Skip to main content

Blog

Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Cloud Native Buildpacks Just Graduated: Why Your PaaS Build Step Shouldn't Belong to One Vendor
·Dora Noda·9 min

Cloud Native Buildpacks Just Graduated: Why Your PaaS Build Step Shouldn't Belong to One Vendor

Cloud Native Buildpacks graduated in August 2026 with 535 contributors and 20+ production adopters. Graduation makes CNB the boring, multi-vendor foundation for a fleet's build step — just as Nixpacks' maintenance mode shows what single-vendor builders cost — but build speed still has to be earned with cache locality.

self-hosting
PaaS
Kubernetes
engineering
CAPH Stopped Checking Your Server Type: What Hetzner's Hardware Churn Teaches About Pinning Machine Templates
·Dora Noda·10 min

CAPH Stopped Checking Your Server Type: What Hetzner's Hardware Churn Teaches About Pinning Machine Templates

CAPH v1.0.7 deleted its hardcoded server-type allowlist after Hetzner's October 2025 lineup rework retired types like cx22. A typo'd or retired type now passes kubectl apply and fails later at Hetzner's API — here is the four-part CI discipline that replaces the deleted guardrail.

self-hosting
PaaS
Kubernetes
infrastructure
You Can't Debug What You Can't See: The Agent Audit Trail Your PaaS Needs Before Agents Get Prod Access
·Dora Noda·10 min

You Can't Debug What You Can't See: The Agent Audit Trail Your PaaS Needs Before Agents Get Prod Access

CNCF's August 2026 field report says agents don't crash with stack traces — they loop, hallucinate, and burn tokens while dashboards stay green. The three pillars that make agent failures reconstructible, and the six-column audit blueprint to require before any agent touches production.

AI agents
PaaS
self-hosting
infrastructure
Your Buildpack Already Wrote the SBOM — Your Cluster Just Isn't Reading It
·Dora Noda·9 min

Your Buildpack Already Wrote the SBOM — Your Cluster Just Isn't Reading It

Cloud Native Buildpacks already emit a per-layer SBOM with every image, but most fleets never enforce it. Attaching that SBOM as a signed Sigstore attestation and verifying it with an admission controller turns scan-after-deploy into a deny decision before an unapproved image ever shares a node with other tenants.

self-hosting
PaaS
Kubernetes
security
+1
AWS Load Balancer Controller Goes GA on Gateway API: Why Your Self-Hosted Ingress Bet Just Got Its Strongest Signal Yet
·Dora Noda·11 min

AWS Load Balancer Controller Goes GA on Gateway API: Why Your Self-Hosted Ingress Bet Just Got Its Strongest Signal Yet

AWS Load Balancer Controller v3.0.0 made Gateway API generally available — the hyperscaler's own controller now targets typed Gateway/HTTPRoute CRDs instead of annotations. What that signals for self-hosted fleets, the four non-portable limits, and an Envoy-vs-Cilium pick table.

self-hosting
PaaS
Kubernetes
infrastructure
Japan Just Named the Kubernetes AI Stack: What a Self-Hosted PaaS Should Adopt, Pilot, or Skip
·Dora Noda·10 min

Japan Just Named the Kubernetes AI Stack: What a Self-Hosted PaaS Should Adopt, Pilot, or Skip

Japan's new CNCF AI Infrastructure SIG names DRA, Kueue, KServe, the Gateway API Inference Extension, and more as one coordinated stack. A concrete adopt-pilot-skip triage for self-hosted PaaS teams: three to adopt now, two to pilot, two stacks to decline, and two watches with dated triggers.

self-hosting
PaaS
Kubernetes
infrastructure
Your AI Budget Will Be Wrong. Your Deploy Bill Doesn't Have to Be
·Dora Noda·9 min

Your AI Budget Will Be Wrong. Your Deploy Bill Doesn't Have to Be

Enterprise surveys say four out of five teams miss their AI spend forecasts. Model inference is inherently unpredictable — but the deploy bill underneath it is a choice. Here is why agent-operated apps belong on flat-rate machines you own.

AI agents
Enterprise AI
self-hosting
PaaS
+1
Ten Platforms, One Accidental Contract: The PORT-and-Start-Script Standard Behind Every Git-Push Deploy
·Dora Noda·9 min

Ten Platforms, One Accidental Contract: The PORT-and-Start-Script Standard Behind Every Git-Push Deploy

Cedar.js set out to fix Railway deploys and found ten platforms sharing one accidental contract: a build script, a start script, PORT, and dual-stack binding. The full convention, the three-tier platform matrix, and the five ways it silently breaks.

self-hosting
PaaS
engineering
Don't Build Cron Into Your PaaS: Running Windmill's Script-to-Webhook Engine as a Tenant Workload
·Dora Noda·9 min

Don't Build Cron Into Your PaaS: Running Windmill's Script-to-Webhook Engine as a Tenant Workload

Every git-push PaaS eventually needs cron and background workers. A concrete build-vs-route decision: run Windmill's open-source workflow engine as a tenant workload, or build your own — with the six-dimension tradeoff table and the three conditions that flip the answer.

self-hosting
PaaS
Kubernetes
guide
Showing 874–882 of 3495 posts

Subscribe

New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.

Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.

Following one topic instead? Browse tags