Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Daytona Went Closed-Source: What It Costs to Build Agent Sandboxes on Borrowed Open Source
·Dora Noda·9 min

Daytona Went Closed-Source: What It Costs to Build Agent Sandboxes on Borrowed Open Source

Daytona moved its core to a private codebase in June 2026, freezing the open repo at v0.190.0 with no security patches. What that costs self-hosters in CVE backports, API drift, and AGPL obligations — plus a five-way comparison of Microsandbox, E2B self-hosted, Beam, CubeSandbox, and the SIG-governed agent-sandbox.

AI agents
self-hosting
infrastructure
security
Belune in a Single Go Binary: What the Newest Self-Hosted PaaS Gets Right (and Where the Box Ends)
·Dora Noda·8 min

Belune in a Single Go Binary: What the Newest Self-Hosted PaaS Gets Right (and Where the Box Ends)

Belune packs git-push deploys, managed databases, and self-explaining HTTPS into one Go binary — the best-kept single box in its class. Its own comparison table admits the ceiling: multiple servers, planned.

self-hosting
PaaS
infrastructure
Your Side Project Doesn't Need Kubernetes: What an Ask HN Deploy Thread Gets Right About the $5-vs-$40 Decision
·Dora Noda·9 min

Your Side Project Doesn't Need Kubernetes: What an Ask HN Deploy Thread Gets Right About the $5-vs-$40 Decision

A four-container side project priced five ways: a $5 Hetzner-class box, a $6 droplet, Railway's $5 meter, Render at $21-plus, and managed Kubernetes at $39 minimal or $79 production-grade. The cost table lands first, then the decision rule keyed on experience, service count, and traffic shape.

self-hosting
PaaS
cost-optimization
migration
Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat
·Dora Noda·9 min

Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat

Deploy-from-chat dies the moment the agent asks for your API key. Arcade.dev's MCP runtime — Engine-vaulted OAuth, URL elicitation co-built with Anthropic, per-call scoped credentials — shows how agents deploy without holding tokens, with the deny, revoke, and re-scope paths spelled out.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access
·Dora Noda·11 min

Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access

40% of reachable MCP servers need no authentication and tool-poisoning fools flagship models. A concrete blueprint — scoped credential exchange, an OPA default-deny policy, ephemeral runners — that makes the gateway, not the model, the enforcement point.

AI agents
Model Context Protocol
security
PaaS
Sidero Omni Wants to Deploy Your Apps Too: Where Cluster Management Ends and a Git-Push PaaS Begins
·Dora Noda·10 min

Sidero Omni Wants to Deploy Your Apps Too: Where Cluster Management Ends and a Git-Push PaaS Begins

Sidero Labs plans to add application deployment to Omni, its Talos fleet manager. A row-by-row accounting of what that changes, what stays hand-built, and why a fleet manager with deploy features still isn't a git-push PaaS.

self-hosting
PaaS
Kubernetes
infrastructure
Give Your Agents a Memory That Lives on Your Machines: Qdrant vs Weaviate vs pgvector
·Dora Noda·9 min

Give Your Agents a Memory That Lives on Your Machines: Qdrant vs Weaviate vs pgvector

AI agents without persistent memory re-derive everything on every run. A number-backed comparison of the three self-hostable vector stores — plus the per-tenant scale ladder that picks pgvector as the default and Qdrant as the escape hatch.

AI agents
self-hosting
PaaS
Kubernetes
+1
Shell Access Is a Loaded Gun: Securing Production Debugging on Kubernetes Before You Hand Tenants the Keys
·Dora Noda·10 min

Shell Access Is a Loaded Gun: Securing Production Debugging on Kubernetes Before You Hand Tenants the Keys

Every PaaS ships a shell-into-production button. The hardened pattern that keeps it a convenience instead of a cross-tenant lateral-movement path: ephemeral containers, namespace-scoped RBAC, non-root debug sessions, audit logging, and allowlisted images.

Kubernetes
PaaS
security
self-hosting
Salesforce Killed Functions, Then Froze Heroku: The Complete Exit Map for Every Workload They Left Behind
·Dora Noda·9 min

Salesforce Killed Functions, Then Froze Heroku: The Complete Exit Map for Every Workload They Left Behind

Salesforce Functions retired in January 2025 and Heroku entered sustaining engineering in February 2026. A workload-by-workload map of where Functions code, dynos, Postgres, and add-ons actually go — and the migration order that avoids moving twice.

self-hosting
PaaS
migration
cost-optimization
Showing 757–765 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags