Found out, you should not post on HN a vercel app running an hobby plan, as you quickly reach KV store usage limit. Fair :)
But upgrading vercel was not a smooth experience : https://twitter.com/skeetmtp/status/1748702685325398388
I've seen it advised to periodically release to production with ASAN/UBSAN/TSAN enabled, with the intention that it's only 1/nth of a deployment, and even then, only deployed for enough time to collect instrumentation. I don't have a citation to share, so take with as many grains of salt as you feel appropriate.
If nothing else, I appreciate the advisement that it can have security implications.
If you leak all the secrets 1% of the time, that's not leaking 1% of the secrets. All of the secrets have been leaked, albeit over a short stretch of time.
I'm pretty interested in this kind of solutions. But I don't really see the real advantages vs a vagrant based setup ? You can already do filesharing and changing port fw only happens once in a while, in my case.
https://ubuntu.com/security/notices/USN-6859-1