Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

MCP Bets H2 2026 on Server Cards: What Your Registry-Less Server Must Hand-Roll Today
The July 2026 MCP spec shipped stateless transport and a mandatory server/discover RPC but left pre-connect Server Cards experimental. Here is the concrete manifest, capability advertisement, and trust signaling a registry-less deploy-from-chat server builds today so the eventual card format is a migration, not a rewrite.

450+ MCP Servers Catalogued and Quality-Scored Daily: What the Ecosystem Census Says About the Tool Sprawl Your Deploy Platform Inherits
A daily census grades 453 MCP servers an average of 16.3 out of 100. Here is what that number means for platform teams, the security gap the score does not cover, and a bless-or-block rubric for governing tenant agent tools.

MCP's 10,000-Server Problem: Building an Allowlisted, Audited Tool Catalog Before an Agent Can Deploy to Your Fleet
With 10,000+ public MCP servers and most scanned servers needing security review, connecting an agent to a tool is now a governance problem. A tiered, allowlisted tool catalog design — plus a deploy-from-chat walkthrough — for teams running agents against production.

Kubernetes Shipped a Sandbox API for AI Agents: What a Declarative Singleton-Workload Primitive Means for a Deploy-From-Chat PaaS
SIG Apps' Agent Sandbox CRD collapses the hand-rolled StatefulSet-plus-Service-plus-PVC stack into one declarative resource for stateful AI agent runtimes. Here is how the four CRDs work, what the gVisor-vs-Kata choice costs, and which parts a self-hosted platform should adopt now.

Your API Server Still Proxies Every kubectl exec in 1.36: What ExtendWebSocketsToKubelet Really Moves and the 4 Checks Before You Upgrade
Kubernetes 1.36 did not cut the API server out of the exec path — it turned it into a pass-through proxy. What really moved to the kubelet, the RBAC change that actually matters, and four checks to run before you upgrade.

KEP-5677: Tell Tenants 'No GPU Left' Up Front Instead of Parking Their Pods in Pending
Kubernetes 1.37's second alpha of KEP-5677 turns GPU availability into a readable API object. Here is how a self-hosted PaaS turns that per-pool snapshot into a tenant-facing capacity page and a fast admission-time refusal instead of pods stuck in Pending.

Hetzner Traffic Overage Math: €1/TB on Owned EU Boxes vs $150/TB on Render, and What It Means for Tenant Bandwidth Pricing
Hetzner Cloud bundles 20 TB of pooled traffic per server with €1/TB overage, while Render charges $150/TB past a 25 GB allowance. Here is the worked math at four egress levels and what flat bandwidth costs mean for pricing tenants on a self-hosted PaaS.

Hetzner Is Giving Away Free Inference. Should Your Fleet Still Run Its Own vLLM?
Hetzner's free OpenAI-compatible inference API gives self-hosted teams zero-capex model access — but rate limits, 5–10s p99 latency, and a scaled-down catalog define what 'free' actually guarantees. Here is the rent-vs-own math and a checklist for when to build your own vLLM.

Hetzner DNS Makes the RRSet TTL Required on September 30: Audit Your DNS Automation Before Updates Start Failing
On September 30, 2026, Hetzner starts rejecting RRSet TTL updates that omit the ttl field. Here is which callers are already safe, which break, and a 20-minute audit to prove your DNS automation is compliant before the cutoff.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags