Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

CIS Shipped the First MCP Server Benchmark: A 10-Domain Hardening Checklist Before Agents Get Production Credentials
The CIS MCP Server Benchmark v1.0.0 packs 55 recommendations into 10 security domains — here is each domain mapped to a concrete pass/fail check for a self-hosted PaaS deploy/operate surface, plus the four gaps to close before agent credentials touch production.

Zero-Downtime Docker Compose Deploys Hit HN: What Compose-Native Blue-Green Means for a Self-Hosted PaaS
StatusDude's HN-surfaced guide proves zero-downtime deploys need only Docker Compose, an HAProxy redispatch config, and a ten-line rolling loop — thousands of checks a minute with nothing dropped. Here is the exact recipe, the true blue-green sibling, and the capability gap that appears the moment deploys span machines.

Windows Just Shipped Its Own Docker Desktop Bypass: What wslc Means for Git-Push Deploys
Microsoft's WSL Containers preview in WSL 2.9.3 gives Windows 11 a built-in OCI container runtime — wslc.exe — with Docker-like commands, twice-as-fast virtiofs file access, and VPN-friendly networking. Here is the license-free build-locally-push-to-PaaS loop and the per-seat math it deletes.

Vercel Renamed the Meters Instead of Cutting Them: Four Pricing Revisions, One Unchanged Bill
Vercel renamed bandwidth to Fast Data Transfer and split serverless billing into Active CPU and Provisioned Memory across four pricing revisions — but the overage economics never moved. A line-by-line translation into real dollars, plus the flat-price self-hosted alternative.

Vercel's fingerprintTools and detectToolDrift: The First Drift-Detection Primitives for MCP Tool Execution
Vercel's AI SDK added fingerprintTools and detectToolDrift to catch MCP servers silently mutating approved tool definitions. Here is how the pinning works, the behavior-swap hole it leaves open, and what a self-hosted deploy MCP server should adopt.

Velero Is a CNCF Project Now: What That Buys Your Self-Hosted Disaster-Recovery Story
Broadcom donated Velero to the CNCF Sandbox at KubeCon EU 2026, ending three years of single-vendor risk on Kubernetes' default backup tool. Here is what neutral governance changes and the concrete DR blueprint for a fleet you own — S3-compatible storage, nightly schedules, and the Cluster API restore drill.

Per-Request Redis Is Cheap Until It Isn't: The $0.20-per-100K Crossover Against Fixed Plans and Self-Hosted Valkey
Upstash's $0.20-per-100K serverless Redis beats the $10 fixed plan until about 5M commands a month — then the meter costs 10-100x more. A worked crossover against fixed plans and self-hosted Valkey, plus the chatty queue and pub/sub patterns that bankrupt you.

SSH Into a Throwaway Instance: Render's Ephemeral Shell and the New Bar for PaaS Debug Access
Render's June 2026 ephemeral SSH instances plus shell-session audit events define what tenant debug access should look like. Here is how to match it on a self-hosted PaaS with same-digest debug pods, session-scoped RBAC, and an explicit call on session recording.

Skupper vs Submariner vs Istio Ambient: Picking the Cross-Cluster Link for a Hetzner-Split Fleet
Submariner merges networks, Skupper links services, and Istio's ambient multicluster — beta since KubeCon EU 2026 — merges meshes. A concrete comparison of what each demands of a Cluster API fleet split across Hetzner regions, and which layer a git-push PaaS should own for tenant traffic.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags