Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Pinterest Runs 66,000 MCP Tool Calls a Month: What Its Registry-and-Approval Blueprint Means for a Deploy-Tools MCP Server
Pinterest's production MCP fleet handles 66,000 tool calls a month behind a central registry and human approval gates. Here is the blueprint, and how it maps onto deploy, rollback, and logs tools for a self-hosted PaaS.

1 Million Agents in 3 Months: What Notion's Enterprise Agent Surge Means for a PaaS Whose Deploy API Is the Agent's Next Tool Call
Notion customers built 1 million AI agents in three months, yet 69% of enterprises still share credentials across agents. This is the five-item checklist — per-agent identity, scoped tokens, agent-aware quotas, audit attribution, MCP deploy tools — a PaaS deploy API needs before agents become its callers.

My Server Started Mining Monero: What a 606-Point Cryptojacking Postmortem Teaches About Hardening Self-Hosted PaaS Nodes
A Hetzner box mined Monero for ten days before anyone noticed — here is the kill chain link by link, and the node-hardening checklist (key-only SSH, egress policy, resource alerts) a self-hosted PaaS should ship by default.

Half a Billion Downloads Get a Diploma: What MCP's First Certification (MCPA) Signals for Platform Teams
The Agentic AI Foundation's MCPA exam arrives as MCP SDK downloads near half a billion a month. What the blueprint's 50% ops-and-security weighting tells platform teams, what the credential doesn't prove, and three moves to make this quarter.

10,000 MCP Servers and 97M Downloads Later, the Bottleneck Is Discovery
MCP passed 10,000 public servers and 97M monthly SDK downloads, so the hard problem is no longer the protocol — it is discovery and trust. What Arcade's brokered runtime and the Coolify agent bridges teach a self-hosted PaaS about shipping a deploy, rollback, and logs server that agents can find and be trusted with.

Kubernetes v1.37 Takes Workload-Aware Scheduling to Beta: Bin-Packing Batch Jobs on Bare Metal Without a Managed Autoscaler
Kubernetes v1.37 graduates gang scheduling and the Workload/PodGroup APIs to Beta. A worked before/after on a fixed 4-node pool shows what atomic placement buys a bare-metal fleet with no autoscaler, plus the exact feature gates and API versions needed to opt in.

Kubernetes v1.36 Route Sync Metric: Catch Your CCM Wasting API Calls on Hetzner
Kubernetes v1.36 adds a route sync counter to the Cloud Controller Manager. Here is what it measures, how to A/B test watch-based reconciliation with it, and which Prometheus alerts to wire on Hetzner.

Your Gateway's Next Feature Doesn't Need an Envoy Fork: What kgateway's Rust Dynamic Modules Actually Buy a Self-Hosted PaaS
kgateway's Rust dynamic modules run custom payload logic inside Envoy at native speed with no fork and no recompile. How the mechanism works, how it compares to Lua, Wasm, and ext_proc, and the three catches a self-hosted platform team should budget for.

Januscape: A 16-Year-Old KVM Escape, the Two CVEs That Fix It, and the One Kernel Flag Your Fleet Should Audit
Januscape (CVE-2026-53359) is a 16-year-old KVM shadow-MMU bug giving guest root a host escape on Intel and AMD — closed by two CVEs and mitigated by one kernel flag. What it means for hypervisor-backed tenant isolation, and the fleet audit that verifies the fix.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags