Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

MCP Went Stateless: What Killing the Session Means for an Endpoint That Deploys Apps From Chat
MCP's 2026-07-28 spec removes protocol-level sessions and the Mcp-Session-Id header entirely. The before/after deployment table — sticky ALB plus session store versus plain round-robin — plus the five things stateless does not fix and what a deploy-from-chat endpoint must change to survive agent load.

Your MCP Server Didn't Break — Its SDK Moved: Surviving MCP Python SDK 2.0's FastMCP-to-MCPServer Rename
MCP Python SDK 2.0 renamed FastMCP to MCPServer with no shim, so every fresh install against an unbounded mcp>=1.x pin fails at import. We cover the five-minute pin, the full port including four gotchas past the rename, and the fresh-resolve CI job that catches the next breaking major.

Let's Encrypt Did the Math for You: What ARI Renewal Exemptions Actually Buy a Self-Hosted PaaS at Tenant Scale
Let's Encrypt caps per-subdomain certificates at 50 per domain a week, but renewals coordinated through ARI are exempt from every rate limit. We work out the onboarding and renewal math for a self-hosted PaaS and what enabling ARI in cert-manager takes.

KWOK Before Scale: Load-Test Your Cluster API Controllers Against 200 Fake Nodes Before Your Tenants Do
SNCF proved Cluster API holds at 200 clusters. KWOK lets you prove your own controllers hold as object counts grow — a four-rung ramp from 50 to 400 fake nodes on a laptop, with pass/fail thresholds and the informer-cache checklist the top rung exists to expose.

Kubernetes 1.37 Deletes Deprecated Kubelet Flags: The Pre-Upgrade Audit That Keeps Your Nodes Joining
Kubernetes 1.37 turns deprecated kubelet flags into fatal unknown-flag errors that stop nodes from joining. The exact failure signature, which flags are in the cleanup wave, and a five-step audit for Cluster API fleets to find every stale flag before upgrade day.

Kubernetes v1.37's Deprecations Are a Ticking Clock: Audit Your Self-Hosted PaaS Before the Upgrade Window Closes
Kubernetes v1.37 puts dated removal timelines on kube-dns, kube-proxy IPVS mode, and cgroup v1. A concrete sunset table plus six runnable audit checks for your Cluster API fleet's controllers, CRDs, webhooks, and node templates — run them between code freeze and GA, not after reconciliation breaks.

Kubernetes 1.36 Resizes Pods In Place — Until It Doesn't: The Two Boundaries Your Autoscaler Still Has to Respect
Kubernetes 1.36 enables pod-level in-place resizing by default, but resizes that cross a QoS class are rejected and memory shrinks below live usage are blocked. What each boundary means and the recreate-not-resize fallback your autoscaler needs.

Controllers Are Cheap to Write Now. Running One Still Isn't
Writing a Kubernetes controller now takes an afternoon thanks to kubebuilder — but each one still costs a replicated deployment, a sized informer cache, and idempotent reconcile logic. A promotion table for six tenant-lifecycle jobs: what a self-hosted PaaS should turn into controllers, and what should stay a script.

Your Scheduler Config Has No Staging Environment: Rehearsing Bin-Packing Changes With kube-scheduler-simulator
Scheduler config changes ship straight to production because a dev cluster cannot reproduce real contention. kube-scheduler-simulator mirrors your fleet's actual nodes and pods so you can replay bin-packing changes and read per-plugin placement verdicts before anything moves.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags