Skip to main content

266 posts tagged with "Model Context Protocol"

Content about the Model Context Protocol (MCP)

View all tags

Read the AI agents and MCP guide

Dokploy Has an MCP Server Too — and It's Bigger Than Coolify's: An AI-Agent Operator's Comparison on a $5 Hetzner Box
·Dora Noda·9 min

Dokploy Has an MCP Server Too — and It's Bigger Than Coolify's: An AI-Agent Operator's Comparison on a $5 Hetzner Box

Dokploy's official MCP server gives AI agents full deploy and lifecycle control while Coolify's built-in MCP is read-only — here is what each agent interface can actually do, and what each control plane costs in idle RAM on a $5 Hetzner box.

PaaS
self-hosting
AI agents
Model Context Protocol
+1
Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway
·Dora Noda·10 min

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway

Hand-writing an MCP server means maintaining a second governed interface. What projecting your REST API through a gateway gives you for free — OpenAPI-derived tools, OAuth 2.1 auth, rate limits — and the write-scoping, approval, and rollback semantics a deploy API still has to build itself.

Model Context Protocol
AI agents
API
security
E2B Is Now Native in OpenAI's Agents SDK: The Bar a Self-Hosted Agent Sandbox Has to Clear
·Dora Noda·10 min

E2B Is Now Native in OpenAI's Agents SDK: The Bar a Self-Hosted Agent Sandbox Has to Clear

OpenAI's Agents SDK declares E2B sandboxes natively since April 2026. This post turns that integration into a six-part checklist — cold start, isolation, templates, lifecycle, MCP sandboxing, egress policy — and scores four self-hosted paths against it.

AI agents
self-hosting
openai
Model Context Protocol
+1
Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production
·Dora Noda·12 min

Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production

An MCP server that can redeploy production is a deploy pipeline with natural-language input. A seven-control hardening checklist — TLS, per-tool scopes, short-lived credentials, schema validation, rate limits, and audit logging — mapped to the three attacks that actually happen.

Model Context Protocol
AI agents
security
infrastructure
+1
MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish
·Dora Noda·10 min

MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish

The final MCP spec deprecates Dynamic Client Registration in favor of Client ID Metadata Documents, with removal eligible after July 2027. Here is the ordered checklist for migrating a self-hosted MCP server, plus the two companion hardenings to ship in the same window.

Model Context Protocol
AI agents
security
self-hosting
Deploy Agents That Wait: Building a Stateless Rollout-and-Approval Agent on MCP Tasks and Multi Round-Trip Requests
·Dora Noda·10 min

Deploy Agents That Wait: Building a Stateless Rollout-and-Approval Agent on MCP Tasks and Multi Round-Trip Requests

MCP's July 2026 release made the protocol stateless and gave agent builders Tasks and Multi Round-Trip Requests. Here is the concrete design for a deploy agent that returns a task handle, polls rollout status against Kubernetes Deployment conditions, and stops for an expiring human approval before promoting to production.

Model Context Protocol
AI agents
Kubernetes
engineering
One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server
·Dora Noda·11 min

One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server

nginx-ui shipped an MCP endpoint without its AuthRequired check — a CVSS 9.8 that left roughly 2,689 servers open to unauthenticated takeover. The full MCPwn timeline, the two-route bug, and a seven-item audit checklist for anyone shipping an MCP server.

security
Model Context Protocol
self-hosting
AI agents
Cloudflare Deprecated McpAgent: What a Stateless MCP Handler Buys (and Costs) a Deploy-From-Chat Server
·Dora Noda·12 min

Cloudflare Deprecated McpAgent: What a Stateless MCP Handler Buys (and Costs) a Deploy-From-Chat Server

Cloudflare's Agents SDK v0.20.0 deprecated McpAgent in favor of a stateless createMcpHandler, tracking MCP spec 2026-07-28. Here is what dropping the per-session Durable Object buys, where multi-step deploy state moves instead, and how to migrate without breaking older clients.

AI agents
Model Context Protocol
self-hosting
PaaS
Falco's Prempti Is a Policy Layer for AI Coding Agents, Not Kernel Security: What It Catches and Misses
·Dora Noda·13 min

Falco's Prempti Is a Policy Layer for AI Coding Agents, Not Kernel Security: What It Catches and Misses

Falco's Prempti judges an AI coding agent's tool calls before they execute — but it never sees a syscall. A scenario-by-scenario map of what hook-level policy, eBPF monitoring, and microVM sandboxes each catch and miss on the deploy-from-chat path.

cybersecurity
AI agents
Model Context Protocol
self-hosting
Showing 145–153 of 266 posts