blog

Blog — page 23 of 38

·8 min read

How push-to-deploy works under the hood

Push-to-deploy looks like magic and is actually five unglamorous mechanisms in a trench coat. Knowing which one is broken saves you from re-pushing an empty commit and hoping.

deploysgithubwebhooks
Ajay Kumar
·9 min read

PandaStack vs Render: an honest comparison

Both take a repo and give you a URL. The difference is what your code lands in — a container sharing a host kernel, or a microVM with its own — and that decides isolation, what you can install, and how idle apps bill.

comparisonrenderapp-hosting
Ajay Kumar
·9 min read

PandaStack vs Railway: an honest comparison

Railway has some of the best developer experience in hosting. The question isn't whether it's good — it is — but whether a container is the right box for what you're running.

comparisonrailwayapp-hosting
Ajay Kumar
·9 min read

The best Heroku alternatives in 2026

Everyone's migration post lists the same eight platforms. The harder question is what Heroku was quietly doing for you that the shortlist doesn't, and which of those things you'll have to rebuild.

herokupaasapp-hosting
Ajay Kumar
·8 min read

Custom domains and automatic TLS, done properly

Letting customers point their own domain at your app is four days of work and one very bad security bug. Here's the ordering that avoids the bug, and why wildcard certs cover less than you think.

custom-domainstlsapp-hosting
Ajay Kumar
·8 min read

Deploying FastAPI without writing a Dockerfile

Python deploys fail in four predictable places, and three of them have nothing to do with your code. Here's each one, why it happens, and the fix — no container image required.

pythonfastapiapp-hosting
Ajay Kumar
·9 min read

Running managed Postgres inside a microVM

Container-per-database and VM-per-database look similar on a diagram and behave nothing alike under load. Here's the architecture, why creates take 30 to 90 seconds, and what a VM buys a database that a container can't.

databasespostgresmicrovm
Ajay Kumar
·8 min read

Postgres point-in-time recovery, explained

A nightly dump gives you a bad day. PITR gives you the minute before someone ran the wrong UPDATE. The mechanism is simpler than it sounds, and the operational details are where it fails.

postgresdatabasesbackups
Ajay Kumar
·8 min read

Cloning production data for testing, safely

Your seed script creates 50 tidy rows. Production has 40 million messy ones, three encodings, and a customer whose name breaks your CSV export. Testing against a clone finds those — if you handle the data properly.

databasestestingpostgres
Ajay Kumar
·8 min read

Suspending idle Postgres databases

A per-customer database fleet is mostly asleep and entirely billed. Suspending idle databases fixes that — but a connection arriving at a suspended database has to be held, not refused, and that's where implementations differ.

databasespostgresscale-to-zero
Ajay Kumar
·7 min read

Routing Postgres connections by SNI

Postgres has no Host header. So how does one endpoint on port 5432 route to a thousand different databases? The answer is in the TLS handshake, and it involves a protocol quirk unique to Postgres.

postgresnetworkingtls
Ajay Kumar
·8 min read

Database failover when the host disappears

Failover is the operation most likely to turn a degraded database into a lost one. The mechanism matters less than one rule: never take down something healthy while trying to fix something you think is broken.

databasespostgresreliability
Ajay Kumar
·7 min read

Rotating database credentials without downtime

Everyone agrees credentials should be rotated. Almost nobody does it, because the naive version drops every connection in the fleet. Here's the version that doesn't.

postgresdatabasessecurity
Ajay Kumar
·8 min read

End-to-end tests with a real app and a real database

The bugs that reach production are the ones between components — the transaction that isn't, the migration that locks, the constraint your mock didn't have. Testing those needs real things, one set per run.

testinge2edatabases
Ajay Kumar
·8 min read

A staging environment per branch, database included

Preview URLs are standard now. Preview databases mostly aren't, so every branch still points at the one shared staging database — which is why your migrations still break each other.

stagingpreview-environmentsdatabases
Ajay Kumar
·8 min read

Contract testing when you can run the real services

Pact and its relatives were designed around a constraint: you can't run twelve services in CI. That constraint has weakened. What survives is the part about who owns the expectation.

testingmicroservicesci
Ajay Kumar
·8 min read

Why your visual regression tests are flaky

A visual regression suite that cries wolf gets muted within a month. Almost every false positive traces to the rendering environment, not the code — and that's fixable.

testingbrowser-automationvisual-regression
Ajay Kumar
·9 min read

Running RL environments in microVMs: isolating rollout workers

An RL environment is the only workload where something is actively optimizing to break it — because breaking it pays. That changes what "sandbox" has to mean.

reinforcement-learningmicrovmsandbox
Ajay Kumar
·9 min read

Sandboxing an AI Agent That Operates Your Kubernetes Clusters

The dangerous thing you hand a Kubernetes agent is not a filesystem, it's a kubeconfig. Isolate the toolchain in a disposable microVM, mint a 10-minute ServiceAccount token per run, and make `kubectl diff` the step that can't be skipped.

ai-agentskubernetessre
Ajay Kumar
·9 min read

Building a load-testing fleet on microVMs

Load generators are the worst container neighbour you can have: they saturate the NIC, exhaust conntrack, and quietly skew everyone else's latency numbers — including the ones you came to measure. One microVM per worker fixes the measurement, not just the isolation.

load-testingk6performance
Ajay Kumar
·9 min read

Firecracker vs libkrun: a VMM you run vs a VMM you link

One of these is a program you supervise; the other is a library you link into your own address space. That single structural difference decides lifecycle, crash blast radius, who owns the jail, and which one belongs in your stack.

firecrackerlibkrunvmm
Ajay Kumar
·9 min read

PandaStack vs Morph Cloud: Snapshot-First Sandboxes

Morph and PandaStack both treat snapshot-and-branch as the core primitive rather than an afterthought. A fair, founder's guide to evaluating the two.

comparisonmorph-cloudai-agents
Ajay Kumar
·10 min read

How to Write a userfaultfd Handler for Firecracker

Firecracker will hand you a userfaultfd over a Unix socket and let you back a guest's entire RAM yourself. Here's how to actually write that handler — the SCM_RIGHTS handshake, the poll/UFFDIO_COPY loop, the page-size traps, and how to turn the fault source into a network fetch.

userfaultfdfirecrackersnapshots
Ajay Kumar
·9 min read

Firecracker Boot Sources: initrd vs a Root Block Device

A microVM has no BIOS, no bootloader, and no GRUB menu — just a kernel, a command line, and one decision: does userland arrive in RAM as a cpio archive, or on a virtio-blk device you mount? The answer changes your memory bill more than your boot time.

firecrackermicrovminitrd
Ajay Kumar