
AWS Now Runs an ACME Server: Why Your Self-Hosted cert-manager Never Needed It
AWS Certificate Manager now speaks ACME, issuing 45-day certificates with IAM governance and per-domain pricing. Here is how it compares to running cert-manager against Let's Encrypt directly, and the renewal-margin checklist short-lived certificates actually demand.

Mimir vs Cortex vs Thanos: Picking the Multi-Tenant Metrics Backend for a PaaS That Bills by Usage
Mimir, Cortex, and Thanos compared as the multi-tenant metrics backend for a self-hosted PaaS that bills by usage — per-tenant cardinality isolation, cost attribution for chargeback, and owned-capacity footprint, with a decision table.

ARC 0.14.0: Ephemeral Tenant CI on Your Own Fleet, Without the Scale-Set Sprawl
ARC 0.14.0 adds multilabel runner scale sets, stale-config protection, and a standalone Go client — a walkthrough of running ephemeral per-job tenant CI on a Cluster-API fleet, from Helm install to listener scheduling.

Your Registry Is a Trust Root: What the JFrog Artifactory Breach Campaign Teaches Self-Hosters
Attackers chained three Artifactory flaws into full admin takeover of self-hosted registries — then planted backdoors that survive patching. The timeline, the kill chain, and a 7-item hardening checklist for your own OCI store.

Kubernetes 1.37 Locks In On-Demand PLEG Relist: What Cost-Sized Nodes Actually Save
Kubernetes 1.37 graduates PLEG on-demand relist to GA, cutting pod-create observation from 1.8s to 1.1s with no opt-out. What the locked-on change saves cost-sized node pools, and a six-step checklist to verify it during your upgrade.

Railway Won the Default for Small Projects in 2026 — Here Are the Edge Cases That Push Growing Teams Off It
Railway won the small-project default with metered pricing, the fastest deploys, and a $5 trial. This inventory names the five edge cases that push growing teams off it — always-on billing, preview costs, ephemeral storage, containerized Postgres, per-seat teams — and works the bill-size threshold where a fixed box wins.

Render Cut Median Builds 40% to 21 Seconds — Can Owned Hardware Match It?
Render cut median service builds from 38 to 21 seconds on faster build nodes. This guide splits the headline into cold/warm and queue/execution cells, cites published 12–15 second warm builds on persistent builders, and prices an owned Hetzner build pool at €97.30/month — with the exact protocol to verify every cell.

30MB vs 800MB: What Rivetr's Single-Binary PaaS Teaches About the Self-Hosted Control-Plane Floor
Rivetr runs a complete self-hosted PaaS control plane in ~30MB of RAM against Coolify's ~800MB stack: an apples-to-apples teardown of what the gap measures, where the 30MB floor comes from, and why footprint is the tiebreaker and fleet lifecycle the decision.

Kubernetes 1.36 Schedules Whole Workloads, Not Pods: Bin-Packing Tenant Apps on Fixed Hardware
Kubernetes 1.36's PodGroup scheduling cycle binds whole workload gangs atomically, but tenant Deployments see almost no change yet. A worked 3-node scenario shows what moves, what doesn't, and where Kueue still wins.