Skip to main content

368 posts tagged with "Engineering"

Engineering insights and technical deep dives

View all tags

Hetzner Deleted the Datacenter Field: Why Your Prometheus Labels Went Quietly Empty (and the 30-Second Check)
·Dora Noda·10 min

Hetzner Deleted the Datacenter Field: Why Your Prometheus Labels Went Quietly Empty (and the 30-Second Check)

Hetzner removed the datacenter field from its Cloud API on July 1, 2026, and unpatched Prometheus and vmagent scrapers answered with empty location labels — green targets, hollow metadata. Here is the 30-second check, the old-to-new label mapping, and a nine-item audit checklist for self-hosted Hetzner fleets.

self-hosting
infrastructure
guide
engineering
Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails
·Dora Noda·9 min

Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails

Across 409,000 approve-or-deny decisions, human reviewers missed a third of malicious AI agent commands — and the credential-stealing ones slipped through three times as often as the obviously destructive ones. The numbers argue for sandboxes, scoped credentials, and policy engines ahead of the approve button.

AI agents
security
developer tools
engineering
TLS for a Bare IP: What Let's Encrypt's Free IP-Address Certificates Change for Self-Hosted Deploys
·Dora Noda·10 min

TLS for a Bare IP: What Let's Encrypt's Free IP-Address Certificates Change for Self-Hosted Deploys

Let's Encrypt's free IP-address certificates went generally available in January 2026: six-day, ACME-automated TLS for a bare IPv4 or IPv6 address. Where they fit in a self-hosted PaaS — node bootstrap before DNS, fallback vhosts, IP-addressed infrastructure — the exact recipe for getting one, and the limits that keep tenant traffic on real domains.

self-hosting
security
infrastructure
engineering
10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools
·Dora Noda·12 min

10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools

Pinterest runs 66,000+ MCP tool calls a month through domain-specific servers behind a central registry. How the registry-plus-fleet pattern solves discovery and access control — and what it means for the deploy tools agents drive.

Model Context Protocol
AI agents
engineering
infrastructure
+1
MCP Streamable HTTP in Production: When Stateless Tool Calls Scale Cleanly and When a Deploy Agent Needs Session Affinity
·Dora Noda·10 min

MCP Streamable HTTP in Production: When Stateless Tool Calls Scale Cleanly and When a Deploy Agent Needs Session Affinity

AWS's FastMCP-on-ECS reference runs MCP servers stateless so any replica can answer any tool call, and the July 2026 spec revision deleted protocol-level sessions entirely. Here is that verdict mapped onto a deploy/rollback agent: which tools stay stateless, where multi-step state lives instead, and how idempotency keys keep privileged infrastructure actions safe across retries.

Model Context Protocol
AI agents
self-hosting
engineering
MCP Tasks and Multi-Round Trips: The Durable Deploy Contract an Agent-Operated PaaS Needs
·Dora Noda·11 min

MCP Tasks and Multi-Round Trips: The Durable Deploy Contract an Agent-Operated PaaS Needs

MCP's July 2026 spec adds asynchronous Tasks and Multi-Round Trip Requests. Together they form a durable deploy state machine: task handles instead of blocked calls, an approval boundary before production promotion, safe retry, cooperative cancel, and rollback as a first-class task.

PaaS
AI agents
Model Context Protocol
self-hosting
+1
The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch
·Dora Noda·9 min

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch

Moltbook leaked 1.5 million agent API tokens within 72 hours of an all-AI-coded launch because Row Level Security was never enabled. A concrete failure-chain postmortem plus the secure-by-default provisioning contract every agent-facing platform should enforce.

AI agents
cybersecurity
engineering
PaaS
When Railpack Detects Wrong: What an Angular SSR App Served as a Static Caddy Site Teaches About Builder Autodetect
·Dora Noda·8 min

When Railpack Detects Wrong: What an Angular SSR App Served as a Static Caddy Site Teaches About Builder Autodetect

Railway's Railpack builder classified an Angular SSR app as a static site and served it through Caddy — a green deploy of the wrong architecture. The before-and-after Dockerfile fix, why fail-open autodetect keeps causing outages, and the five detect-time log lines a self-hosted PaaS should emit.

self-hosting
PaaS
developer tools
engineering
Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.
·Dora Noda·11 min

Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.

Refuse is an open-source, self-hostable gate that blocks known-vulnerable package installs across 18 package managers before anything hits disk — including installs your coding agent runs. Here is how it works, where it belongs in a PaaS build pipeline, and what it cannot catch.

security
PaaS
self-hosting
AI agents
+1
Showing 64–72 of 368 posts