Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

What the MCP 2026-07-28 Spec Broke: Your Server's Auth Fix Checklist
The MCP 2026-07-28 spec turned every remote server into a formal OAuth 2.1 resource server, and working servers now fail closed. Here is the six-item fix checklist: metadata endpoint, 401 pointer, audience enforcement, issuer validation, and the DCR-to-CIMD plan.

An AI Agent Found a WireGuard Bug in GKE: A Blueprint for Agent-Led Triage on Your Own Fleet
Lovable's agent surfaced a crash-looping GKE networking daemon buried in millions of log lines; humans did everything after. The honest agent-vs-human split from that incident, plus a trust-boundary matrix for giving a triage agent read-only cluster access on your own fleet.

Kubernetes 1.37 Scales HPA Workloads to Zero (Beta): What It Replaces in Your Idle-Reaping Playbook — and What It Doesn't
Kubernetes 1.37 graduates HPA scale-to-zero to beta with one line — minReplicas: 0. Queue consumers can drop the bespoke idle-reaper, but HTTP services still need Knative-style request buffering, and four policy gaps stay on the platform.

Kubernetes v1.37 Finally Lets You noexec a Volume Mount: Closing the 9-Year-Old Hole in readOnlyRootFilesystem
Kubernetes v1.37 adds alpha bindMountOptions and emptyDir mode fields that finally let operators mount volumes noexec and stop emptyDir from defaulting to 0777. What the two knobs block, and the gate rollout checklist for multi-tenant fleets.

Ingress-NGINX Is Retired. Your PaaS Inherited Its Quirks — Audit Them Before They Become Outages
Ingress-NGINX retired in March 2026, leaving five silent routing behaviors behind. This behavior-by-behavior audit maps each quirk to what breaks on a naive Gateway API migration — and what a self-hosted PaaS routing layer must now own explicitly.

Heroku's Quiet End of Life: A 90-Day Exit Playbook for Teams Still Paying by the Dyno
Salesforce moved Heroku to sustaining engineering in February 2026: no new features, no new Enterprise contracts. A 90-day exit playbook with the Salesforce sunset precedent, a 12-row pre-migration audit, week-by-week phases for a Postgres plus web plus worker stack, and the honest first-year cost of moving versus waiting.

gVisor vs Kata vs Firecracker: Picking Sandbox Isolation for an Agent Layer on Shared Nodes
An agent sandbox on a node shared with paying tenants must survive hostile model-generated code. This concrete comparison of gVisor, Kata Containers, and Firecracker covers cold starts, memory per sandbox, and blast-radius containment — plus a decision rule for self-hosted fleets.

Gateway API v1.6 Makes TCPRoute and UDPRoute Standard: Own Your PaaS's L4 Traffic Without Ingress Annotations
Gateway API v1.6 graduates TCPRoute and UDPRoute to the Standard channel as stable v1 resources. Here is the one-Gateway design for tenant Postgres, game, DNS, and agent-protocol traffic — copy-paste YAML, a port-allocation policy that keeps tenants off each other's listeners, and the controller support matrix to check first.

100 MCP Servers in Production: What a Fortune 500 Deployment Teaches Self-Hosted Agent Ops
A Fortune 500 bank went from failing AI coding assistants to 100 governed MCP servers in three months. Five practices from that deployment — registry gates, gateway auth, tool consolidation, token budgets, gateway observability — that self-hosted teams should adopt on day one.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags