Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Daytona's Customer-Managed Compute: What 'Bring Your Own Hetzner Account' Actually Costs and Controls
Daytona lets you point its control plane at your own cloud account instead of theirs. Here's what that customer-managed compute tier still costs, still controls, and where it's a genuine middle ground versus renting trust.

Your Cursor Sandbox Was Never the Thing Protecting You: Inside DuneSlide's Zero-Click RCE
Two CVSS 9.8 bugs in Cursor let a zero-click prompt injection escape the sandbox and reach full code execution. The real lesson isn't the sandbox bug — it's that the agent held the developer's standing machine permissions the whole time.

Crossplane's API-First Infrastructure Bet: What Agent-Operated Infra via Declarative CRDs Gets Right That a REST Deploy API Doesn't
CNCF's case for Crossplane says AI agents operate better against Kubernetes-style CRDs than a REST deploy API. Here's the mechanism-by-mechanism reason why, what the tradeoff actually costs, and what a Render-compatible API should borrow from it.

Kubernetes Can Checkpoint Your Containers Now — It Still Can't Restore Them
Kubernetes can freeze a running container to disk today. It cannot restore one natively. A capability matrix, the GPU and security gaps behind it, and what sandbox vendors built instead while they waited.

Coolify, Dokploy, and CapRover Hit a Docker Swarm Ceiling
Coolify, Dokploy, and CapRover get a solo developer to a running app fast — but a side-by-side of node failure recovery, storage, and tenant isolation shows exactly where their shared Docker Swarm architecture caps out, and when a Cluster API-provisioned fleet is worth the switch.

Coolify Fixed 11 Critical CVEs in January. The Same Root Cause Struck Again in July
Coolify patched 11 critical CVEs at CVSS 9.4-10.0 in January 2026, then shipped a fix for the same root-cause bug class in July. Here's what the repeat says about single-daemon PaaS architecture versus RBAC-scoped, Kubernetes-native control planes.

CNCF's 2026 Platform Engineering Report Says 35% of Teams Bolt AI Onto What They Already Have — Is 'AI-Native From Day One' the Wrong Pitch?
The report's 35% hybrid-platform stat looks like a case against AI-native architecture. Priced out against what hybrid actually costs in auth, golden paths, and governance, it reads the opposite way.

Cluster API Provider OpenStack Ships v1beta2 Behind a New ORC Dependency: What Declarative Fleet Lifecycle Looks Like on Private OpenStack Instead of Hetzner
CAPO's new v1beta2 API ships behind a hard dependency on openstack-resource-controller — here's what continuous reconciliation buys a Cluster API fleet on private OpenStack that Terraform-on-OpenStack can't, and why the model was never Hetzner-specific to begin with.

CloudNativePG 1.30's DatabaseRole CRD and Lease Election: What Changes for a Self-Hosted PaaS's Postgres Layer
CloudNativePG 1.30 ships a declarative DatabaseRole CRD and a Lease-based primary election, plus two CVE fixes, right as the 1.28.x line hits end of life — here's what that concretely changes for a PaaS running CNPG as its own managed-Postgres engine.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags