Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Your MCP Server Lost Its Confirmation Prompt on July 28: Rebuilding the Delete Gate on input_required
·Dora Noda·10 min

Your MCP Server Lost Its Confirmation Prompt on July 28: Rebuilding the Delete Gate on input_required

The 2026-07-28 MCP spec deleted server-initiated requests, and with them the only way a destructive tool could stop and ask a human. Here is the replacement on the wire: a delete_service gate built on resultType input_required, the signed requestState ticket that survives a round-robin load balancer, and the once-only guarantee the protocol makes your problem.

Model Context Protocol
AI agents
security
infrastructure
+1
Kubernetes Finally Has a Checkpoint/Restore Working Group. Here's What Pausing a Mid-Task Agent Sandbox Actually Saves
·Dora Noda·10 min

Kubernetes Finally Has a Checkpoint/Restore Working Group. Here's What Pausing a Mid-Task Agent Sandbox Actually Saves

A line-by-line cost model for pausing idle AI agent sandboxes on Kubernetes: PVC hibernation already captures 67% of the savings, CRIU checkpoint/restore is worth a further 59%, and today's kubelet checkpoint API can't deliver either.

Kubernetes
AI agents
cost-optimization
infrastructure
+1
Hetzner Removed the EC2-Compatible Metadata Routes on August 1 — Every Bootstrap Script Still Curling /latest/ Is Now Broken
·Dora Noda·9 min

Hetzner Removed the EC2-Compatible Metadata Routes on August 1 — Every Bootstrap Script Still Curling /latest/ Is Now Broken

On August 1, 2026 Hetzner removed the EC2-compatible /latest/ and /2009-04-04/ metadata routes, breaking every bootstrap script that inherited the AWS curl idiom. The full route-by-route migration table, a repo audit command, and the CAPH preKubeadmCommands diff that fixes it.

Kubernetes
self-hosting
PaaS
infrastructure
+1
Hetzner Unfroze the 50-Second Load Balancer Idle Timeout — Your Build Logs Will Still Die at 15 Seconds
·Dora Noda·10 min

Hetzner Unfroze the 50-Second Load Balancer Idle Timeout — Your Build Logs Will Still Die at 15 Seconds

Hetzner made its 50-second load balancer idle timeout configurable in April 2026, but on a Kubernetes stack it is rarely the rung that kills your log stream. The full timeout ladder — with real defaults, the idle-vs-total distinction, and the heartbeat math that survives all of it.

Kubernetes
self-hosting
PaaS
infrastructure
+1
Hetzner Is Building an LLM Inference API: What €889/Month of GPU and a Free Experimental Endpoint Do to the Self-Hosted AI Math
·Dora Noda·16 min

Hetzner Is Building an LLM Inference API: What €889/Month of GPU and a Free Experimental Endpoint Do to the Self-Hosted AI Math

Hetzner is testing an OpenAI-compatible inference API alongside its €889/month RTX PRO 6000 GEX131 — what the experiment changes for self-hosted AI rent-vs-own math, EU sovereignty, and running inference as a regular tenant workload.

AI
LLM
self-hosting
infrastructure
+1
Field Is Immutable: Why helm upgrade Dies at the API Server, and Which Escape Hatch Actually Scales
·Dora Noda·10 min

Field Is Immutable: Why helm upgrade Dies at the API Server, and Which Escape Hatch Actually Scales

A community Helm chart renames one label and your upgrade dies in the API server's validation path. Here is the full table of immutable Kubernetes fields with their exact error strings, the five ways out priced against each other, and the fleet size where a platform operator finally beats the runbook.

Kubernetes
self-hosting
PaaS
infrastructure
+1
What a Git-Push PaaS Should Actually Clone: Shallow vs Partial Clones and What Checkout Time Adds to Every Build
·Dora Noda·11 min

What a Git-Push PaaS Should Actually Clone: Shallow vs Partial Clones and What Checkout Time Adds to Every Build

Shallow clones are 4-6x faster and the industry default, but they break versioning tools and make every later fetch 25x more expensive. Benchmarks, real PaaS defaults from Render to Heroku, and the break-even point where blobless partial clones win.

PaaS
self-hosting
developer tools
engineering
+1
The Entrypoint You Didn't Write: Buildpacks Is Moving Its 2.9 MB Launcher Into the Run Image and Rewriting It in Rust
·Dora Noda·13 min

The Entrypoint You Didn't Write: Buildpacks Is Moving Its 2.9 MB Launcher Into the Run Image and Rewriting It in Rust

Every buildpack-built image runs a 2.9 MB Go binary you never chose, and it is why your scanner is red. Two open CNB RFCs would move it into the run image and rewrite it in Rust — here is what each one actually fixes, and what it does not.

self-hosting
PaaS
security
developer tools
+1
Bring Your Own Hetzner Account: Edka, Cluster API, and the Token With Only Two Permission Levels
·Dora Noda·11 min

Bring Your Own Hetzner Account: Edka, Cluster API, and the Token With Only Two Permission Levels

A 3-node Hetzner cluster priced three ways — closed PaaS, a BYO-account control plane, and DIY Cluster API — plus the uncomfortable detail underneath all of it: a Hetzner API token has exactly two permission levels and one scope.

Kubernetes
self-hosting
PaaS
security
+1
Showing 1189–1197 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags