How to vibe code securely (without getting hacked) @googlecloudtech
How to vibe code securely (without getting hacked)  @googlecloudtech
Uploaded August 2026 | Updated September 2026, 2 weeks ago
In this video, Aron Eidelman talks Martin Omander through how to dramatically increase the safety of any code you write with the help of AI coding agents. If you have been "vibe coding" but worry about security vulnerabilities, buggy implementations, or untrusted code execution, this breakdown is for you.

*Key takeaways & topics covered*
The duo breaks down the shift from blind prompting to setting rigorous rules of engagement for AI sidekicks. Here is what we cover in this episode:
* The Strict TDD loop: Learn how to force AI agents into a rigid red-green-refactor loop. This prevents the AI from modifying tests to fit a flawed implementation.
* Context engineering: Discover how to use .gemini files to set developer persona, style guides, and OWASP requirements. This automatically enforces strict input validation and parameterized SQL queries by default.
* Secure code execution: Contrast raw Docker direct kernel access with gVisor sandboxed syscalls. This allows developers to safely run untrusted, AI-generated code without risking host machine takeover.
* Multi-layered defense: Balance least privilege, manual confirmation, and agent supply chain security. This establishes robust fail-safes so no single exploit ruins your backend.

Chapters:
0:00 - Intro
1:16 - Small batches
3:36 - Context engineering
5:01 - Access control and sandboxing
6:21 - External verification
8:22 - Takeaways

πŸ”— Resources mentioned:
* DORA article about pervasive security β†’ https://goo.gle/45D7WhR
* DORA 2025 report β†’ https://goo.gle/4fLryoM

Watch more Serverless Expeditions β†’ https://goo.gle/ServerlessExpeditions
πŸ”” Subscribe to Google Cloud Tech β†’ https://goo.gle/GoogleCloudTech

#ServerlessExpeditions #GoogleCloud

Speakers: Martin Omander, Aron Eidelman
Products Mentioned: Gemini, DORA Research Project
How to vibe code securely (without getting hacked)Whats new for AI on GKE: Training, serving, and agentsNext gen agentic architecture: Hands on with Gemini 3.5 & ADKNoSQL for modern apps and AI: The future of Memorystore, Firestore, and BigtableReal-time voice AI agents, explained (before you build one)Agent context engineering for productionScale infrastructure as code: Proven strategies and productive workflowsWhats new with data agentsWhy use GKE for AI/ML workloads?7 AI agent patterns to improve your coding workflowNavigate the agentic shift in software development with GoogleIntro to AI agents
Google Cloud Tech |

How to vibe code securely (without getting hacked)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER