Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Render Cut Median Builds 40% to 21 Seconds — Can Owned Hardware Match It?
Render cut median service builds from 38 to 21 seconds on faster build nodes. This guide splits the headline into cold/warm and queue/execution cells, cites published 12–15 second warm builds on persistent builders, and prices an owned Hetzner build pool at €97.30/month — with the exact protocol to verify every cell.

Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec
A production design for a deploy-capable remote MCP server under the 2026-07-28 spec: OAuth discovery via protected-resource metadata, audience-bound tokens, narrow per-environment scopes, human approval gates for destructive tools, and chain-complete audit logs.

Railway Killed Prepaid Billing. That's Your Migration-Timing Signal.
Railway now requires a post-paid card, ending prepaid credits. A prepaid balance is lock-in; post-paid is month-to-month exit freedom — plus a 5-check migration-timing checklist and a cost anchor for the same workload.

Railway Won the Default for Small Projects in 2026 — Here Are the Edge Cases That Push Growing Teams Off It
Railway won the small-project default with metered pricing, the fastest deploys, and a $5 trial. This inventory names the five edge cases that push growing teams off it — always-on billing, preview costs, ephemeral storage, containerized Postgres, per-seat teams — and works the bill-size threshold where a fixed box wins.

Kubernetes 1.37 Locks In On-Demand PLEG Relist: What Cost-Sized Nodes Actually Save
Kubernetes 1.37 graduates PLEG on-demand relist to GA, cutting pod-create observation from 1.8s to 1.1s with no opt-out. What the locked-on change saves cost-sized node pools, and a six-step checklist to verify it during your upgrade.

Whose Token Is It? Solving the MCP and OAuth2 Identity Problem for AI Agent Deploys
Every deploy, rollback, or scale call an AI agent makes must answer who authorized it: the developer, the agent, or the tenant. This post maps the three-identity model, the July 2026 MCP authorization rules, and the token-exchange pattern that keeps deploy-from-chat auditable.

Your TLS Renewals Have an Expiration Date Too: Auditing cert-manager for Let's Encrypt's 45-Day Countdown
Let's Encrypt drops to 45-day certificates by 2028 — run this four-step cert-manager audit on versions, hardcoded renewBefore windows, the ARI gate, and expiry alerting before fixed renewal intervals start breaking.

Kubernetes Rewrote Its Image Promoter and Deleted 20% of It: A 7-Phase Registry Lesson for Self-Hosted PaaS
Kubernetes rewrote kpromo, its registry.k8s.io image promoter, deleting 20% of the code while cutting plan time from 20 minutes to 2 and signature replication from 17 hours to 15 minutes. A close read of the 7-phase pipeline — and what a self-hosted PaaS should copy and skip.

Your Registry Is a Trust Root: What the JFrog Artifactory Breach Campaign Teaches Self-Hosters
Attackers chained three Artifactory flaws into full admin takeover of self-hosted registries — then planted backdoors that survive patching. The timeline, the kill chain, and a 7-item hardening checklist for your own OCI store.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags