Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

One GPU, Two Tenants: Where DRA, MIG, vCluster, and DCGM Share a Card — and Where the Trust Boundary Says Stop
CNCF's AI-factory guide lists DRA, MIG, vCluster, and DCGM as one stack. A concrete two-tenant design for a self-hosted fleet — which layers can share a single GPU within one trust domain, and why untrusted tenants still need whole cards or dedicated nodes.

NGINX Is Back: Gateway Fabric vs Envoy vs Cilium for Your Self-Hosted PaaS
F5's March 2026 Kubernetes roadmap puts NGINX Gateway Fabric back in the ingress race just as ingress-nginx retires. A concrete three-way comparison with Envoy Gateway and Cilium, plus the decision guide for a Cluster API fleet routing every tenant domain through one gateway.

Netlify Calls the Model for You: What Zero-Key Agent Runners Teach Self-Hosted MCP Servers About Auth
Netlify's Agent Runners remove model API keys by billing inference through its AI Gateway; why a self-hosted deploy-from-chat platform should answer with tenant-held keys plus short-lived OAuth 2.1 agent credentials instead of rebuilding the broker.

A Chip Vendor Put Its Catalog Inside Your AI Assistant: What Microchip's MCP Server Teaches Every Platform API
Microchip's MCP server lets any AI assistant answer engineering questions from verified parts data. The five things it does that every platform API must copy — and the read-only-vs-read-write caveat that decides whether your agent interface is safe.

Let's Encrypt Won't Make 6-Day Certificates the Default: the 6-Question Automation Exam Before You Opt In
Let's Encrypt's 160-hour certificates are GA but staying opt-in because most renewal automation can't hold a six-day clock. The per-cert slack math, a six-question pass/fail exam with a cert-manager example, and why a PaaS that owns its whole TLS path can go first.

Kyverno 1.17's CEL Policies Hit v1: What One Policy Language From Admission to Audit Buys a Multi-Tenant Fleet Over Gatekeeper's Rego
Kyverno 1.17 promotes its CEL policy engine to v1 and starts a removal clock on legacy ClusterPolicy, with deletion planned for v1.20 in October 2026. A side-by-side of validation, tenant defaulting, and image verification in CEL versus Rego, plus an eight-step migration checklist for multi-tenant fleets.

Kubero's GitOps Engine: What Reconciliation-Driven Deploys Buy You Over Compose-on-a-VPS
Kubero implements GitOps on Kubernetes while Coolify and Dokploy shell out to Compose over SSH. A table-driven walkthrough of six lifecycle events shows exactly what reconciliation buys you — and where the cluster bill still lands.

All or Nothing: What Kubernetes v1.36's PodGroup Scheduling Buys a Self-Hosted PaaS That Packs Tenants Tight
Kubernetes v1.36 gives kube-scheduler native all-or-nothing gang placement plus rack-aware co-location. A mini-fleet walkthrough shows what that saves a self-hosted PaaS bin-packing tenants onto fixed nodes — and the alpha limits that say don't run it in production yet.

Kubernetes Fits in a Browser Tab: What ngrok's 140KiB Cluster Says Your Edge Fleet Can Drop
ngrok's webernetes project squeezed a working Kubernetes cluster into 140KiB of browser JavaScript. Its keep/drop inventory — verified against k3s — draws the line between what a single-node fleet can shed and what it must keep.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags