
KYAML Goes Stable in Kubernetes v1.37: What a Canonical YAML Subset Means for the Manifests a Git-Push PaaS Generates on Every Deploy
Kubernetes 1.37 promotes KYAML — a strict, unambiguous YAML subset with a stable kubectl output — to GA. What canonical manifests change for platforms that generate YAML on every deploy, and why compliance belongs at emit time.

MinIO Vanished From Docker Hub: The One-Line Fix and the Migration You Actually Owe Yourself
MinIO deleted minio/minio and minio/mc from Docker Hub in mid-September 2026, breaking every cold docker compose pull. The quay.io repoint restores green builds today — but that image is frozen forever, so here is the honest SeaweedFS vs Garage vs RustFS comparison plus the registry mirror that makes the next deletion a non-event.

Railway's Fifth Outage Since November: What the July 2 US East Failure Reveals About Multi-Tenant PaaS Blast Radius
Railway's July 2 US East outage — twenty minutes with no internet route, storage at a third of speed, 20,000 blackholed private links — was its fifth major incident since November. What the cascade reveals about shared fate on multi-tenant platforms, and how to evaluate a host by outage rate instead of postmortems.

Firecracker's First Escape CVEs: What CVE-2026-5747 and CVE-2026-1386 Mean for MicroVM Sandboxes
Firecracker's zero-escape-CVE record broke twice in 2026: an out-of-bounds write in the virtio-pci transport and a symlink overwrite in the jailer. What both bugs mean for teams running AI-agent sandboxes on microVMs, and the patching checklist that keeps the isolation story intact.

Fly.io's Four-Incident Day: What September 23's Networking Pileup Teaches About Depending on Someone Else's Mesh
On September 23, 2026, Fly.io suffered four incidents in twelve hours — DFW IPv6 failure, Upstash dark in Frankfurt, 6PN mesh errors, and a Sprites outage that spread regions overnight. Here is the timeline, an honest accounting of what tenants could do, and what changes when you own the mesh.

Someone Already Wrote the Hetzner MCP Server: What a Live Changelog Audit Teaches Deploy-From-Chat
A community MCP server mapping the Hetzner Cloud, Storage Box, and Robot APIs survived six provider changelog deltas in three months with zero broken tools — thanks to a published endpoint audit, pass-through writes, and an eval that expects deprecation. Here is what that discipline teaches any deploy-from-chat roadmap, and the tenant-scoping and audit-logging layer a PaaS still has to build itself.

HPA Scales to Zero Now. Should Your Fleet Retire KEDA or Knative?
Kubernetes 1.37 graduates HPA scale-to-zero to beta and turns it on by default. Queue workers can consolidate onto the native primitive — but HTTP services still need Knative's request buffering and event-diverse fleets still need KEDA's scaler catalog. Here is the per-workload decision.

Laravel MCP 1.0 Ships: Your Laravel App Is Now an Agent Tool — What Changes on the Deploy Surface
Laravel MCP 1.0 adopts the stateless MCP 2026-07-28 spec with searchable tool catalogs, cache hints, and mandatory OAuth PKCE — plus header validation that 400s old clients. Here is the upgrade checklist and what per-app MCP servers mean for anyone operating Laravel apps.

No More Self-Hosted Git After 15 Years: What AI Actually Changed About the Self-Hosting Calculus
A veteran Linux developer shut down his public git server after 15 years because AI scrapers killed it — then watched the eulogy hit 298 points on Hacker News. His real reason, the two AI pressures behind it, and a keep/move/hedge framework for deciding what stays on your own machines.