Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

The Self-Hosted Governance Gap: Why Your Compliance Team Says No to Coolify, Dokku, CapRover, and Dokploy
Coolify, Dokku, CapRover, and Dokploy win engineering evaluations and lose security reviews: no enterprise SSO, no audit trail. A capability-by-capability look at what compliance-bound teams need and what a self-hosted PaaS must build to win them.

Rootless Kubelet Hits Beta in Kubernetes 1.37: What Dropping Host Root Changes for Multi-Tenant Nodes (and What Still Needs It)
Kubernetes 1.37 promotes rootless kubelet mode to beta, so node components run as a non-root host user and breakouts stay confined to one account. Here is the blast-radius accounting, the full compatibility inventory, and a one-pool pilot playbook for Hetzner fleets.

Render Shipped Official Python and TypeScript SDKs: SDK Parity Is Now the Render-Compatibility Bar
Render's September 10 release of official Python and TypeScript SDKs moves the Render-compatibility bar from matching REST endpoints to matching the full client surface: typed methods, per-item cursor pagination, and machine-readable error codes.

Render's Agentic Playbook, Read as a Platform Spec: What the Platform Ships vs What Stays Your Code
Render's July 2026 agentic-applications playbook draws an honest line between what a deploy platform ships — queues, retries, per-run history — and what stays in your code: idempotency, compensation, and join policy. This post reads that line as a spec for any Render-compatible API.

Render Cut Median Builds From 38s to 21s: What Matching It on a Hetzner Builder You Own Actually Costs
Render's August 2026 changelog cut median builds from 38 to 21 seconds with faster disks. Priced three ways against a $10/month Hetzner builder — Render, Railway, and Depot-metered rates — with breakeven volumes, cache strategy, and the burst caveat.

Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.
Refuse is an open-source, self-hostable gate that blocks known-vulnerable package installs across 18 package managers before anything hits disk — including installs your coding agent runs. Here is how it works, where it belongs in a PaaS build pipeline, and what it cannot catch.

Red Hat OpenShift AI Bakes In MCP — and the Bottleneck Moves to Discovery at 10,000 Servers
Red Hat is baking MCP into OpenShift AI as governed infrastructure — Playground validation, a verified catalog, a lifecycle operator, and a gateway. Why the agent tooling gap moved from protocol to discovery at 10,000+ servers, and a six-item checklist for a self-hosted platform's own MCP server.

When Railpack Detects Wrong: What an Angular SSR App Served as a Static Caddy Site Teaches About Builder Autodetect
Railway's Railpack builder classified an Angular SSR app as a static site and served it through Caddy — a green deploy of the wrong architecture. The before-and-after Dockerfile fix, why fail-open autodetect keeps causing outages, and the five detect-time log lines a self-hosted PaaS should emit.

Preview Databases Are the Part of Preview Environments Nobody Demos
Northflank's Railway-alternatives matrix concedes the awkward half of preview environments: Coolify and Fly.io need custom configuration for per-PR databases, and only teardown automation keeps forgotten previews from compounding. How seed time, snapshot restore, and per-PR isolation decide whether previews are shippable — and the self-hosted recipe that closes the gap.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags