Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Your CI Runner Already Trusts an AI Agent: What Claude Code and Codex CLI's Non-Interactive Mode Doesn't Guard Against
Claude Code and Codex CLI both ship non-interactive modes built for unattended CI, but neither ships the scoped tokens, transcript redaction, or agent-independent rollback that make letting an agent push to prod safe rather than a demo.

Kubernetes Quietly Fixed a Years-Old cgroup v1-to-v2 CPU Priority Bug: What the January 2026 Formula Rewrite Means
A linear formula meant to convert cgroup v1 CPU shares into v2 CPU weight silently gave 1-CPU containers about 39% of the priority they should've had, invisible to kubectl and metrics-server the whole time. Here's the fixed formula, the exact command to audit your own nodes, and what rolling it out across a self-hosted fleet's node images actually requires.

CAPD vs CAPH: One Cluster API, From Your Laptop to Real Hetzner Bare Metal
CAPD and CAPH speak the exact same Cluster API contract at opposite extremes — one fakes the hardware for local dev, the other provisions real Hetzner dedicated servers. Here's what changes, what doesn't, and the gotchas in between.

AWS Closed App Runner to New Customers on April 30 — and Proved the PaaS Layer Is the First Thing Even a Hyperscaler Cuts
AWS closed App Runner to new signups on April 30, 2026 — not because the underlying compute was unprofitable, but because the git-push convenience layer on top of it wasn't worth maintaining, even for the company that owns every piece underneath it.

AI Sandbox Pricing at Scale: $7,200 vs $16,819 vs $24,491 vs $35,000 for 200 Sandboxes
Five vendors charge $7,200 to $35,770 a month for the same 200-sandbox AI-agent workload. Here's where the 4x+ spread actually comes from, and what the same workload costs bin-packed onto your own post-price-hike Hetzner hardware.

Agentic GitOps: Why Your Deploy Agent Should Open a Pull Request, Not Call the API Directly
A Cursor agent's direct API call deleted a production volume and its backups in nine seconds. Here's why routing agent-originated infrastructure changes through a pull request, not a live API call, is the safer default for deploy-from-chat.

The 47-Day Certificate Era: TLS Automation Becomes Mandatory for Self-Hosted Infrastructure
CA/Browser Forum rules cut TLS certificate lifetimes from 398 to 47 days by 2029, with domain-validation reuse shrinking to 7 hours. Here's the full timeline and what it breaks in self-hosted TLS automation.

The AI Agent Sandbox Wars: E2B vs Daytona vs Modal vs Fly Machines Compared
E2B, Daytona, Modal, and Fly Machines each bet on a different isolation architecture for running AI-generated code — a normalized cost comparison and what the isolation tradeoffs mean for a self-hosted platform.

Railpack Replaces Nixpacks: What Railway's BuildKit Rewrite Means for Git-Push Builds Everywhere
Railway replaced Nixpacks with Railpack, a BuildKit-based rewrite promising 38-77% smaller images — here's the real comparison against Cloud Native Buildpacks and what self-hosted tools like Coolify and Dokploy should do next.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags