Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Gateway API 1.4 Stabilizes BackendTLSPolicy: Encrypting the Gateway-to-Pod Hop Without a Service Mesh
Gateway API 1.4 graduates BackendTLSPolicy to stable, giving shared clusters a portable way to encrypt gateway-to-Pod traffic with fail-closed validation — here is the complete YAML and the rollout checklist for multi-tenant platforms.

Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers
CNCF's Platform Engineering 2.0 names AI agents as platform consumers with their own access, scope, and governance needs. Here is the concrete design that follows: per-agent identity, least-privilege roles, machine-speed quotas — and why MCP auth must be agent-first from day one.

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

Zayo Put Network Operations Behind an MCP Server: What Governed Agent Access to the Underlay Means for Deploy-from-Chat
Zayo's September 2026 Agentic Networking launch puts network operations behind a governed MCP server. What an underlay-aware deploy agent can do, and the five-rule governance boundary your own agent tools should copy.

Versioning MCP Deploy Tools at 10,000-Server Scale: What Breaking Tool-Schema Changes Do to Agents Pinned Against Your Endpoint
Past 10,000 servers, your MCP tool schemas are a public API with pinned agent clients. A breaking-vs-safe change table, two worked deploy-tool examples — one loud, one silent — and a six-rule versioning discipline for self-hosted endpoints.

Temporal Went From $5B to $12.5B in Seven Months: Why Deploy-From-Chat Agents Need Durable Execution
Temporal's $550M raise at $12.55B and its GA OpenAI Agents SDK integration mark durable execution as production-required for agents. A worked deploy-from-chat crash scenario shows what breaks without it, plus a cloud vs self-hosted vs lighter-engine decision guide.

StackQL v0.11 Turns Every Agent Cloud Query Into an OpenTelemetry Record: What That Buys Your Fleet's Audit Trail
StackQL v0.11 speaks MCP revision 2026-07-28 and emits its agent audit log as OTLP records. The exact collector config that ingests it with no transform, the stateless-HTTP tradeoff, and what remains before inventory queries become deploy authority.

The Forge That Sketched Its Own PaaS, Then Cut It: What Cave's Deferred Podman Deploy Tells Teams Rebuilding Git-Push Without a Vendor
Cave's design PRD made podman deploy a launch pillar, then the author cut all container deploy functionality indefinitely. The spec, the cut, and a row-by-row accounting of what a forge answers versus what still needs a platform.

Renovate as a Kubernetes CRD: Patching Build Images Without a Hosted Bot Account
Mogenius's Renovate Operator runs dependency updates as a Kubernetes-native controller. Here is a worked design for patching a self-hosted PaaS's build images with it, plus the quota, credential, and blast-radius guardrails that keep automation safe.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags