
Skupper vs Submariner vs Istio Ambient: Picking the Cross-Cluster Link for a Hetzner-Split Fleet
Submariner merges networks, Skupper links services, and Istio's ambient multicluster — beta since KubeCon EU 2026 — merges meshes. A concrete comparison of what each demands of a Cluster API fleet split across Hetzner regions, and which layer a git-push PaaS should own for tenant traffic.

Velero Is a CNCF Project Now: What That Buys Your Self-Hosted Disaster-Recovery Story
Broadcom donated Velero to the CNCF Sandbox at KubeCon EU 2026, ending three years of single-vendor risk on Kubernetes' default backup tool. Here is what neutral governance changes and the concrete DR blueprint for a fleet you own — S3-compatible storage, nightly schedules, and the Cluster API restore drill.

One Shared Quota Took Down Every Connector: What a 402 on MCP Initialize Teaches About Self-Hosting Agent Tools
On September 9, 2026, one exhausted shared quota answered MCP initialize with HTTP 402 and took every OptimNow connector down at once. The 14-file move to Fly.io scale-to-zero is a complete template for self-hosting production agent tools — here is the incident anatomy and the checklist.

Two PaaS Freezes, One Exit Plan: Where App Runner and Heroku Workloads Go Next
AWS closed App Runner to new customers and Heroku froze its roadmap twelve weeks apart — this side-by-side maps each stranded workload to its landing zone and lays out the ordered exit checklist, from portable builds to cutover with rollback.

Zero-CVE Buildpacks Are Here: What BellSoft's Hardened Paketo Builder Means for a Git-Push PaaS
BellSoft's hardened Paketo builder promises zero-CVE images, 24-hour patching, signed builds, and automatic SBOMs with no workflow change. Here is what a git-push PaaS actually gains, what stays its problem, and how to evaluate the swap in an afternoon.

Heroku's Data Layer Is the Hard Part of the Exit
Every Heroku exit guide prices the $50 dynos and waves at the add-ons — but sustaining mode froze the platform, not the Postgres EOL treadmill. A data-first playbook: what the freeze means for Postgres, Redis, and Kafka, size-tiered migration mechanics, and where the state lands.

Still on Heroku? A Stay-or-Leave Framework for the Long Tail, From $5 Eco Dynos to $250 Performance-M
Salesforce gave Heroku no end-of-life date — only a sustaining-mode freeze. A cohort-by-cohort stay-or-leave framework from $5 Eco dynos to $250 Performance-M, keyed on dyno count, Postgres entanglement, and ops capacity.

Kubernetes v1.37 Node Lifecycle Conditions: Machine-Readable Node State for Agent-Driven Fleet Ops
Kubernetes v1.37 adds five Node Lifecycle Conditions — DrainInProgress, Drained, MaintenancePlanned, MaintenanceInProgress, and GracefulNodeShutdownInProgress — so nodes report intent, not just readiness. Here is who should publish each one on a Cluster API fleet, how to rewrite NotReady paging, and the agent policy that turns machine-readable state into safe machine operators.

Your Fleet Patches Weekly but Reboots Never: Kured Closes the Stale-Kernel Gap
Unattended upgrades patch the disk, but the running kernel stays old until something reboots the node. Kured automates the cordon-drain-reboot cycle one node at a time — here is the runbook it replaces and the four guardrails (MHC timeouts, PDBs, drain timeouts, alert gates) that make it safe on multi-tenant CAPI fleets.