
Green Status Page, Broken Deploy: What Two July 2026 Vercel Incidents Teach About Scoped Failures in Multi-Tenant PaaS
Vercel's July 2026 status history holds two scoped failures — four hours of Hobby-only invocation errors and a six-minute telemetry gap disclosed the next day — with two more recurrences that quarter. What they share structurally, and four incident-communication guarantees a multi-tenant deploy platform should build instead.

Delete Your Validating Webhook: What Kubernetes 1.36 Declarative Validation GA Actually Means for PaaS Operators
Kubernetes 1.36 graduated declarative validation to GA — but CRD CEL rules shipped in 1.29. What each milestone means for platforms defining App and Tenant CRDs, with a before/after webhook deletion guide.

Your Queue Is Retrying Itself Slow: What OpenFaaS Adaptive Concurrency Fixes About Async Batch Work on Kubernetes
OpenFaaS's April 2026 queue-worker update replaces greedy async dispatch with a feedback loop that learns each function's capacity — clearing the same batch about 50% faster with far fewer 429 retries. How it works, what it costs, and whether a git-push PaaS should host functions or just containers.

GitHub Cut Hosted-Runner Prices 39%. Here Is the New Breakeven for Owning Your CI Runners
GitHub cut hosted-runner prices up to 39% in January 2026 while a proposed per-minute charge on self-hosted runners was shelved. Pricing both sides of CI — hosted meter versus an owned box running Tekton — puts the breakeven near 3,000 metered minutes a month.

Heroku Fir Doesn't Take Docker: The Migration Audit for Teams Stranded Between Cedar and Fir
Heroku's Fir generation doesn't support Docker deploys and Cedar is frozen under sustaining engineering. A five-point audit for heroku.yml teams: what breaks, where container workloads go, and the real bill delta.

Grafana OnCall Is Dead. Here Is the $0 Paging Stack for a Two-Person Platform
Grafana archived OnCall OSS in March 2026 and PagerDuty pricing assumes a rota you don't have. A concrete free paging stack for tiny platform teams: Uptime Kuma probing from outside, Alertmanager routing by severity, self-hosted ntfy buzzing your phone, and a dead-man's-switch heartbeat so the monitor can't die silently.

Every Pull Request Gets a Live URL: What Preview Environments Really Cost a Git-Push PaaS to Build
Per-PR preview URLs became baseline CI/CD hygiene in 2026. Here is what separates a manual branch deploy from an automatic open-comment-teardown lifecycle: a worked cost model, a database decision table, and a six-step build checklist for git-push platforms.

Ten Platforms, One Accidental Contract: The PORT-and-Start-Script Standard Behind Every Git-Push Deploy
Cedar.js set out to fix Railway deploys and found ten platforms sharing one accidental contract: a build script, a start script, PORT, and dual-stack binding. The full convention, the three-tier platform matrix, and the five ways it silently breaks.

Your Buildpack Already Wrote the SBOM — Your Cluster Just Isn't Reading It
Cloud Native Buildpacks already emit a per-layer SBOM with every image, but most fleets never enforce it. Attaching that SBOM as a signed Sigstore attestation and verifying it with an admission controller turns scan-after-deploy into a deny decision before an unapproved image ever shares a node with other tenants.