Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

k3s vs Kubernetes vs MicroK8s: the 4x RAM Gap Is Real — and Where a Lightweight Distro Stops Being a Fleet
k3s agents run in 512 MB against a kubeadm worker's 2 GB — a real 4x gap on full upstream Kubernetes. What that buys on a €4 Hetzner box, the one-way doors waiting at machine two, and the on-call moment when Cluster API takes over.

Who Resolves Your Subdomain When One DNS Node Dies? Technitium Clustering vs Pi-hole HA, Compared Honestly
Technitium's built-in DNS clustering and the community pihole-ha add-on solve the same outage — one dead DNS node — from opposite directions. A concrete side-by-side on sync models, failover times, DHCP, and DNSSEC, plus which one fits a self-hosted PaaS's public wildcard path.

One ClusterProfile vs One Flux per Cluster: What Sveltos v1.13 Changes About Fleet Add-On Delivery
Sveltos delivers fleet add-ons from one management cluster to auto-discovered Cluster API clusters, replacing one Flux installation per workload cluster. A concrete before/after comparison — targeting, rollouts, drift, dry runs — plus what v1.13's Helm-update visibility adds and where Sveltos stops.

SNCF Ships Its Cluster API Providers as OCI Artifacts: What an ORAS-Based Provider Supply Chain Buys a Self-Hosted Fleet
SNCF manages its Cluster API providers as versioned OCI artifacts via ORAS instead of pulling YAML from GitHub releases. How the pattern works mechanically, how it compares to clusterctl's documented air-gap paths, and when a small Hetzner fleet should copy it.

Ship the Agent, Not Just the App: Curie vs Deployah and the Future of the Git-Push Deploy Contract
Curie ships Claude Code agents to Kubernetes via git push while Deployah shrinks the manifest to a short spec with nothing in-cluster: a side-by-side of the two deploy contracts, the six deploy-time concerns agents add, and which end a git-push PaaS should extend first.

Your Scanner Said Clean. The Kubernetes CVE Record Was Wrong.
Kubernetes corrected four CVE records to 'affects all versions' on June 1, 2026 — three were never fixed and never will be. The five-check audit a self-hosted fleet operator should run before trusting the next automated patch decision.

The Reliability Tier Is the Real Price Tag: Railway HA vs Render's New Plans vs Your Own Fleet
Railway's experimental HA Postgres and Render's flat-rate workspace plans repriced reliability in spring 2026: about $187/mo versus $116/mo for a two-replica HA setup against $35/mo on owned Hetzner machines, plus the sensitivity math on replicas, egress, and team size.

Pangolin Puts SSO and WireGuard in Front of LLM Access Instead of API Keys: What Tunnel-Based Identity Means for Agent Credential Hygiene
Pangolin's AI Gateway authenticates LLM access with SSO-backed WireGuard tunnels instead of static API keys, and joins self-hosted models to the same gateway as public ones. Here's how the mechanism works, how it compares to Tailscale Aperture, and what it changes in your threat model.

A Full PaaS on One $11 ARM Server: What Real CAX21 Usage Data Says About Tenant Capacity
A measured teardown of a full multi-tenant PaaS on a €10.99 Hetzner CAX21 ARM server: per-component RAM tables, per-tier tenant footprints, and the 10–25 tenant capacity the numbers support — plus the scaling ladder to €33 and ~€200.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags