Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Convex's FSL License Bans Building a Competitor: What 'Open, Except to Compete With Us' Actually Costs You
Convex's backend is source-available under the Functional Source License — free to self-host, but banned from powering a competing hosted product for two years. Here's what that non-compete clause actually forecloses, concretely, versus a plain Apache-2.0 license.

containerd's June 2026 CRI Advisory: Three Ways to Escape a Shared Node That RuntimeClass Can't Stop
AWS's June 2026 bulletin disclosed five containerd CRI plugin CVEs, and patching the daemon — not picking gVisor or Kata for your RuntimeClass — is the only real fix. Here's what each bug requires and what a shared-node fleet needs to check this week.

CNCF's Platform Engineering Maturity Model Just Got a v2 — We Ran a Cluster-API PaaS Through All 5 Aspects
CNCF shipped a v2 of its Platform Engineering Maturity Model at KubeCon EU 2026. Here's what actually changed in the rubric, and a concrete, honest self-assessment of a Cluster-API git-push PaaS against all 5 aspects.

Cloud Run Worker Pools Hit GA With Blackwell GPUs: The Math Against an Owned Hetzner Box
Cloud Run Worker Pools went GA with Blackwell GPU support in the same window Fly.io announced it's exiting GPU hosting entirely. A line-by-line recompute of what an always-on Worker Pool actually bills against an owned Hetzner GPU box.

Chainguard and Wolfi Cross 2,000 Zero-CVE Images: Should a Self-Hosted PaaS Default to Them?
Chainguard's Wolfi-based images cut CVE counts from ~280 to zero and shaved 60-80% off build time and egress in a real migration. Here's what defaulting a git-push PaaS's build output to Wolfi would actually change — and the honest build-vs-buy call against Chainguard's paid catalog.

CVE-2026-25518: The cert-manager Bug That Lets a Poisoned DNS Reply Crash Your Whole TLS Pipeline
A crafted DNS response can crash the cert-manager controller mid-renewal. Here's exactly what CVE-2026-25518 breaks, why the fix isn't just an upgrade, and the two config changes a self-hosted PaaS's TLS automation needs today.

CAPH's Bare-Metal Hetzner Robot Servers vs Cloud VMs: The Real Cost Delta on a Cluster API Node Pool
A RAM-and-core-matched cost comparison of Hetzner Robot bare-metal servers against Hetzner Cloud VMs shows a 4.2x-5.6x price gap after 2026's cloud price hikes — and the concrete rule for which workloads belong on which side of a mixed CAPH node pool.

CAPH Quietly Renamed Its Annotations and Finalizers — Here's Every Old-to-New Key
CAPH renamed every annotation and finalizer key to match Kubernetes convention back in 2024 with zero announcement — here's the full old-to-new mapping, why finalizers self-healed but annotations didn't, and the grep to run before you trust either one.

Buildpacks Now Auto-Detect 80% of New Web Apps in 2026: What the Remaining 20% Actually Needs From a Real Dockerfile
Zero-config buildpacks now cover roughly 80% of new web apps with no Dockerfile at all — but native dependencies, unsupported runtimes, multi-stage builds, and monorepos make up the other 20%, and how a platform handles that failure, cleanly or not, is a design choice.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags