Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

PowerDNS as a Self-Hosted Route53: What Owning Your DNS Layer Really Costs
·Dora Noda·9 min

PowerDNS as a Self-Hosted Route53: What Owning Your DNS Layer Really Costs

At 1,000 tenant domains Route53 bills around $620 a month while a two-server PowerDNS setup costs $10–55 plus an ops bill of monitoring, patching, and DNSSEC key ceremonies. Here is the full math and the rule for when owning your DNS layer pays.

self-hosting
PaaS
Domain
infrastructure
Theo Graded the Platforms. Fly.io Answered. Both Missed the Exit Costs
·Dora Noda·10 min

Theo Graded the Platforms. Fly.io Answered. Both Missed the Exit Costs

Theo Browne questioned whether Fly.io survives the year; CEO Kurt Mackey answered with a fundraise, a new CEO, and a pivot to agent computers. Pricing the same terabyte on six platforms — and scoring who pays when platforms pivot — shows what tier lists miss and where a €10 Hetzner box lands.

self-hosting
PaaS
cost-optimization
hosting
+1
One PaaS API on k3s and EKS: What Ownkube's Dual Substrates Really Cost vs Owning One Cluster API Fleet
·Dora Noda·11 min

One PaaS API on k3s and EKS: What Ownkube's Dual Substrates Really Cost vs Owning One Cluster API Fleet

Ownkube runs one PaaS API on k3s and EKS. We price both shapes against a single-substrate Cluster API fleet on Hetzner, name every seam the shared API hides, and give a rule for picking.

Kubernetes
PaaS
cost-optimization
self-hosting
The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain
·Dora Noda·9 min

The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain

The OpenClaw Kubernetes operator packs non-root pods, dropped capabilities, and a default-deny NetworkPolicy into one install — a solid floor for running AI agents in-cluster. But Pod hardening stops at the process boundary: prompt injection, over-broad MCP credentials, and destructive-tool authorization need a governance layer no CRD provides.

AI agents
security
Kubernetes
Model Context Protocol
+1
Nvidia Runs OpenBao in Production: The Vault Fork's Enterprise Moment, and How to Wire It Into Kubernetes
·Dora Noda·9 min

Nvidia Runs OpenBao in Production: The Vault Fork's Enterprise Moment, and How to Wire It Into Kubernetes

NVIDIA runs its serverless GPU platform's secrets on OpenBao, eight vendors now sell commercial support, and v2.6 added per-namespace sealing — why the Vault fork is now safe to bet a self-hosted platform on, and how to wire it into Kubernetes with the External Secrets Operator.

self-hosting
PaaS
security
Kubernetes
The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted
·Dora Noda·11 min

The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted

Between March and June 2026, Axios, node-ipc, Red Hat's npm namespace, and the Mastra framework were all compromised — each defeating a different defense. A concrete accounting of all four attacks and the five build-layer controls that survive them: frozen lockfiles, disabled install scripts, DNS-aware egress sandboxing, honest provenance, and per-build SBOMs.

security
cybersecurity
developer tools
self-hosting
+1
Northflank Ranked 6 Railway Alternatives — I Priced the Same App on All of Them
·Dora Noda·11 min

Northflank Ranked 6 Railway Alternatives — I Priced the Same App on All of Them

Northflank's June 2026 roundup ranked six Railway alternatives on credit-free uptime, visibility, and BYOC. Pricing the same always-on workload on all six runs from ~$77 on Railway to ~€12 on owned hardware — and the BYOC control-plane meter is the number that matters.

self-hosting
PaaS
cost-optimization
migration
The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch
·Dora Noda·9 min

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch

Moltbook leaked 1.5 million agent API tokens within 72 hours of an all-AI-coded launch because Row Level Security was never enabled. A concrete failure-chain postmortem plus the secure-by-default provisioning contract every agent-facing platform should enforce.

AI agents
cybersecurity
engineering
PaaS
Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered
·Dora Noda·11 min

Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered

Microsoft's Agent 365 platform went GA on May 1, 2026 with Shadow AI Discovery that surfaces unmanaged MCP servers through Defender and Intune. Here are the five governance controls it ships — and what a self-hosted PaaS must build itself, since Microsoft's discovery cannot see its fleet.

AI agents
Model Context Protocol
cybersecurity
self-hosting
Showing 694–702 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags