Skip to main content

691 posts tagged with "Self-Hosting"

Running your own PaaS and infrastructure on machines you own

View all tags

Read the Self-hosted PaaS guide

CAPH Quietly Renamed Its Annotations and Finalizers — Here's Every Old-to-New Key
·Dora Noda·9 min

CAPH Quietly Renamed Its Annotations and Finalizers — Here's Every Old-to-New Key

CAPH renamed every annotation and finalizer key to match Kubernetes convention back in 2024 with zero announcement — here's the full old-to-new mapping, why finalizers self-healed but annotations didn't, and the grep to run before you trust either one.

self-hosting
PaaS
infrastructure
engineering
CAPH's Bare-Metal Hetzner Robot Servers vs Cloud VMs: The Real Cost Delta on a Cluster API Node Pool
·Dora Noda·10 min

CAPH's Bare-Metal Hetzner Robot Servers vs Cloud VMs: The Real Cost Delta on a Cluster API Node Pool

A RAM-and-core-matched cost comparison of Hetzner Robot bare-metal servers against Hetzner Cloud VMs shows a 4.2x-5.6x price gap after 2026's cloud price hikes — and the concrete rule for which workloads belong on which side of a mixed CAPH node pool.

self-hosting
PaaS
cost-optimization
infrastructure
CVE-2026-25518: The cert-manager Bug That Lets a Poisoned DNS Reply Crash Your Whole TLS Pipeline
·Dora Noda·9 min

CVE-2026-25518: The cert-manager Bug That Lets a Poisoned DNS Reply Crash Your Whole TLS Pipeline

A crafted DNS response can crash the cert-manager controller mid-renewal. Here's exactly what CVE-2026-25518 breaks, why the fix isn't just an upgrade, and the two config changes a self-hosted PaaS's TLS automation needs today.

self-hosting
PaaS
security
infrastructure
+1
Chainguard and Wolfi Cross 2,000 Zero-CVE Images: Should a Self-Hosted PaaS Default to Them?
·Dora Noda·9 min

Chainguard and Wolfi Cross 2,000 Zero-CVE Images: Should a Self-Hosted PaaS Default to Them?

Chainguard's Wolfi-based images cut CVE counts from ~280 to zero and shaved 60-80% off build time and egress in a real migration. Here's what defaulting a git-push PaaS's build output to Wolfi would actually change — and the honest build-vs-buy call against Chainguard's paid catalog.

self-hosting
PaaS
security
infrastructure
+1
Cloud Run Worker Pools Hit GA With Blackwell GPUs: The Math Against an Owned Hetzner Box
·Dora Noda·8 min

Cloud Run Worker Pools Hit GA With Blackwell GPUs: The Math Against an Owned Hetzner Box

Cloud Run Worker Pools went GA with Blackwell GPU support in the same window Fly.io announced it's exiting GPU hosting entirely. A line-by-line recompute of what an always-on Worker Pool actually bills against an owned Hetzner GPU box.

PaaS
cost-optimization
self-hosting
cloud infrastructure
CNCF's Platform Engineering Maturity Model Just Got a v2 — We Ran a Cluster-API PaaS Through All 5 Aspects
·Dora Noda·9 min

CNCF's Platform Engineering Maturity Model Just Got a v2 — We Ran a Cluster-API PaaS Through All 5 Aspects

CNCF shipped a v2 of its Platform Engineering Maturity Model at KubeCon EU 2026. Here's what actually changed in the rubric, and a concrete, honest self-assessment of a Cluster-API git-push PaaS against all 5 aspects.

self-hosting
PaaS
infrastructure
engineering
containerd's June 2026 CRI Advisory: Three Ways to Escape a Shared Node That RuntimeClass Can't Stop
·Dora Noda·9 min

containerd's June 2026 CRI Advisory: Three Ways to Escape a Shared Node That RuntimeClass Can't Stop

AWS's June 2026 bulletin disclosed five containerd CRI plugin CVEs, and patching the daemon — not picking gVisor or Kata for your RuntimeClass — is the only real fix. Here's what each bug requires and what a shared-node fleet needs to check this week.

security
infrastructure
self-hosting
PaaS
Convex's FSL License Bans Building a Competitor: What 'Open, Except to Compete With Us' Actually Costs You
·Dora Noda·9 min

Convex's FSL License Bans Building a Competitor: What 'Open, Except to Compete With Us' Actually Costs You

Convex's backend is source-available under the Functional Source License — free to self-host, but banned from powering a competing hosted product for two years. Here's what that non-compete clause actually forecloses, concretely, versus a plain Apache-2.0 license.

self-hosting
PaaS
developer tools
engineering
Coolify Shipped an Audit Log. It Still Wouldn't Survive a SOC 2 Review.
·Dora Noda·9 min

Coolify Shipped an Audit Log. It Still Wouldn't Survive a SOC 2 Review.

Coolify v4.1 shipped the first structured audit log among self-hosted PaaS platforms — but it only covers API mutations. Here's the gap against a real SOC 2 review, and the checklist a compliance-ready deploy API actually needs.

compliance
security
PaaS
self-hosting
Showing 397–405 of 691 posts
Prev45 / 77Next