Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

GitLab Is Putting Its API on a Meter: What the October 19 Rate Limits Mean for Your Agents and CI
GitLab.com caps anonymous API traffic at 60 requests per hour starting October 19, with tier-aligned budgets for Free, Premium, and Ultimate. How to tell whether your agents and CI break, the cheapest fixes in order, and when self-hosting wins.

Your Tenants Now Ship a Spec With the Code: What GitHub Spec Kit's spec.md/plan.md/tasks.md Would Change for PaaS Build Detection
GitHub's Spec Kit is turning spec-before-code into a repo-layout convention tenants push with every deploy. This breakdown maps each artifact — spec.md, plan.md, tasks.md, constitution — to the build-detection signal it carries, and draws the trust boundary that keeps a spec-reading platform safe.

GitHub's September 25 Runner Deadline: What the Version Floor Actually Fixes (and the Build-Fleet Holes It Leaves Open)
GitHub starts enforcing self-hosted runner versions on September 25. Here is exactly what changes, why the last three CI supply-chain attacks would not have been stopped by a version floor, and the checklist to run before Friday.

GitHub Actions Tripled Capacity and Cut Prices 39% in 2026: The Honest Math on CI Minutes vs PaaS Builds
GitHub cut Actions runner prices up to 39% and tripled capacity in 2026. This breakdown compares CI minutes against self-hosted runners and PaaS build meters line by line — with breakeven points and the hidden costs that matter more than the rate.

Every Hopped from Railway to Render. What the Hop Fixed — and the Ceiling It Didn't Touch.
Every moved its whole fleet from Railway to Render in March 2026. A row-by-row audit of what the hop fixed, what it merely moved to a different status page, and why the ceiling only moves with owned machines.

The EU CRA's 24-Hour Clock Is Now Running: What the First Week of Mandatory Vulnerability Reporting Demands of a Self-Hosted PaaS Vendor
Since September 11, 2026, software vendors selling into the EU must report actively exploited vulnerabilities within 24 hours through ENISA's Single Reporting Platform. Here is the three-stage clock, what the first week of coverage revealed, and the readiness checklist for a self-hosted PaaS vendor.

Coolify's Second Critical RCE of 2026: How a Dockerfile Path Became a Shell (CVE-2026-34038)
Coolify's CVE-2026-34038 lets any user with application write access run shell commands on the host and pull secrets out through deployment logs — the sixth deploy-field injection in seven months, and a case study in single-daemon blast radius.

After You Leave Render, Heroku, or Fly.io: Which Cost-Visibility Tools Survive the Move to Flat-Rate Hardware
Qovery's guide walks a 25-person team through eight cost tools for life after Render, Heroku, or Fly.io — but every pick assumes AWS, GCP, or Azure. This post re-runs the shortlist for flat-rate owned hardware, where the meter disappears and only OpenCost plus auto-stop still earn their keep.

Cilium 1.20 Retires Two More Boxes: TCP Routes, Gateway Auth, and the Case for a CNI-Run Fleet
Cilium 1.20 adds TCPRoute/UDPRoute and gateway ExternalAuth to its Gateway API support, closing the last gaps that kept small fleets running a separate ingress controller and auth proxy. Here is the consolidation map, the concrete migration costs, and where a service mesh still earns its keep.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags