Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Let's Encrypt's 6-Day Certificates Are GA: The Renewal Math Your PaaS's ACME Automation Needs to Survive It
·Dora Noda·9 min

Let's Encrypt's 6-Day Certificates Are GA: The Renewal Math Your PaaS's ACME Automation Needs to Survive It

Let's Encrypt's 6-day certificates are live and 45-day defaults are coming by 2028 — the renewal-frequency math, the real rate-limit bottleneck (your DNS provider, not Let's Encrypt), and what a self-hosted PaaS's ACME automation needs to change first.

self-hosting
PaaS
security
infrastructure
+1
Kubero vs a Cluster-API PaaS: Two Kubernetes-Native Bets on "Heroku Without the Monthly Bill"
·Dora Noda·7 min

Kubero vs a Cluster-API PaaS: Two Kubernetes-Native Bets on "Heroku Without the Monthly Bill"

Kubero and a Cluster-API-based PaaS both promise Heroku without the invoice, but they eliminate different halves of it — here's the CRD-level breakdown of what each actually owns, what it costs, and which problem it solves.

self-hosting
PaaS
infrastructure
engineering
+1
Kubernetes 1.36's User Namespaces Go GA: The hostUsers: false Default Every Multi-Tenant PaaS Should Ship
·Dora Noda·9 min

Kubernetes 1.36's User Namespaces Go GA: The hostUsers: false Default Every Multi-Tenant PaaS Should Ship

Kubernetes 1.36 graduated User Namespaces to GA — here's the exact node-image, subuid, and admission-policy recipe to make hostUsers: false the cluster-wide default for every tenant pod, plus the shared-kernel limitation it doesn't fix.

self-hosting
PaaS
security
infrastructure
+1
Kubernetes 1.35's Job managedBy Field Ends the Reconciliation Fight Over Agent-Triggered Batch Work
·Dora Noda·8 min

Kubernetes 1.35's Job managedBy Field Ends the Reconciliation Fight Over Agent-Triggered Batch Work

Kubernetes 1.35 made the Job managedBy field GA, letting a platform's own controller claim a Job's status end-to-end instead of racing the built-in controller for it — here's what that means for AI agents triggering migrations and one-off tasks from chat.

self-hosting
PaaS
infrastructure
engineering
+1
Kubernetes 1.36's Pod-Level Resource Managers: The Sidecar Bin-Packing Math, After Hetzner's Price Hikes
·Dora Noda·9 min

Kubernetes 1.36's Pod-Level Resource Managers: The Sidecar Bin-Packing Math, After Hetzner's Price Hikes

Kubernetes 1.36 lets a Pod share one CPU/memory budget across its containers instead of summing per-container reservations. Here's the worked bin-packing math — in real CCX43 nodes and euros, after Hetzner's 2026 price hikes.

self-hosting
PaaS
infrastructure
cost-optimization
+1
Kamal 2 Bet Against Kubernetes and Rails 8 Made It the Default: What SSH-Based Docker Deploy Gets Right (and Where It Runs Out of Room)
·Dora Noda·8 min

Kamal 2 Bet Against Kubernetes and Rails 8 Made It the Default: What SSH-Based Docker Deploy Gets Right (and Where It Runs Out of Room)

Kamal 2 ships zero-downtime Docker deploys over plain SSH with no cluster and no control plane — here's the exact technical wall it hits, and what a Cluster-API-managed fleet does differently on the other side of it.

self-hosting
PaaS
infrastructure
engineering
Ingress NGINX Is Officially Dead: The Gateway API Migration a Self-Hosted PaaS Can't Skip
·Dora Noda·8 min

Ingress NGINX Is Officially Dead: The Gateway API Migration a Self-Hosted PaaS Can't Skip

Ingress-nginx went EOL on March 24, 2026 with no more CVE fixes ever. Here's the head-to-head on the two sanctioned exits — Traefik as a drop-in stopgap vs. migrating straight to Gateway API's Gateway/HTTPRoute model — plus the before/after YAML a self-hosted PaaS's routing layer should generate.

self-hosting
PaaS
infrastructure
engineering
+1
The Hidden PaaS Tax Nobody Puts in the Pricing Table
·Dora Noda·11 min

The Hidden PaaS Tax Nobody Puts in the Pricing Table

Render and Vercel both charge $100/month for a static outbound IP, on completely unrelated billing models — a line-by-line invoice reconstruction of what a real indie-SaaS topology costs on Render, Railway, Fly.io, and Vercel versus a single owned Hetzner box.

PaaS
self-hosting
cost-optimization
migration
Hetzner Already Killed the datacenter Field — What a CAPH Fleet Must Check Before August 1
·Dora Noda·8 min

Hetzner Already Killed the datacenter Field — What a CAPH Fleet Must Check Before August 1

Hetzner already removed the datacenter field from its API on July 1, and EC2-compatible metadata routes disappear August 1 — here's exactly what breaks in a CAPH-managed fleet, what's already patched, and how to check.

self-hosting
PaaS
infrastructure
engineering
Showing 1738–1746 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags