Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

What the MCP 2026-07-28 Spec Broke: Your Server's Auth Fix Checklist
·Dora Noda·10 min

What the MCP 2026-07-28 Spec Broke: Your Server's Auth Fix Checklist

The MCP 2026-07-28 spec turned every remote server into a formal OAuth 2.1 resource server, and working servers now fail closed. Here is the six-item fix checklist: metadata endpoint, 401 pointer, audience enforcement, issuer validation, and the DCR-to-CIMD plan.

Model Context Protocol
security
identity
AI agents
+1
An AI Agent Found a WireGuard Bug in GKE: A Blueprint for Agent-Led Triage on Your Own Fleet
·Dora Noda·11 min

An AI Agent Found a WireGuard Bug in GKE: A Blueprint for Agent-Led Triage on Your Own Fleet

Lovable's agent surfaced a crash-looping GKE networking daemon buried in millions of log lines; humans did everything after. The honest agent-vs-human split from that incident, plus a trust-boundary matrix for giving a triage agent read-only cluster access on your own fleet.

AI agents
Kubernetes
self-hosting
security
Kubernetes 1.37 Scales HPA Workloads to Zero (Beta): What It Replaces in Your Idle-Reaping Playbook — and What It Doesn't
·Dora Noda·9 min

Kubernetes 1.37 Scales HPA Workloads to Zero (Beta): What It Replaces in Your Idle-Reaping Playbook — and What It Doesn't

Kubernetes 1.37 graduates HPA scale-to-zero to beta with one line — minReplicas: 0. Queue consumers can drop the bespoke idle-reaper, but HTTP services still need Knative-style request buffering, and four policy gaps stay on the platform.

Kubernetes
PaaS
self-hosting
cost-optimization
Kubernetes v1.37 Finally Lets You noexec a Volume Mount: Closing the 9-Year-Old Hole in readOnlyRootFilesystem
·Dora Noda·8 min

Kubernetes v1.37 Finally Lets You noexec a Volume Mount: Closing the 9-Year-Old Hole in readOnlyRootFilesystem

Kubernetes v1.37 adds alpha bindMountOptions and emptyDir mode fields that finally let operators mount volumes noexec and stop emptyDir from defaulting to 0777. What the two knobs block, and the gate rollout checklist for multi-tenant fleets.

Kubernetes
security
self-hosting
PaaS
Ingress-NGINX Is Retired. Your PaaS Inherited Its Quirks — Audit Them Before They Become Outages
·Dora Noda·11 min

Ingress-NGINX Is Retired. Your PaaS Inherited Its Quirks — Audit Them Before They Become Outages

Ingress-NGINX retired in March 2026, leaving five silent routing behaviors behind. This behavior-by-behavior audit maps each quirk to what breaks on a naive Gateway API migration — and what a self-hosted PaaS routing layer must now own explicitly.

Kubernetes
self-hosting
migration
guide
Heroku's Quiet End of Life: A 90-Day Exit Playbook for Teams Still Paying by the Dyno
·Dora Noda·13 min

Heroku's Quiet End of Life: A 90-Day Exit Playbook for Teams Still Paying by the Dyno

Salesforce moved Heroku to sustaining engineering in February 2026: no new features, no new Enterprise contracts. A 90-day exit playbook with the Salesforce sunset precedent, a 12-row pre-migration audit, week-by-week phases for a Postgres plus web plus worker stack, and the honest first-year cost of moving versus waiting.

migration
self-hosting
PaaS
cost-optimization
gVisor vs Kata vs Firecracker: Picking Sandbox Isolation for an Agent Layer on Shared Nodes
·Dora Noda·13 min

gVisor vs Kata vs Firecracker: Picking Sandbox Isolation for an Agent Layer on Shared Nodes

An agent sandbox on a node shared with paying tenants must survive hostile model-generated code. This concrete comparison of gVisor, Kata Containers, and Firecracker covers cold starts, memory per sandbox, and blast-radius containment — plus a decision rule for self-hosted fleets.

AI
security
infrastructure
self-hosting
+1
Gateway API v1.6 Makes TCPRoute and UDPRoute Standard: Own Your PaaS's L4 Traffic Without Ingress Annotations
·Dora Noda·10 min

Gateway API v1.6 Makes TCPRoute and UDPRoute Standard: Own Your PaaS's L4 Traffic Without Ingress Annotations

Gateway API v1.6 graduates TCPRoute and UDPRoute to the Standard channel as stable v1 resources. Here is the one-Gateway design for tenant Postgres, game, DNS, and agent-protocol traffic — copy-paste YAML, a port-allocation policy that keeps tenants off each other's listeners, and the controller support matrix to check first.

Kubernetes
PaaS
self-hosting
infrastructure
100 MCP Servers in Production: What a Fortune 500 Deployment Teaches Self-Hosted Agent Ops
·Dora Noda·10 min

100 MCP Servers in Production: What a Fortune 500 Deployment Teaches Self-Hosted Agent Ops

A Fortune 500 bank went from failing AI coding assistants to 100 governed MCP servers in three months. Five practices from that deployment — registry gates, gateway auth, tool consolidation, token budgets, gateway observability — that self-hosted teams should adopt on day one.

Model Context Protocol
AI agents
Enterprise AI
self-hosting
+1
Showing 298–306 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags