Blog — page 7 of 38
The Best Metabase Hosting Platforms in 2026
Running metabase.jar takes five seconds. Running it in production means an application database that is not H2, a heap the kernel agrees with, and a SQL console you have not accidentally published.
The best ways to host MLflow in 2026
MLflow looks like a web app and is actually a database, a bucket, and a code-distribution channel wearing one name. An honest look at where to put each part — including where we're the wrong answer.
Conntrack Table Limits: The Shared Resource Under Your MicroVM Fleet
Your guests have separate kernels, separate namespaces and separate subnets. They share one fixed-size hash table, and one port scanner can fill it for everybody.
Hyper-Threading and microVM Isolation: the SMT Decision
The most expensive security decision in multi-tenant compute is one nobody puts in a slide: do you leave SMT on? Two threads on one core share the L1, the TLBs, the branch predictors and the execution ports — below the level where a hypervisor can isolate anything. Here's the topology, the sysfs evidence, and the four rungs of the decision.
How to deploy a Qwik app
Qwik's adapter is not a detail you pick at the end — it is the deployment model itself. Here is what resumability changes about the server, and how to ship the Node path.
How to Self-Host authentik for SSO
authentik is a genuinely good open-source identity provider with an unusual abstraction. Here is the component model, the concepts that trip people up, and the operational promises you are making.
What Is an AI Agent?
An AI agent is a language model in a loop: it proposes an action, your code runs it, the result goes back into context, repeat. The loop is twenty lines. The environment those actions run in is the actual product.
Ephemeral Databases for AI Agents
Give an agent a run_sql tool and it will use it — including the DELETE it emits while debugging its own step. The fix isn't a better statement filter; it's a database that exists for one task and is deleted when the task ends.
The best Inngest alternatives in 2026
Most teams shopping for an Inngest alternative do not want a different step DSL. They want the same work expressed as an ordinary long-running process they own.
The Best Dagster Hosting Platforms in 2026
You do not deploy 'Dagster'. You deploy a webserver, a daemon that must be a singleton, one or more code-location servers, and a Postgres you cannot skip. Here is how the hosting options handle that, honestly.
The Best Ways to Host Grafana Loki in 2026
Loki's whole pitch is that logs go in object storage and only labels get indexed. That is what makes it cheap, and it is also the exact thing people break in week one.
The best Typesense hosting platforms in 2026
Typesense keeps its index in memory. Every hosting decision below — node size, cluster shape, monthly bill, and whether you should cluster at all — falls out of that one sentence.
ffmpeg Command Injection: The Filename Is Input Too
A filename is user input. If you build your ffmpeg command with an f-string, so is your shell — and fixing that still leaves a C parser eating attacker bytes.
Buildkite Agents on MicroVMs: One Job, One Machine
Buildkite's whole premise is that you supply the compute. That makes 'what do agents run on?' a product decision, not a detail — and containers answer it badly for CI.
Running Nix Builds Inside a Disposable VM
Nix's sandbox is a hermeticity fence, not a hypervisor — a hostile derivation still runs on your kernel. Here's how to put Nix inside a disposable VM without a cold /nix/store making every build miserable.
Webhook Replay and Relay: Ingest First, Process Later
The provider retried for eleven hours, gave up, and the event is gone with no record you can inspect. The fix is boring and it is one afternoon of work: ingest first, process later.
Building Container Images for Untrusted Repos Without Privileged Docker
Every RUN line in a user's Dockerfile is a shell command on your builder, as root, at build time. The build is the untrusted workload — not the thing you build.
BuildKit vs Kaniko vs microVMs for Untrusted Image Builds
Every image builder is a code-execution engine wearing a build tool's clothes. Here is the honest comparison of the three ways teams solve that.
Per-Tenant SQLite: One File, One microVM, and No Noisy Neighbours
One SQLite file per customer gets the data model right: blast radius is a path, erasure is rm. Then you put a thousand of them in one process and discover that a file boundary is not a failure boundary.
Bazel Remote Execution Workers on Firecracker microVMs
A remote cache poisoned by a leaky worker is a supply-chain compromise with excellent uptime — every developer pulls it, nobody rebuilds it, and the digests all check out.
Ephemeral Jenkins Agents on Firecracker MicroVMs
An eight-year-old build agent is a museum with a Jenkinsfile. Here is how to give every build a fresh microVM instead — EC2-plugin freshness at container-plugin latency.
The Best Self-Hosted CI Runners in 2026
You've decided to run your own build infrastructure. Now you have to pick the runner software and, whether you meant to or not, an isolation model — because a CI runner is a machine that executes whatever is in a YAML file someone can open a pull request against.
GPU Passthrough and microVMs: The Honest Answer
The question comes up weekly, and the answer is no. Firecracker has no PCI bus and no VFIO device assignment, on purpose. Here is what to build instead.
Observability for Machines That Live 200 Milliseconds
Every observability tool you know assumes the host is still there when you go looking. A fleet of two-second Firecracker VMs is not a scrape target — it is a stream of machines that leave no note.