Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Render Will Pay You Up to $10K to Leave Railway: What Migration Credits Actually Cover
·Dora Noda·9 min

Render Will Pay You Up to $10K to Leave Railway: What Migration Credits Actually Cover

Render offers up to $10,000 in migration credits plus a migrate-from-Railway guide. A worked burn-down shows the credits buy years of compute but zero hours of engineering — plus the flat-hardware math that outlasts any credit.

self-hosting
PaaS
migration
cost-optimization
One Team Membership Was Enough: How Rancher CVE-2026-41053 Handed Every GitHub Org Member Every Team's RBAC Grants
·Dora Noda·8 min

One Team Membership Was Enough: How Rancher CVE-2026-41053 Handed Every GitHub Org Member Every Team's RBAC Grants

Rancher CVE-2026-41053 (CVSS 8.8) let any user with one GitHub team membership inherit every team's Rancher permissions. Affected versions, the broken expansion loop, and the remediation checklist.

security
infrastructure
self-hosting
engineering
Render's $25 Flat Team Plan vs Railway's $20 Seats vs Fly.io's $0.02 Egress: Pricing the Same 5-Person Workload in 2026
·Dora Noda·10 min

Render's $25 Flat Team Plan vs Railway's $20 Seats vs Fly.io's $0.02 Egress: Pricing the Same 5-Person Workload in 2026

We price one 5-person team workload — web service, Postgres, five preview envs, 500 GB egress — on Railway, Render, and Fly.io using July 2026 third-party benchmarks, then run the same workload as owned Hetzner capacity to show when the benchmark winner or the exit is the right call.

self-hosting
PaaS
cost-optimization
migration
Railway Patches Your Postgres CVEs and Ships MySQL and Redis HA: What That Managed-Data Moat Really Costs a Self-Hoster
·Dora Noda·10 min

Railway Patches Your Postgres CVEs and Ships MySQL and Redis HA: What That Managed-Data Moat Really Costs a Self-Hoster

Railway's August 2026 data-layer bundle — automatic Postgres CVE patching, MySQL and Redis HA, and CLI Postgres management — itemized line by line: what each job costs to replicate on owned hardware, what a typical app pays on the meter versus a flat Hetzner box, and why bex treats managed databases as a non-goal.

self-hosting
PaaS
cost-optimization
migration
+1
Every Pull Request Gets Its Own URL: The Real Recipe and Cost Math for Preview Environments on Self-Hosted Kubernetes
·Dora Noda·12 min

Every Pull Request Gets Its Own URL: The Real Recipe and Cost Math for Preview Environments on Self-Hosted Kubernetes

A concrete recipe for per-PR preview URLs on machines you own — namespace-per-PR lifecycle, one wildcard certificate, three database options with honest prices, and the scheduling math at 5, 20, and 50 open pull requests.

self-hosting
PaaS
Kubernetes
cost-optimization
Porter's $300 Rule: Where Heroku and Render Bills Tip Over Into Kubernetes on Hardware You Own
·Dora Noda·10 min

Porter's $300 Rule: Where Heroku and Render Bills Tip Over Into Kubernetes on Hardware You Own

Porter told customers spending under $300/month to stay on Heroku. Re-priced against a small HA Kubernetes fleet on owned Hetzner hardware, the real crossover lands lower — around $150-250 once staging and ops time enter the math.

cost-optimization
migration
self-hosting
Kubernetes
OpenTofu Is the Majority Terraform Engine on One Major Platform: What the 63% Tipping Point Means for Your Fleet's IaC Layer
·Dora Noda·10 min

OpenTofu Is the Majority Terraform Engine on One Major Platform: What the 63% Tipping Point Means for Your Fleet's IaC Layer

OpenTofu now runs 63% of workloads on a major IaC platform and powers 72% of new workspaces. We scope the numbers honestly, compare where the fork leads and lags Terraform, cite Fidelity's 50,000-state-file migration, and set the default for a Cluster-API fleet's provisioning layer.

self-hosting
PaaS
Kubernetes
infrastructure
Northflank Killed Its microVM Init Container: What One Deleted Startup Step Reveals About PaaS Isolation Overhead
·Dora Noda·9 min

Northflank Killed Its microVM Init Container: What One Deleted Startup Step Reveals About PaaS Isolation Overhead

Northflank quietly removed the default init container from its microVM secure runtime. A concrete look at what that per-pod isolation scaffolding cost, and why a fleet that owns its machines pays for isolation once per node pool instead of on every pod start.

PaaS
self-hosting
Kubernetes
security
Michelin Deleted Its Second CNI: What 70-Plus Clusters With Zero Network Visibility Teach a Self-Hosted PaaS About Day One
·Dora Noda·10 min

Michelin Deleted Its Second CNI: What 70-Plus Clusters With Zero Network Visibility Teach a Self-Hosted PaaS About Day One

Michelin ran 70-plus Kubernetes clusters on two CNIs with no network visibility, then consolidated onto Cilium in two months with zero outages. What the blindness cost, how the migration worked, and a five-item checklist for getting the CNI decision right on day one.

Kubernetes
self-hosting
PaaS
infrastructure
+1
Showing 838–846 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags