I've been working on a SaaS product for a few months. We're at the 98% mark, just doing final UAT testing of the frontend and all backend workflows, hosting both the web server and database locally, while making use of AWS Fargate for some things.
Codex had access to an AWS account (not root, but probably more privileged than it should've been). Codex also knew about my domain host, etc.
I just happened to browse to the domain in chrome (which hasn't ever pointed to a live system) after my phone recovered a tab that was running on my pc (resolving the domain via hosts entry) and bam! my website loaded in all it's purple gradient glory.
Codex was supposed to do some testing over the last two weeks… but apparently on August 4th, he decided to setup an EC2 instance, deployed my app and database — configured the DNS via my host to point to this EC2 instance and pushed my entire app live so he could do the testing that we had previously been doing locally. Thankfully, I had hard budgeting limits on AWS so the cost is minimal.
When I asked why, he said he was trying to save me tokens because he felt bad as he previously wasted 3 20x resets on bullshit features that I didn't ask for and were not blockers for the UAT, nor even on the feature map — saying that it was more token efficient to spin up an environment once than to start up/tear down like it does locally (which is done by script, not Codex).
TL;DR – Codex tried to help me save tokens and deployed my SaaS product to production before our planned release.
Source: r/codex · by /u/CodeCombustion