Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Gateway API 1.4 Stabilizes BackendTLSPolicy: Encrypting the Gateway-to-Pod Hop Without a Service Mesh
·Dora Noda·10 min

Gateway API 1.4 Stabilizes BackendTLSPolicy: Encrypting the Gateway-to-Pod Hop Without a Service Mesh

Gateway API 1.4 graduates BackendTLSPolicy to stable, giving shared clusters a portable way to encrypt gateway-to-Pod traffic with fail-closed validation — here is the complete YAML and the rollout checklist for multi-tenant platforms.

Kubernetes
PaaS
self-hosting
security
Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers
·Dora Noda·11 min

Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers

CNCF's Platform Engineering 2.0 names AI agents as platform consumers with their own access, scope, and governance needs. Here is the concrete design that follows: per-agent identity, least-privilege roles, machine-speed quotas — and why MCP auth must be agent-first from day one.

AI agents
Model Context Protocol
security
Kubernetes
An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
·Dora Noda·11 min

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands

Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

AI agents
security
Model Context Protocol
identity
+1
Zayo Put Network Operations Behind an MCP Server: What Governed Agent Access to the Underlay Means for Deploy-from-Chat
·Dora Noda·10 min

Zayo Put Network Operations Behind an MCP Server: What Governed Agent Access to the Underlay Means for Deploy-from-Chat

Zayo's September 2026 Agentic Networking launch puts network operations behind a governed MCP server. What an underlay-aware deploy agent can do, and the five-rule governance boundary your own agent tools should copy.

Model Context Protocol
AI agents
PaaS
self-hosting
Versioning MCP Deploy Tools at 10,000-Server Scale: What Breaking Tool-Schema Changes Do to Agents Pinned Against Your Endpoint
·Dora Noda·10 min

Versioning MCP Deploy Tools at 10,000-Server Scale: What Breaking Tool-Schema Changes Do to Agents Pinned Against Your Endpoint

Past 10,000 servers, your MCP tool schemas are a public API with pinned agent clients. A breaking-vs-safe change table, two worked deploy-tool examples — one loud, one silent — and a six-rule versioning discipline for self-hosted endpoints.

Model Context Protocol
AI agents
API
developer tools
Temporal Went From $5B to $12.5B in Seven Months: Why Deploy-From-Chat Agents Need Durable Execution
·Dora Noda·9 min

Temporal Went From $5B to $12.5B in Seven Months: Why Deploy-From-Chat Agents Need Durable Execution

Temporal's $550M raise at $12.55B and its GA OpenAI Agents SDK integration mark durable execution as production-required for agents. A worked deploy-from-chat crash scenario shows what breaks without it, plus a cloud vs self-hosted vs lighter-engine decision guide.

AI agents
openai
Model Context Protocol
self-hosting
+1
StackQL v0.11 Turns Every Agent Cloud Query Into an OpenTelemetry Record: What That Buys Your Fleet's Audit Trail
·Dora Noda·11 min

StackQL v0.11 Turns Every Agent Cloud Query Into an OpenTelemetry Record: What That Buys Your Fleet's Audit Trail

StackQL v0.11 speaks MCP revision 2026-07-28 and emits its agent audit log as OTLP records. The exact collector config that ingests it with no transform, the stateless-HTTP tradeoff, and what remains before inventory queries become deploy authority.

Model Context Protocol
AI agents
developer tools
cloud infrastructure
The Forge That Sketched Its Own PaaS, Then Cut It: What Cave's Deferred Podman Deploy Tells Teams Rebuilding Git-Push Without a Vendor
·Dora Noda·12 min

The Forge That Sketched Its Own PaaS, Then Cut It: What Cave's Deferred Podman Deploy Tells Teams Rebuilding Git-Push Without a Vendor

Cave's design PRD made podman deploy a launch pillar, then the author cut all container deploy functionality indefinitely. The spec, the cut, and a row-by-row accounting of what a forge answers versus what still needs a platform.

self-hosting
PaaS
developer tools
Renovate as a Kubernetes CRD: Patching Build Images Without a Hosted Bot Account
·Dora Noda·10 min

Renovate as a Kubernetes CRD: Patching Build Images Without a Hosted Bot Account

Mogenius's Renovate Operator runs dependency updates as a Kubernetes-native controller. Here is a worked design for patching a self-hosted PaaS's build images with it, plus the quota, credential, and blast-radius guardrails that keep automation safe.

self-hosting
Kubernetes
PaaS
security
Showing 487–495 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags