Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

A2A Hit 150 Organizations in a Year: The Agent-to-Agent Protocol MCP Was Never Meant to Be
A2A grew from a Google proposal to 150+ organizations and a stable v1.0 in twelve months. What the agent-to-agent protocol covers that MCP deliberately doesn't — plus the precise triggers for when a deploy-from-chat roadmap needs both.

Valkey Won the Default: What a git-push PaaS Should Bundle Now That the Redis Fork Became the Safe Choice
Two years after Redis gave up the BSD license, Valkey is the default on major Linux distros and the recommended engine on ElastiCache at 20-33% lower prices. A cost-vs-gain accounting for making it your platform's standard cache, plus the one boundary where Redis still wins.

Railway vs Vercel vs Cloudflare: What Bursty Builds Really Cost Per Second (and When a Flat Hetzner Node Wins)
Railway, Vercel, and Cloudflare all bill per second but meter different things. A worked recompute at three burst tiers shows where metered builds beat a flat Hetzner node — and where they quietly lose.

CPU at 40%, Everything on Fire: What Kubernetes 1.36's PSI Metrics Finally Tell a Bin-Packed Fleet
Kubernetes 1.36 graduates PSI metrics to GA, exposing CPU, memory, and I/O stall percentages per node, pod, and container. Here is what that reveals on a bin-packed fleet, the kernel and cgroup v2 checklist to enable it, and three stall-based queries to run before your next 'utilization looks fine' incident.

Your npm Token Is the Next Supply-Chain Incident: A Tokenless Publishing Playbook for Git-Push Pipelines
npm's OIDC trusted publishing replaces the long-lived NPM_TOKEN with per-run workload identity and automatic provenance. A six-step migration checklist with version floors and failure modes, the 2026 enforcement timeline through January 2027, and what the pattern means for a self-hosted build pipeline.

The Gate That Wasn't There: What Nomad's CVE-2026-14891 Teaches About Scheduler Isolation
Nomad 2.0.4 fixed a CVE that let any job submitter land a container in the host's PID, network, or IPC namespaces — because the allow_privileged check was never evaluated. What the bug, its two sibling fixes, and Kubernetes' admission-time enforcement say about choosing a scheduler for untrusting tenants.

Kubernetes v1.37's Node Lifecycle Conditions: Teaching MachineHealthCheck to Tell 'Draining' Apart From 'Dying'
Kubernetes v1.37 reserves five Node Lifecycle Conditions that finally let a node say 'I'm draining' instead of just going NotReady. What MaintenancePlanned changes for MachineHealthCheck remediation, what MHC already covers, and what a Cluster-API fleet should publish this quarter.

MCP Goes Stateless: What Losing Long-Lived Connections Costs — and Buys — the Servers You Self-Host
MCP's 2026-07-28 revision deletes sessions, the initialize handshake, and every server-to-client primitive. A gains-versus-costs accounting for operators of self-hosted MCP tool servers, plus the task-based redesign for deploys that outlive one request.

Six Days to Renew: What Let's Encrypt's Short-Lived Certificates Do to Your Renewal Margin
Let's Encrypt's 160-hour shortlived certificates cut renewal slack from 30 days to about 53 hours. The before/after margin math, plus the automation, monitoring, and default-or-opt-in checklist a self-hosted platform needs first.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags