Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Gateway API v1.5 Moves Six Features to Stable: Which Ones Your Git-Push PaaS Should Adopt First
·Dora Noda·8 min

Gateway API v1.5 Moves Six Features to Stable: Which Ones Your Git-Push PaaS Should Adopt First

Gateway API v1.5 graduates ListenerSet, TLSRoute, and four more features to the stable channel. A verdict table and migration checklist for platforms weighing the typed routing API against Ingress annotations.

Kubernetes
PaaS
self-hosting
engineering
Fly.io Killed GPUs on August 1: Where the Workloads Go and What They Cost Now
·Dora Noda·10 min

Fly.io Killed GPUs on August 1: Where the Workloads Go and What They Cost Now

Fly.io shut down its entire GPU line on August 1, 2026 — not because it is failing, but because GPUs were never its core business. A side-by-side cost comparison with owned Hetzner hardware and hourly GPU markets, plus a migration map by workload shape.

PaaS
migration
cost-optimization
self-hosting
The $5 Free Credit Is Gone: What It Really Costs to Evaluate a PaaS in 2026
·Dora Noda·10 min

The $5 Free Credit Is Gone: What It Really Costs to Evaluate a PaaS in 2026

Fly.io ended its $5 monthly credit for new accounts, leaving a 2-VM-hour trial before pay-from-dollar-one billing. A worked comparison of what 30 days of evaluation costs on Fly.io, Railway, Render, and a €3.79 Hetzner box.

PaaS
hosting
cost-optimization
self-hosting
The EU's 24-Hour Vulnerability Clock Is Now Law: What the Cyber Resilience Act Means for a Self-Hosted PaaS Sold Commercially
·Dora Noda·13 min

The EU's 24-Hour Vulnerability Clock Is Now Law: What the Cyber Resilience Act Means for a Self-Hosted PaaS Sold Commercially

On September 11, 2026, the CRA's 24-hour vulnerability reporting clock became law, with fines up to €15M. What manufacturer status, SBOM duties, and the five-year support window mean for a company selling an open-source self-hosted PaaS — and the five things to stand up now.

cybersecurity
regulatory compliance
self-hosting
PaaS
From Metered API to RuntimeClass: Building E2B-Style Sandboxes on Your Own K8s Fleet
·Dora Noda·11 min

From Metered API to RuntimeClass: Building E2B-Style Sandboxes on Your Own K8s Fleet

The sandbox cost math already settled: past ~400 sandbox-hours a month, owned hardware wins. This is the build guide for what comes next — three paths to E2B-style sandboxes on your own fleet, with Kata Containers on Cluster API as the one that skips the second orchestrator.

PaaS
AI agents
self-hosting
Kubernetes
+1
E2B Is Now Native in OpenAI's Agents SDK: The Bar a Self-Hosted Agent Sandbox Has to Clear
·Dora Noda·10 min

E2B Is Now Native in OpenAI's Agents SDK: The Bar a Self-Hosted Agent Sandbox Has to Clear

OpenAI's Agents SDK declares E2B sandboxes natively since April 2026. This post turns that integration into a six-part checklist — cold start, isolation, templates, lifecycle, MCP sandboxing, egress policy — and scores four self-hosted paths against it.

AI agents
self-hosting
openai
Model Context Protocol
+1
Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway
·Dora Noda·10 min

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway

Hand-writing an MCP server means maintaining a second governed interface. What projecting your REST API through a gateway gives you for free — OpenAPI-derived tools, OAuth 2.1 auth, rate limits — and the write-scoping, approval, and rollback semantics a deploy API still has to build itself.

Model Context Protocol
AI agents
API
security
Dokploy Killed Its Global Build Queue After Two Years: What Per-Server Build Slots Reveal About Scheduling Outgrowing One Box
·Dora Noda·10 min

Dokploy Killed Its Global Build Queue After Two Years: What Per-Server Build Slots Reveal About Scheduling Outgrowing One Box

Dokploy ran every build on every server through one global queue for two years — then v0.29.11 gave each server its own. The wait-time math behind the fix, where per-box caps still strand capacity, and what a fleet build pool owes default-1.

self-hosting
PaaS
Kubernetes
engineering
CVE-2026-42533: The 15-Year-Old Core-NGINX Heap Overflow Your Gateway API Migration Didn't Escape
·Dora Noda·10 min

CVE-2026-42533: The 15-Year-Old Core-NGINX Heap Overflow Your Gateway API Migration Didn't Escape

F5's July 2026 disclosure of CVE-2026-42533 — a CVSS 9.2 heap overflow in core NGINX's map directive — reaches Gateway Fabric, the F5 Ingress Controller, and every product embedding the NGINX engine. Here is the patch matrix, the config that makes you exploitable, and the upgrade order.

cybersecurity
self-hosting
PaaS
infrastructure
+1
Showing 658–666 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags