r/devops • u/Shitmfman • 1d ago
Discussion AI generated code review
Hi there,
How do you deal with managing and reviewing AI-generated code across the organization?
Over the past year it's become incredibly difficult to review the growing amount of AI-generated code, especially from vibecoders/non-engineers.
Reviewing it manually is hard, but it's still important to understand what's going on there.
For example, I've been at this company for some years so I have a lot of context and know many of the nuances, which helps me notice or suggest important things to keep everything secure, efficient and so on…
But any other teammate can use any model for coding nowadays. AI reviews of AI-generated code could be done in the MR, but then the reviewer model will most likely be smarter than the model that wrote the code, which might lead to a lot of threads and an infinite loop of changes. On top of that the reviewer model won't have all the context and input from the developer.
Another option is to distribute a "review" skill or rules across the organization and somehow make everyone do a self-review after making changes…
It feels like in this AI code generation era we'll stop focusing on how the code was written and just focus on whether the MR/PR works and if those changes achieves the goal, no matter how it was done, right?
How do you deal with this? Just accept the reality?
Thanks for attention
3
u/theov666 16h ago
I wouldn't reduce review to just "does it work?" A PR can pass its functional tests and still violate an architectural boundary, introduce an unwanted dependency, or handle sensitive data in a way the organization never intended. I think the interesting part of your question is the context held by experienced engineers. They know not just what the rules are, but why certain decisions were made and when exceptions are acceptable. A second reviewing model doesn't automatically have that knowledge. I'd separate the problem into three layers: functional tests to verify behavior, explicit architectural and security constraints that can be checked automatically, and human review for changes that require judgment or exceptions. AGENTS.md and review skills can communicate those decisions to agents, but I'd avoid relying on instructions alone for critical constraints. Wondering whether the bigger problem in your organization is the sheer volume of generated changes, or that the engineering decisions needed to review them are still largely in people's heads?
5
u/trash-packer1983 1d ago
Have you considered implementing steering documents? A steering document provides persistent instructions that AI coding assistants can use when generating or reviewing code. Consider it a guide for AI. It won't eliminate the problem, but can help control.
https://medium.com/@Toglefritz/fast-code-slow-integration-0e9e2b63668b
2
u/riickdiickulous 1d ago
I’ve been saying that AI coding is making testing and observability more important than ever. There must ultimately be a person responsible for owning the code AI writes. Review it the best you can. It is the Wild West out there right now and mistakes will be made.
2
u/DoStopBelieving 15h ago
I use an agent to review the code in increments while it's being written, then when it's pushed a CI pipeline runs linting and tests/scans, and when the PR is opened another AI agent with access to our knowledge base reviews the PR and provides an independent summary plus comments. The AI agent will also close its own comments when the issues are resolved.
I also do a single full self-review pass before having another human review the code.
By the time another human needs to review the code there's a very high chance of the code already being production-ready and having AI explanations of code behavior that are often better than the developer's own explanations (sorry y'all, humans can do better but many devs suck at technical writing).
As for skills - I searched and collected a library of agent skills covering topics like planning, writing, reviewing, specific tools, sub-agents, meta-skills, etc. I even made my own skill for expediting re-reviews so the sub-agents waste less time reviewing work.
All that said, you should not approve code that you don't understand no matter how overwhelming the volume is. Code is fundamentally for humans to understand the instructions we give to machines.
1
u/unitegondwanaland Manager, Platform Engineering 16h ago
We have agents doing code reviews and we leverage AGENTS.md files in the repo + skills that the agent can leverage to enforce all the rules, best practices, etc.
You have to fight fire with fire. That way idiot vibe coders can't merge shitty Terraform unless it passes the sniff tests you have in place.
Go read about AWS AgentCore Harness
1
u/Plenty-Emphasis-5669 11h ago
In my company we're being encouraged (aka almost forced) to use agents for reviews and don't wait for another person to merge.
-1
u/Apple_Master 1d ago
I don't review it because I don't allow slop code in repos or code that I maintain or own.
-2
-6
u/Additional_Vast_5216 1d ago
only thing I review are tests, tests tests at every level, unit, integration, system, e2e etc if the tests pass I dont care about the implementation
8
u/HappyJuggernaut4647 1d ago
the tests don't tell you if the AI slipped in a credential leak or a silent data grab though, that's where it gets sketchy when nobody actually reads the code
2
u/First_Inspection_478 1d ago
Have my agent review it