531 posts tagged with "AI agents"
AI agents and autonomous systems

A Czech Self-Hosting Hub Gave Claude Shell Access to Its Coolify Fleet: A 130-Line MCP Bridge Teardown
A Czech self-hosting hub wired Claude to its Coolify fleet through a 133-line MCP bridge — and handed the agent raw SSH instead of scoped deploy tokens. A code-level teardown of all seven tools, plus the five authorization rules a platform-owned MCP server needs.

Chat Deploys My App: What the Coolify–AnythingLLM MCP Bridge Proves, and the 5 Gaps a Render-Compatible MCP Server Closes
A community MCP server lets an LLM inspect, restart, and debug apps on a self-hosted Coolify box through AnythingLLM chat — but behind one shared API token sit a docker-socket tap and a root shell over SSH. Here is what the bridge proves, how Render's official MCP server scopes agent power instead, and the five gaps a Render-compatible MCP server still has to close.

Dokploy Has an MCP Server Too — and It's Bigger Than Coolify's: An AI-Agent Operator's Comparison on a $5 Hetzner Box
Dokploy's official MCP server gives AI agents full deploy and lifecycle control while Coolify's built-in MCP is read-only — here is what each agent interface can actually do, and what each control plane costs in idle RAM on a $5 Hetzner box.

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway
Hand-writing an MCP server means maintaining a second governed interface. What projecting your REST API through a gateway gives you for free — OpenAPI-derived tools, OAuth 2.1 auth, rate limits — and the write-scoping, approval, and rollback semantics a deploy API still has to build itself.

E2B Is Now Native in OpenAI's Agents SDK: The Bar a Self-Hosted Agent Sandbox Has to Clear
OpenAI's Agents SDK declares E2B sandboxes natively since April 2026. This post turns that integration into a six-part checklist — cold start, isolation, templates, lifecycle, MCP sandboxing, egress policy — and scores four self-hosted paths against it.

From Metered API to RuntimeClass: Building E2B-Style Sandboxes on Your Own K8s Fleet
The sandbox cost math already settled: past ~400 sandbox-hours a month, owned hardware wins. This is the build guide for what comes next — three paths to E2B-style sandboxes on your own fleet, with Kata Containers on Cluster API as the one that skips the second orchestrator.

AI-Assisted Commits Leak Secrets at Twice the Baseline Rate — Why Your PaaS Should Scan Every Push
GitGuardian counted 28.65 million new hardcoded secrets on public GitHub in 2025, with AI-assisted commits leaking at 3.2% against a 1.5% baseline. Why a default-on push-time scan catches what Vault, OpenBao, and Infisical never see, and what the gate should look like.

Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production
An MCP server that can redeploy production is a deploy pipeline with natural-language input. A seven-control hardening checklist — TLS, per-tool scopes, short-lived credentials, schema validation, rate limits, and audit logging — mapped to the three attacks that actually happen.

Kamal vs Coolify: How Much Platform Should Actually Run on Your Server?
Kamal runs almost nothing on your server; Coolify runs the whole platform. A concrete side-by-side of footprint, previews, and automation — and where a Render-compatible API splits the difference.