Skip to main content

761 posts tagged with "Infrastructure"

Blockchain infrastructure and node services

View all tags

Sprites Speak MCP: When the Agent Sandbox Becomes a Tool the Agent Calls Itself
·Dora Noda·12 min

Sprites Speak MCP: When the Agent Sandbox Becomes a Tool the Agent Calls Itself

Fly.io's Sprites now expose their full lifecycle over MCP, so agents provision disposable machines from inside their own loop. Here is the six-tool sandbox contract — create, exec, checkpoint, restore, destroy, list — and the quotas, TTLs, and per-tenant budgets a self-hosted platform needs before the agent becomes the capacity planner.

AI agents
Model Context Protocol
PaaS
self-hosting
+1
step-ca vs Let's Encrypt: What an Internal-Only ACME CA Buys Your Fleet's Service-to-Service TLS
·Dora Noda·11 min

step-ca vs Let's Encrypt: What an Internal-Only ACME CA Buys Your Fleet's Service-to-Service TLS

Let's Encrypt logs every certificate publicly and refuses private hostnames by design. step-ca gives a Cluster API fleet automated internal TLS with 24-hour certs and no CT-log exposure — here's the full setup, plus the honest cost of running your own CA.

security
infrastructure
self-hosting
Kubernetes
Six Traefik Gateway API Advisories in Six Months: The Namespace-Boundary Probes Your Shared Ingress Owes Every Tenant
·Dora Noda·13 min

Six Traefik Gateway API Advisories in Six Months: The Namespace-Boundary Probes Your Shared Ingress Owes Every Tenant

Traefik shipped six Gateway API isolation advisories between March and August 2026 — including a 9.9 CRITICAL REST-provider exposure and a route-key collision with no workaround. Seven concrete namespace-boundary probes, each with the manifest and the exact assertion, for any platform routing many tenants through one shared ingress.

security
Kubernetes
PaaS
self-hosting
+1
CNCF's Platform Engineering 2.0 Five Pillars: Grading a Self-Hosted PaaS Against the AI-Era Scorecard
·Dora Noda·11 min

CNCF's Platform Engineering 2.0 Five Pillars: Grading a Self-Hosted PaaS Against the AI-Era Scorecard

CNCF's July 2026 Platform Engineering 2.0 framework sets five AI-era pillars. We grade a Cluster-API-managed, Render-compatible self-hosted PaaS against each one — one pass, two partials, two gaps — and map the honest upgrade path.

Kubernetes
PaaS
self-hosting
AI agents
+1
Docker Hub's 2026 Pricing Squeeze: What Self-Hosting a Registry Cache Actually Saves Your CI Pipeline
·Dora Noda·11 min

Docker Hub's 2026 Pricing Squeeze: What Self-Hosting a Registry Cache Actually Saves Your CI Pipeline

Docker Hub's 2026 free tier is 10 pulls/hour unauthenticated and 40/hour on Personal, with roughly 10x overage past paid plan limits. A line-by-line cost model shows a real CI pipeline paying $160–300/month on Docker Hub versus under €12 for a self-hosted pull-through cache — and exactly where the crossover sits.

self-hosting
cost-optimization
infrastructure
PaaS
Docker Hub Almost Cut You to 40 Pulls an Hour: The Math for Sizing Your Own Registry Cache
·Dora Noda·12 min

Docker Hub Almost Cut You to 40 Pulls an Hour: The Math for Sizing Your Own Registry Cache

Docker's walked-back 10/40-per-hour limits were a preview, not a false alarm: a 15-developer team with ephemeral CI runners and a 12-node cluster hits today's enforced 100/200-per-6-hour buckets on an ordinary Tuesday. The full pull ledger, the tipping-point formula, and how to size and wire a registry cache — registry:2 or Harbor — into a Cluster API fleet.

infrastructure
self-hosting
Kubernetes
cost-optimization
GAMMA Extends Your HTTPRoutes East-West: Does a Self-Hosted PaaS Need a Service Mesh, or Just the Ingress Layer It Already Owns?
·Dora Noda·11 min

GAMMA Extends Your HTTPRoutes East-West: Does a Self-Hosted PaaS Need a Service Mesh, or Just the Ingress Layer It Already Owns?

GAMMA lets the HTTPRoute objects a PaaS already provisions for ingress govern east-west traffic too — retries, timeouts, and canary splits without a service mesh. A capability map, worked YAML, real mesh cost numbers, and a decision framework for self-hosted platforms.

Kubernetes
PaaS
self-hosting
infrastructure
Your Cluster Runs at 8% CPU: Bin-Packing Defaults for a Self-Hosted Fleet That Can't Return Capacity
·Dora Noda·11 min

Your Cluster Runs at 8% CPU: Bin-Packing Defaults for a Self-Hosted Fleet That Can't Return Capacity

Cast AI's 2026 report puts average Kubernetes CPU utilization at 8% and memory at 20%. On elastic cloud that's an expensive bill; on owned hardware it's capacity you already paid for and can't return. Concrete request/limit defaults, a bin-packing scheduler config, and a worked Hetzner-vs-cloud cost delta.

Kubernetes
self-hosting
cost-optimization
infrastructure
Kubernetes v1.36 Ships Admission Policies That Can't Be Deleted: Closing the Bootstrap Window in Your Fleet's Guardrails
·Dora Noda·11 min

Kubernetes v1.36 Ships Admission Policies That Can't Be Deleted: Closing the Bootstrap Window in Your Fleet's Guardrails

Kubernetes v1.36's manifest-based admission control loads policies from files before the API server serves its first request — undeletable via any RBAC. What it forecloses for a multi-tenant self-hosted PaaS, and the Cluster API bootstrap sequencing that makes guardrails live before the first tenant pod.

Kubernetes
security
self-hosting
PaaS
+1
Showing 109–117 of 761 posts
Prev13 / 85Next