Skip to main content

527 posts tagged with "AI agents"

AI agents and autonomous systems

View all tags

Read the AI agents and MCP guide

Ship the Agent, Not Just the App: Curie vs Deployah and the Future of the Git-Push Deploy Contract
·Dora Noda·13 min

Ship the Agent, Not Just the App: Curie vs Deployah and the Future of the Git-Push Deploy Contract

Curie ships Claude Code agents to Kubernetes via git push while Deployah shrinks the manifest to a short spec with nothing in-cluster: a side-by-side of the two deploy contracts, the six deploy-time concerns agents add, and which end a git-push PaaS should extend first.

AI agents
Kubernetes
PaaS
self-hosting
+1
CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools
·Dora Noda·10 min

CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools

CIS released the first consensus hardening baseline for MCP servers on September 16, 2026: 55 recommendations across 10 domains. Here is how each domain maps onto MCP tools that deploy, roll back, and read secrets — what a sane self-hosted surface already passes, and what still needs building.

Model Context Protocol
AI agents
security
self-hosting
+1
16 Claude Code CVEs and Counting: Why Container Sandbox Escape Is a Vulnerability Class, Not a Bug
·Dora Noda·8 min

16 Claude Code CVEs and Counting: Why Container Sandbox Escape Is a Vulnerability Class, Not a Bug

Sixteen CVEs against one coding agent prove container sandbox escape is a permanent vulnerability class, not a patchable bug. Here is the CVE record, the isolation ladder with real latency numbers, and why agent-generated code belongs behind its own kernel.

cybersecurity
AI agents
Claude
self-hosting
+1
The Deploy Exists Before the Account Does: What Cloudflare Drop's 60-Minute Anonymous Preview Means for Git-Push PaaS Onboarding
·Dora Noda·11 min

The Deploy Exists Before the Account Does: What Cloudflare Drop's 60-Minute Anonymous Preview Means for Git-Push PaaS Onboarding

Cloudflare Drop inverts PaaS onboarding: drag a folder into the browser, get a live URL for 60 minutes, and only sign up if you claim it. Here is the four-part blueprint for bringing signup-last deploys to a git-push platform — and the state boundary where the pattern breaks.

PaaS
self-hosting
AI agents
security
Coolify and Dokploy Are 'Not Designed for AI Agent Auto Deploy': What the HN Verdict Gets Right 6 Months Later
·Dora Noda·10 min

Coolify and Dokploy Are 'Not Designed for AI Agent Auto Deploy': What the HN Verdict Gets Right 6 Months Later

Six months after Hacker News declared Coolify and Dokploy 'not designed for AI agent auto deploy,' we score both tools against MCP-first rivals on six agent-operability dimensions — and show what it actually takes to hand the 2am rollback to an agent.

AI agents
Model Context Protocol
self-hosting
PaaS
Crossplane's Case for API-First Infrastructure: What an AI Agent That Deploys Actually Needs From an API
·Dora Noda·11 min

Crossplane's Case for API-First Infrastructure: What an AI Agent That Deploys Actually Needs From an API

Crossplane's CNCF graduation made composable infrastructure APIs mainstream, but an agent that deploys needs a contract shape — schema, desired state, status, watch, safe retry — not a specific framework. A head-to-head of composite resources against a purpose-built deploy API, with a decision rule for which to build.

Kubernetes
AI agents
Model Context Protocol
infrastructure
Should Your AI Agent Write YAML or Call Tools? Crossplane's API-First Case vs MCP Agent Ops
·Dora Noda·13 min

Should Your AI Agent Write YAML or Call Tools? Crossplane's API-First Case vs MCP Agent Ops

Crossplane says agents should declare desired state and let controllers reconcile; the MCP ecosystem says agents should call tools step by step. A head-to-head on the same task, a mid-provision crash traced through both, and three reconciliation ideas every platform MCP server should borrow.

AI agents
Kubernetes
infrastructure
self-hosting
What an E2B-Style Sandbox Actually Needs Before an Agent Touches Production
·Dora Noda·10 min

What an E2B-Style Sandbox Actually Needs Before an Agent Touches Production

Sandbox isolation is a solved purchase — E2B, Daytona, and Modal all sell it. The pre-deploy gate around execution (substrate parity, artifact promotion, teardown-on-reject, credential scoping, and a tested-vs-shipped audit trail) is the harder infrastructure you still have to build, priced here against September 2026 vendor primitives.

PaaS
AI agents
self-hosting
security
Your Deploy Agent Can Be Talked Into Anything: Deterministic Policy for MCP Tools That Ship Production
·Dora Noda·12 min

Your Deploy Agent Can Be Talked Into Anything: Deterministic Policy for MCP Tools That Ship Production

Sente Labs' extensible-mcp proxy puts deterministic policy between the LLM and its MCP servers — on-demand tool discovery, Rego-enforced calls, and signed approvals on the roadmap. What that buys any MCP surface whose tools can deploy and roll back production.

Model Context Protocol
AI agents
cybersecurity
self-hosting
Showing 19–27 of 527 posts