Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

MCP Governance for Deploy APIs: A Playground-to-Production Control Plane
·Dora Noda·10 min

MCP Governance for Deploy APIs: A Playground-to-Production Control Plane

A practical Playground-to-production lifecycle for MCP deploy tools, with catalog review, policy-gateway controls, audience-bound tokens, approvals, and audit trails.

AI agents
Model Context Protocol
security
infrastructure
MCP Calls the Control Plane; A2A Coordinates the Investigation
·Dora Noda·9 min

MCP Calls the Control Plane; A2A Coordinates the Investigation

A concrete design for using MCP for audited PaaS actions and A2A for agent-to-agent deployment investigations without sharing a blanket infrastructure token.

AI agents
AI
cloud infrastructure
self-hosting
CVE-2026-35469: Audit SPDY Exposure in Your Self-Hosted Kubernetes Fleet
·Dora Noda·8 min

CVE-2026-35469: Audit SPDY Exposure in Your Self-Hosted Kubernetes Fleet

CVE-2026-35469 affects a SPDY dependency, not a single Kubernetes version. Use this practical audit to identify reachable parsers, verify vendor fixes, and roll self-hosted nodes safely.

Kubernetes
security
self-hosting
infrastructure
Karpenter on Bare Metal Is Not Magic: The Supply Chain Behind a NodeClaim
·Dora Noda·11 min

Karpenter on Bare Metal Is Not Magic: The Supply Chain Behind a NodeClaim

A NodeClaim can choose capacity; only an automatable machine supply can deliver it. Follow a realistic burst from pending Pod to Ready bare-metal worker.

Kubernetes
infrastructure
self-hosting
PaaS
Hetzner DNS Makes `ttl` Mandatory: Audit the One ACME Call That Can Break Renewal
·Dora Noda·9 min

Hetzner DNS Makes `ttl` Mandatory: Audit the One ACME Call That Can Break Renewal

Hetzner Cloud DNS will require an explicit TTL on one RRSet action after September 30, 2026. Identify whether your ACME path uses it, patch the request correctly, and rehearse a safe renewal.

cloud infrastructure
Kubernetes
self-hosting
security
Gateway API 1.6 Gives Agent Sandboxes a Named Egress Target—Not an Egress Policy
·Dora Noda·10 min

Gateway API 1.6 Gives Agent Sandboxes a Named Egress Target—Not an Egress Policy

Gateway API 1.6's experimental XBackend can make an AI API destination reviewable. Here is the complete control stack required to turn that declaration into safe sandbox egress.

AI agents
self-hosting
PaaS
Kubernetes
+1
Ethereum’s Economic Zone: A Composability Design—and the Revenue Model It Still Owes
·Dora Noda·10 min

Ethereum’s Economic Zone: A Composability Design—and the Revenue Model It Still Owes

Gnosis's proposed Ethereum Economic Zone targets atomic L1-L2 composability, but its public materials do not yet define a protocol-enforced revenue share.

Ethereum
layer-2
zkp
blockchain
Beam Chain Is Not ‘Ethereum 3.0’: A 2026 Reality Check on Faster Slots, Staking, and Quantum Safety
·Dora Noda·9 min

Beam Chain Is Not ‘Ethereum 3.0’: A 2026 Reality Check on Faster Slots, Staking, and Quantum Safety

Beam Chain is a research direction, not an approved Ethereum release. See what faster finality, staking changes, and quantum safety would actually require in 2026.

Ethereum
staking
cryptography
blockchain
CI Runner Pricing in 2026: Depot, Blacksmith, and the Cost of Reserving Your Own Build Capacity
·Dora Noda·8 min

CI Runner Pricing in 2026: Depot, Blacksmith, and the Cost of Reserving Your Own Build Capacity

A reproducible CI-runner cost model across 2, 8, and 20 concurrent jobs: current Depot and Blacksmith pricing beside the fixed cost of reserving self-hosted build nodes.

self-hosting
PaaS
cost-optimization
Kubernetes
Showing 1036–1044 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags