
Hetzner Deleted the Datacenter Field: Why Your Prometheus Labels Went Quietly Empty (and the 30-Second Check)
Hetzner removed the datacenter field from its Cloud API on July 1, 2026, and unpatched Prometheus and vmagent scrapers answered with empty location labels — green targets, hollow metadata. Here is the 30-second check, the old-to-new label mapping, and a nine-item audit checklist for self-hosted Hetzner fleets.

Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails
Across 409,000 approve-or-deny decisions, human reviewers missed a third of malicious AI agent commands — and the credential-stealing ones slipped through three times as often as the obviously destructive ones. The numbers argue for sandboxes, scoped credentials, and policy engines ahead of the approve button.

TLS for a Bare IP: What Let's Encrypt's Free IP-Address Certificates Change for Self-Hosted Deploys
Let's Encrypt's free IP-address certificates went generally available in January 2026: six-day, ACME-automated TLS for a bare IPv4 or IPv6 address. Where they fit in a self-hosted PaaS — node bootstrap before DNS, fallback vhosts, IP-addressed infrastructure — the exact recipe for getting one, and the limits that keep tenant traffic on real domains.

10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools
Pinterest runs 66,000+ MCP tool calls a month through domain-specific servers behind a central registry. How the registry-plus-fleet pattern solves discovery and access control — and what it means for the deploy tools agents drive.

MCP Streamable HTTP in Production: When Stateless Tool Calls Scale Cleanly and When a Deploy Agent Needs Session Affinity
AWS's FastMCP-on-ECS reference runs MCP servers stateless so any replica can answer any tool call, and the July 2026 spec revision deleted protocol-level sessions entirely. Here is that verdict mapped onto a deploy/rollback agent: which tools stay stateless, where multi-step state lives instead, and how idempotency keys keep privileged infrastructure actions safe across retries.

MCP Tasks and Multi-Round Trips: The Durable Deploy Contract an Agent-Operated PaaS Needs
MCP's July 2026 spec adds asynchronous Tasks and Multi-Round Trip Requests. Together they form a durable deploy state machine: task handles instead of blocked calls, an approval boundary before production promotion, safe retry, cooperative cancel, and rollback as a first-class task.

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch
Moltbook leaked 1.5 million agent API tokens within 72 hours of an all-AI-coded launch because Row Level Security was never enabled. A concrete failure-chain postmortem plus the secure-by-default provisioning contract every agent-facing platform should enforce.

When Railpack Detects Wrong: What an Angular SSR App Served as a Static Caddy Site Teaches About Builder Autodetect
Railway's Railpack builder classified an Angular SSR app as a static site and served it through Caddy — a green deploy of the wrong architecture. The before-and-after Dockerfile fix, why fail-open autodetect keeps causing outages, and the five detect-time log lines a self-hosted PaaS should emit.

Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.
Refuse is an open-source, self-hostable gate that blocks known-vulnerable package installs across 18 package managers before anything hits disk — including installs your coding agent runs. Here is how it works, where it belongs in a PaaS build pipeline, and what it cannot catch.