
Tekton Joins the CNCF: What Building a Git-Push PaaS's Pipeline Directly on Kubernetes CRDs Actually Buys You
Tekton became a CNCF incubating project on March 24, 2026. Here's what building a self-hosted PaaS's build pipeline directly on its Task and Pipeline CRDs actually gets you architecturally — and where the platform still has to fill in the gaps.

Pinterest Ran 66,000 MCP Tool Calls a Month — Here's the Gate Your Deploy Agent Needs
Pinterest's production MCP fleet handled 66,000 tool calls a month across 844 users. Here's the registry-and-gate architecture behind those numbers, and the concrete rate-limit and audit-retention policy a deploy-from-chat PaaS should ship on day one.

Kubelet Config Drop-in Directories Just Went GA: What Kubernetes 1.35 Actually Buys a Cluster API Fleet
Kubernetes 1.35 took kubelet's --config-dir flag to GA, letting drop-in KubeletConfiguration snippets replace one monolithic file. Here's the exact Cluster API YAML that uses it, and the node drift it still doesn't fix.

The Kubernetes Descheduler Can Cut Compute Spend 30-50% — Here's the Math on a Real Hetzner Fleet
A worked example turning the abstract 'bin-packing cuts compute 30-50%' claim into real node counts and euros on a Hetzner fleet, plus the PodDisruptionBudget and eviction-cadence config a multi-tenant PaaS needs before enabling it.

PSI Metrics Reach GA in Kubernetes 1.36: What Your Node's CPU/Memory Graphs Have Been Hiding
Kubernetes 1.36 graduates PSI metrics to GA, but the kubelet's own eviction manager still doesn't read them. Here's the exact wiring a self-hosted, Cluster-API-managed fleet needs to build itself — and the CPU-PSI gotcha that will burn you if you skip it.

Your Buildpack Only Checks bun.lockb. Bun Stopped Writing It in 2026.
Bun 1.2 quietly changed its default lockfile from bun.lockb to bun.lock, and it's already broken Bun detection on Railway, Cloudflare Pages, and Netlify. Here's the detection logic that survives the next lockfile change, and why 'build with Bun, run on Node' is the right default for existing projects.

Dokploy Ships Four Buildpack Backends: What Buildpack Plurality Buys a Git-Push Platform Over Picking One
Dokploy runs four separate buildpack backends side by side. A concrete look at what that plurality costs in real bugs, which languages each one actually covers, and whether a self-hosted PaaS should copy the model or pick one.

Railway Killed the Builder It Built: What Railpack's Nix-to-BuildKit Rewrite Means for a Self-Hosted PaaS's Buildpack Bet
Railway shipped Railpack in March 2026 to replace Nixpacks, the builder it built and open-sourced. The result: 38% smaller Node images, 77% smaller Python images, and a language-coverage gap at launch. Here's what the Nix-to-BuildKit rewrite actually changed, and what it means for a self-hosted PaaS choosing between Railpack and Cloud Native Buildpacks.

Vercel's Coding Agents Now Trigger Half of All Deployments: What a Platform Sized for Humans Has to Rebuild
Vercel's coding-agent-triggered deployments went from under 3% to over 50% of all deploys in six months. Here's the concrete build-queue, concurrency, and preview-URL math a human-sized deploy pipeline never had to do — and what changes when the platform treats an MCP tool call and a git push as the same event from day one.