Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Railway Built a 30M RPS CDN in 30 Days: What Self-Hosters Can Steal From Hikari
Railway's Hikari CDN absorbs 30M requests per second with Rust and per-request WebAssembly. Four of its patterns transfer directly to a self-hosted fleet — and the bandwidth math says building your own cache tier beats CloudFront pricing by 60x.

Railway Put Deploys Inside ChatGPT and Grok: The 7 API Primitives Chat-as-Console Actually Needs From a Render-Compatible API
Railway spent six weeks putting deploys inside ChatGPT and Grok. The plugins are just the surface — here is the seven-primitive API spec underneath them, and the guard checklist a self-hosted Render-compatible platform needs to copy.

Railway Agent Runs on Your ChatGPT Subscription: What BYO-Model Billing Concedes About PaaS Agent Margins
Railway's September changelog lets Railway Agent bill to your ChatGPT plan instead of its own meter. The math behind the move: token margins now belong to the model vendor, and platforms are left competing on agent UX and compute.

Railpack vs render.yaml vs fly.toml: What Three Deploy-Config Philosophies Teach a Self-Hosted PaaS
Railway detects your stack, Render wants a YAML blueprint, and Fly.io hands you 200 lines of TOML. A side-by-side of all three deploy configs — and why a self-hosted PaaS should pair zero-config detection with a declarative escape hatch.

The Protocol Is Free, the Control Plane Isn't: What Qovery's MCP-for-Infra Play Shares — and Keeps
Qovery's agent Skill deploys new apps while its MCP server manages existing infrastructure — and the protocol behind both is free. A row-by-row verdict on which parts of MCP-for-infra any self-hosted PaaS shares, and which parts only the rented control plane keeps.

Running a Production MCP Server on Kubernetes: OAuth 2.0, Audit Logging, and the Enterprise Deployment Checklist
A ten-item production checklist for running a Model Context Protocol server on Kubernetes: Streamable HTTP transport, OAuth authorization with per-action token scopes, replayable audit logging, and cluster hardening — plus an honest comparison with hosted endpoints.

Pod Certificates Are GA in Kubernetes 1.37: Per-Tenant TLS Without the cert-manager Glue
Kubernetes 1.37 graduates Pod Certificates and Cluster Trust Bundles to stable, turning per-pod X.509 identity and shared trust anchors into platform APIs. Here is how the issuance flow works, what replaces Certificate-per-service sprawl, and the four-item checklist before a self-hosted PaaS adopts it.

Stop Handing Agents Immortal Keys: Short-Lived Sandbox Credentials with Kubernetes 1.37 Pod Certificates
Kubernetes 1.37 graduates Pod Certificates and Cluster Trust Bundles to stable, replacing copyable bearer tokens with short-lived X.509 sandbox identity. Here is the pod-spec design, the migration off immortal service-account secrets, and the audit evidence to gather before agents deploy on their own.

Pangolin Put SSH, RDP, and VNC in the Browser. Should Your PaaS Ingress Copy It?
Pangolin 1.19 turned SSH, RDP, and VNC sessions into browser URLs behind its self-hosted tunnels. A need-by-need look at what that model covers for a self-hosted PaaS ingress — and where it stops.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags