Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Daytona's Core Went Private: What a Frozen Sandbox Repo Teaches About Who Owns Your Agent Isolation Layer
·Dora Noda·11 min

Daytona's Core Went Private: What a Frozen Sandbox Repo Teaches About Who Owns Your Agent Isolation Layer

Daytona froze its open-source sandbox repo in June 2026, four months after a $24M Series A. What the freeze costs teams pinned to v0.190.0, how MinIO CE ran the same playbook, and a priced look at staying, renting, or owning your agent isolation layer.

AI agents
self-hosting
Kubernetes
cybersecurity
Coolify vs Dokku vs CapRover vs Ownkube: What the 2026 Shootout Gets Right — and What Breaks at Box Two
·Dora Noda·11 min

Coolify vs Dokku vs CapRover vs Ownkube: What the 2026 Shootout Gets Right — and What Breaks at Box Two

A September 2026 four-way comparison crowns a winner for every team size — but its real finding is that each panel breaks differently at the second machine. This read-through prices all four ceilings, including the vendor's own.

self-hosting
PaaS
Kubernetes
migration
Your Operator's /readyz Is Lying: The controller-runtime Cache-Sync Trap Behind Green Dashboards and Stalled Reconciles
·Dora Noda·8 min

Your Operator's /readyz Is Lying: The controller-runtime Cache-Sync Trap Behind Green Dashboards and Stalled Reconciles

A kubebuilder operator's scaffolded readyz check returns 200 before the informer cache syncs, before leader election completes, and before webhooks serve. The three readiness checks that close the gap, the RBAC stall that makes them necessary, and the audit to run this week.

Kubernetes
engineering
infrastructure
tutorial
Claude Cowork Broke Containment Twice in July: VM Root on Windows, Host Files on Mac
·Dora Noda·13 min

Claude Cowork Broke Containment Twice in July: VM Root on Windows, Host Files on Mac

In July 2026, Claude Cowork broke containment twice — a root chain on Windows and a kernel-to-host escape on Mac. This teardown walks both attack chains and maps the isolation tiers and hardening checklist your own agent sandboxes need.

AI agents
security
self-hosting
Kubernetes
One Gateway or Fifty Servers? What AWS and Google's Opposite MCP Bets Mean for Your Deploy Surface
·Dora Noda·11 min

One Gateway or Fifty Servers? What AWS and Google's Opposite MCP Bets Mean for Your Deploy Surface

AWS ships one MCP server with a fixed tool set while Google ships more than fifty, one per service. This post compares both designs on context cost, auth, versioning, and audit, then recommends a concrete tool vocabulary for a deploy surface agents can operate.

Model Context Protocol
AI agents
cloud computing
PaaS
+1
Your Deploy-from-Chat MCP Server Has Too Many Tools: What Anthropic's 98.7% Token Cut Means for Agent-Operated Infrastructure
·Dora Noda·11 min

Your Deploy-from-Chat MCP Server Has Too Many Tools: What Anthropic's 98.7% Token Cut Means for Agent-Operated Infrastructure

Anthropic cut a multi-step agent task from 150,000 tokens to 2,000 by having agents write code against MCP tools instead of calling them one by one. Here is what that 98.7% saving means for deploy-from-chat servers, and why every mutation still needs its own approval and audit entry.

Model Context Protocol
AI agents
developer tools
self-hosting
Your AI Agent Pushed Code and Nothing Deployed: Vercel's Git-Author Check vs the Age of Agent Committers
·Dora Noda·8 min

Your AI Agent Pushed Code and Nothing Deployed: Vercel's Git-Author Check vs the Age of Agent Committers

Vercel blocks deployments when the git commit author is not a recognized team member — a check that silently fails the moment an AI agent commits as itself. Four real cases, four working fixes, and why agent-first platforms authenticate the deploy call instead of the commit.

AI agents
PaaS
developer tools
Model Context Protocol
Uber Burned Its Entire 2026 AI Coding Budget by April: What Ungoverned Agentic Spend Means for Teams Running Their Own Deploy Infra
·Dora Noda·11 min

Uber Burned Its Entire 2026 AI Coding Budget by April: What Ungoverned Agentic Spend Means for Teams Running Their Own Deploy Infra

Uber burned its entire 2026 AI budget in four months after Claude Code adoption jumped from 32% to 84% of its 5,000 engineers. The timeline, the token economics behind it, and a six-control governance playbook for teams whose agents also deploy.

AI agents
Claude
Enterprise AI
cost-optimization
Synacktiv's Unpatched Argo CD Repo-Server Flaw: Why Any Pod That Can Reach the gRPC Service Is Equivalent to an Authenticated Attacker
·Dora Noda·10 min

Synacktiv's Unpatched Argo CD Repo-Server Flaw: Why Any Pod That Can Reach the gRPC Service Is Equivalent to an Authenticated Attacker

Argo CD's repo-server exposes an unauthenticated gRPC endpoint that turns any pod with network reachability into a path to cluster takeover. This breakdown covers Synacktiv's exploit chain, which installs are exposed, and the exact NetworkPolicies that close it.

security
Kubernetes
self-hosting
developer tools
Showing 586–594 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags