Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Cloud Native Buildpacks Just Graduated: Why Your PaaS Build Step Shouldn't Belong to One Vendor
Cloud Native Buildpacks graduated in August 2026 with 535 contributors and 20+ production adopters. Graduation makes CNB the boring, multi-vendor foundation for a fleet's build step — just as Nixpacks' maintenance mode shows what single-vendor builders cost — but build speed still has to be earned with cache locality.

CAPH Stopped Checking Your Server Type: What Hetzner's Hardware Churn Teaches About Pinning Machine Templates
CAPH v1.0.7 deleted its hardcoded server-type allowlist after Hetzner's October 2025 lineup rework retired types like cx22. A typo'd or retired type now passes kubectl apply and fails later at Hetzner's API — here is the four-part CI discipline that replaces the deleted guardrail.

You Can't Debug What You Can't See: The Agent Audit Trail Your PaaS Needs Before Agents Get Prod Access
CNCF's August 2026 field report says agents don't crash with stack traces — they loop, hallucinate, and burn tokens while dashboards stay green. The three pillars that make agent failures reconstructible, and the six-column audit blueprint to require before any agent touches production.

Your Buildpack Already Wrote the SBOM — Your Cluster Just Isn't Reading It
Cloud Native Buildpacks already emit a per-layer SBOM with every image, but most fleets never enforce it. Attaching that SBOM as a signed Sigstore attestation and verifying it with an admission controller turns scan-after-deploy into a deny decision before an unapproved image ever shares a node with other tenants.

AWS Load Balancer Controller Goes GA on Gateway API: Why Your Self-Hosted Ingress Bet Just Got Its Strongest Signal Yet
AWS Load Balancer Controller v3.0.0 made Gateway API generally available — the hyperscaler's own controller now targets typed Gateway/HTTPRoute CRDs instead of annotations. What that signals for self-hosted fleets, the four non-portable limits, and an Envoy-vs-Cilium pick table.

Japan Just Named the Kubernetes AI Stack: What a Self-Hosted PaaS Should Adopt, Pilot, or Skip
Japan's new CNCF AI Infrastructure SIG names DRA, Kueue, KServe, the Gateway API Inference Extension, and more as one coordinated stack. A concrete adopt-pilot-skip triage for self-hosted PaaS teams: three to adopt now, two to pilot, two stacks to decline, and two watches with dated triggers.

Your AI Budget Will Be Wrong. Your Deploy Bill Doesn't Have to Be
Enterprise surveys say four out of five teams miss their AI spend forecasts. Model inference is inherently unpredictable — but the deploy bill underneath it is a choice. Here is why agent-operated apps belong on flat-rate machines you own.

Ten Platforms, One Accidental Contract: The PORT-and-Start-Script Standard Behind Every Git-Push Deploy
Cedar.js set out to fix Railway deploys and found ten platforms sharing one accidental contract: a build script, a start script, PORT, and dual-stack binding. The full convention, the three-tier platform matrix, and the five ways it silently breaks.

Don't Build Cron Into Your PaaS: Running Windmill's Script-to-Webhook Engine as a Tenant Workload
Every git-push PaaS eventually needs cron and background workers. A concrete build-vs-route decision: run Windmill's open-source workflow engine as a tenant workload, or build your own — with the six-dimension tradeoff table and the three conditions that flip the answer.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags