Skip to main content

531 posts tagged with "AI agents"

AI agents and autonomous systems

View all tags

Read the AI agents and MCP guide

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
·Dora Noda·11 min

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands

Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

AI agents
security
Model Context Protocol
identity
+1
Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers
·Dora Noda·11 min

Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers

CNCF's Platform Engineering 2.0 names AI agents as platform consumers with their own access, scope, and governance needs. Here is the concrete design that follows: per-agent identity, least-privilege roles, machine-speed quotas — and why MCP auth must be agent-first from day one.

AI agents
Model Context Protocol
security
Kubernetes
Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes
·Dora Noda·10 min

Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes

CNCF's Q1 2026 radar put Backstage in 'Adopt' while its agentic-enterprise commentary demands machine-consumable platform interfaces. The official MCP plugin, read-through sync, and four hard parts — auth, writes, refresh, drift — decide whether the pairing holds.

AI agents
Model Context Protocol
PaaS
security
+1
Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority
·Dora Noda·12 min

Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority

A community MCP server turns Coolify into agent-callable deploy tools for about 13 dollars a month — but the agent holds a deploy-level API token with nothing between it and delete. Scoped, audited agent credentials are the missing primitive.

AI agents
Model Context Protocol
security
PaaS
+1
Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?
·Dora Noda·11 min

Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?

Daytona boots sandboxes in under 90ms while E2B's Firecracker microVMs take about 150ms — but model latency dwarfs both in real agent loops. A numbers-first look at when the gap matters, how the two pricing shapes compare, and what a self-hosted sandbox should copy from each.

AI agents
self-hosting
PaaS
cost-optimization
+1
Your Agent's Firewall Can't Read SQL. Deno's Claw Patrol Can.
·Dora Noda·11 min

Your Agent's Firewall Can't Read SQL. Deno's Claw Patrol Can.

Deno's open-source Claw Patrol terminates agent TCP connections and parses HTTP, Postgres, SSH, and Kubernetes on the wire, so policy sees the query instead of just the connection. How it works, what it costs, and where it belongs on a self-hosted platform.

AI agents
cybersecurity
self-hosting
engineering
Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet
·Dora Noda·9 min

Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet

Railway's May 2026 changelog lets enterprise workspaces restrict deployments to approved GitHub orgs. Here is what the guardrail enforces and how to rebuild it on your own fleet with ArgoCD source pinning, Kyverno admission policy, and pipeline owner checks.

PaaS
self-hosting
Kubernetes
security
+1
Hetzner Is Giving Away Free Inference. Should Your Fleet Still Run Its Own vLLM?
·Dora Noda·11 min

Hetzner Is Giving Away Free Inference. Should Your Fleet Still Run Its Own vLLM?

Hetzner's free OpenAI-compatible inference API gives self-hosted teams zero-capex model access — but rate limits, 5–10s p99 latency, and a scaled-down catalog define what 'free' actually guarantees. Here is the rent-vs-own math and a checklist for when to build your own vLLM.

self-hosting
PaaS
cost-optimization
AI agents
KEP-5677: Tell Tenants 'No GPU Left' Up Front Instead of Parking Their Pods in Pending
·Dora Noda·11 min

KEP-5677: Tell Tenants 'No GPU Left' Up Front Instead of Parking Their Pods in Pending

Kubernetes 1.37's second alpha of KEP-5677 turns GPU availability into a readable API object. Here is how a self-hosted PaaS turns that per-pool snapshot into a tenant-facing capacity page and a fast admission-time refusal instead of pods stuck in Pending.

Kubernetes
AI agents
self-hosting
infrastructure
Showing 136–144 of 531 posts