Skip to main content
Dora Noda

Dora Noda

Software Engineer

2333 posts · View all authors

User Namespaces Are GA in Kubernetes 1.36: Exactly What It Buys You (and What It Doesn't) for Multi-Tenant and AI-Agent Nodes
·Dora Noda·11 min

User Namespaces Are GA in Kubernetes 1.36: Exactly What It Buys You (and What It Doesn't) for Multi-Tenant and AI-Agent Nodes

Kubernetes 1.36 makes User Namespaces GA — a near-free identity remap that neutralizes four real container-escape CVEs, but stops short of the kernel-level isolation AI agents running untrusted code still need.

security
self-hosting
PaaS
infrastructure
+1
Kubernetes 1.36's Volume Group Snapshots Go GA: Can Your Self-Hosted Fleet Actually Use It?
·Dora Noda·9 min

Kubernetes 1.36's Volume Group Snapshots Go GA: Can Your Self-Hosted Fleet Actually Use It?

Kubernetes 1.36 graduated VolumeGroupSnapshot to GA — a crash-consistent, multi-volume snapshot API. Here's the CSI driver support matrix that decides whether a Hetzner or Longhorn fleet can actually use it today, and the one path that works.

self-hosting
PaaS
infrastructure
engineering
Let's Encrypt's DNS-PERSIST-01: One TXT Record Replaces Every Renewal for Multi-Tenant TLS
·Dora Noda·8 min

Let's Encrypt's DNS-PERSIST-01: One TXT Record Replaces Every Renewal for Multi-Tenant TLS

A new Let's Encrypt challenge type lets a tenant authorize a platform's ACME account once instead of on every renewal — here's the record format, the security tradeoff, and what it changes for a self-hosted PaaS issuing certs at fleet scale.

self-hosting
PaaS
Domain
security
+1
MCP's Enterprise-Managed Authorization Goes Stable: What the ID-JAG Grant Fixes and What It Doesn't
·Dora Noda·8 min

MCP's Enterprise-Managed Authorization Goes Stable: What the ID-JAG Grant Fixes and What It Doesn't

MCP's Enterprise-Managed Authorization extension went stable in June 2026, killing per-server OAuth consent screens via a new ID-JAG grant flow — but it only governs connections, not individual tool calls, leaving per-action authorization for agent deploy/rollback tools squarely up to the platform.

Model Context Protocol
AI agents
self-hosting
security
MCP Goes Vendor-Neutral: What the Linux Foundation Handoff Actually Buys Down
·Dora Noda·8 min

MCP Goes Vendor-Neutral: What the Linux Foundation Handoff Actually Buys Down

Anthropic handed MCP's governance to a new Linux Foundation body, and the protocol's biggest breaking change yet ships in three weeks. Here's what actually changed, what didn't, and what it means for a platform betting on MCP as its agent interface.

Model Context Protocol
AI agents
governance
self-hosting
+1
MCP's Sticky-Session Problem Is Over: What the July 28, 2026 Stateless Spec Means for a Deploy-From-Chat MCP Server
·Dora Noda·9 min

MCP's Sticky-Session Problem Is Over: What the July 28, 2026 Stateless Spec Means for a Deploy-From-Chat MCP Server

MCP's July 28, 2026 spec removes protocol-level sessions entirely. Here's exactly what breaks, what SEP-2567 and the Tasks extension replace it with, and the migration checklist for a self-hosted PaaS's own deploy-from-chat MCP server.

Model Context Protocol
AI agents
self-hosting
PaaS
MCP Drops Sticky Sessions: What the July 28 Stateless Spec Actually Removes From Your Infrastructure
·Dora Noda·8 min

MCP Drops Sticky Sessions: What the July 28 Stateless Spec Actually Removes From Your Infrastructure

The MCP spec finalizing July 28, 2026 deletes the session ID and the handshake. Here's the actual infrastructure a production MCP server gets to delete with it — and the two things that don't get any simpler.

Model Context Protocol
self-hosting
PaaS
infrastructure
+1
60% of MCP Servers Have Security Issues: The Checklist Before You Expose Deploy/Rollback to an Agent
·Dora Noda·10 min

60% of MCP Servers Have Security Issues: The Checklist Before You Expose Deploy/Rollback to an Agent

A July 2026 census scanned 9,695 MCP servers and found 5,832 with security issues. Here's the breakdown and the concrete checklist a deploy-from-chat PaaS needs to clear before letting an agent touch production.

Model Context Protocol
cybersecurity
AI agents
self-hosting
+1
Metal3 Enters CNCF Incubation: What the Bare-Metal Provisioning Layer Actually Changes for a Cluster API Fleet Not Already Running It
·Dora Noda·8 min

Metal3 Enters CNCF Incubation: What the Bare-Metal Provisioning Layer Actually Changes for a Cluster API Fleet Not Already Running It

Metal3 just became a CNCF incubating project, but the badge only matters to a Cluster API fleet the day its hardware stops living behind a single vendor's API. Here's the concrete Redfish/IPMI-vs-Hetzner-API line that decides when to adopt it.

self-hosting
PaaS
infrastructure
engineering
+1
Showing 613–621 of 2333 posts
Prev69 / 260Next