Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Headscale at 40,000+ Stars: Mesh Your Multi-Region Fleet Without Anyone Else's Control Plane
Headscale passed 43,000 GitHub stars as the open-source, self-hosted Tailscale control server. A concrete build for meshing a multi-region fleet — embedded DERP, pre-auth keys, per-site subnet routers, ACLs in git — plus the single-instance HA catch and the cost math against Tailscale's 2026 per-user pricing.

Your 8B Model Isn't Dumb. Its Harness Is: Forge's 53%-to-99% Guardrail Lesson for Platform Ops
Forge's May 2026 result took an 8B model from 53% to 99.3% on agentic tasks with guardrails alone — beating unguardrailed Claude Sonnet outright. What the retry-nudge math, the 75-point serving-backend swing, and a worked token-vs-hardware breakeven mean for running platform-ops agents on a self-hosted GPU.

Coolify's Zero-Downtime Asterisk: Why Every Docker Compose Deploy Still Goes Down
Coolify deploys single-container apps with zero downtime but takes Docker Compose stacks offline on every deploy — a 10-to-30-second 502 window. The mechanical reason runners can't do what orchestrators get for free, where Dokploy's Swarm bet fits, and the four questions that cut through any self-hosted PaaS feature matrix.

Your Build Takes 4 Minutes and Nobody Knows Why: What Cloud Native Buildpacks' RFC 0131 Would Itemize
Deploy-from-git builds report success or failure and nothing else — no per-buildpack timing, no cache-hit signal, no failure attribution. RFC 0131 would fix that with opt-in OpenTelemetry traces per phase and buildpack, and a self-hosted PaaS can turn them into tenant-facing build receipts plus fleet-wide dashboards.

Render Traded $19 Seats for a $0.15/GB Meter: A 20-Person Team's Bill at 1TB, 2TB, and 5TB
Render's August 1 rollout swapped $19 per-seat pricing for a $25 flat Pro plan with unlimited members — and cut included bandwidth from 500GB to 25GB at $0.15/GB over. A worked before/after bill for a 20-person team at 1TB, 2TB, and 5TB, the small-team cases that pay more, and what the same traffic costs on owned hardware.

SmolVM vs. Firecracker: Which MicroVM Should Actually Isolate Your AI Agent's Code?
SmolVM's sub-200ms boot challenges Firecracker's two-year default. A measured comparison of boot time, memory density, and what actually isolates untrusted agent code from the host kernel across SmolVM, Firecracker, OpenSandbox, and Docker Sandboxes.

Kubernetes Metrics API Is Stable in v1.37: What a Self-Hosted PaaS Must Expose Before Agents Can Safely Autoscale Apps
Kubernetes 1.37 made the Metrics API stable, but stability doesn't make it safe for an AI agent to autoscale on. Here's the isolation, staleness, and admission contract a self-hosted PaaS needs first.

The Heroku Exit Playbook: Procfile to Buildpack, Every Add-on Decision, and the Real Before/After Bill
A step-by-step playbook for actually leaving Heroku's sustaining-engineering mode: Procfile to manifest, add-ons sorted into keep/replace/lose, secrets without a leak window, a rehearsed database cutover, and a real before/after bill.

Run a Claude Fable Security Scan with Bex Security
Run a Claude Fable security scan with Claude Code and Bex Security. The exact command, the model row that actually runs, and the sandbox policy Bex enforces around Claude.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags