Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

MCP's July 2026 Authorization Hardening: How RFC 9207 Issuer Checks Protect Agents That Hold Deploy Keys
·Dora Noda·11 min

MCP's July 2026 Authorization Hardening: How RFC 9207 Issuer Checks Protect Agents That Hold Deploy Keys

The MCP 2026-07-28 specification closes the authorization-server mix-up attack with mandatory RFC 9207 issuer validation and issuer-bound credentials. Here is how the attack steals an agent's deploy credentials, and the server-side checklist for infrastructure MCP servers.

Model Context Protocol
security
AI agents
self-hosting
One in Five MCP Access Policies Is Broken or Missing: The Audit to Run Before Agents Touch Your Deploy Pipeline
·Dora Noda·12 min

One in Five MCP Access Policies Is Broken or Missing: The Audit to Run Before Agents Touch Your Deploy Pipeline

One in five MCP access policies is broken or missing, Splunk's MCP server leaked tokens in cleartext until v1.0.3, and the July 2026 spec rebuilt authorization from scratch. What it means for deploy tools exposed to agents, and the ten-check audit to run first.

Model Context Protocol
AI agents
security
self-hosting
MCP at 97 Million Downloads: the Protocol Won, but Sessions and Sandboxes Are Still Open Problems
·Dora Noda·9 min

MCP at 97 Million Downloads: the Protocol Won, but Sessions and Sandboxes Are Still Open Problems

MCP hit 97 million monthly downloads and 10,000+ production servers — but stateful sessions still break behind load balancers and every agent framework ships its own sandbox. What the adoption numbers prove, and the two gaps they don't.

Model Context Protocol
AI agents
scalability
self-hosting
Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS
·Dora Noda·10 min

Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS

Kubernetes signs its releases with Sigstore — but a signature nobody verifies is theater. How to wire Cosign keyless signing into a git-push pipeline and enforce it with a Kyverno admission policy before unsigned images reach your nodes.

security
Kubernetes
self-hosting
PaaS
Kubernetes 1.37 Scales HPA to Zero in Core: No More Paying for Idle Pods
·Dora Noda·13 min

Kubernetes 1.37 Scales HPA to Zero in Core: No More Paying for Idle Pods

Kubernetes 1.37 graduates HPA scale-to-zero to a default-on beta, so queue workers and preview environments can drop to zero replicas on an external metric. This post works the idle-economics math, shows the exact wiring, and maps where KEDA and Knative still fit.

Kubernetes
cost-optimization
self-hosting
PaaS
Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself
·Dora Noda·9 min

Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself

Kubernetes 1.36 graduates fine-grained kubelet authorization to GA, replacing the over-broad nodes/proxy grant that lets read-only agents execute code in any pod. This playbook maps every kubelet endpoint to its least-privilege subresource and walks through the five-step migration for fleets running untrusted tenant workloads.

Kubernetes
security
self-hosting
infrastructure
Hetzner After the June 2026 Price Hikes: Auction Metal vs Cloud VMs as Kubernetes Fleet Nodes
·Dora Noda·11 min

Hetzner After the June 2026 Price Hikes: Auction Metal vs Cloud VMs as Kubernetes Fleet Nodes

Hetzner's June 2026 hikes tripled dedicated cloud prices while auction boxes held at €37–€46 — a euro-level comparison of auction metal versus cloud VMs as Kubernetes fleet nodes, the operational tradeoffs, and which roles fit each.

self-hosting
Kubernetes
cost-optimization
PaaS
Hetzner's Post-July API Churn: The Primary IP Flip and Prometheus 3.14 Label Drop Your CAPH Fleet Still Hasn't Pinned
·Dora Noda·9 min

Hetzner's Post-July API Churn: The Primary IP Flip and Prometheus 3.14 Label Drop Your CAPH Fleet Still Hasn't Pinned

Hetzner's July datacenter removal was only the headline: unassigned Primary IPs flipped to assignee_type unassigned on August 1, Prometheus 3.14 dropped the Hetzner datacenter label, and the datacenters API goes 410 on October 1. A per-break fix table plus a six-grep audit runbook for CAPH fleets.

self-hosting
Kubernetes
cloud infrastructure
guide
Hetzner Pulled openSUSE 15 and Deprecated Debian 11: Rebuild Your CAPH Node Images Before November 30
·Dora Noda·10 min

Hetzner Pulled openSUSE 15 and Deprecated Debian 11: Rebuild Your CAPH Node Images Before November 30

Hetzner removed openSUSE 15 for new servers on July 30 and will do the same to Debian 11 after November 30. This runbook shows Cluster API (CAPH) operators how to audit pinned images, pick a replacement base, and roll the fleet before scale-up starts failing.

Kubernetes
self-hosting
cloud infrastructure
guide
Showing 514–522 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags