Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

The "PaaS-First, Kubernetes as Exception" Narrative of 2026 Misses the Platforms Built on Kubernetes You Never See
Coolify and CapRover are cited as proof self-hosting should default to a single-node PaaS with Kubernetes as the exception. But Render, Railway, and Heroku Fir all run on Kubernetes underneath a git-push UX you never see — here's what a Cluster-API-managed fleet gets you that Docker Swarm structurally can't.

OVHcloud's Bare Metal Barely Moved in 2026 — Hetzner's Cloud VMs Didn't Get So Lucky
OVHcloud's VPS price jumped 44.5% in 2026 and its Bare Metal line only rose 5-16% — the same split Hetzner shows between its hammered CCX cloud instances and its barely-touched AX dedicated servers. A spec-matched price table shows where the 2026 DRAM shock actually lands.

OpenTelemetry Graduates CNCF in May 2026: Why Self-Hosted Collectors Beat Egress-Metered Observability SaaS
OpenTelemetry's May 2026 CNCF graduation locked in OTLP as the universal interchange format, and the cost gap it exposed between egress-metered SaaS and self-hosted collectors runs 38x to 166x depending on scale — with worked numbers to prove it.

Kubernetes Swap Went Stable in 1.34: What LimitedSwap Actually Buys a Self-Hosted PaaS on NVMe
Kubernetes' node swap support graduated to stable in 1.34. A walkthrough of what LimitedSwap actually protects against, what it doesn't, and the concrete tenant-density math it unlocks on a Hetzner NVMe node that a fixed-instance managed PaaS can't touch.

Kubernetes Quietly Corrected Three 'Fixed' CVEs That Were Never Patched — What That Means for Your Cluster's Threat Model
Kubernetes just admitted three CVE records carried a fake 'fixed' field for years — a concrete look at what the correction reveals about trusting scanner output, and the version-pinned scanning check a Cluster-API fleet needs instead.

OCI VolumeSource Goes Stable in Kubernetes 1.36: Do You Still Need to Bake Large Assets Into Your App Image?
Kubernetes 1.36 made OCI VolumeSource stable, letting a Pod mount any OCI image as a read-only volume. Here's the honest before/after against a well-cached Dockerfile, a worked build-pipeline split, and what a self-hosted platform must verify before offering it to tenants.

Kubernetes 1.36's Declarative Validation Went GA — But Not for the CRDs Your Agent Actually Writes To
Kubernetes 1.36 graduated Declarative Validation to GA — for built-in types only. The CEL rules that actually govern your CRDs have been GA since 1.29. Here's the real timeline, a worked example from Cluster API's own CRDs, and what it means for an agent generating manifests.

Kelos Turns Autonomous Coding Agents Into Kubernetes CRDs
Kelos turns an AI coding agent's entire working context into four Kubernetes CRDs you can kubectl get and git-revert. Here's what each primitive actually does, and the concrete case for treating it as a reference architecture rather than a dependency.

KEDA's Scale-to-Zero: What It Actually Buys a Self-Hosted PaaS Billing Tenants for Idle Containers
A dormant tenant app held at a minimum of one replica costs real money — on Railway's metered pricing, about $30/month for a 1 vCPU/1GB container that serves zero requests. Here's what wiring KEDA's true scale-to-zero into a Cluster API fleet actually changes, in dollars and in cold-start seconds.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags