Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Kueue 1.3 Plus JobSet: Skip the Second Scheduler for Agent Batch Jobs — Until You Can't
Kueue 1.3 added first-class JobSet support, completing a native quota-plus-gang batch stack that runs on the default scheduler. Tabled here: what it covers, the worked manifests, and the three triggers that still justify Volcano.

kuberc Is On by Default: Your kubectl Habits Finally Move Out of the Kubeconfig
Kubernetes 1.36 keeps kuberc beta and on by default, adds a real management CLI, and turns the credential-plugin allowlist rename into a hard error. What the preferences/kubeconfig split means for a shared ops box.

Ingress-NGINX Is Retired: A Zero-Downtime Migration Plan for Every Tenant Domain on Your Git-Push PaaS
Ingress-NGINX stopped receiving security patches in March 2026. A staged runbook for moving wildcard and tenant custom domains to Gateway API with Ingress2Gateway 1.0 — shadow validation, weighted-DNS cutover, and rollback triggers included.

Ingress-NGINX Is Retired. Your Annotations Aren't Portable: A Gateway API Migration Audit
Ingress-NGINX lost upstream maintenance in March 2026 and Gateway API v1.5 did not add the WebSocket and retry features the headlines suggest. A row-by-row audit of which NGINX annotations have a first-class Gateway API equivalent, which need a vendor policy CRD, and which have no equivalent — plus the cutover sequence that avoids a routing gap.

Hetzner's Datacenters API Goes 410 on October 1: The 4-Row Checklist for Your CAPH Fleet
On October 1, 2026, Hetzner's datacenters API endpoints start returning HTTP 410 Gone — while retired server-type names and a removed datacenter field can already break provisioning today. A four-row migration checklist for Cluster API fleets on Hetzner, with the greps and the runbook.

Your Ingress-Nginx Has an Expiry Date: What Moving to Gateway API Actually Takes
ingress-nginx maintenance ended in March 2026 and the last vendor patch bridge runs out in November 2026. A before/after resource map, a four-phase migration with no flag day, and the full TLS story for self-hosted fleets.

Europe's Sovereign GPU Price Table: The Two Break-Evens That Decide Rent-vs-Own Inference
Hetzner rents H100s at ~$2.80/hr and OVHcloud at ~$3.20/hr, neither sells H200 time, and a $989/month dedicated box beats both past ~45% utilization. The full table, the math, and why sovereignty is a discount here.

eBPF Ate the Sidecar: What Hubble, Pixie, and Coroot Actually Replace on a Self-Hosted Fleet
67% of Kubernetes teams at scale already run eBPF observability. The sidecar-per-pod telemetry model costs ~250MB RAM per pod and milliseconds per request — a per-node kernel agent replaces it at a fraction of the cost. What Hubble, Pixie, and Coroot each replace, and which one a team that patches its own stack should run.

E2B's $150/Month Sandbox Meter vs a $70 Hetzner Box: What Agent Sandbox-Hours Really Cost
E2B bills agent sandboxes per second on top of a $150/month Pro plan; a Hetzner box you own runs the same Firecracker isolation for a flat $70. A worked recompute across three team sizes shows where the meter wins, where the flat box wins by 10x, and why E2B's CPU-only ceiling settles the GPU question before pricing does.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags