Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Gateway API v1.5 Moves Six Features to Stable: Which Ones Your Git-Push PaaS Should Adopt First
Gateway API v1.5 graduates ListenerSet, TLSRoute, and four more features to the stable channel. A verdict table and migration checklist for platforms weighing the typed routing API against Ingress annotations.

Fly.io Killed GPUs on August 1: Where the Workloads Go and What They Cost Now
Fly.io shut down its entire GPU line on August 1, 2026 — not because it is failing, but because GPUs were never its core business. A side-by-side cost comparison with owned Hetzner hardware and hourly GPU markets, plus a migration map by workload shape.

The $5 Free Credit Is Gone: What It Really Costs to Evaluate a PaaS in 2026
Fly.io ended its $5 monthly credit for new accounts, leaving a 2-VM-hour trial before pay-from-dollar-one billing. A worked comparison of what 30 days of evaluation costs on Fly.io, Railway, Render, and a €3.79 Hetzner box.

The EU's 24-Hour Vulnerability Clock Is Now Law: What the Cyber Resilience Act Means for a Self-Hosted PaaS Sold Commercially
On September 11, 2026, the CRA's 24-hour vulnerability reporting clock became law, with fines up to €15M. What manufacturer status, SBOM duties, and the five-year support window mean for a company selling an open-source self-hosted PaaS — and the five things to stand up now.

From Metered API to RuntimeClass: Building E2B-Style Sandboxes on Your Own K8s Fleet
The sandbox cost math already settled: past ~400 sandbox-hours a month, owned hardware wins. This is the build guide for what comes next — three paths to E2B-style sandboxes on your own fleet, with Kata Containers on Cluster API as the one that skips the second orchestrator.

E2B Is Now Native in OpenAI's Agents SDK: The Bar a Self-Hosted Agent Sandbox Has to Clear
OpenAI's Agents SDK declares E2B sandboxes natively since April 2026. This post turns that integration into a six-part checklist — cold start, isolation, templates, lifecycle, MCP sandboxing, egress policy — and scores four self-hosted paths against it.

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway
Hand-writing an MCP server means maintaining a second governed interface. What projecting your REST API through a gateway gives you for free — OpenAPI-derived tools, OAuth 2.1 auth, rate limits — and the write-scoping, approval, and rollback semantics a deploy API still has to build itself.

Dokploy Killed Its Global Build Queue After Two Years: What Per-Server Build Slots Reveal About Scheduling Outgrowing One Box
Dokploy ran every build on every server through one global queue for two years — then v0.29.11 gave each server its own. The wait-time math behind the fix, where per-box caps still strand capacity, and what a fleet build pool owes default-1.

CVE-2026-42533: The 15-Year-Old Core-NGINX Heap Overflow Your Gateway API Migration Didn't Escape
F5's July 2026 disclosure of CVE-2026-42533 — a CVSS 9.2 heap overflow in core NGINX's map directive — reaches Gateway Fabric, the F5 Ingress Controller, and every product embedding the NGINX engine. Here is the patch matrix, the config that makes you exploitable, and the upgrade order.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags