Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

GitHub Tried to Meter Self-Hosted CI Runners, Then Backed Off
·Dora Noda·8 min

GitHub Tried to Meter Self-Hosted CI Runners, Then Backed Off

GitHub announced a $0.002/minute charge on self-hosted Actions runners, then postponed it within 48 hours. Here's the cost math it would have meant, and the control-plane dependency it exposed even for teams that already self-host their compute.

self-hosting
PaaS
cost-optimization
infrastructure
+1
Gateway API v1.5's ListenerSet Just Solved Multi-Tenant Custom Domains — Here's the RBAC Layout That Replaces Your Ingress Hacks
·Dora Noda·7 min

Gateway API v1.5's ListenerSet Just Solved Multi-Tenant Custom Domains — Here's the RBAC Layout That Replaces Your Ingress Hacks

Gateway API v1.5's ListenerSet lets tenants self-serve custom domains on a shared Gateway without cluster-wide write access — here's the actual YAML, precedence rules, and RBAC layout that makes it safe, not just self-service.

self-hosting
PaaS
infrastructure
security
Envoy AI Gateway Hits v1.0: A CNCF Blueprint for Securing Your Own MCP Server
·Dora Noda·8 min

Envoy AI Gateway Hits v1.0: A CNCF Blueprint for Securing Your Own MCP Server

Envoy AI Gateway's v1.0 release stabilizes MCPRoute and MCPRouteSecurityPolicy, giving self-hosted platforms CEL-based per-tool authorization and audit trails for AI agents — without building an MCP authorization layer from scratch.

self-hosting
PaaS
infrastructure
security
+1
E2B Joined the OpenAI Agents SDK. The Real Story Is How Many Times It's Had To.
·Dora Noda·9 min

E2B Joined the OpenAI Agents SDK. The Real Story Is How Many Times It's Had To.

E2B's OpenAI Agents SDK integration is its tenth publicly documented per-product integration guide, not its first — here's what the real count reveals about building versus betting on MCP for a self-hosted sandbox platform.

self-hosting
PaaS
AI agents
Model Context Protocol
+1
Dokploy's CVE-2026-27130: OS Command Injection via the appName Parameter in a Popular Self-Hosted PaaS, and What It Means to Trust a Deploy Tool With Root on Your Fleet
·Dora Noda·9 min

Dokploy's CVE-2026-27130: OS Command Injection via the appName Parameter in a Popular Self-Hosted PaaS, and What It Means to Trust a Deploy Tool With Root on Your Fleet

Dokploy's CVSS 9.9 command injection through the appName field, why it's the second time that field has been the entry point, and why the same bug class keeps recurring across self-hosted PaaS deploy tools.

security
cybersecurity
PaaS
self-hosting
+1
Docker's MCP Gateway Caps Every Tool Call at 1 CPU / 2GB: The Container Security Model Your Deploy Bot Should Steal
·Dora Noda·8 min

Docker's MCP Gateway Caps Every Tool Call at 1 CPU / 2GB: The Container Security Model Your Deploy Bot Should Steal

A critical RCE in Anthropic's MCP SDK won't be patched at the protocol layer, so containment has to happen at the tool-server layer. Here's exactly what Docker's MCP Gateway locks down by default, and how to size the same model for a PaaS's own deploy/rollback/scale tools.

security
self-hosting
PaaS
AI
+1
Coolify's 58K Stars vs Dokploy's 35K: What Two Self-Hosted PaaS Growth Curves Actually Say
·Dora Noda·8 min

Coolify's 58K Stars vs Dokploy's 35K: What Two Self-Hosted PaaS Growth Curves Actually Say

A same-day GitHub API check of Coolify's and Dokploy's star counts, MCP capabilities, and architecture puts the 'fastest growing PaaS' claim to the test — and finds the two projects' AI-agent tooling tells a very different story than their star counts do.

self-hosting
PaaS
infrastructure
engineering
Cluster API v1.12 In-Place Updates and Chained Upgrades: The End of Node-Replacement-Only Kubernetes Lifecycle
·Dora Noda·9 min

Cluster API v1.12 In-Place Updates and Chained Upgrades: The End of Node-Replacement-Only Kubernetes Lifecycle

Cluster API v1.12 lets Machines change without being deleted and recreated, and lets a fleet jump several Kubernetes minors in one declared upgrade. Here's how both mechanisms work and what they actually change for a bare-metal Hetzner fleet.

self-hosting
PaaS
infrastructure
cloud computing
Cloudflare's 60-Minute Disposable Workers: The Zero-Signup Deploy Target AI Agents Actually Need
·Dora Noda·8 min

Cloudflare's 60-Minute Disposable Workers: The Zero-Signup Deploy Target AI Agents Actually Need

Cloudflare shipped a Worker deploy an agent can create with zero signup, live for exactly 60 minutes. Here's the mechanism, how it stacks up against E2B/Daytona/Fly/Modal, and whether a Cluster-API PaaS can build the same thing without a sandbox vendor.

self-hosting
PaaS
AI agents
Model Context Protocol
+1
Showing 1747–1755 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags