Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

PowerDNS as a Self-Hosted Route53: What Owning Your DNS Layer Really Costs
At 1,000 tenant domains Route53 bills around $620 a month while a two-server PowerDNS setup costs $10–55 plus an ops bill of monitoring, patching, and DNSSEC key ceremonies. Here is the full math and the rule for when owning your DNS layer pays.

Theo Graded the Platforms. Fly.io Answered. Both Missed the Exit Costs
Theo Browne questioned whether Fly.io survives the year; CEO Kurt Mackey answered with a fundraise, a new CEO, and a pivot to agent computers. Pricing the same terabyte on six platforms — and scoring who pays when platforms pivot — shows what tier lists miss and where a €10 Hetzner box lands.

One PaaS API on k3s and EKS: What Ownkube's Dual Substrates Really Cost vs Owning One Cluster API Fleet
Ownkube runs one PaaS API on k3s and EKS. We price both shapes against a single-substrate Cluster API fleet on Hetzner, name every seam the shared API hides, and give a rule for picking.

The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain
The OpenClaw Kubernetes operator packs non-root pods, dropped capabilities, and a default-deny NetworkPolicy into one install — a solid floor for running AI agents in-cluster. But Pod hardening stops at the process boundary: prompt injection, over-broad MCP credentials, and destructive-tool authorization need a governance layer no CRD provides.

Nvidia Runs OpenBao in Production: The Vault Fork's Enterprise Moment, and How to Wire It Into Kubernetes
NVIDIA runs its serverless GPU platform's secrets on OpenBao, eight vendors now sell commercial support, and v2.6 added per-namespace sealing — why the Vault fork is now safe to bet a self-hosted platform on, and how to wire it into Kubernetes with the External Secrets Operator.

The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted
Between March and June 2026, Axios, node-ipc, Red Hat's npm namespace, and the Mastra framework were all compromised — each defeating a different defense. A concrete accounting of all four attacks and the five build-layer controls that survive them: frozen lockfiles, disabled install scripts, DNS-aware egress sandboxing, honest provenance, and per-build SBOMs.

Northflank Ranked 6 Railway Alternatives — I Priced the Same App on All of Them
Northflank's June 2026 roundup ranked six Railway alternatives on credit-free uptime, visibility, and BYOC. Pricing the same always-on workload on all six runs from ~$77 on Railway to ~€12 on owned hardware — and the BYOC control-plane meter is the number that matters.

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch
Moltbook leaked 1.5 million agent API tokens within 72 hours of an all-AI-coded launch because Row Level Security was never enabled. A concrete failure-chain postmortem plus the secure-by-default provisioning contract every agent-facing platform should enforce.

Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered
Microsoft's Agent 365 platform went GA on May 1, 2026 with Shadow AI Discovery that surfaces unmanaged MCP servers through Defender and Intune. Here are the five governance controls it ships — and what a self-hosted PaaS must build itself, since Microsoft's discovery cannot see its fleet.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags