Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Why Self-Hosted PaaS Secrets Managers Still Default to Plaintext Env Vars: A Survey of Coolify, Dokploy, and CapRover
Coolify, Dokploy, and CapRover all hand your production credentials to anyone with dashboard access — a feature-by-feature survey of how each stores secrets, why plaintext env vars are an architectural default, and what a Sealed Secrets or External Secrets Operator pattern on Kubernetes buys instead.

Kubernetes Just Buried Its Own Dashboard: Why Headlamp Is Now the Default Operator UI for a CAPI-Managed Fleet
The Kubernetes Dashboard is archived and the project's own blog now points operators to Headlamp. What the June 2026 migration guide and the new Cluster API plugin mean for a CAPI-managed fleet: which plugin features cover which operator surfaces, and when embedding Headlamp beats building a bespoke dashboard.

IPv6-Only Worker Nodes on Hetzner: What Dropping the €0.50 IPv4 Line Item Saves a 10–50 Node Fleet, and What Breaks First
Hetzner bills every primary IPv4 at €0.50/month while IPv6 is free. The real savings math for a 10-50 node CAPH fleet after the June 2026 repricing, why GitHub and ghcr.io break first on IPv6-only nodes, and the four bridges — public NAT64, Jool, a NAT gateway, or a registry cache.

Gateway API v1.5 Moves Gateway Merging to Stable: One Load Balancer, Many Tenant Apps, No Ingress Controller Sprawl
Gateway API v1.5 graduates ListenerSet, letting one platform-owned Gateway and a single load balancer carry every tenant's HTTPS listeners with tenant-owned certificates. The before/after topology, a working YAML example, the Hetzner LB cost math, and the admission work the merged model shifts onto your control plane.

Nine Seconds, Zero Backups: What the PocketOS Wipe Demands From a PaaS That Doesn't Manage Your Database
A Cursor agent deleted PocketOS's production database and every backup in nine seconds. The real failures were architectural: co-located backups and an omnipotent API token. Here is the backup design that survives a rogue agent — and what a PaaS that doesn't manage your database still owes you.

Cilium Becomes the Default Kubernetes CNI Everywhere but AWS: What eBPF Networking Buys a Self-Hosted PaaS on Hetzner
GKE and AKS now run Cilium by default while EKS holds out — here's what eBPF service routing, Hubble flow observability, and identity-based network policy actually buy a self-hosted PaaS on Hetzner bare metal, with the benchmarks, memory costs, and a decision table.

Backstage's DevLake-to-DORA Plugin Puts a Standard DORA Card on Every Service — Here's What That Means for a Self-Hosted PaaS
A new DevLake-to-DORA backend module puts deployment frequency, lead time, change failure rate, and recovery time on every Backstage service page. Here is how it works, where each number comes from, and how a self-hosted PaaS wires its own deploy API into the card with one webhook and an annotation.

Cluster API v1.12's In-Place Updates and Chained Upgrades: What Changes for a Platform Team Running CAPH/CAPD in Production
Cluster API v1.12 shipped in-place updates and chained upgrades. For a 3-control-plane, 20-worker Hetzner fleet jumping three Kubernetes minors, that turns 29 replace-and-drain cycles under best pre-v1.12 practice into as few as zero — and three hand-sequenced hops into one declared version. The before/after runbook, with the CAPD rehearsal loop.

Flagger vs Argo Rollouts in 2026: Which Progressive-Delivery Operator Should Power a Git-Push PaaS's Canary Rollouts?
Flagger and Argo Rollouts shipped releases three days apart in July 2026, but they make opposite bets: wrap the Deployment or replace it, headless reconciler or human dashboard. A build-vs-choose comparison of each operator's stack assumptions, with a concrete verdict for a git-push PaaS on a Cluster API fleet.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags