Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server
·Dora Noda·11 min

One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server

nginx-ui shipped an MCP endpoint without its AuthRequired check — a CVSS 9.8 that left roughly 2,689 servers open to unauthenticated takeover. The full MCPwn timeline, the two-route bug, and a seven-item audit checklist for anyone shipping an MCP server.

security
Model Context Protocol
self-hosting
AI agents
Deploy Agents That Wait: Building a Stateless Rollout-and-Approval Agent on MCP Tasks and Multi Round-Trip Requests
·Dora Noda·10 min

Deploy Agents That Wait: Building a Stateless Rollout-and-Approval Agent on MCP Tasks and Multi Round-Trip Requests

MCP's July 2026 release made the protocol stateless and gave agent builders Tasks and Multi Round-Trip Requests. Here is the concrete design for a deploy agent that returns a task handle, polls rollout status against Kubernetes Deployment conditions, and stops for an expiring human approval before promoting to production.

Model Context Protocol
AI agents
Kubernetes
engineering
MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish
·Dora Noda·10 min

MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish

The final MCP spec deprecates Dynamic Client Registration in favor of Client ID Metadata Documents, with removal eligible after July 2027. Here is the ordered checklist for migrating a self-hosted MCP server, plus the two companion hardenings to ship in the same window.

Model Context Protocol
AI agents
security
self-hosting
KubeCon Japan 2026 Sold Out Again: What It Signals for a Hetzner-Only Fleet's APAC Roadmap
·Dora Noda·9 min

KubeCon Japan 2026 Sold Out Again: What It Signals for a Hetzner-Only Fleet's APAC Roadmap

KubeCon Japan 2026 sold out for the second straight year. What the six-track lineup and Japan's enterprise demand data say about APAC appetite for Kubernetes — and the latency math a Hetzner-only fleet must face before expanding east of Singapore.

Kubernetes
PaaS
self-hosting
event
kops Is Tracking Kubernetes 1.37 in 2026 — and Still Proves Why Cluster API Won the Heterogeneous Fleet
·Dora Noda·10 min

kops Is Tracking Kubernetes 1.37 in 2026 — and Still Proves Why Cluster API Won the Heterogeneous Fleet

kops shipped 1.36 and already tracks Kubernetes 1.37 — yet its own release notes show why declarative Cluster API won fleets spanning clouds and bare metal, and which upgrade disciplines a self-hosted platform should steal from it.

Kubernetes
self-hosting
PaaS
engineering
Kamal vs Coolify: How Much Platform Should Actually Run on Your Server?
·Dora Noda·10 min

Kamal vs Coolify: How Much Platform Should Actually Run on Your Server?

Kamal runs almost nothing on your server; Coolify runs the whole platform. A concrete side-by-side of footprint, previews, and automation — and where a Render-compatible API splits the difference.

self-hosting
PaaS
developer tools
AI agents
Hetzner Nearly Tripled Bare-Metal Prices: What the AX102's €124-to-€454 Jump Means for Self-Hosting Math
·Dora Noda·9 min

Hetzner Nearly Tripled Bare-Metal Prices: What the AX102's €124-to-€454 Jump Means for Self-Hosting Math

Hetzner's June 2026 repricing pushed the AX102 from €124 to €454 a month. A worked before-and-after comparison shows the self-hosting case compressed but intact — and why a plannable step hike beats a silent usage meter.

self-hosting
cost-optimization
hosting
infrastructure
Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production
·Dora Noda·12 min

Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production

An MCP server that can redeploy production is a deploy pipeline with natural-language input. A seven-control hardening checklist — TLS, per-tool scopes, short-lived credentials, schema validation, rate limits, and audit logging — mapped to the three attacks that actually happen.

Model Context Protocol
AI agents
security
infrastructure
+1
AI-Assisted Commits Leak Secrets at Twice the Baseline Rate — Why Your PaaS Should Scan Every Push
·Dora Noda·9 min

AI-Assisted Commits Leak Secrets at Twice the Baseline Rate — Why Your PaaS Should Scan Every Push

GitGuardian counted 28.65 million new hardcoded secrets on public GitHub in 2025, with AI-assisted commits leaking at 3.2% against a 1.5% baseline. Why a default-on push-time scan catches what Vault, OpenBao, and Infisical never see, and what the gate should look like.

security
AI agents
developer tools
PaaS
Showing 649–657 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags