Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

MCP's July 2026 Authorization Hardening: How RFC 9207 Issuer Checks Protect Agents That Hold Deploy Keys
The MCP 2026-07-28 specification closes the authorization-server mix-up attack with mandatory RFC 9207 issuer validation and issuer-bound credentials. Here is how the attack steals an agent's deploy credentials, and the server-side checklist for infrastructure MCP servers.

One in Five MCP Access Policies Is Broken or Missing: The Audit to Run Before Agents Touch Your Deploy Pipeline
One in five MCP access policies is broken or missing, Splunk's MCP server leaked tokens in cleartext until v1.0.3, and the July 2026 spec rebuilt authorization from scratch. What it means for deploy tools exposed to agents, and the ten-check audit to run first.

MCP at 97 Million Downloads: the Protocol Won, but Sessions and Sandboxes Are Still Open Problems
MCP hit 97 million monthly downloads and 10,000+ production servers — but stateful sessions still break behind load balancers and every agent framework ships its own sandbox. What the adoption numbers prove, and the two gaps they don't.

Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS
Kubernetes signs its releases with Sigstore — but a signature nobody verifies is theater. How to wire Cosign keyless signing into a git-push pipeline and enforce it with a Kyverno admission policy before unsigned images reach your nodes.

Kubernetes 1.37 Scales HPA to Zero in Core: No More Paying for Idle Pods
Kubernetes 1.37 graduates HPA scale-to-zero to a default-on beta, so queue workers and preview environments can drop to zero replicas on an external metric. This post works the idle-economics math, shows the exact wiring, and maps where KEDA and Knative still fit.

Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself
Kubernetes 1.36 graduates fine-grained kubelet authorization to GA, replacing the over-broad nodes/proxy grant that lets read-only agents execute code in any pod. This playbook maps every kubelet endpoint to its least-privilege subresource and walks through the five-step migration for fleets running untrusted tenant workloads.

Hetzner After the June 2026 Price Hikes: Auction Metal vs Cloud VMs as Kubernetes Fleet Nodes
Hetzner's June 2026 hikes tripled dedicated cloud prices while auction boxes held at €37–€46 — a euro-level comparison of auction metal versus cloud VMs as Kubernetes fleet nodes, the operational tradeoffs, and which roles fit each.

Hetzner's Post-July API Churn: The Primary IP Flip and Prometheus 3.14 Label Drop Your CAPH Fleet Still Hasn't Pinned
Hetzner's July datacenter removal was only the headline: unassigned Primary IPs flipped to assignee_type unassigned on August 1, Prometheus 3.14 dropped the Hetzner datacenter label, and the datacenters API goes 410 on October 1. A per-break fix table plus a six-grep audit runbook for CAPH fleets.

Hetzner Pulled openSUSE 15 and Deprecated Debian 11: Rebuild Your CAPH Node Images Before November 30
Hetzner removed openSUSE 15 for new servers on July 30 and will do the same to Debian 11 after November 30. This runbook shows Cluster API (CAPH) operators how to audit pinned images, pick a replacement base, and roll the fleet before scale-up starts failing.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags