Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

MCP Tasks and Multi-Round Trips: The Durable Deploy Contract an Agent-Operated PaaS Needs
MCP's July 2026 spec adds asynchronous Tasks and Multi-Round Trip Requests. Together they form a durable deploy state machine: task handles instead of blocked calls, an approval boundary before production promotion, safe retry, cooperative cancel, and rollback as a first-class task.

MCP Streamable HTTP in Production: When Stateless Tool Calls Scale Cleanly and When a Deploy Agent Needs Session Affinity
AWS's FastMCP-on-ECS reference runs MCP servers stateless so any replica can answer any tool call, and the July 2026 spec revision deleted protocol-level sessions entirely. Here is that verdict mapped onto a deploy/rollback agent: which tools stay stateless, where multi-step state lives instead, and how idempotency keys keep privileged infrastructure actions safe across retries.

10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools
Pinterest runs 66,000+ MCP tool calls a month through domain-specific servers behind a central registry. How the registry-plus-fleet pattern solves discovery and access control — and what it means for the deploy tools agents drive.

MCP Won the Protocol War — the Lock-In Just Moved Up a Layer: A Self-Hoster's Field Test
MCP became the universal agent interface — and the lock-in moved into security policies, drift detection, and Skills libraries. A hands-on field test shows which moats self-hosting defeats and which one follows you home.

15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild
In September 2025 the npm package postmark-mcp shipped fifteen clean releases, then added a one-line BCC backdoor in v1.0.16 — the first malicious MCP server caught in the wild. What the incident proves about version-history trust, plus a concrete checklist for teams installing third-party MCP servers and platforms distributing their own.

Lint the Dockerfile Before You Build It: What hadolint, dockle, and Docker Scout Catch That a Green Build Never Will
A green docker build waves through unpinned base tags, root users, baked-in secrets, and known CVEs. How hadolint at PR time, dockle at build time, and Docker Scout at deploy time each catch a failure class the others cannot see — with gate configs you can copy.

TLS for a Bare IP: What Let's Encrypt's Free IP-Address Certificates Change for Self-Hosted Deploys
Let's Encrypt's free IP-address certificates went generally available in January 2026: six-day, ACME-automated TLS for a bare IPv4 or IPv6 address. Where they fit in a self-hosted PaaS — node bootstrap before DNS, fallback vhosts, IP-addressed infrastructure — the exact recipe for getting one, and the limits that keep tenant traffic on real domains.

Kubernetes 1.36 Teaches Controllers to Distrust Their Own Cache: Why a Skipped Sync Beats a Wrong Reconcile
Kubernetes 1.36 makes DaemonSet, StatefulSet, ReplicaSet, and Job controllers skip any sync where the informer cache lags their own last write. The mechanism, the two metrics that expose it, and why a lean self-hosted fleet feels every wrong reconcile as an invoice.

k0rdent Turns One: What a Year of Shipping a Cluster API Fleet Orchestrator Proves About Not Building Your Platform From Scratch
k0rdent went from v0.1 to v1.7 in its first year, and RBC Capital Markets now runs 50+ clusters on it. What the Cluster API-based orchestrator's lifecycle, state, and observability layers prove — and which parts a small self-hosted fleet should borrow, skip, or work around.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags