Blog
Insights, analysis, and updates from the AI agent economy. Browse by tag · Browse the archive.

Your Three Replicas Are All in FSN1: TopologySpreadConstraints, Hetzner Failure Domains, and the Placement Policy a Self-Hosted PaaS Owes Its Tenants
Two replicas across three Hetzner locations at maxSkew 1 lands 1/1/0, with one location always empty. The skew formula behind it, the minDomains trap that wedges pods in Pending, what cross-location spread really costs on Hetzner's private networks, and the soft-by-default placement policy a self-hosted PaaS should ship.

Six Minutes, 84 Malicious Versions: What the TanStack npm Compromise Teaches Every Build Pipeline
On May 11, 2026, attackers published 84 malicious versions across 42 TanStack npm packages in six minutes without touching a maintainer credential. How the pull_request_target, cache-poisoning, and OIDC-extraction chain worked, and the build-pipeline checklist every self-hosted PaaS should verify.

Kubernetes 1.37's StatefulSet Recreate Strategy (Alpha): Stop Deleting Stuck Pods by Hand
Kubernetes 1.37 adds an alpha Recreate update strategy for StatefulSets that deletes old-revision pods wholesale instead of halting behind the first stuck pod. What it changes, the full-outage price, and where a self-hosted PaaS may use it — and where it must not.

SOPS with Age vs Sealed Secrets: What GitOps Secrets Cost to Rotate on a Cluster API Fleet
Committing encrypted secrets to Git is the easy part. A fleet-scale comparison of SOPS with age versus Bitnami Sealed Secrets on what each costs to rotate, audit, and recover after the management cluster dies — with runbooks and the February 2026 rotation CVE that settles it.

Railway Has No $0 Anymore: A Line-by-Line Cost Audit of the $5 Trial Credit vs. Self-Hosting on Hetzner
Railway's $5 trial credit is a one-time grant, not a tier. A worked line-by-line audit puts a web service, worker, and Postgres at ~$23-28/mo on Hobby versus ~EUR 4.49 flat on Hetzner — and explains why the missing $0 state matters more than the unit prices.

Scale Before the Spike: Predictive GPU Pre-Warming for a Cluster API Fleet Without the Always-On Bill
Reactive autoscaling leaves a roughly 45-minute gap between an inference spike and ready GPUs. A concrete pre-warm design for a Cluster API fleet — request-side forecast signals, a measured boot budget, and a capped warm reserve — priced against Hetzner's monthly GPU boxes.

Harvest Now, Decrypt Later Comes for Your MCP Server: Why Agent Deploy Calls Are Worth Storing
A June 2026 executive order made harvest-now-decrypt-later federal policy — and the ciphertext most worth storing is your agent's deploy calls. A three-layer exposure audit plus a concrete checklist for hybrid post-quantum key exchange on an infra MCP server's own transport.

One Control Plane, Four Operators: What OpenChoreo's MCP Bet Teaches Self-Hosted PaaS Builders
OpenChoreo 1.0 treats AI agents as first-class platform consumers through MCP servers on a single Kubernetes system of record. A four-surface replay plus an identity, dependency-graph, policy, and audit-trail checklist for letting agents investigate — and eventually change — deployments.

Open-Weight AI's Kubernetes Moment: Stress-Testing the Analogy Phase by Phase
Tobi Knaup argues open-weight AI sits where Kubernetes sat in 2016. We grade the analogy across all four phases of the Kubernetes decade — substrate, distro fight, hyperscaler absorption, and the self-hosting price — with the utilization math that decides it.
Subscribe
New posts land in your reader as soon as they publish. Pick a format — all three carry the same posts.
Current feeds keep roughly two days of posts so daily polling does not miss a burst. Older entries stay reachable from the feed's next-page link in readers that follow it, or from the blog archive.
Following one topic instead? Browse tags