531 posts tagged with "AI agents"
AI agents and autonomous systems

MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish
The final MCP spec deprecates Dynamic Client Registration in favor of Client ID Metadata Documents, with removal eligible after July 2027. Here is the ordered checklist for migrating a self-hosted MCP server, plus the two companion hardenings to ship in the same window.

Deploy Agents That Wait: Building a Stateless Rollout-and-Approval Agent on MCP Tasks and Multi Round-Trip Requests
MCP's July 2026 release made the protocol stateless and gave agent builders Tasks and Multi Round-Trip Requests. Here is the concrete design for a deploy agent that returns a task handle, polls rollout status against Kubernetes Deployment conditions, and stops for an expiring human approval before promoting to production.

One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server
nginx-ui shipped an MCP endpoint without its AuthRequired check — a CVSS 9.8 that left roughly 2,689 servers open to unauthenticated takeover. The full MCPwn timeline, the two-route bug, and a seven-item audit checklist for anyone shipping an MCP server.

SmolVM Packs a MicroVM Into a Single Binary That Boots in Under 200ms — What It Changes for a Firecracker-Only Agent Sandbox
SmolVM boots any OCI image as a hardware-isolated microVM from a single binary in under 200ms, with pack and branch primitives Firecracker never shipped. Here is how it compares head-to-head and what to verify before adding it to a self-hosted agent-sandbox stack.

TurboFieldfare Fits a 26B MoE Model in 2GB of RAM: What SSD-Streamed Experts Mean for Your Cheapest Inference Node
TurboFieldfare runs Gemma 4 26B-A4B in ~2GB of RAM by streaming 4-bit experts from SSD — 5–6 tok/s on an M2 Air, 31–35 on an M5 Pro. The per-token byte math behind those numbers, and how to size a €49 NVMe box as your cheapest inference tier.

Whole GPU or Nothing Is Over: Wiring DRA GPU Scheduling on a Bare-Metal Cluster API Fleet
Kubernetes' device-plugin era of whole-GPU-or-nothing scheduling is ending. What WG Device Management standardized with DRA, what coarse allocation costs a small bare-metal fleet, and the exact checklist a Cluster API fleet needs before tenants can deploy with a GPU.

Cloudflare Deprecated McpAgent: What a Stateless MCP Handler Buys (and Costs) a Deploy-From-Chat Server
Cloudflare's Agents SDK v0.20.0 deprecated McpAgent in favor of a stateless createMcpHandler, tracking MCP spec 2026-07-28. Here is what dropping the per-session Durable Object buys, where multi-step deploy state moves instead, and how to migrate without breaking older clients.

Daytona's Repo Is Frozen — Will the Fork Survive? What Three Open-Source Relicenses Teach About Betting on Nightona
Daytona froze its public repo at v0.190.0 in June 2026 and moved development private. Community fork Nightona carries the AGPL tree forward, but the HashiCorp, Redis, and Elasticsearch precedents say forks survive only with funded maintainers, neutral governance, and API compat — Nightona scores half a point out of three.

Firecracker Is the Easy 5%: What Self-Hosting an E2B-Style Agent Sandbox Really Operates
E2B's enterprise pitch admits the microVM is the easy part. An eight-piece control-plane inventory plus a hosted-vs-self-hosted cost comparison shows what running agent sandboxes yourself actually operates.