Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Gateway API v1.5 Went All-In on Stable: Your Ingress-to-Gateway Migration Checklist for a Self-Hosted Fleet
With ingress-nginx past end of life and Gateway API v1.5 promoting six features to Standard, migrating off Ingress is now a scheduled project. A worked conversion, a manual-pass checklist, and a cutover runbook for small self-hosted fleets.

Fly.io Postgres vs Self-Hosted CloudNativePG: Pricing the Multi-Region Story
Fly.io's Postgres story is really two products — deprecated multi-region fly pg and single-region-first Managed Postgres. This inventory prices MPG, legacy fly pg, and a self-hosted CNPG fleet for a typical HA workload, with a decision rule for when Postgres-near-every-region earns its invoice.
Building Agents That Don't Break Themselves: Fly.io's Sprite Safety Patterns and the Deploy-from-Chat Risk Model
Fly.io's June 2026 Sprite safety patterns — splitting the agent loop from execution, per-run credentials, and checkpoint restores — map directly onto what a deploy platform needs before agents can ship code: scoped credentials, audit logs, and guaranteed rollback.

Every Pull Request Gets a Live Environment: The Namespace-Per-PR Blueprint for Self-Hosted Kubernetes
Preview environments are now the default developers expect: 40% of teams run them and top performers nearly all do. What the Vercel/Railway bar requires, the namespace-per-PR blueprint for your own cluster, database strategies that stop short of a DBaaS, and the cost math versus always-on staging.

Dokploy Shipped 508 MCP Tools. The Community Deleted 95% of Them.
Dokploy's official MCP server mirrors every API endpoint as a tool — 508 of them, burning roughly 74k tokens before the first question. Community rivals cover the same API with 13 to 28 curated tools. The measured numbers behind the backlash, and five design rules for the next infrastructure MCP.

DMCA Takedowns Land on the Platform, Not the Tenant: The Notice-and-Takedown Runbook a Self-Hosted PaaS Needs Before the First Complaint
The moment tenants serve content from your domains, abuse notices land on your desk — and safe-harbor protection depends on machinery built before the first one. A concrete DMCA and DSA runbook for self-hosted PaaS operators: designated agent, repeat-infringer policy, per-tenant suspension, and shared-domain defense.

Only 21% of Teams Can Stand Up a Pipeline in Under Two Hours — The Setup Tax Git-Push PaaS Erases
Harness's 2026 survey found only 21% of teams can add a build-and-deploy pipeline in under two hours — while elite teams deploy 973x more often than laggards. A timed, row-by-row breakdown of where the setup hours go on the Dockerfile path, and what the git-push path deletes.

CrowdSec 1.8 Adds Bot Detection to Its Open-Source WAF: What Fingerprinting Plus Proof-of-Work Changes at a Self-Hosted Edge
CrowdSec 1.8 adds fingerprint-plus-proof-of-work bot detection to its open-source WAF and a Kubernetes datasource that lets one instance read pod logs from the API server. How the challenge scores bots, what it changes versus fail2ban and Anubis, and a six-item adoption checklist for your ingress.

Crossplane and AI: Why Agent-Operated Platforms Need Declarative APIs, Not Dashboards
CNCF's case that AI agents need API-first declarative infrastructure is right — but Crossplane's sprawling CRD surface is the wrong window into it. Agents need a small typed PaaS API over declarative machinery.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags