Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Pulumi Neo Is GA and Reads Your Terraform State Directly — Here's Why bex's Deploy API Won't
·Dora Noda·8 min

Pulumi Neo Is GA and Reads Your Terraform State Directly — Here's Why bex's Deploy API Won't

Pulumi Neo reads live Terraform and CloudFormation state directly and executes changes inside it. bex's MCP server calls a fixed, enumerable set of verbs instead. Here's the concrete case for why an agent that can create and destroy production infrastructure needs to know which shape it's actually operating under.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Your Node Buildpack's --ignore-scripts Flag Didn't Stop Phantom Gyp
·Dora Noda·7 min

Your Node Buildpack's --ignore-scripts Flag Didn't Stop Phantom Gyp

A June 2026 npm worm called Phantom Gyp bypassed --ignore-scripts entirely by hiding in binding.gyp instead of a lifecycle script — here's the exact mechanism, why it worked, and what a git-push buildpack needs to do instead of trusting one flag.

security
cybersecurity
self-hosting
PaaS
+1
Railway vs. Fly.io vs. Owning the Box: The Cost Comparison No PaaS Vendor Will Run For You
·Dora Noda·9 min

Railway vs. Fly.io vs. Owning the Box: The Cost Comparison No PaaS Vendor Will Run For You

Northflank's Railway-vs-Fly.io teardown never asks what the same workload costs on an owned Hetzner box — here's the post-price-hike math, tier by tier, including the one case where per-second billing is supposed to win.

PaaS
self-hosting
cost-optimization
infrastructure
+1
Kubernetes SIG Storage's Next Move Isn't Another Snapshot Feature: What Volume Health Monitoring and Mutable PV Affinity Actually Buy a Self-Hosted Fleet
·Dora Noda·8 min

Kubernetes SIG Storage's Next Move Isn't Another Snapshot Feature: What Volume Health Monitoring and Mutable PV Affinity Actually Buy a Self-Hosted Fleet

Kubernetes SIG Storage's Volume Health Monitoring and Mutable PV Affinity don't need Hetzner's still-missing CSI snapshot support to matter — but only one of them actually works on a self-hosted fleet today. Here's the verified breakdown of both KEPs, straight from the spec text and the driver source.

self-hosting
PaaS
Kubernetes
infrastructure
+1
Kubernetes 1.34 Ships KYAML: What a Safer YAML Subset Does (and Doesn't) Fix for a Manifest-Generating PaaS
·Dora Noda·8 min

Kubernetes 1.34 Ships KYAML: What a Safer YAML Subset Does (and Doesn't) Fix for a Manifest-Generating PaaS

Kubernetes 1.34 shipped KYAML to kill YAML's Norway-problem bugs, but the KEP is explicit that it's a kubectl output format, not a server-side change. Here's what that actually means for a platform generating Cluster API and tenant manifests programmatically.

Kubernetes
PaaS
self-hosting
infrastructure
Kubernetes' Partitionable GPU Devices (KEP-4815): The Real Cost Math Behind Slicing One GPU Into 7 Schedulable Sandboxes
·Dora Noda·8 min

Kubernetes' Partitionable GPU Devices (KEP-4815): The Real Cost Math Behind Slicing One GPU Into 7 Schedulable Sandboxes

Kubernetes' Partitionable Devices KEP lets one GPU serve multiple independently-scheduled sandboxes instead of one tenant. Here's the actual cost math on 7-way MIG slicing versus whole-card allocation, and what a Cluster API GPU node needs to expose those slices.

Kubernetes
self-hosting
PaaS
infrastructure
+1
Kubernetes 1.36's CRI List Streaming Doesn't Cut Kubelet Memory — It Removes a Hard Container-Count Wall Bin-Packed Nodes Actually Hit
·Dora Noda·8 min

Kubernetes 1.36's CRI List Streaming Doesn't Cut Kubelet Memory — It Removes a Hard Container-Count Wall Bin-Packed Nodes Actually Hit

KEP-5825's own text admits CRI List Streaming does not reduce kubelet memory usage. The real fix is a hard 11,000-container / 14,000-pod gRPC ceiling that's already bricked production nodes — and it matters more on a fixed Hetzner box than an autoscaling cloud fleet.

Kubernetes
self-hosting
PaaS
kro Just Landed in CNCF's 'Adopt' Tier Next to Helm — While Still Being Alpha Software
·Dora Noda·9 min

kro Just Landed in CNCF's 'Adopt' Tier Next to Helm — While Still Being Alpha Software

CNCF and SlashData's Q1 2026 Platform Engineering Radar put kro in the 'Adopt' tier alongside Helm and Backstage — a maturity signal for a project still shipping a v1alpha1 API. Here's the actual RGD YAML, what the rating measured, and what building a tenant-facing App CRD on kro's pattern would cost a Cluster API fleet.

self-hosting
PaaS
Kubernetes
infrastructure
+1
CVE-2026-24834: The Kata Containers Bug That Turned a Hardware Isolation Boundary Into a Config Default
·Dora Noda·7 min

CVE-2026-24834: The Kata Containers Bug That Turned a Hardware Isolation Boundary Into a Config Default

A container process with nothing but CAP_MKNOD got root inside a Kata Containers microVM meant to be hardware-isolated. Here's the exploit, the exact audit to run against your fleet, and why the fix was a config default, not a KVM flaw.

security
self-hosting
PaaS
Kubernetes
+1
Showing 1333–1341 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags