The dream of shipping an AI agent to the world often dies the moment a random visitor decides to stress-test your API key. Developer Dinesh recently documented a pragmatic solution to this exact problem, deploying a code review agent on a free Render host while strictly limiting public access to read-only interactions. By leveraging Hindsight for memory and Groq for the LLM, the project showcases how environment variables can act as a hard firewall between your development sandbox and the wild, wild web.

The Architecture of Denial

The core mechanism relies on a simple but effective toggle in the FastAPI application. When the environment variable READ_ONLY is set to 1, the endpoints /review, /feedback, and /github-pr immediately raise a 403 HTTP exception. This prevents any external user from triggering a model call or writing to the memory bank. Simultaneously, PUBLIC_MODE=1 hides the /docs page, reducing the attack surface and hiding the internal API structure from casual snoopers. The code snippet provided in the source demonstrates this cleanly, with the block_if_read_only function acting as a gatekeeper for all write operations.

Isolating Memory Banks

Perhaps the most critical architectural decision was the separation of Hindsight memory banks. The public deployment uses a distinct BANK_ID (review-agent-public) compared to the local development instance. This ensures that the dozens of test comments accepted and rejected during development do not pollute the data seen by public visitors. It is a subtle but vital distinction for maintaining the integrity of the agent's knowledge base when it is exposed to a global audience. The developer explicitly notes that this isolation prevents test decisions from leaking into the public experience.

Hardening the Input Pipeline

Even with writes disabled, the application does not trust input blindly. The developer implemented strict validation limits, such as capping diff sizes at 200,000 characters and flattening comment text to 500 characters. Rejection reasons are restricted to three allowed values, and categories are sanitized to lowercase alphanumerics. The /github-pr endpoint is further hardened by accepting only URLs matching the specific GitHub PR pattern and restricting outbound calls solely to api.github.com. These measures mitigate risks from malformed payloads or attempted injection attacks, even if the primary write vectors are blocked.

The Cost of Free Infrastructure

Running on Render's free tier comes with the expected trade-off: cold starts. The first request can take 30 to 90 seconds as the service spins up. The developer chooses to accept this latency rather than pay for a persistent instance, arguing that a warning line in the documentation is cheaper than keeping the server awake. This is a classic indie hacker compromiseβ€”sacrificing immediate responsiveness for zero-cost uptime. The .env file remains uncommitted, and the deployment triggers automatically on push, keeping the workflow streamlined despite the infrastructure constraints.

Key Takeaways

  • Use environment variables (READ_ONLY, PUBLIC_MODE) to physically disable write endpoints for public deployments.
  • Isolate memory banks (e.g., BANK_ID) to prevent development test data from contaminating public-facing agent knowledge.
  • Accept cold start latency (30-90s) on free hosts as a trade-off for zero-cost API quota preservation.
  • Implement strict input validation (diff limits, text capping) even when write operations are disabled to prevent resource exhaustion.

The Bottom Line

Public-facing LLM agents must treat every visitor as a potential cost center. Enforcing read-only modes via environment variables is the single most effective barrier against API quota exhaustion for hobbyist developers.