527 posts tagged with "AI agents"
AI agents and autonomous systems

Ship the Agent, Not Just the App: Curie vs Deployah and the Future of the Git-Push Deploy Contract
Curie ships Claude Code agents to Kubernetes via git push while Deployah shrinks the manifest to a short spec with nothing in-cluster: a side-by-side of the two deploy contracts, the six deploy-time concerns agents add, and which end a git-push PaaS should extend first.

CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools
CIS released the first consensus hardening baseline for MCP servers on September 16, 2026: 55 recommendations across 10 domains. Here is how each domain maps onto MCP tools that deploy, roll back, and read secrets — what a sane self-hosted surface already passes, and what still needs building.

16 Claude Code CVEs and Counting: Why Container Sandbox Escape Is a Vulnerability Class, Not a Bug
Sixteen CVEs against one coding agent prove container sandbox escape is a permanent vulnerability class, not a patchable bug. Here is the CVE record, the isolation ladder with real latency numbers, and why agent-generated code belongs behind its own kernel.

The Deploy Exists Before the Account Does: What Cloudflare Drop's 60-Minute Anonymous Preview Means for Git-Push PaaS Onboarding
Cloudflare Drop inverts PaaS onboarding: drag a folder into the browser, get a live URL for 60 minutes, and only sign up if you claim it. Here is the four-part blueprint for bringing signup-last deploys to a git-push platform — and the state boundary where the pattern breaks.

Coolify and Dokploy Are 'Not Designed for AI Agent Auto Deploy': What the HN Verdict Gets Right 6 Months Later
Six months after Hacker News declared Coolify and Dokploy 'not designed for AI agent auto deploy,' we score both tools against MCP-first rivals on six agent-operability dimensions — and show what it actually takes to hand the 2am rollback to an agent.

Crossplane's Case for API-First Infrastructure: What an AI Agent That Deploys Actually Needs From an API
Crossplane's CNCF graduation made composable infrastructure APIs mainstream, but an agent that deploys needs a contract shape — schema, desired state, status, watch, safe retry — not a specific framework. A head-to-head of composite resources against a purpose-built deploy API, with a decision rule for which to build.

Should Your AI Agent Write YAML or Call Tools? Crossplane's API-First Case vs MCP Agent Ops
Crossplane says agents should declare desired state and let controllers reconcile; the MCP ecosystem says agents should call tools step by step. A head-to-head on the same task, a mid-provision crash traced through both, and three reconciliation ideas every platform MCP server should borrow.

What an E2B-Style Sandbox Actually Needs Before an Agent Touches Production
Sandbox isolation is a solved purchase — E2B, Daytona, and Modal all sell it. The pre-deploy gate around execution (substrate parity, artifact promotion, teardown-on-reject, credential scoping, and a tested-vs-shipped audit trail) is the harder infrastructure you still have to build, priced here against September 2026 vendor primitives.

Your Deploy Agent Can Be Talked Into Anything: Deterministic Policy for MCP Tools That Ship Production
Sente Labs' extensible-mcp proxy puts deterministic policy between the LLM and its MCP servers — on-demand tool discovery, Rego-enforced calls, and signed approvals on the roadmap. What that buys any MCP surface whose tools can deploy and roll back production.