Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Heroku vs Railway vs Render vs Fly.io: Read the Feature Matrix, Not the Price List (2026)
·Dora Noda·10 min

Heroku vs Railway vs Render vs Fly.io: Read the Feature Matrix, Not the Price List (2026)

Heroku, Railway, Render, and Fly.io look interchangeable until you read the feature matrix: free-tier expiries, Postgres row caps, egress meters, and the operational rows that decide year two — plus which rows a self-hosted fleet beats on day one.

PaaS
migration
cost-optimization
self-hosting
Headlamp Ships a Cluster API Plugin: Declarative Cluster Lifecycle Finally Gets the UI Kubernetes Dashboard Never Had
·Dora Noda·8 min

Headlamp Ships a Cluster API Plugin: Declarative Cluster Lifecycle Finally Gets the UI Kubernetes Dashboard Never Had

Headlamp's June 2026 Cluster API plugin brings clusters, machines, and rollout state into a maintained browser UI just as the Kubernetes Dashboard goes dark — here is what it ships, how to try it, and where it still stops short.

Kubernetes
PaaS
self-hosting
infrastructure
Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet
·Dora Noda·9 min

Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet

Railway's May 2026 changelog lets enterprise workspaces restrict deployments to approved GitHub orgs. Here is what the guardrail enforces and how to rebuild it on your own fleet with ArgoCD source pinning, Kyverno admission policy, and pipeline owner checks.

PaaS
self-hosting
Kubernetes
security
+1
Your Agent's Firewall Can't Read SQL. Deno's Claw Patrol Can.
·Dora Noda·11 min

Your Agent's Firewall Can't Read SQL. Deno's Claw Patrol Can.

Deno's open-source Claw Patrol terminates agent TCP connections and parses HTTP, Postgres, SSH, and Kubernetes on the wire, so policy sees the query instead of just the connection. How it works, what it costs, and where it belongs on a self-hosted platform.

AI agents
cybersecurity
self-hosting
engineering
Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?
·Dora Noda·11 min

Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?

Daytona boots sandboxes in under 90ms while E2B's Firecracker microVMs take about 150ms — but model latency dwarfs both in real agent loops. A numbers-first look at when the gap matters, how the two pricing shapes compare, and what a self-hosted sandbox should copy from each.

AI agents
self-hosting
PaaS
cost-optimization
+1
Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority
·Dora Noda·12 min

Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority

A community MCP server turns Coolify into agent-callable deploy tools for about 13 dollars a month — but the agent holds a deploy-level API token with nothing between it and delete. Scoped, audited agent credentials are the missing primitive.

AI agents
Model Context Protocol
security
PaaS
+1
Your Admission Webhook Never Saw That Container: Runtime Supply-Chain Verification With containerd's NRI
·Dora Noda·12 min

Your Admission Webhook Never Saw That Container: Runtime Supply-Chain Verification With containerd's NRI

Static pods, direct node access, and webhook outages all bypass API-layer image checks. A CNCF-backed NRI plugin moves SLSA, VEX, and VSA verification into the container runtime itself — here is how it works and what it costs to run across a fleet.

Kubernetes
security
self-hosting
PaaS
Buildpacks RFC 0130: Zero-Config OCI Provenance Your SOC 2 Auditor Can Actually Read
·Dora Noda·11 min

Buildpacks RFC 0130: Zero-Config OCI Provenance Your SOC 2 Auditor Can Actually Read

Cloud Native Buildpacks approved RFC 0130, stamping buildpack images with source, commit, and version metadata automatically. What that buys a SOC 2 or FedRAMP audit, what unsigned annotations can't prove, and the SBOM plus signed-attestation checklist that closes the gap.

PaaS
compliance
security
self-hosting
Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes
·Dora Noda·10 min

Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes

CNCF's Q1 2026 radar put Backstage in 'Adopt' while its agentic-enterprise commentary demands machine-consumable platform interfaces. The official MCP plugin, read-through sync, and four hard parts — auth, writes, refresh, drift — decide whether the pairing holds.

AI agents
Model Context Protocol
PaaS
security
+1
Showing 478–486 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags