531 posts tagged with "AI agents"
AI agents and autonomous systems

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers
CNCF's Platform Engineering 2.0 names AI agents as platform consumers with their own access, scope, and governance needs. Here is the concrete design that follows: per-agent identity, least-privilege roles, machine-speed quotas — and why MCP auth must be agent-first from day one.

Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes
CNCF's Q1 2026 radar put Backstage in 'Adopt' while its agentic-enterprise commentary demands machine-consumable platform interfaces. The official MCP plugin, read-through sync, and four hard parts — auth, writes, refresh, drift — decide whether the pairing holds.

Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority
A community MCP server turns Coolify into agent-callable deploy tools for about 13 dollars a month — but the agent holds a deploy-level API token with nothing between it and delete. Scoped, audited agent credentials are the missing primitive.

Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?
Daytona boots sandboxes in under 90ms while E2B's Firecracker microVMs take about 150ms — but model latency dwarfs both in real agent loops. A numbers-first look at when the gap matters, how the two pricing shapes compare, and what a self-hosted sandbox should copy from each.

Your Agent's Firewall Can't Read SQL. Deno's Claw Patrol Can.
Deno's open-source Claw Patrol terminates agent TCP connections and parses HTTP, Postgres, SSH, and Kubernetes on the wire, so policy sees the query instead of just the connection. How it works, what it costs, and where it belongs on a self-hosted platform.

Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet
Railway's May 2026 changelog lets enterprise workspaces restrict deployments to approved GitHub orgs. Here is what the guardrail enforces and how to rebuild it on your own fleet with ArgoCD source pinning, Kyverno admission policy, and pipeline owner checks.

Hetzner Is Giving Away Free Inference. Should Your Fleet Still Run Its Own vLLM?
Hetzner's free OpenAI-compatible inference API gives self-hosted teams zero-capex model access — but rate limits, 5–10s p99 latency, and a scaled-down catalog define what 'free' actually guarantees. Here is the rent-vs-own math and a checklist for when to build your own vLLM.

KEP-5677: Tell Tenants 'No GPU Left' Up Front Instead of Parking Their Pods in Pending
Kubernetes 1.37's second alpha of KEP-5677 turns GPU availability into a readable API object. Here is how a self-hosted PaaS turns that per-pool snapshot into a tenant-facing capacity page and a fast admission-time refusal instead of pods stuck in Pending.