Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Every PaaS Ships an MCP Server Now: Dokploy vs. Railway in the Agent-Interface Race
Dokploy mirrors all 508 API endpoints as MCP tools while Railway curates ten hosted tools plus a TypeScript deploy-your-own guide — an operation-by-operation comparison across deploy, logs, env, and rollback, and the nine-item checklist a self-hosted Render-compatible MCP surface must clear.

E2B Ended 30-Day Sandbox Deletion — What a Self-Hosted Sandbox Should Still Do Differently
E2B quietly replaced its 30-day paused-sandbox deletion with indefinite retention — but the 1-hour and 24-hour runtime caps, the 5-minute kill-by-default timeout, and the sandbox-is-storage coupling remain. A concrete teardown of what those limits cost long-running agent workflows, plus four lifecycle policies a self-hosted sandbox should set differently.

The Vendor Ships the Protocol, the Community Ships the Policy: What Coolify's Governed MCP Servers Teach About Agent Interfaces
Coolify's built-in MCP server covers reads while community servers add operation modes, scoped tokens, approval gates, and audit logging — a field guide to the seven governance controls every self-hosted PaaS agent interface should launch with.

AWS Now Runs an ACME Server: Why Your Self-Hosted cert-manager Never Needed It
AWS Certificate Manager now speaks ACME, issuing 45-day certificates with IAM governance and per-domain pricing. Here is how it compares to running cert-manager against Let's Encrypt directly, and the renewal-margin checklist short-lived certificates actually demand.

Coolify v4 Is a Rolling Beta: What Pinning the Platform Underneath Your Apps Actually Requires
Coolify v4.3.1 was 'latest patched' on August 12 and four releases behind by August 16 — inside a CVE cluster with RCE to host root. How to run a rolling-beta PaaS panel safely: version-pinned installs, a staging canary box, and advisory-feed monitoring.

One Webhook, Every Repo Traced: Zero-Instrumentation CI Tracing With OTel's githubreceiver
A single org-level GitHub webhook plus the OTel Collector's githubreceiver turns workflow_run and workflow_job events into drillable traces — slow, flaky, and queued-job visibility across every repo with zero workflow-file edits, and a sizing method worth copying.

Kubernetes 1.36 Schedules Whole Workloads, Not Pods: Bin-Packing Tenant Apps on Fixed Hardware
Kubernetes 1.36's PodGroup scheduling cycle binds whole workload gangs atomically, but tenant Deployments see almost no change yet. A worked 3-node scenario shows what moves, what doesn't, and where Kueue still wins.

Your Build Server Was Owned for 24 Days. Patching It Doesn't Tell You What Shipped Clean.
Attackers held admin access to self-hosted JFrog Artifactory servers for 24 days in August-September 2026, planting Rust backdoors with remote C2. A triage table for which window artifacts are suspect, the rebuild-and-compare procedure that re-verifies them, and the SLSA signing checklist that makes the next incident answerable.

30MB vs 800MB: What Rivetr's Single-Binary PaaS Teaches About the Self-Hosted Control-Plane Floor
Rivetr runs a complete self-hosted PaaS control plane in ~30MB of RAM against Coolify's ~800MB stack: an apples-to-apples teardown of what the gap measures, where the 30MB floor comes from, and why footprint is the tiebreaker and fleet lifecycle the decision.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags