
Heroku Killed 12 TLS Ciphers: The Legacy-Client Audit Your Self-Hosted PaaS Needs Too
Heroku removed 12 legacy TLS cipher suites and enabled TLS 1.3 with HTTP/2 on August 24, 2026. Here is which clients break, a reproducible openssl/sslyze/testssl.sh audit for your own domains, and the cert-manager plus Gateway API baseline to match it.

Render Cut Docker Builds From 87s to 32s: Where the Seconds Went and How to Match It on Hardware You Own
Render cut median Docker builds from 87 seconds to 32 with upload tuning, faster scheduling, and registry-backed caching. A lever-by-lever teardown of where those seconds lived, and the owned-hardware recipe — warm BuildKit builders, registry cache, cache mounts — that matches it.

Render's 75% Faster Builds, Decoded: What Native Environments Really Measure and the Bar for Self-Hosted Pipelines
Render's native environments claim 75% faster builds than Dockerfiles through intelligent layer caching. Decoding the warm-rebuild arithmetic behind the number, the three Dockerfile mistakes that hand it over, and the benchmark checklist a self-hosted BuildKit pipeline must clear to match it.

France's Railway Runs Kubernetes on Cluster API: What a National Railway's Declarative Rebuild Teaches a Two-Person Fleet Team
SNCF cut cluster provisioning from a month to 30 minutes and now updates every cluster monthly with Cluster API on its own hardware. Three lessons transfer directly to a two-person team on Hetzner — and four pieces of enterprise ceremony to skip.

Five Subsystems, Sixteen Days: Vercel's July 2026 Incident Cluster, Counted
Between July 8 and July 23, 2026, five separate Vercel subsystems failed — builds, SSO login, GitHub deploys, the dashboard, and telemetry export. Counting the whole cluster shows the real background failure rate of shared platforms, and why a six-minute Log Drains gap marked unrecoverable can't happen when your logs never cross a third-party pipe.

Coolify's Zero-Downtime Asterisk: Why Every Docker Compose Deploy Still Goes Down
Coolify deploys single-container apps with zero downtime but takes Docker Compose stacks offline on every deploy — a 10-to-30-second 502 window. The mechanical reason runners can't do what orchestrators get for free, where Dokploy's Swarm bet fits, and the four questions that cut through any self-hosted PaaS feature matrix.

Kubernetes 1.37 Will Reject Your Static Pods: the kubeadm Audit to Run Before You Upgrade
Kubernetes 1.37 removes the opt-out and has the kubelet refuse any static pod referencing a Secret or ConfigMap. The one-line audit for every control-plane node, the full list of rejected fields, and the hostPath and extraVolumes patterns that replace them.

Kubernetes Metrics API Is Stable in v1.37: What a Self-Hosted PaaS Must Expose Before Agents Can Safely Autoscale Apps
Kubernetes 1.37 made the Metrics API stable, but stability doesn't make it safe for an AI agent to autoscale on. Here's the isolation, staleness, and admission contract a self-hosted PaaS needs first.

Kubernetes Metrics API Is Stable in v1.37: The Contract Agents Need Before Autoscaling Apps
Kubernetes v1.37 makes metrics.k8s.io stable, but stable data is not safe automation. Here is the concrete, tenant-scoped contract a self-hosted PaaS should expose before an AI agent changes replicas.