Blog — page 16 of 38
The best Aiven alternatives in 2026
Most teams land on Aiven for managed Postgres and end up paying for a multi-service data platform they use a tenth of. Here's how the alternatives actually differ.
The best Hono hosting platforms in 2026
Hono's selling point is that the same routes run on five runtimes. That makes it unusually easy to host and unusually easy to pick the wrong target.
The best Angular hosting platforms in 2026
Half the Angular deploy problems people hit come from treating an SSR build like a static one. Check what your build actually emits, then pick the host.
The best Koyeb alternatives in 2026
Koyeb sits in a crowded middle: nicer than raw Kubernetes, more infrastructure-shaped than Vercel. Here's how the neighbours differ on the things that actually bite.
How to add pgvector to a Postgres database
Adding pgvector is one statement. Getting queries to use the index — and getting the distance operator to match how the index was built — is where people lose an afternoon.
How to tail logs and debug a running app
"Check the logs" is unhelpful advice when there are three kinds. Here's how to tell which one holds the answer, before you start guessing.
How to add OpenTelemetry tracing to a deployed app
Tracing answers the question logs can't: where did the 3 seconds go? Here's the shortest path from a running app to a trace you can read.
How to give a LlamaIndex agent a code execution tool
LlamaIndex agents are great at retrieval and bad at arithmetic. A code tool fixes that, and the interesting part is what you hand back to the model.
How to give a Pydantic AI agent a code execution tool
Pydantic AI's dependency injection is the right place to put a sandbox. Here's the tool, the lifecycle, and how ModelRetry turns errors into progress.
How to use Prisma with a managed Postgres database
Prisma with managed Postgres works perfectly until you put a pooler in front of it. Here's the configuration that avoids every version of that afternoon.
From Prompt Injection to RCE: The Agent Tool-Call Attack Chain
Prompt injection isn't a chatbot party trick. Give the agent a shell tool and injected text becomes a command running with your service account's credentials. Here's the chain, link by link, and the defenses ranked by what they actually buy you.
node:vm Is Not a Sandbox (And Neither Was vm2)
vm.runInNewContext looks like a sandbox, is named like a sandbox, and is documented as not being one. Here's what it actually gives you, why the escape class is structural rather than a bug, and what boundary to reach for instead.
Shrinking PCI DSS Scope With Per-Transaction microVMs
Scope is the cost function of PCI DSS, and a shared kernel turns your segmentation boundary into a twenty-page argument that one config change invalidates. Here is the per-transaction microVM shape — and an honest list of what it does not buy you.
Honeypots on microVMs: a machine you expect to lose
A high-interaction honeypot is, by definition, a machine you expect an attacker to root. Putting one on a kernel you share with anything else is a strange decision to make on purpose.
Customer-Authored dbt Runs, One microVM Per Tenant
A dbt project looks like SQL and YAML. It is Jinja macros, run-operation, hooks, and packages fetched from wherever — all executing on your worker, against whatever connection profiles.yml hands them.
KSM Memory Deduplication for MicroVMs — And Why It's a Trap
Eighty microVMs running the same kernel and the same libc, and the host is storing eighty copies. KSM will merge them — for a permanent CPU tax, a merge that evaporates on first write, and a timing oracle across tenant boundaries. Here's how ksmd actually works, and why sharing at the snapshot layer beats scanning for duplicates you should never have made.
overlayfs Inside the Guest: Read-Only Rootfs, Writable Upper Layer
Mount the template read-only, stack a writable layer on top, let the kernel merge them: overlayfs is three lines of mount options and a surprising number of sharp edges. Whole-file copy_up, whiteouts, metacopy, inode weirdness — and why PandaStack does its copy-on-write below the guest instead.
Runloop vs E2B: Choosing a Sandbox for Coding Agents
Runloop and E2B are both credible places to put a coding agent, but they're built around different units of work — a repo-shaped devbox versus a general-purpose execution sandbox. A fair head-to-head.
The best Elixir and Phoenix hosting platforms in 2026
Phoenix is not a request-response app that happens to use a different language. It is a long-lived BEAM node holding thousands of open sockets, a supervision tree that assumes it will still be alive in an hour, and sometimes a cluster. Platforms differ mostly in how many of those they treat as normal.
The best Nuxt hosting platforms in 2026
Nuxt doesn't have one deploy target, it has a build system that changes shape depending on a single config value. Pick the wrong Nitro preset and your app fails in ways that have nothing to do with your code.
How to connect to Postgres with a connection pooler
Postgres gives every connection its own process. Serverless gives every request its own connection. That arithmetic is why your database is refusing connections at 2pm.
How to restore a Postgres database to a point in time
Someone ran an UPDATE without a WHERE clause. The rule for the next ten minutes: do not restore first. Clone first, look, then decide.
How to manage environment variables and secrets
Every team leaks a secret the same way: someone needed the staging key on their laptop, so it went in a Slack DM. Here's the setup that removes the reason.
How to run database migrations on every deploy
During a zero-downtime deploy, the old code and the new schema are live at the same time. Every migration rule worth knowing follows from that one sentence.