Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

CPU Lies: What a Git-Push PaaS Should Autoscale Tenants On Instead
·Dora Noda·11 min

CPU Lies: What a Git-Push PaaS Should Autoscale Tenants On Instead

CPU sits at 35% while your service melts — because it was waiting, not working. A concrete pipeline for autoscaling tenants on in-flight requests and queue depth, the adapter-vs-KEDA decision, multi-tenant guardrails, and what Render and Railway get right.

self-hosting
PaaS
Kubernetes
scalability
Borrow the Claim, Skip the Cloud Sprawl: What Crossplane's Modelplane Teaches a Self-Hosted PaaS About GPU APIs
·Dora Noda·8 min

Borrow the Claim, Skip the Cloud Sprawl: What Crossplane's Modelplane Teaches a Self-Hosted PaaS About GPU APIs

Modelplane puts GPU inference fleets behind a Crossplane claim API so teams request an endpoint, not a machine. The before/after YAML, a six-row borrow-vs-skip table for a Hetzner CAPI fleet, and the €184/mo card math that decides it.

Kubernetes
PaaS
self-hosting
AI
Coolify v5's Multi-Server Bet: What the Most Popular Single-Box PaaS Hitting Its Ceiling Teaches About Cluster Orchestration
·Dora Noda·11 min

Coolify v5's Multi-Server Bet: What the Most Popular Single-Box PaaS Hitting Its Ceiling Teaches About Cluster Orchestration

Coolify named multi-server scalability as v5's core feature — with no release date. A concrete accounting of what a second server buys you in v4 today, what v5 is actually building, and why the gap is a scheduler-shaped hole only cluster orchestration fills.

self-hosting
PaaS
Kubernetes
One Token, Seven Tools, Total Access: What a Czech Community's Coolify MCP Bridge Teaches About Agent-Operated Self-Hosting
·Dora Noda·11 min

One Token, Seven Tools, Total Access: What a Czech Community's Coolify MCP Bridge Teaches About Agent-Operated Self-Hosting

A Czech community's 200-line MCP bridge lets AI agents operate Coolify apps from AnythingLLM behind a single bearer token, no permission model, and TLS verification off. A code-level inventory of its seven tools and the guardrail checklist that separates homelab experiments from tenant-ready agent platforms.

PaaS
self-hosting
AI agents
Model Context Protocol
containerd 2.1 Is Dead and the CVE Has No Patch: Rolling a Forced Runtime Upgrade Across a Cluster API Fleet
·Dora Noda·9 min

containerd 2.1 Is Dead and the CVE Has No Patch: Rolling a Forced Runtime Upgrade Across a Cluster API Fleet

containerd 2.1 went end-of-life with no patch for Critical CVE-2026-46680, a runAsNonRoot bypass. Which versions are safe, how to pick a landing zone, and the five-step Cluster API runbook: audit, image, template, roll, verify.

Kubernetes
security
self-hosting
guide
Cloudflare's Agents Week 2026 Is a Requirements Doc for Agent Infrastructure: A Self-Hosted Reading
·Dora Noda·10 min

Cloudflare's Agents Week 2026 Is a Requirements Doc for Agent Infrastructure: A Self-Hosted Reading

Cloudflare's August 2026 Agents Week maps, day by day, everything AI agents need from infrastructure — per-task computers, machine-readable APIs, per-agent identity, and a way to pay. Each item translated into what it takes to run it on machines you own, with an honest ledger of what shipped versus what is still beta.

AI agents
self-hosting
PaaS
Model Context Protocol
+1
Rent the Session or Own the Process? What Anthropic's Managed Agents Mean for Self-Hosted Agent Sandboxes
·Dora Noda·11 min

Rent the Session or Own the Process? What Anthropic's Managed Agents Mean for Self-Hosted Agent Sandboxes

Anthropic's Managed Agents API rents you the agent session — sandbox, state, and audit trail included — while the Agent SDK leaves all of that on your machines. A side-by-side of the five platform bills, the worked cost math showing tokens dwarf the session fee, and what a self-hosted PaaS should copy.

AI agents
Claude
self-hosting
cost-optimization
Buildpacks RFC 331: Getting the Extend Phase Off Vendored Kaniko
·Dora Noda·11 min

Buildpacks RFC 331: Getting the Extend Phase Off Vendored Kaniko

A Dockerfile hides inside every Dockerfile-free buildpack build — applied by a kaniko copy baked into the lifecycle image. RFC 331 would pull the extender out behind a configurable URI; Chainguard's kaniko fork bought time but didn't fix the coupling. The before/after table and the six-item operator checklist.

self-hosting
PaaS
Kubernetes
security
One Script, Five Hours, Three Dead Layers: What Azure's West US Outage Reveals About the Shared Fate Inside Every Managed Region
·Dora Noda·9 min

One Script, Five Hours, Three Dead Layers: What Azure's West US Outage Reveals About the Shared Fate Inside Every Managed Region

On July 23, 2026, a maintenance-automation bug deleted network routes across Azure West US for five hours, taking down AKS, managed Postgres, and ingress together. Why zone redundancy couldn't help, what multi-region survival actually costs, and what owned hardware decouples.

self-hosting
PaaS
Kubernetes
cloud infrastructure
Showing 919–927 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags