blog

Blog — page 13 of 38

·9 min read

How to run Puppeteer in a sandbox

Puppeteer in production fails in a small number of very repeatable ways — a missing shared library, a shared memory limit, and a browser process nobody killed. An isolated VM per session removes most of them.

how-topuppeteerbrowser-automation
Ajay Kumar
·8 min read

How to deploy an Astro site without Docker

Astro's output changes shape depending on whether you added an adapter. Nearly every confusing Astro deployment comes from that one fact — here is how to work out which you have.

how-toastrodeploys
Ajay Kumar
·10 min read

Running a 2009 app in 2026: legacy workloads in microVMs

Containerising a genuinely old application is where modernisation projects go to die, because a container shares the host kernel and a container image never pins one. A microVM boots its own. Here is the practical shape: rescue, isolate, snapshot, then strangle.

legacy-modernizationmicrovmcontainers
Ajay Kumar
·10 min read

On-prem without regrets: shipping your product as a microVM

The bank has the budget and the bank will not send you its data. So you ship your software into their datacentre instead, where you are the untrusted party and they are the untrusted party, and nobody gets a shell. A microVM image is a surprisingly good answer to both halves of that.

on-premiseair-gappedenterprise
Ajay Kumar
·11 min read

One microVM per DSAR: exporting a person's data without leaking someone else's

A data-subject access request is the one job in your estate that deliberately builds a complete dossier on a single human being and then emails a link to it. Here is why that job should get its own machine, and why that machine should stop existing when the archive is sealed.

gdprcomplianceprivacy
Ajay Kumar
·11 min read

Scheduling sandbox bursts: why 50 creates land on one host

Fifty creates arrive in 200ms. Every one of them reads the same cached capacity snapshot, computes the same winner, and lands on the same host. The scheduler did exactly what it was told and produced exactly the outcome it exists to prevent.

schedulingdistributed-systemsmicrovm
Ajay Kumar
·10 min read

eBPF for sandbox observability: what it can and cannot see

eBPF observes the kernel it is loaded into. That one sentence decides everything else: why a host probe sees every container's execve in full colour, why it sees none of a microVM's, and why the boundary that blinds you is the same boundary that protects you.

ebpfobservabilitymicrovm
Ajay Kumar
·10 min read

PandaStack vs Azure Container Apps: an honest head-to-head

These two products look adjacent and are actually answering different questions. Azure Container Apps is a superb way to run your own microservices inside an Azure estate. PandaStack is a way to run somebody else's code without lying to yourself about the boundary. Here is the honest split.

comparisonazure-container-appsmicrovm
Ajay Kumar
·9 min read

How to give an Agno agent a code execution tool

In Agno a tool is a plain Python function with a docstring, which makes the code-execution tool ten lines long and easy to get catastrophically wrong. Here is the version that survives production.

agnopythonai-agents
Ajay Kumar
·9 min read

How to Give a Semantic Kernel Agent a Code Execution Tool

Semantic Kernel agents usually run inside an app that already holds a managed identity, a Graph token and a database pool. A code-execution plugin inherits every bit of that. Here is the plugin shape that does not.

how-tosemantic-kernelai-agents
Ajay Kumar
·11 min read

How to Give a DSPy Program a Code Execution Sandbox

In a single run, exec() is a risk you took. During a DSPy compile it is a service you are operating — thousands of model-written programs, many generated from prompts the optimiser invented specifically because you would not have written them.

dspyhow-toai-agents
Ajay Kumar
·11 min read

Best Apache Airflow Hosting Platforms in 2026

Everyone shops for a managed Airflow control plane. The decisions that actually bite are the metadata database you under-provisioned and the shared worker where every DAG author's dependencies fight.

airflowdata-engineeringcomparison
Ajay Kumar
·10 min read

Best Judge0 Alternatives (2026): Code Execution APIs Compared

Judge0 is still the default answer for 'run this submission and give me stdout.' Here is when it stops being the right answer, and what the honest alternatives are — Piston, Sphere Engine, E2B, PandaStack, and rolling your own.

comparisonjudge0code-execution
Ajay Kumar
·10 min read

Best Flask Hosting Platforms (2026)

Flask is easy to write and surprisingly easy to deploy badly. A practical comparison of where to host it in 2026 — with the gunicorn, worker-count, and background-job questions that actually bite.

comparisonflaskpython
Ajay Kumar
·10 min read

Best Gradio Hosting Platforms (2026)

Gradio makes the demo trivial and the hosting decision surprisingly loaded. A practical comparison — including the honest question of whether you need a GPU at all.

comparisongradiopython
Ajay Kumar
·10 min read

Best Dokploy Alternatives (2026): Self-Hosted PaaS Compared

Dokploy makes a VPS feel like Heroku. Here is when that stops being enough — multi-tenancy, isolation, upgrade risk — and what the honest alternatives look like.

comparisondokployself-hosted
Ajay Kumar
·10 min read

Best Cloudflare D1 Alternatives (2026)

D1 is excellent until you hit a limit that is structural rather than a quota. Here is how to tell which wall you have hit, and which alternative actually solves it.

comparisoncloudflare-d1database
Ajay Kumar
·9 min read

How to Give an AutoGen Agent a Code Execution Tool

AutoGen ships local and Docker code executors. Here is how to give your agents a real VM boundary instead — and the shared-state decision that quietly breaks multi-agent teams.

how-toautogenai-agents
Ajay Kumar
·9 min read

How to Give a smolagents Agent a Code Execution Sandbox

In smolagents, every agent action is Python. That makes the code executor the single most important security decision in the whole framework — here is how to get it right.

how-tosmolagentsai-agents
Ajay Kumar
·9 min read

How to Generate a Typed API Client From an OpenAPI Spec

Hand-written HTTP wrappers rot. Here is how to generate a typed client from an OpenAPI spec instead, and the three places generators reliably fall over.

how-toopenapiapi
Ajay Kumar
·9 min read

How to Receive Webhooks for Deploys and Quota Events

Polling an API every thirty seconds to find out whether a deploy finished is a habit worth breaking. Here is the webhook version, including signature verification done right.

how-towebhooksapi
Ajay Kumar
·8 min read

How to Expose a Sandbox Port on a Public URL

Your agent just started a dev server inside a VM. Getting a link to it is one line — but the URL is a capability, and that is worth understanding before you paste it into Slack.

how-tosandboxpreview-urls
Ajay Kumar
·10 min read

One microVM per Terraform run: isolating IaC per tenant

A Terraform runner downloads third-party Go binaries and executes them with a customer's cloud credentials in its environment. If you run every tenant's HCL in one shared pod, you have built a credential blender. Here is the per-run microVM shape instead.

terraformmulti-tenancyinfrastructure-as-code
Ajay Kumar
·10 min read

Your Backup Is a Hypothesis: DR Drills in Disposable microVMs

Almost nobody tests their restore path, because testing it properly means restoring production data somewhere real — and the available venues are production itself and a staging environment that drifted two years ago. Here is a third one.

disaster-recoverypostgresbackups
Ajay Kumar