Dora Noda
Software Engineer
2331 posts · View all authors
AWS Open-Sourced the Exact MCP Governance Layer Snowflake Just Paid to Acquire
Snowflake just paid an undisclosed sum to acquire Natoma's MCP governance gateway. AWS's Apache-2.0 mcp-gateway-registry already does the same identity, policy, and audit job — self-hosted on EKS, ECS, or a single Docker Compose file.
Backstage's 89% Market Share Hides a 10% Adoption Problem
Backstage owns 89% of the IDP market but gets opened by about 10% of eligible engineers at a typical adopter. Here's what the plugin-upgrade tax behind that gap means for any platform's golden-path bet.
Buildpacks Now Auto-Detect 80% of New Web Apps in 2026: What the Remaining 20% Actually Needs From a Real Dockerfile
Zero-config buildpacks now cover roughly 80% of new web apps with no Dockerfile at all — but native dependencies, unsupported runtimes, multi-stage builds, and monorepos make up the other 20%, and how a platform handles that failure, cleanly or not, is a design choice.
CAPH Quietly Renamed Its Annotations and Finalizers — Here's Every Old-to-New Key
CAPH renamed every annotation and finalizer key to match Kubernetes convention back in 2024 with zero announcement — here's the full old-to-new mapping, why finalizers self-healed but annotations didn't, and the grep to run before you trust either one.
CAPH's Bare-Metal Hetzner Robot Servers vs Cloud VMs: The Real Cost Delta on a Cluster API Node Pool
A RAM-and-core-matched cost comparison of Hetzner Robot bare-metal servers against Hetzner Cloud VMs shows a 4.2x-5.6x price gap after 2026's cloud price hikes — and the concrete rule for which workloads belong on which side of a mixed CAPH node pool.
CVE-2026-25518: The cert-manager Bug That Lets a Poisoned DNS Reply Crash Your Whole TLS Pipeline
A crafted DNS response can crash the cert-manager controller mid-renewal. Here's exactly what CVE-2026-25518 breaks, why the fix isn't just an upgrade, and the two config changes a self-hosted PaaS's TLS automation needs today.
Chainguard and Wolfi Cross 2,000 Zero-CVE Images: Should a Self-Hosted PaaS Default to Them?
Chainguard's Wolfi-based images cut CVE counts from ~280 to zero and shaved 60-80% off build time and egress in a real migration. Here's what defaulting a git-push PaaS's build output to Wolfi would actually change — and the honest build-vs-buy call against Chainguard's paid catalog.
Cloud Run Worker Pools Hit GA With Blackwell GPUs: The Math Against an Owned Hetzner Box
Cloud Run Worker Pools went GA with Blackwell GPU support in the same window Fly.io announced it's exiting GPU hosting entirely. A line-by-line recompute of what an always-on Worker Pool actually bills against an owned Hetzner GPU box.
CNCF's Platform Engineering Maturity Model Just Got a v2 — We Ran a Cluster-API PaaS Through All 5 Aspects
CNCF shipped a v2 of its Platform Engineering Maturity Model at KubeCon EU 2026. Here's what actually changed in the rubric, and a concrete, honest self-assessment of a Cluster-API git-push PaaS against all 5 aspects.