509 posts tagged with "Kubernetes"
Container orchestration, Cluster API, and self-hosted control planes

Karmada Just Graduated: What Multi-Cluster Kubernetes Maturity Means for Your Single-Region Fleet
Karmada graduated from the CNCF on September 8, 2026, with v1.19's AI-training scheduling in tow. For a Hetzner-only Cluster API fleet, the move is to borrow its propagation and failover patterns now and adopt the control plane when a second region arrives.

kube-hetzner vs CAPH: What Your First Hetzner Provisioning Choice Costs by the Second Cluster
Terraform or Cluster API for Hetzner Kubernetes? A day-2 comparison of kube-hetzner and CAPH across upgrades, node replacement, and the June 2026 server-type churn — and exactly where the answer flips.

Node Lifecycle Conditions Land as Alpha in v1.37: The Machine-Readable Node Health Vocabulary Your Agent Operator Has Been Waiting For
Kubernetes v1.37 reserves five well-known Node conditions for drains, maintenance, and graceful shutdown. No core controller reads them yet — but for agent operators, a stable machine-readable vocabulary is the prerequisite, and self-hosted fleets can start publishing today.

Northflank BYOC vs Owning Hetzner Boxes: What Bring-Your-Own-Cloud Actually Saves
The same API-plus-Postgres stack priced five ways: Render, Railway, Northflank managed, Northflank BYOC on AWS, and a Hetzner box under Cluster API — plus the sensitivity analysis that decides which one is actually cheapest for your workload.

Ownkube's Named AI Agents Run Your Ops — but the AWS Bill Is Still Yours
Ownkube pairs a Heroku-style deploy UX with named AI agents for cost, incident, scaling, and security — but its Production shape still runs on EKS. A worked 8-vCPU comparison puts the AWS route at $460–510 a month against €60–90 on owned hardware.

Railway's Guardrails, Rebuilt in Kubernetes: Two Admission Policies That Keep Internal Services Off the Public Internet
Railway's April 2026 Guardrails stop non-admins from exposing internal services via public domains or TCP proxies. Here is how to enforce the same two policies on a self-hosted Kubernetes platform with ValidatingAdmissionPolicy and Kyverno.

Render Gave Every Service a Deploys Page: The Minimum Deploy Visibility Your Self-Hosted Dashboard Owes You
Render's September 2026 Deploys page gives every service uncapped deploy history, a Live badge, and rollout status. How kubectl, ArgoCD, Coolify, and Dokploy score against that bar, and the five-item visibility spec a self-hosted fleet dashboard must meet.

Authorizer Puts Agents on the Org Chart: A2A Token Exchange, OAuth-2.1 MCP, and Secretless Kubernetes Identity
Authorizer 2.4 gives AI agents first-class identities: RFC 8693 delegation with nested actor chains, an MCP server behind OAuth 2.1 with audience-bound tokens, and secretless Kubernetes workload auth — a credential model where agents hold scoped delegations instead of god-keys.

Contabo vs Hetzner, September 2026: Where Should a Self-Hosted Fleet Rent Its Boxes?
After Hetzner's June 2026 price hike, Contabo ships double the RAM per euro while Hetzner keeps hourly billing and steadier cores. A role-by-role fleet placement with worked monthly totals for control planes, elastic workers, and APAC edge nodes.