Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Your AI Agent Can Now Restart Prod Postgres From Chat: What the Coolify–AnythingLLM MCP Bridge Costs in Audit and Rollback
An open-source MCP server lets an AI agent deploy, restart, and roll back Coolify apps from an AnythingLLM chat window. A threat-model teardown of what agent-driven deploys cost in scope, attribution, and reversibility — and the five-item checklist any agent-facing deploy server must pass.

Contabo vs Hetzner, September 2026: Where Should a Self-Hosted Fleet Rent Its Boxes?
After Hetzner's June 2026 price hike, Contabo ships double the RAM per euro while Hetzner keeps hourly billing and steadier cores. A role-by-role fleet placement with worked monthly totals for control planes, elastic workers, and APAC edge nodes.

bex Is in Public Alpha: What Ships Today, What It Costs, and What 'Alpha' Means for the Open-Source, Agent-Operable Render Alternative
bex is open for signup as a public alpha: git push to HTTPS on machines you own, a Render-compatible API and CLI, 179 MCP tools for agents, and prices 30% under Render. Here is the ledger of what ships, what is missing, what it costs, and what must be true before 1.0.

Authorizer Puts Agents on the Org Chart: A2A Token Exchange, OAuth-2.1 MCP, and Secretless Kubernetes Identity
Authorizer 2.4 gives AI agents first-class identities: RFC 8693 delegation with nested actor chains, an MCP server behind OAuth 2.1 with audience-bound tokens, and secretless Kubernetes workload auth — a credential model where agents hold scoped delegations instead of god-keys.

Your Agent Knows Your API Keys: Credential Brokering With Infisical's Agent Vault
AI agents that can read API keys can be prompt-injected into repeating them. Infisical's open-source Agent Vault brokers credentials at an egress proxy so secrets never enter the context window — here is the mechanism, the alternatives, and the build checklist.

A2A Turns One: What 150+ Organizations Standardizing Agent-to-Agent Messaging Means for a PaaS Whose Agents Deploy Apps
A2A hit v1.0 with 150+ organizations and production rollouts at Microsoft, AWS, Salesforce, SAP, and ServiceNow. Here is the MCP-vs-A2A routing rule, a worked deploy-agent delegation, and when a self-hosted PaaS should ship its own Agent Card endpoint.

Toward a World Where Builds Don't Exist: What Railway's VM-Powered Thesis Gives Up in Provenance
Railway wants a world where builds don't exist and your app is just live. But the build produces the digest, SBOM, provenance, and rollback artifact that incident response and the EU's new reporting rules depend on — here is the full inventory of what disappears with it.

Whole GPU or Nothing Is Over: Wiring DRA GPU Scheduling on a Bare-Metal Cluster API Fleet
Kubernetes' device-plugin era of whole-GPU-or-nothing scheduling is ending. What WG Device Management standardized with DRA, what coarse allocation costs a small bare-metal fleet, and the exact checklist a Cluster API fleet needs before tenants can deploy with a GPU.

Your .com Renews at $10.97 in November: The Tenant Domain Bill Your PaaS Can't Automate Away
Verisign raises wholesale .com prices to $10.97 on November 1, 2026, while uncapped registries reprice at will — .info is up 75% since 2019. Here is what tenants actually pay per domain, what a self-hosted PaaS automates to zero, and the registrar bill no platform can touch.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags