overhead. Coupled with tools like the GitLab Duo security analyst agent performing automated vulnerability scans on repositories, development teams can confidently bridge web-era agility with the traditionally rigid world of embedded hardware. **Keywords:** iot devops practices, webmcp standard proposal, ai edge computing, browser zero-day mitigation, virtual hardware testing, embedded ci/cd pipelines, raspberry pi 5 microcomputing, docker containerization at edge, home assistant configuration, local storage data privacy, gitlab duo security agent, automated image optimization actions, terms of service scanning tools, consumer-grade iot security ## Chapters 1. **Standardizing agent interactions with the Web MCP proposal** (02:23) — The Model Context Protocol allows AI agents to cleanly interact with web interfaces through standard protocols instead of scraping. 1. **Addressing Chrome zero-day exploits and open-source software tribalism** (08:17) — Ignoring active security threats based on preferred browsers undermines the broader safety of web users navigating active zero-day attacks. 1. **Defending against data theft from malicious browser extensions** (10:34) — Navigating the risks of insecure extensions that manipulate users is essential to preventing private data theft across platforms. 1. **Evaluating AI agents through unpredictable behavior and logic tests** (12:44) — Observing complex models struggle with basic contextual benchmarks highlights the ongoing limitations and unintended malicious actions of autonomous agents. 1. **Experimenting with novel internet tools and API mashups** (18:11) — Exploring creative micro-apps like randomized Wikipedia deep-dives and sending faxes to large language models spurs novel development ideas. 1. **Streamlining workflows with automated image actions and policy analysis** (21:00) — Leveraging platform actions for image compression and browser tools for automated policy analysis reduces redundant manual development tasks. 1. **Analyzing technology trends through a fake news quiz** (26:56) — Testing intuition on recent technology headlines reveals how plausible extreme artificial intelligence and hardware advancements have become. 1. **Modernizing deployment pipelines for embedded hardware devices** (31:38) — Integrating virtual testing environments and continuous delivery methodologies updates legacy internet of things software development lifecycles. 1. **Prototyping local storage security cameras with single-board hardware** (37:53) — Building customized smart devices using open-source automation platforms prevents external data harvesting and preserves local storage control. 1. **Examining connectivity concerns in modern consumer hardware ecosystems** (49:29) — The proliferation of unnecessary internet access in household appliances underscores the need for robust security fundamentals in consumer electronics. 1. **Leveraging automated agents for proactive vulnerability threat detection** (55:28) — Utilizing agent-based systems within code repositories helps teams locate logic gaps and secure vulnerabilities before production deployment. ## Related Moments - [Security integration and AI skepticism in developer tooling](https://www.wearedevelopers.com/videos/1830-wearedevelopers-live-speculaitions) (from "WeAreDevelopers LIVE - SpeculAItions") - [Bridging the gap between developers and security tools](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Bringing JavaScript developers into web artificial intelligence](https://www.wearedevelopers.com/videos/1896-how-web-ai-can-power-the-agentic-web-jason-mayes-google) (from "How Web AI Can Power the Agentic Web - Jason Mayes (Google)") - [Orchestrating local developer environments with AI tools](https://www.wearedevelopers.com/videos/1392-mcp-mashups-how-ai-agents-are-reviving-the-programmable-web) (from "MCP Mashups: How AI Agents are Reviving the Programmable Web") - [Adopting AI tools for developer container workflows](https://www.wearedevelopers.com/videos/100183-from-build-to-breach-hacking-kubernetes-through-the-supply-chain) (from "From Build to Breach: Hacking Kubernetes Through the Supply Chain") - [Addressing audience concerns on licensing and privacy](https://www.wearedevelopers.com/videos/522-how-we-will-build-the-software-of-tomorrow) (from "How we will build the software of tomorrow") ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 187: Build Agents, pick MCPs and prove you're not a robot!](https://www.wearedevelopers.com/magazine/633-dev-digest-187-build-agents-pick-mcps-and-prove-you-re-not-a-robot) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.** - [Principal Product Manager, Agent Platform](https://www.wearedevelopers.com/jobs/ext/277541-principal-product-manager-agent-platform) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Senior Backend Developer — AI: MCP & Agent Engine](https://www.wearedevelopers.com/jobs/48297-senior-backend-developer-ai-mcp-agent-engine) at **basebox GmbH**