Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Oracle Halved Its Free ARM Cloud. Here's the $0-vs-$5 Kubernetes Math Now.
Oracle cut its Always Free Ampere allowance from 4 OCPUs/24GB to 2/12 in June 2026 and started terminating over-limit instances in August. A worked comparison of the most always-on Kubernetes still available for $0 versus a flat ~$5 Hetzner box, with the reclaim, capacity, and grandfathering catches priced in.

OpenAI Built Codex a Windows Sandbox Out of SIDs and Firewall Rules: What It Teaches a Linux-First PaaS About Isolating Agent Code
OpenAI's May 2026 write-up shows how Codex sandboxes agent commands on Windows with synthetic SIDs, write-restricted tokens, dedicated sandbox users, and firewall rules — here is the two-tier design, the three isolation lessons a Linux-first PaaS should take from it, and an explicit verdict on whether it needs a Windows tier.

Open-Weight AI Is Having Its Kubernetes Moment — Here's What Your Fleet Needs to Serve It
Open-weight models are becoming the default infrastructure layer for AI. This post maps the standardized Kubernetes inference stack — OCI weights, DRA, InferencePool, KServe, llm-d — and shows what a self-hosted fleet needs to serve models next to tenant apps.

The npm Worm With Valid Provenance: What ChainDrop's 400 Poisoned Packages Mean for Anyone Building Tenant Images
ChainDrop poisoned 400+ npm packages with valid SLSA provenance after the keyv maintainer's GitHub account was compromised. Here is what provenance-only trust breaks and the five build-pipeline controls every tenant-image builder needs.

Node 26 Hits Active LTS on October 28: A Builder Checklist for Git-Push PaaS Teams
Node.js 26 becomes Active LTS on October 28, 2026 — with Yarn v1 and Corepack gone from builder images and six tenant-facing breakages to triage. A dated checklist for git-push PaaS operators covering default-flip timing, EOL warnings, and the annual cadence that starts with Node 27.

Your Dockerfile Cache Is Blind to Your Monorepo: What Build-Graph Caching Adds to a Git-Push PaaS Pipeline
A one-line monorepo change costs about 11 builder-minutes under Docker layer caching versus 4 with Turborepo/Bazel remote cache hits — the worked time-and-cost math, the September 2026 Namespace/Depot/Blacksmith landscape, and when a git-push PaaS should offer graph-aware caching natively.

Surviving a Full Hetzner Datacenter Outage: What 3-DC k0s HA Really Costs Versus Single-DC
A 3-datacenter k0s cluster on Hetzner survives a full DC outage for about $103/mo in servers and $0 in extra traffic — but every etcd write pays ~25ms and a third of worker capacity must sit idle. Here is the layer-by-layer HA design, the verified cost math, and when single-DC plus backups wins instead.

MLflow's MCP Registry: Versioned, Governed Tool Dependencies for Production Agents
MLflow 3.15.0's experimental MCP Registry versions MCP servers with semver, promotes them through staging and production aliases, snapshots their tools, and links traces to exact versions — a worked walkthrough of the promotion loop, the registry-vs-gateway boundary, and when a second tenant makes the catalog mandatory.

MCP Won: Why Every Major AI Vendor Shipping One Protocol Makes 'Deploy From Chat' a Safe Roadmap Bet
Anthropic, OpenAI, Google, Microsoft, and Amazon all ship MCP now — 97M monthly SDK downloads, 10,000+ servers, neutral foundation governance. What that convergence changes about betting your platform's deploy/rollback/logs agent surface on one protocol, and the four residual risks to budget for.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags