Skip to main content

531 posts tagged with "AI agents"

AI agents and autonomous systems

View all tags

Read the AI agents and MCP guide

Kubernetes Shipped a Sandbox API for AI Agents: What a Declarative Singleton-Workload Primitive Means for a Deploy-From-Chat PaaS
·Dora Noda·10 min

Kubernetes Shipped a Sandbox API for AI Agents: What a Declarative Singleton-Workload Primitive Means for a Deploy-From-Chat PaaS

SIG Apps' Agent Sandbox CRD collapses the hand-rolled StatefulSet-plus-Service-plus-PVC stack into one declarative resource for stateful AI agent runtimes. Here is how the four CRDs work, what the gVisor-vs-Kata choice costs, and which parts a self-hosted platform should adopt now.

Kubernetes
AI agents
self-hosting
Model Context Protocol
MCP's 10,000-Server Problem: Building an Allowlisted, Audited Tool Catalog Before an Agent Can Deploy to Your Fleet
·Dora Noda·10 min

MCP's 10,000-Server Problem: Building an Allowlisted, Audited Tool Catalog Before an Agent Can Deploy to Your Fleet

With 10,000+ public MCP servers and most scanned servers needing security review, connecting an agent to a tool is now a governance problem. A tiered, allowlisted tool catalog design — plus a deploy-from-chat walkthrough — for teams running agents against production.

Model Context Protocol
AI agents
security
self-hosting
450+ MCP Servers Catalogued and Quality-Scored Daily: What the Ecosystem Census Says About the Tool Sprawl Your Deploy Platform Inherits
·Dora Noda·12 min

450+ MCP Servers Catalogued and Quality-Scored Daily: What the Ecosystem Census Says About the Tool Sprawl Your Deploy Platform Inherits

A daily census grades 453 MCP servers an average of 16.3 out of 100. Here is what that number means for platform teams, the security gap the score does not cover, and a bless-or-block rubric for governing tenant agent tools.

Model Context Protocol
AI agents
security
self-hosting
MCP Bets H2 2026 on Server Cards: What Your Registry-Less Server Must Hand-Roll Today
·Dora Noda·10 min

MCP Bets H2 2026 on Server Cards: What Your Registry-Less Server Must Hand-Roll Today

The July 2026 MCP spec shipped stateless transport and a mandatory server/discover RPC but left pre-connect Server Cards experimental. Here is the concrete manifest, capability advertisement, and trust signaling a registry-less deploy-from-chat server builds today so the eventual card format is a migration, not a rewrite.

Model Context Protocol
AI agents
self-hosting
security
Your Agent Doesn't Need Your API Key: What Qovery's Infrastructure-MCP Play Proves About Governed Tool Interfaces
·Dora Noda·11 min

Your Agent Doesn't Need Your API Key: What Qovery's Infrastructure-MCP Play Proves About Governed Tool Interfaces

Qovery's infrastructure-MCP writeup defines the governed alternative to pasting API keys into agents: scoped per-tool authority, server-side budget caps, and a per-call audit trail. What that boundary contains, why it became a product category in 2026, and what self-hosting it on your own machines requires.

AI agents
Model Context Protocol
security
self-hosting
+1
Deploy From Chat: What Coolify, Arcade, and Azure APIM Prove About MCP Servers for PaaS Ops
·Dora Noda·13 min

Deploy From Chat: What Coolify, Arcade, and Azure APIM Prove About MCP Servers for PaaS Ops

Coolify's community MCP bridge, Arcade's 8,000-tool OAuth runtime, and Azure APIM's REST-to-MCP exposure prove agents can deploy, roll back, and tail logs from chat. The protocol is the easy part — discovery, scoped credentials, and confused-deputy hardening decide whether an agent gets real authority.

AI agents
Model Context Protocol
PaaS
security
+1
Modal's $355M Series C Puts a Price on the Sandbox: What $0.33/Hour Per Agent Sandbox Really Costs vs Self-Hosted
·Dora Noda·8 min

Modal's $355M Series C Puts a Price on the Sandbox: What $0.33/Hour Per Agent Sandbox Really Costs vs Self-Hosted

Modal's $355M raise at a $4.65B valuation prices agent sandboxes as their own category. Working through the per-second meter against owned hardware puts the crossover at about 5% utilization — and memory-while-alive metering is the line item that decides it.

AI agents
cost-optimization
fundraising
self-hosting
Railway Turned Its CLI MCP Server Into a Proxy: One Credential for Every Agent, and an Audit Trail You Can No Longer See
·Dora Noda·12 min

Railway Turned Its CLI MCP Server Into a Proxy: One Credential for Every Agent, and an Audit Trail You Can No Longer See

Railway's September 2026 changelog flips railway mcp from a bundled local server to a proxy for its hosted MCP endpoint. Here is the three-way tradeoff — local vs proxy-to-hosted vs self-hosted — across credentials, logging, scope enforcement, and audit ownership, plus a decision rule for production agent access.

Model Context Protocol
AI agents
security
self-hosting
+1
Six Coding Agents on a Private Network: Threat-Model the Credential Blast Radius Before You Copy Railway's Sandbox
·Dora Noda·12 min

Six Coding Agents on a Private Network: Threat-Model the Credential Blast Radius Before You Copy Railway's Sandbox

Railway's June 2026 sandboxes preinstall six coding agents with private-network reach to production data. Four Kubernetes controls — per-session identities, default-deny egress, approval-gated mutations, and auditable teardown — keep the convenience without the nine-second-wipe blast radius.

AI agents
security
Kubernetes
self-hosting
+1
Showing 145–153 of 531 posts