
Buildpacks Is Cutting Kaniko Out of Your git-push Pipeline
Cloud Native Buildpacks compiles kaniko's executor into the lifecycle binary behind every git-push build — and the plan to cut it out runs through a fork-hop, grype reachability triage, and a separate extender binary. What the extraction means for your builder's CVE surface and provenance story.

Should You Run Plain Docker Compose in Production in 2026? Where the Single-Host Ceiling Actually Sits
A May 2026 Hacker News thread's verdict on Docker Compose in production, turned into a three-gap accounting: which of zero-downtime deploys, self-healing, and multi-host have cheap single-host fixes, where the real ceiling sits, and what a Cluster-API-managed fleet closes.

Gateway API v1.5 Is Stable: What a Self-Hosted Fleet Gains by Leaving Ingress Behind, and What the Move Costs
Gateway API v1.5 and v1.6 graduated TLS passthrough, CORS, mTLS, and TCP/UDP routing to stable while ingress-nginx went unpatched. A self-hosted fleet's migration guide: an annotation mapping table, a worked Ingress-to-HTTPRoute rewrite, and the real cost of the move.

Your Secret Scanner's CI Broke Overnight: Gitleaks' Org License Gate, Porsche's TruffleHog Swap, and What a Git-Push Pipeline Should Standardize On
Gitleaks' GitHub Action now fails org repos without a license key while the CLI stays MIT. Compare the three fixes — license, vendored CLI, or TruffleHog verified mode — with Porsche's ADR-0011 as the worked case study and a pinned baseline for git-push build pipelines.

Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec
A production design for a deploy-capable remote MCP server under the 2026-07-28 spec: OAuth discovery via protected-resource metadata, audience-bound tokens, narrow per-environment scopes, human approval gates for destructive tools, and chain-complete audit logs.

Your Build Server Was Owned for 24 Days. Patching It Doesn't Tell You What Shipped Clean.
Attackers held admin access to self-hosted JFrog Artifactory servers for 24 days in August-September 2026, planting Rust backdoors with remote C2. A triage table for which window artifacts are suspect, the rebuild-and-compare procedure that re-verifies them, and the SLSA signing checklist that makes the next incident answerable.

Sealed Secrets vs External Secrets Operator in 2026: What Git-Stored Ciphertext Really Costs a Three-Person Platform Team Against Vault Sync
Sealed Secrets vs External Secrets Operator for tenant secrets on a self-hosted multi-tenant fleet: a grounded cost comparison of vault sync against git-stored ciphertext, with tenant-isolation recipes and the thresholds for switching.

MLflow's MCP Registry: Versioned, Governed Tool Dependencies for Production Agents
MLflow 3.15.0's experimental MCP Registry versions MCP servers with semver, promotes them through staging and production aliases, snapshots their tools, and links traces to exact versions — a worked walkthrough of the promotion loop, the registry-vs-gateway boundary, and when a second tenant makes the catalog mandatory.

Your Dockerfile Cache Is Blind to Your Monorepo: What Build-Graph Caching Adds to a Git-Push PaaS Pipeline
A one-line monorepo change costs about 11 builder-minutes under Docker layer caching versus 4 with Turborepo/Bazel remote cache hits — the worked time-and-cost math, the September 2026 Namespace/Depot/Blacksmith landscape, and when a git-push PaaS should offer graph-aware caching natively.