Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Cursor Made Sandboxes Interchangeable: What Eight Backends Behind One Agent Pool Means for Self-Hosted Platforms
Cursor's Self-Hosted Machines launch routes cloud-agent sessions through one worker pool across eight sandbox backends — Lambda, Cloudflare, Coder, Daytona, E2B, Modal, Namespace, and Vercel. The pool and the idle-machine lifecycle are the real product, and here is the four-item checklist for making your own fleet backend number nine.

Coolify Fixed 11 Critical CVEs in v4.0.0 — How to Audit Any Self-Hosted PaaS Before Trusting It With Secrets
Coolify's v4.0.0 release rolled up fixes for 11 critical CVEs, several scoring CVSS 10.0. A breakdown of what the flaws allowed, the patterns they share, and a six-point checklist for auditing any self-hosted platform before it holds your secrets.

Coolify's MCP Server Just Made Deploy-From-Chat Table Stakes: What 'Ask Claude to Ship It' Really Covers (and What It Doesn't)
Coolify's native read-only MCP endpoint plus 42-tool community servers let agents deploy to self-hosted infrastructure from chat. A labeled walkthrough of the Postgres-to-FastAPI loop, and the five governance controls a fast follower needs.

Colmena vs Cluster API: Nix Fleet Management Without Kubernetes — What It Gets Right and Where It Stops
Colmena manages a NixOS fleet with no control plane, no agent, and no state database — but it cannot provision machines, schedule containers, or heal dead processes. A grounded comparison with Cluster API, an honest NixOps 4 status check, and a decision checklist.

One Cluster for Training and Inference: How a Bank Cut AI Token Costs 60% on Kubernetes
China Merchants Bank won the CNCF End User Case Study Contest for running AI training and inference on a single Kubernetes stack of nearly 10,000 accelerator cards — lifting utilization from 35% to over 60% and cutting inference cost per million tokens by more than 60%. The component-by-component breakdown, the fairness rules behind it, and what smaller self-hosted fleets can copy.

100x Faster Than Containers: What Cloudflare's Dynamic Workers Get Right About Sandboxing Agent Code
Cloudflare's Dynamic Workers run AI-generated snippets in V8 isolates with millisecond startup — but the 100x headline only holds for sub-second tool calls. Here are the real numbers against containers and microVMs, the isolation tradeoff Spectre exposed, and the two-tier sandbox rule for self-hosted platforms.

ClawBleed: How One Clicked Link Turned 40,000 Self-Hosted Agent Gateways Into Remote Shells
CVE-2026-25253 let one malicious link steal an OpenClaw gateway token and take over the host. The kill chain, the 40,000 exposed instances, and the gateway-auth checklist for anything an agent can deploy through.

Your PaaS Quietly Reweighted Every Tenant's CPU: The cgroup v1-to-v2 Conversion Kubernetes Fixed in January 2026
Moving a node to cgroup v2 silently cut a 1-CPU pod's priority to a weight of 39 against the default 100. How the January 2026 quadratic fix restores fair share, what stays transparent, and a four-check audit for your fleet.

The Tenant Domain That Didn't Renew: cert-manager vs Gardener vs certctl for Per-Tenant TLS
One certificate per tenant collides with Let's Encrypt's 50-per-week ceiling fast. A concrete comparison of cert-manager, Gardener cert-management, and certctl on challenges, secret distribution, and renewal failure modes — plus which one a self-hosted PaaS should default to.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags