Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

MCP Goes Vendor-Neutral: What the Linux Foundation Handoff Actually Buys Down
·Dora Noda·8 min

MCP Goes Vendor-Neutral: What the Linux Foundation Handoff Actually Buys Down

Anthropic handed MCP's governance to a new Linux Foundation body, and the protocol's biggest breaking change yet ships in three weeks. Here's what actually changed, what didn't, and what it means for a platform betting on MCP as its agent interface.

Model Context Protocol
AI agents
governance
self-hosting
+1
MCP's Enterprise-Managed Authorization Goes Stable: What the ID-JAG Grant Fixes and What It Doesn't
·Dora Noda·8 min

MCP's Enterprise-Managed Authorization Goes Stable: What the ID-JAG Grant Fixes and What It Doesn't

MCP's Enterprise-Managed Authorization extension went stable in June 2026, killing per-server OAuth consent screens via a new ID-JAG grant flow — but it only governs connections, not individual tool calls, leaving per-action authorization for agent deploy/rollback tools squarely up to the platform.

Model Context Protocol
AI agents
self-hosting
security
Let's Encrypt's DNS-PERSIST-01: One TXT Record Replaces Every Renewal for Multi-Tenant TLS
·Dora Noda·8 min

Let's Encrypt's DNS-PERSIST-01: One TXT Record Replaces Every Renewal for Multi-Tenant TLS

A new Let's Encrypt challenge type lets a tenant authorize a platform's ACME account once instead of on every renewal — here's the record format, the security tradeoff, and what it changes for a self-hosted PaaS issuing certs at fleet scale.

self-hosting
PaaS
Domain
security
+1
Kubernetes 1.36's Volume Group Snapshots Go GA: Can Your Self-Hosted Fleet Actually Use It?
·Dora Noda·9 min

Kubernetes 1.36's Volume Group Snapshots Go GA: Can Your Self-Hosted Fleet Actually Use It?

Kubernetes 1.36 graduated VolumeGroupSnapshot to GA — a crash-consistent, multi-volume snapshot API. Here's the CSI driver support matrix that decides whether a Hetzner or Longhorn fleet can actually use it today, and the one path that works.

self-hosting
PaaS
infrastructure
engineering
User Namespaces Are GA in Kubernetes 1.36: Exactly What It Buys You (and What It Doesn't) for Multi-Tenant and AI-Agent Nodes
·Dora Noda·11 min

User Namespaces Are GA in Kubernetes 1.36: Exactly What It Buys You (and What It Doesn't) for Multi-Tenant and AI-Agent Nodes

Kubernetes 1.36 makes User Namespaces GA — a near-free identity remap that neutralizes four real container-escape CVEs, but stops short of the kernel-level isolation AI agents running untrusted code still need.

security
self-hosting
PaaS
infrastructure
+1
Kubernetes 1.36's unusedSince Field Turns Orphaned-Volume Hunting Into a Query
·Dora Noda·8 min

Kubernetes 1.36's unusedSince Field Turns Orphaned-Volume Hunting Into a Query

Kubernetes 1.36 adds an unusedSince timestamp to every PVC's status, turning orphaned-volume hunting from a manual cross-reference script into a one-line query — and a self-hosted PaaS's precondition for automated reclaim jobs.

infrastructure
self-hosting
PaaS
cost-optimization
The 20-40% Kubernetes Tax: What Small-Team Maintenance Data Actually Costs, and When Fleet Management Pays It Off
·Dora Noda·8 min

The 20-40% Kubernetes Tax: What Small-Team Maintenance Data Actually Costs, and When Fleet Management Pays It Off

Small teams running their own Kubernetes lose 20-40% of an engineer's time to upgrades, cert rotation, and etcd backups — here's what that costs in dollars, and when Cluster API automation actually claws it back.

self-hosting
PaaS
infrastructure
engineering
+1
Kubernetes 1.36's Fine-Grained Kubelet Authorization Is GA — Here's Exactly What It Doesn't Fix
·Dora Noda·8 min

Kubernetes 1.36's Fine-Grained Kubelet Authorization Is GA — Here's Exactly What It Doesn't Fix

Kubernetes 1.36 splits kubelet API permissions out of the all-or-nothing nodes/proxy grant — but exec, attach, and portforward stay bundled together by design, so tenant kubectl exec access is exactly as risky as before.

security
self-hosting
PaaS
infrastructure
+1
The Kubernetes CSI Driver Bug That Turns a Tenant's subDir Into a Delete Weapon
·Dora Noda·9 min

The Kubernetes CSI Driver Bug That Turns a Tenant's subDir Into a Delete Weapon

CVE-2026-3864 and CVE-2026-3865 let a crafted subDir value in a PersistentVolume escape onto the shared NFS or SMB export it's mounted from. Here's the exact mechanism, who can actually trigger it on a self-hosted PaaS, and the audit checklist that closes it.

security
self-hosting
PaaS
infrastructure
Showing 1684–1692 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags