Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Bitwarden's July 2026 Update Broke Every Vaultwarden Overnight: The Real Cost of Reimplementing a Protocol You Don't Own
·Dora Noda·9 min

Bitwarden's July 2026 Update Broke Every Vaultwarden Overnight: The Real Cost of Reimplementing a Protocol You Don't Own

Bitwarden's 2026.7.0 client silently repurposed a wire-format field Vaultwarden had emitted for eight years, breaking every self-hosted deployment overnight. A concrete cost accounting of running a compatible reimplementation of a protocol you don't control — and why bex's Render-compatible API carries the same risk.

self-hosting
security
infrastructure
engineering
AWS DevOps Agent Goes GA But Still Can't Deploy the Fix: The Diagnose-Not-Act Line
·Dora Noda·10 min

AWS DevOps Agent Goes GA But Still Can't Deploy the Fix: The Diagnose-Not-Act Line

AWS DevOps Agent reached GA finding root causes in minutes — but it still refuses to execute the fix. Why every enterprise agentic-ops vendor stops at diagnosis, and the five pieces of platform machinery needed before an AI agent can safely deploy the rollback itself.

AI agents
Enterprise AI
PaaS
infrastructure
+1
Webhook Signature Verification for Git-Push Deploys: What a Self-Hosted PaaS Has to Get Right That GitHub's Own Docs Gloss Over
·Dora Noda·11 min

Webhook Signature Verification for Git-Push Deploys: What a Self-Hosted PaaS Has to Get Right That GitHub's Own Docs Gloss Over

On a git-push PaaS, the webhook endpoint is a remote build trigger — and HMAC verification is its entire security boundary. A 10-point audit checklist covering the raw-body trap, the === timing leak, the timingSafeEqual length-throw, the SHA-1 header ghost, and the replay gap GitHub's docs never assemble into one place.

security
PaaS
self-hosting
guide
Solana's Kora Fee Relayer: Gasless UX in Any SPL Token — and Who Actually Pays the Bill
·Dora Noda·11 min

Solana's Kora Fee Relayer: Gasless UX in Any SPL Token — and Who Actually Pays the Bill

Kora, the Solana Foundation's audited fee relayer, lets users transact with zero SOL by paying fees in USDC or any SPL token. How the five-step relay flow works, what a kora.toml node deployment looks like, why Ethereum needed ERC-4337 to match it — and who ends up holding the SOL bill.

Solana
infrastructure
account-abstraction
AI agents
Your Base Image Is Six Months Stale: Making Renovate's FROM-Line Patching a Self-Hosted PaaS Default
·Dora Noda·10 min

Your Base Image Is Six Months Stale: Making Renovate's FROM-Line Patching a Self-Hosted PaaS Default

A git-push PaaS rebuilds your app on every push — and never touches the FROM line between pushes. How a platform-run Renovate loop with digest pinning and health-gated automerge bounds base-image staleness from unbounded to about a day, the exact renovate.json to do it, and where the loop still falls short of buildpack rebase.

security
PaaS
self-hosting
infrastructure
Render Says Buildpacks Beat Your Dockerfile by 75%. Can Nixpacks or Paketo Match That on Your Own Hardware?
·Dora Noda·10 min

Render Says Buildpacks Beat Your Dockerfile by 75%. Can Nixpacks or Paketo Match That on Your Own Hardware?

Render's 75% faster-builds claim is standard Cloud Native Buildpacks layer caching, and both Paketo and Nixpacks reproduce it on hardware you own. What the number actually measures, the exact cache-image and cache-key commands for a fleet of ephemeral builders, and the five cache policies a shared build node platform needs.

PaaS
self-hosting
infrastructure
developer tools
Railway's July 2026 US East Outage: What One ISP's Bad Route Cost Every App — and What Owning the Network Costs Instead
·Dora Noda·11 min

Railway's July 2026 US East Outage: What One ISP's Bad Route Cost Every App — and What Owning the Network Costs Instead

One carrier's backbone degradation left every app in Railway's US East zone degraded for over four hours — including 20 minutes with no internet route at all. A worked breakdown of what the outage cost and what owning your own network path actually costs, from a €40 Hetzner box to a full ASN with dual transit.

PaaS
self-hosting
infrastructure
cost-optimization
Kubernetes v1.36 Ships Admission Policies That Can't Be Deleted: Closing the Bootstrap Window in Your Fleet's Guardrails
·Dora Noda·10 min

Kubernetes v1.36 Ships Admission Policies That Can't Be Deleted: Closing the Bootstrap Window in Your Fleet's Guardrails

Kubernetes v1.36's manifest-based admission control loads policies from files before the API server serves its first request — undeletable via any RBAC. What it forecloses for a multi-tenant self-hosted PaaS, and the Cluster API bootstrap sequencing that makes guardrails live before the first tenant pod.

Kubernetes
security
self-hosting
PaaS
+1
Your Cluster Runs at 8% CPU: Bin-Packing Defaults for a Self-Hosted Fleet That Can't Return Capacity
·Dora Noda·10 min

Your Cluster Runs at 8% CPU: Bin-Packing Defaults for a Self-Hosted Fleet That Can't Return Capacity

Cast AI's 2026 report puts average Kubernetes CPU utilization at 8% and memory at 20%. On elastic cloud that's an expensive bill; on owned hardware it's capacity you already paid for and can't return. Concrete request/limit defaults, a bin-packing scheduler config, and a worked Hetzner-vs-cloud cost delta.

Kubernetes
self-hosting
cost-optimization
infrastructure
Showing 1234–1242 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags