Skip to main content

368 posts tagged with "Engineering"

Engineering insights and technical deep dives

View all tags

Buildpacks Is Cutting Kaniko Out of Your git-push Pipeline
·Dora Noda·9 min

Buildpacks Is Cutting Kaniko Out of Your git-push Pipeline

Cloud Native Buildpacks compiles kaniko's executor into the lifecycle binary behind every git-push build — and the plan to cut it out runs through a fork-hop, grype reachability triage, and a separate extender binary. What the extraction means for your builder's CVE surface and provenance story.

security
self-hosting
PaaS
engineering
Should You Run Plain Docker Compose in Production in 2026? Where the Single-Host Ceiling Actually Sits
·Dora Noda·13 min

Should You Run Plain Docker Compose in Production in 2026? Where the Single-Host Ceiling Actually Sits

A May 2026 Hacker News thread's verdict on Docker Compose in production, turned into a three-gap accounting: which of zero-downtime deploys, self-healing, and multi-host have cheap single-host fixes, where the real ceiling sits, and what a Cluster-API-managed fleet closes.

self-hosting
PaaS
migration
engineering
Gateway API v1.5 Is Stable: What a Self-Hosted Fleet Gains by Leaving Ingress Behind, and What the Move Costs
·Dora Noda·10 min

Gateway API v1.5 Is Stable: What a Self-Hosted Fleet Gains by Leaving Ingress Behind, and What the Move Costs

Gateway API v1.5 and v1.6 graduated TLS passthrough, CORS, mTLS, and TCP/UDP routing to stable while ingress-nginx went unpatched. A self-hosted fleet's migration guide: an annotation mapping table, a worked Ingress-to-HTTPRoute rewrite, and the real cost of the move.

Kubernetes
self-hosting
migration
engineering
Your Secret Scanner's CI Broke Overnight: Gitleaks' Org License Gate, Porsche's TruffleHog Swap, and What a Git-Push Pipeline Should Standardize On
·Dora Noda·10 min

Your Secret Scanner's CI Broke Overnight: Gitleaks' Org License Gate, Porsche's TruffleHog Swap, and What a Git-Push Pipeline Should Standardize On

Gitleaks' GitHub Action now fails org repos without a license key while the CLI stays MIT. Compare the three fixes — license, vendored CLI, or TruffleHog verified mode — with Porsche's ADR-0011 as the worked case study and a pinned baseline for git-push build pipelines.

security
self-hosting
PaaS
engineering
Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec
·Dora Noda·13 min

Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec

A production design for a deploy-capable remote MCP server under the 2026-07-28 spec: OAuth discovery via protected-resource metadata, audience-bound tokens, narrow per-environment scopes, human approval gates for destructive tools, and chain-complete audit logs.

Model Context Protocol
AI agents
security
engineering
Your Build Server Was Owned for 24 Days. Patching It Doesn't Tell You What Shipped Clean.
·Dora Noda·12 min

Your Build Server Was Owned for 24 Days. Patching It Doesn't Tell You What Shipped Clean.

Attackers held admin access to self-hosted JFrog Artifactory servers for 24 days in August-September 2026, planting Rust backdoors with remote C2. A triage table for which window artifacts are suspect, the rebuild-and-compare procedure that re-verifies them, and the SLSA signing checklist that makes the next incident answerable.

cybersecurity
self-hosting
engineering
guide
Sealed Secrets vs External Secrets Operator in 2026: What Git-Stored Ciphertext Really Costs a Three-Person Platform Team Against Vault Sync
·Dora Noda·9 min

Sealed Secrets vs External Secrets Operator in 2026: What Git-Stored Ciphertext Really Costs a Three-Person Platform Team Against Vault Sync

Sealed Secrets vs External Secrets Operator for tenant secrets on a self-hosted multi-tenant fleet: a grounded cost comparison of vault sync against git-stored ciphertext, with tenant-isolation recipes and the thresholds for switching.

Kubernetes
security
self-hosting
engineering
MLflow's MCP Registry: Versioned, Governed Tool Dependencies for Production Agents
·Dora Noda·9 min

MLflow's MCP Registry: Versioned, Governed Tool Dependencies for Production Agents

MLflow 3.15.0's experimental MCP Registry versions MCP servers with semver, promotes them through staging and production aliases, snapshots their tools, and links traces to exact versions — a worked walkthrough of the promotion loop, the registry-vs-gateway boundary, and when a second tenant makes the catalog mandatory.

Model Context Protocol
AI agents
engineering
self-hosting
Your Dockerfile Cache Is Blind to Your Monorepo: What Build-Graph Caching Adds to a Git-Push PaaS Pipeline
·Dora Noda·11 min

Your Dockerfile Cache Is Blind to Your Monorepo: What Build-Graph Caching Adds to a Git-Push PaaS Pipeline

A one-line monorepo change costs about 11 builder-minutes under Docker layer caching versus 4 with Turborepo/Bazel remote cache hits — the worked time-and-cost math, the September 2026 Namespace/Depot/Blacksmith landscape, and when a git-push PaaS should offer graph-aware caching natively.

PaaS
self-hosting
engineering
developer tools
Showing 1–9 of 368 posts