blog

Blog — page 14 of 38

·10 min read

One microVM Per Sync Run: Isolating SCIM Connectors

To sell upmarket you have to sync users from every customer's Okta, Entra ID, Workspace and LDAP — which means holding hundreds of long-lived identity-provider credentials in one process. Here is what it looks like when each sync run gets its own microVM instead.

scimidentitymulti-tenancy
Ajay Kumar
·10 min read

Your Free Tier Is a Mining Pool: Stopping Cryptomining Abuse

The day you offer strangers free compute with a shell, you have opened a very generous mining pool. The miners will find it before your first paying customer does — here is what actually stops them.

securityabuse-preventioncryptomining
Ajay Kumar
·11 min read

userfaultfd in Production: How the Pager Fails

With userfaultfd you have volunteered to be the pager for someone else's kernel. When you stop answering, nothing returns an error — you get a guest that is alive, scheduled, and permanently stopped mid-instruction.

userfaultfdfirecrackerreliability
Ajay Kumar
·11 min read

Sparse Files and Hole Punching: Why Your Snapshot Lies About Its Size

A Firecracker memory snapshot for a 4 GiB guest is a 4 GiB file that may be occupying a small fraction of that on disk. That gap is one of the most useful facts about snapshot storage — and one of the easiest to destroy by accident with a single cp.

firecrackersparse-filessnapshots
Ajay Kumar
·10 min read

MAP_PRIVATE vs MAP_SHARED: The mmap Flag That Decides Everything

One flag in one syscall decides whether your writes are invisible scratch, visible to every other process, or durable on disk. Here's what MAP_PRIVATE and MAP_SHARED actually do to a page, why VMMs, databases and caches pick opposite sides, and the traps — SIGBUS on truncate, msync that does nothing, and RSS numbers that lie.

mmaplinux-kernelcopy-on-write
Ajay Kumar
·10 min read

Mount namespaces and pivot_root, explained for sandboxing: how filesystem isolation really works

A mount namespace gives a process its own copy of the mount table, and pivot_root replaces its root so there is nothing left to escape to. Both are excellent. Neither one gives the code a different kernel.

mount-namespacespivot-rootlinux-kernel
Ajay Kumar
·11 min read

How to give a Google ADK agent a code execution tool

In ADK a tool is a Python function and its docstring is the prompt. The hard part isn't the wiring — it's deciding how long the sandbox lives and what you hand back to the model.

google-adkpythonai-agents
Ajay Kumar
·11 min read

Best Temporal Hosting Platforms in 2026

Everyone shops for a place to run the Temporal cluster. The part that actually decides your architecture is where the workers live — long-lived pollers that must not be killed mid-activity.

temporalworkflow-enginedeployment
Ajay Kumar
·11 min read

Every Listing Is a Stranger's Agent: Isolating a Marketplace

You launched an agent marketplace. Every listing is code a stranger wrote, driven by a model, calling tools you didn't write, against your customers' credentials. Here's the isolation shape that survives that.

securityai-agentsmarketplace
Ajay Kumar
·10 min read

Hostile and Precious: Per-Case microVMs for Forensics and E-Discovery

The PST you have to open is full of the malware that caused the incident, and you are also legally obligated not to change a single byte of it. One VM per matter is the shape that satisfies both.

securityforensicse-discovery
Ajay Kumar
·9 min read

One Demo per Prospect: Sales Environments You Can Throw Away

Two AEs demo at the same time and one of them watches their data change live on the call. The fix is structural: bake one golden demo — app plus seeded database — and fork it per prospect, so "give me a clean environment" is a button and not a ticket.

demo-environmentssales-engineeringmicrovm
Ajay Kumar
·11 min read

Run the PoC: Vulnerability Triage in Disposable microVMs

A bug bounty report is a stranger's script plus a claim, and the only way to check the claim is to run the script — against a system you have deliberately made vulnerable. Here is the per-report microVM shape that makes that a routine Tuesday instead of an incident.

securityvulnerability-managementbug-bounty
Ajay Kumar
·11 min read

Your Firecracker Snapshot Restore Failed: A Field Guide

A restore either works in tens of milliseconds or fails with an error that tells you almost nothing. Here are the seven classes of Firecracker snapshot restore failure, what each looks like, and how to bisect your way to the real cause.

firecrackersnapshotsdebugging
Ajay Kumar
·10 min read

You Ship the Kernel: Firecracker Guest 5.10 vs 6.1

In a microVM, the guest kernel is a build artifact of your platform, not something a distro picks for you. Here's the honest 5.10 vs 6.1 trade — and the snapshot re-bake nobody budgets for.

firecrackermicrovmlinux-kernel
Ajay Kumar
·10 min read

Should You Compress Firecracker Memory Snapshots?

Compression looks like free money when your snapshot bucket is measured in terabytes. Then you discover that a compressed stream has no byte N — and your lazy 49ms restore turns into reading four gigabytes you were never going to touch.

firecrackersnapshotscompression
Ajay Kumar
·10 min read

Best n8n Hosting Platforms in 2026: A Self-Hoster's Guide

You've decided to self-host n8n. Now you have to pick infrastructure for a stateful, always-on, long-running service that also happens to execute arbitrary JavaScript for a living.

n8nself-hostingautomation
Ajay Kumar
·11 min read

Best LangGraph Deployment Platforms in 2026

Your graph works in the notebook. Now it has to survive a deploy, a crash, and a human who takes three days to approve step 7. Here are the requirements that eliminate most platforms, and the seven that are left.

langgraphai-agentsdeployment
Ajay Kumar
·10 min read

Firecracker vs Proxmox: a VMM Is Not a Platform

Proxmox VE manages VMs. Firecracker runs one. The comparison is a layer mismatch — but the question underneath it is real, and the answer usually comes down to whether your guests are pets or cattle.

firecrackerproxmoxvirtualization
Ajay Kumar
·10 min read

The best Strapi hosting platforms in 2026

Strapi is four hosting problems in a trenchcoat: a long-running Node server, a real database, an uploads directory that must survive deploys, and an admin panel rebuilt at deploy time. Skip any one and it breaks in a specific, predictable way.

strapicmshosting
Ajay Kumar
·10 min read

The best MCP server hosting platforms in 2026

A remote MCP server is not a REST API with a different schema. It holds session state, streams server-to-client messages over a connection that stays open, and runs tool calls that some model decided on. Most hosting advice ignores all three.

mcphostingai-agents
Ajay Kumar
·9 min read

The best Discord bot hosting platforms in 2026

A Discord bot is the clearest example of a workload serverless cannot host. It holds a WebSocket open indefinitely, has three seconds to acknowledge an interaction, and must not miss events while asleep. Here is what that means for where you run it.

discordbotshosting
Ajay Kumar
·10 min read

The best Vercel Postgres alternatives in 2026

Vercel Postgres was never really Vercel's database — it was Neon with Vercel's billing on top, and it has since become a marketplace integration. If you are re-choosing anyway, choose on the things that are hard to change later.

postgresdatabasesvercel
Ajay Kumar
·10 min read

The best Cloudflare Containers alternatives in 2026

Cloudflare Containers exist because Workers cannot run ffmpeg. They are a good answer to that, with an unusual shape: no public ingress, a Durable Object as the control plane, and sizes chosen from a short list. Here is when to look elsewhere.

cloudflarecontainersalternatives
Ajay Kumar
·10 min read

The best Morph Cloud alternatives in 2026

Morph Cloud is built around one idea: snapshot a running VM and branch it instantly, so an agent can explore several futures from the same state. Most sandbox platforms do not have that primitive at all, which makes this a narrower comparison than it looks.

ai-agentssandboxesalternatives
Ajay Kumar