Skip to main content

531 posts tagged with "AI agents"

AI agents and autonomous systems

View all tags

Read the AI agents and MCP guide

Crossplane's API-First Infrastructure Bet: What Agent-Operated Infra via Declarative CRDs Gets Right That a REST Deploy API Doesn't
·Dora Noda·8 min

Crossplane's API-First Infrastructure Bet: What Agent-Operated Infra via Declarative CRDs Gets Right That a REST Deploy API Doesn't

CNCF's case for Crossplane says AI agents operate better against Kubernetes-style CRDs than a REST deploy API. Here's the mechanism-by-mechanism reason why, what the tradeoff actually costs, and what a Render-compatible API should borrow from it.

PaaS
self-hosting
infrastructure
AI agents
+1
Your Cursor Sandbox Was Never the Thing Protecting You: Inside DuneSlide's Zero-Click RCE
·Dora Noda·8 min

Your Cursor Sandbox Was Never the Thing Protecting You: Inside DuneSlide's Zero-Click RCE

Two CVSS 9.8 bugs in Cursor let a zero-click prompt injection escape the sandbox and reach full code execution. The real lesson isn't the sandbox bug — it's that the agent held the developer's standing machine permissions the whole time.

Cursor
security
AI agents
Model Context Protocol
Dremio's MCP Server Doesn't Give AI Agents a Separate Policy — Here's the Kubernetes Version for a Self-Hosted PaaS's Deploy Tools
·Dora Noda·9 min

Dremio's MCP Server Doesn't Give AI Agents a Separate Policy — Here's the Kubernetes Version for a Self-Hosted PaaS's Deploy Tools

Dremio's lakehouse MCP server enforces the same row/column policies for an AI agent as for the human who's logged in — no separate agent policy to write or drift out of sync. Here's the exact Kubernetes primitives (TokenRequest, RBAC impersonation, audit logging) that build the same guarantee into a self-hosted PaaS's deploy and rollback tools.

Model Context Protocol
self-hosting
PaaS
security
+1
kubectl for AI Agents: What Klaw.sh Reveals About the Layer Between CrewAI and Kubernetes
·Dora Noda·8 min

kubectl for AI Agents: What Klaw.sh Reveals About the Layer Between CrewAI and Kubernetes

Klaw.sh borrowed kubectl's verbs for AI agent fleets instead of pods. Here's what layer that actually is, and a concrete verdict on whether a PaaS control plane that already runs Cluster API should absorb it or leave it alone.

self-hosting
PaaS
AI agents
infrastructure
Your MCP Traffic and Your Tenants' LLM Calls Just Got a Real Kubernetes Primitive
·Dora Noda·9 min

Your MCP Traffic and Your Tenants' LLM Calls Just Got a Real Kubernetes Primitive

Kubernetes' new AI Gateway Working Group is formalizing token-based rate limiting, model-aware routing, and provider failover as Gateway API primitives. Here's what's already GA, what's still a proposal, and what it means for a platform routing both tenant and agent MCP traffic through one ingress layer.

infrastructure
self-hosting
PaaS
AI agents
+1
10,000 MCP Servers and Counting: Why Deploy-From-Chat's Real Bottleneck Is Discovery, Not Capability
·Dora Noda·9 min

10,000 MCP Servers and Counting: Why Deploy-From-Chat's Real Bottleneck Is Discovery, Not Capability

The official MCP Registry now lists nearly 10,000 servers and MCP SDKs hit 97 million monthly downloads. Here's why that scale makes discovery and trust the real bottleneck for a deploy-from-chat MCP server — and what actually closes the gap.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Microsoft's Poisoned MCP Tool Descriptions: When an Approved Tool's Metadata Silently Changes to Leak Data, Not Its Code
·Dora Noda·11 min

Microsoft's Poisoned MCP Tool Descriptions: When an Approved Tool's Metadata Silently Changes to Leak Data, Not Its Code

Microsoft's June 2026 guidance shows an MCP tool's approved name and summary can stay frozen while its description silently changes to smuggle a hidden instruction. Here's the attack, three real precedents, and the checklist a deploy-from-chat MCP server needs to catch it.

Model Context Protocol
AI agents
cybersecurity
self-hosting
+1
Northflank's Vibe-Coding Playbook Has Four Stages. bex Only Ships Two of Them by Default
·Dora Noda·9 min

Northflank's Vibe-Coding Playbook Has Four Stages. bex Only Ships Two of Them by Default

Northflank's enterprise vibe-coding guidance reduces to four jobs a platform owes an AI-generated app: audit, harden, observe, sandbox. Here's which two bex ships as defaults today, and which two are still the tenant's job — checked against the actual bex.yml schema.

self-hosting
PaaS
AI agents
security
+1
SPIFFE/SPIRE for AI Agents: Cryptographic Workload Identity Instead of Long-Lived Service Account Tokens
·Dora Noda·9 min

SPIFFE/SPIRE for AI Agents: Cryptographic Workload Identity Instead of Long-Lived Service Account Tokens

A hands-on look at issuing an AI deploy-agent a cryptographic identity distinct from a human's with SPIFFE/SPIRE — and the honest operational cost next to the Vault/External-Secrets-Operator setup most self-hosted platforms already run.

security
self-hosting
PaaS
AI agents
+1
Showing 415–423 of 531 posts