Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

CloudNativePG's Snapshot PITR Can Restore a Multi-TB Postgres in Minutes — Hetzner's CSI Driver Still Can't Take the Snapshot
·Dora Noda·9 min

CloudNativePG's Snapshot PITR Can Restore a Multi-TB Postgres in Minutes — Hetzner's CSI Driver Still Can't Take the Snapshot

CloudNativePG's snapshot-based backup can restore a multi-terabyte Postgres cluster in minutes, but Hetzner's own CSI driver has never implemented volume snapshots. Here's what actually runs on Hetzner today — the Barman Cloud Plugin path — and when swapping in Piraeus/LINSTOR for snapshot support is worth the operational cost.

self-hosting
PaaS
infrastructure
engineering
+1
CloudNativePG's First CVE Is a 9.4: How Scraping Metrics Handed Out Postgres Superuser
·Dora Noda·10 min

CloudNativePG's First CVE Is a 9.4: How Scraping Metrics Handed Out Postgres Superuser

CloudNativePG's first-ever CVE let a low-privileged database user escalate to PostgreSQL superuser and OS command execution through the default metrics exporter — the exploit chain, the fix, and the unrelated failover bug that shipped in the same release.

cybersecurity
self-hosting
PaaS
Kubernetes
+1
Cloudflare Tunnel Is Now Fully Free — What Zero-Open-Ports Ingress Means for Your Self-Hosted PaaS
·Dora Noda·9 min

Cloudflare Tunnel Is Now Fully Free — What Zero-Open-Ports Ingress Means for Your Self-Hosted PaaS

Cloudflare Tunnel is now free with unmetered bandwidth and unlimited tunnels — but an October 5, 2026 API change breaks anything scripted against its old routes. Here's what it buys a self-hosted PaaS's tenants, what it costs, and the migration checklist.

self-hosting
PaaS
infrastructure
security
Cloudflare R2 Was Down for 17 Hours in July 2026 — Here's What 'Zero Egress' Actually Costs When It Breaks
·Dora Noda·8 min

Cloudflare R2 Was Down for 17 Hours in July 2026 — Here's What 'Zero Egress' Actually Costs When It Breaks

Cloudflare R2 returned 500 errors across three separate incidents in July 2026, blowing past its own 99.9% SLA by roughly 30x in one month. Here's the SLA math, a worked cost comparison against Hetzner-owned object storage, and the exact egress volume where R2's free-egress pricing actually starts winning.

self-hosting
PaaS
infrastructure
cloud computing
+1
Cloudflare Containers Went GA on 128MB-Workers Money: What Per-10ms Billing Actually Costs a Real Backend
·Dora Noda·8 min

Cloudflare Containers Went GA on 128MB-Workers Money: What Per-10ms Billing Actually Costs a Real Backend

Cloudflare Containers left beta on April 13, 2026 billing every 10ms of active CPU on top of the $5/mo Workers Paid plan. A worked recompute: what a persistent backend actually costs on that meter versus a flat €5.49/mo owned Hetzner box — and the bursty workload where Containers wins outright.

PaaS
self-hosting
infrastructure
cost-optimization
Cilium's Sidecarless mTLS Kills the Service-Mesh Tax — But Not the Way You'd Assume
·Dora Noda·10 min

Cilium's Sidecarless mTLS Kills the Service-Mesh Tax — But Not the Way You'd Assume

Real numbers on what a sidecar mesh actually costs, how Cilium's eBPF mTLS removes it, and the eventually-consistent identity cache that a documented security review found exploitable — plus what a multi-tenant self-hosted PaaS should actually run.

self-hosting
PaaS
security
infrastructure
cgroup v1 Is About to Break Your Kubernetes Nodes: A Migration Checklist Before August 26, 2026
·Dora Noda·8 min

cgroup v1 Is About to Break Your Kubernetes Nodes: A Migration Checklist Before August 26, 2026

Kubernetes v1.37 makes kubelet refuse to boot on cgroup v1 nodes by default. Here's the exact command to check your fleet, what changes in tenant CPU/memory enforcement, and a migration checklist before the August 26, 2026 deadline.

infrastructure
engineering
PaaS
self-hosting
Your Tenants' 'edit' Role Could Steal Another Tenant's DNS Credentials: The cert-manager Challenge Bug and the RBAC Audit to Run Today
·Dora Noda·8 min

Your Tenants' 'edit' Role Could Steal Another Tenant's DNS Credentials: The cert-manager Challenge Bug and the RBAC Audit to Run Today

A cert-manager bug let any tenant with Kubernetes' built-in edit or admin role steal another tenant's DNS credentials through a crafted ACME Challenge — not from a misconfiguration, but from an RBAC aggregation label almost no one audits. Here's the mechanism and a six-check audit to run against your own multi-tenant TLS setup.

security
Kubernetes
self-hosting
PaaS
+1
Kaniko Is Archived: What Actually Changes When a Buildpacks Pipeline Switches to Buildah
·Dora Noda·9 min

Kaniko Is Archived: What Actually Changes When a Buildpacks Pipeline Switches to Buildah

Google archived Kaniko in June 2025 and its Chainguard fork is maintenance-only. Here's exactly what changes in a Kubernetes build pod's spec, caching architecture, and registry auth when a buildpacks-based PaaS switches its Dockerfile-fallback builder to Buildah — and the one dependency on Kaniko you can't migrate away from.

self-hosting
PaaS
infrastructure
engineering
Showing 1396–1404 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags