Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

PSI Metrics Reach GA in Kubernetes 1.36: What Your Node's CPU/Memory Graphs Have Been Hiding
Kubernetes 1.36 graduates PSI metrics to GA, but the kubelet's own eviction manager still doesn't read them. Here's the exact wiring a self-hosted, Cluster-API-managed fleet needs to build itself — and the CPU-PSI gotcha that will burn you if you skip it.

Incus as a Cluster API Node Substrate: A Real Provider, a Narrow Case, and a Default You Should Flip
cluster-api-provider-incus already exists and already works — but it defaults to privileged containers, ships pre-1.0, and doesn't beat gVisor/Kata on the isolation question that matters most. Here's the concrete case for and against exposing it.

GhostApproval: The AI Coding Agent Flaw That Turned 'Approve This Edit?' Into a Rubber Stamp
Wiz's GhostApproval disclosure shows six AI coding assistants following symlinks out of their sandboxes while their approval dialogs described a different file than the one being written. Three vendors patched it; two said a patch isn't possible.

Your PaaS Bill Lied to You: The Hidden Line Items on Render, Railway, and Fly.io — and the Ones Self-Hosting Doesn't Tell You About Either
Render, Railway, Fly.io, and Vercel all publish a sticker price — but egress, IPv4, and snapshot metering are what turn a bad month into a very different bill. Here's the real rate card, and the line items self-hosting doesn't put on its own homepage either.

Hetzner Tripled Some Cloud Tiers in 2026 — OVHcloud and Scaleway Didn't: A Line-by-Line Node-Pool Cost Comparison
Hetzner raised its dedicated-vCPU cloud tier up to 173% in 2026 while OVHcloud and Scaleway raised comparable tiers by single digits — a line-by-line node-pool cost comparison, and why multi-sourcing across Cluster API providers is the real hedge.

Vercel's Coding Agents Now Trigger Half of All Deployments: What a Platform Sized for Humans Has to Rebuild
Vercel's coding-agent-triggered deployments went from under 3% to over 50% of all deploys in six months. Here's the concrete build-queue, concurrency, and preview-URL math a human-sized deploy pipeline never had to do — and what changes when the platform treats an MCP tool call and a git push as the same event from day one.

Render's Aug 1, 2026 Repricing Deadline: What Auto-Migrating to Flat Fees and a 25GB Egress Cap Actually Costs You vs a Self-Hosted Fleet
Render auto-migrates every legacy workspace to flat-fee pricing on August 1, 2026. The math splits sharply by seat count and egress — here's the exact breakeven, and what the same traffic costs on a self-hosted box instead.

Railway Killed the Builder It Built: What Railpack's Nix-to-BuildKit Rewrite Means for a Self-Hosted PaaS's Buildpack Bet
Railway shipped Railpack in March 2026 to replace Nixpacks, the builder it built and open-sourced. The result: 38% smaller Node images, 77% smaller Python images, and a language-coverage gap at launch. Here's what the Nix-to-BuildKit rewrite actually changed, and what it means for a self-hosted PaaS choosing between Railpack and Cloud Native Buildpacks.

PaaS-First Killed Kubernetes-by-Default in 2026 — Except Underneath
The 2026 shift to 'PaaS-first, Kubernetes is the exception' quietly crowns single-server tools like Dokku and CapRover as the correct answer. A three-layer breakdown of who actually holds Kubernetes's complexity shows why a Cluster API-backed PaaS was never the thing that consensus rejected.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags