Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Your Deploy Agent Doesn't Need 100 Tools in Context: Progressive Discovery for Infrastructure MCP Servers
Connecting a deploy agent to a 100-tool MCP server eats the context window before any work starts. A three-tier catalog design keeps agents sharp, with the numbers and spec grounding to back it.

MCP Multi-Round Trips: Human Approval Gates for Agent-Initiated Production Deploys
MCP's July 2026 release lets a server pause mid-call and ask a human to approve the exact plan before acting. Here is the four-step deploy gate — plan, digest-bound approval, single-use execution, auditable receipt — that replaces standing agent permission.

MCP Joins the Linux Foundation: What Neutral Governance and Server Cards Mean for Shipping a Deploy Server Today
MCP is now neutral Linux Foundation infrastructure with 97M monthly SDK downloads — here is why that plus the stateless 2026-07-28 spec means you should ship your deploy-from-chat MCP server now, and treat Server Cards as a distribution upgrade, not a blocker.

MCP's 2026 Enterprise-Readiness Push: Audit Trails, SSO, and Gateway Patterns for Agent Infrastructure You'd Otherwise Build Yourself
MCP hit 97M monthly downloads while shipping without a governance story. What the July 2026 spec hardened, what a production gateway must still add, and what vendors charge for.

30+ MCP CVEs in Two Months: What the Early-2026 Vulnerability Wave Means for Your Deploy MCP Server's Supply Chain
More than 30 MCP CVEs landed in the first two months of 2026 — most in proxies, registries, and SDKs, not tool code. What the wave teaches teams shipping a deploy MCP server, and the seven-row supply-chain checklist that falls out of it.

Maintenant Monitors Docker, Kubernetes, and Uptime From One Go Binary: What No PromQL and No Exporters Actually Costs
Maintenant packs Docker, Kubernetes, uptime, TLS, cron, logs, and CVE monitoring into one Go binary idling under 30MB of RAM. Here is which parts of the ten-component Prometheus stack it genuinely replaces — and the retention, query, and dashboard costs where the deal ends.

Kubernetes v1.37 Puts No-Exec Volumes in the Pod Spec: What a PaaS Can Delete From OPA
Kubernetes v1.37 adds noexec bind-mount flags and emptyDir permission modes to the Pod spec. Here is what moves from OPA policy to kernel enforcement, what stays in the policy engine, and the five rollout gotchas.

Korifi Brings cf Push to Kubernetes: The Forgotten Git-Push PaaS, Compared
Korifi puts Cloud Foundry's cf push on Kubernetes with buildpack staging and a service-broker Marketplace — here is how it stacks up against Dokku, Coolify, CapRover, and Render-compatible layers, and which teams should shortlist the industry's most battle-tested git-push UX.

KEDA 2.20's Event-RBAC Migration and Two Panic Fixes: What Breaks When Scale-to-Zero Runs Through One Controller
KEDA 2.20 moved event recording to events.k8s.io but dropped the legacy permission its own client library still needed, then shipped two panic fixes for the operator that owns scale-to-zero. A blast-radius breakdown of each failure and an upgrade checklist for fleets you run yourself.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags