💬 Host Commentary

Episode 6 is a “platform tax” week.

Not because anything is fun and shiny, but because a bunch of the stuff that keeps your org shipping quietly changed shape at the same time: CI economics, IaC platform limits, and new security boundaries thanks to AI agents.

We start with GitHub Actions. GitHub floated a new charge for self-hosted runners, got immediate pushback, and then paused the change while they re-evaluate. The important part isn’t the drama. It’s the signal: Actions is a control plane, and GitHub is clearly thinking hard about how it gets priced. We also got the perfect timing joke with a GitHub incident the same week, which is a reminder that CI isn’t just “dev convenience.” For a lot of teams it’s the delivery pipeline, the GitOps loop, and the break-glass path… until it isn’t.

Then we shift to HashiCorp and Terraform Cloud. Legacy Free orgs are heading toward end-of-life in 2026, with transitions to the newer Free tier capped at 500 managed resources. That number is either totally fine or instantly painful depending on how real your infrastructure is. The practical takeaway is simple: know your resource count, clean up zombie stacks, and decide early whether you’re paying, consolidating, or migrating. Don’t make it a March 2026 emergency.

After that, we talk about PromptPwnd and the broader “AI in CI” problem. Teams are wiring agents into pipelines that read PRs and issues, and if you feed untrusted text into prompts while the agent has tools and tokens, you’ve created a new kind of supply chain risk. The fix is the same boring security posture we always preach: sanitize inputs, minimize permissions, and don’t let an agent auto-execute anything just because it sounds confident.

We also touch a classic security hygiene story around long-lived access exposure as a reminder that secrets, blast radius, and detection still matter more than whatever new automation you just bolted on.

Lightning round hits CDKTF being sunset/archived, Bitbucket cleaning up free unused workspaces, and SourceHut’s proposed pricing changes as more evidence that tooling economics are shifting everywhere.

This episode is basically a reminder that platform engineering isn’t only Kubernetes and Terraform. It’s also vendor models, dependency planning, and making sure your pipelines don’t turn into single points of failure.

Show notes below have the links if you want to dig into the announcements and write-ups.

📝 Show Notes

This week on Ship It Weekly, Brian looks at how the “platform tax” is showing up everywhere: pricing model shifts, CI dependencies, and new security boundaries thanks to AI agents.

We start with GitHub Actions. GitHub announced a new “cloud platform” charge for self-hosted runners in private/internal repos… then hit pause after backlash. Hosted runner price reductions for 2026 are still planned. We also got the perfect timing joke: a GitHub incident the same week.

Next up is HashiCorp. Legacy HCP Terraform (Terraform Cloud) Free is reaching end-of-life in 2026, with orgs moving to the newer Free tier capped at 500 managed resources. If you’re running real infrastructure, this is a good moment to audit what you’re actually managing and decide whether you’re cleaning up, paying, or planning a migration.

Then we talk PromptPwnd: why stuffing untrusted PR/issue text into AI agent prompts (inside CI) can turn into a supply chain/security problem. The short version: treat AI inputs like hostile user input, keep tokens/permissions minimal, and don’t let agents “run with scissors.”

We also cover the Home Depot report about long-lived access exposure as a reminder that secrets hygiene, blast radius, and detection still matter more than the shiny tools.

In the lightning round: CDKTF is sunset/archived, Bitbucket is cleaning up free unused workspaces, and SourceHut is proposing pricing changes. We wrap with a human note on “platform whiplash” and why a simple watchlist beats carrying all this stuff in your head.

Links from this episode

GitHub Actions pricing + pause https://runs-on.com/blog/github-self-hosted-runner-fee-2026/ https://x.com/github/status/2001372894882918548 https://www.githubstatus.com/incidents/x696x0g4t85l

HashiCorp / Terraform Cloud free plan changes https://github.com/hashicorp/terraform-cdk?tab=readme-ov-file#sunset-notice https://www.reddit.com/r/Terraform/s/slYm77wzYr

PromptPwnd / AI agents in CI https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents

Home Depot access exposure report https://techcrunch.com/2025/12/12/home-depot-exposed-access-to-internal-systems-for-a-year-says-researcher/

Bitbucket cleanup https://community.atlassian.com/forums/Bitbucket-articles/Bitbucket-cleanup-of-free-unused-workspaces-what-you-need-to/ba-p/3144063

SourceHut pricing proposal https://sourcehut.org/blog/2025-12-01-proposed-pricing-changes/