Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Proxly Puts ngrok on Your Own Domain — but Your Laptop Is Still the Server
Proxly is a self-hosted ngrok alternative that exposes localhost on subdomains of your own domain through a VPS relay and wildcard DNS. How its WebSocket relay works, what it costs against ngrok's paid tiers, and why a tunnel still isn't a deployment.

Ownkube's Named AI Agents Run Your Ops — but the AWS Bill Is Still Yours
Ownkube pairs a Heroku-style deploy UX with named AI agents for cost, incident, scaling, and security — but its Production shape still runs on EKS. A worked 8-vCPU comparison puts the AWS route at $460–510 a month against €60–90 on owned hardware.

Northflank BYOC vs Owning Hetzner Boxes: What Bring-Your-Own-Cloud Actually Saves
The same API-plus-Postgres stack priced five ways: Render, Railway, Northflank managed, Northflank BYOC on AWS, and a Hetzner box under Cluster API — plus the sensitivity analysis that decides which one is actually cheapest for your workload.

Node Lifecycle Conditions Land as Alpha in v1.37: The Machine-Readable Node Health Vocabulary Your Agent Operator Has Been Waiting For
Kubernetes v1.37 reserves five well-known Node conditions for drains, maintenance, and graceful shutdown. No core controller reads them yet — but for agent operators, a stable machine-readable vocabulary is the prerequisite, and self-hosted fleets can start publishing today.

Netlify Killed Per-Seat Pricing and Doubled Bandwidth Meters: What Your App Actually Pays Now
Netlify traded $20-per-seat billing for unlimited seats and doubled usage meters. A credit-by-credit recompute of what traffic-heavy apps pay under the new rates — and the few-hundred-gigabyte crossover where owned hardware wins.

Your Migrated App Still Asks Which PaaS It's On
Migrated apps keep sniffing for DYNO, RAILWAY_*, and FLY_APP_NAME long after they leave those platforms. The concrete inject list and do-not-fake list a Render-compatible self-hosted API must honor so tenants' health checks and telemetry keep telling the truth.

MCPwn: How nginx-ui's Unauthenticated MCP Endpoint Handed Attackers Full nginx Takeover — and the Checklist That Would Have Stopped It
nginx-ui shipped MCP support with one endpoint missing authentication, exposing 12 tools — including config writes with automatic reload — to anyone on the network. CVE-2026-33032 scored 9.8 and was exploited in the wild; here is how the takeover worked and a seven-item checklist for any panel adding agent access.

The MCPA Is Here: What a 120-Minute, 5-Domain MCP Exam Says About Production MCP Operations
The Agentic AI Foundation's new MCPA exam puts half its weight on tool execution and security. A read of what that syllabus reveals about where MCP breaks in production, plus a five-domain checklist for hardening your own MCP server.

kube-hetzner vs CAPH: What Your First Hetzner Provisioning Choice Costs by the Second Cluster
Terraform or Cluster API for Hetzner Kubernetes? A day-2 comparison of kube-hetzner and CAPH across upgrades, node replacement, and the June 2026 server-type churn — and exactly where the answer flips.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags