[{"title":"Hot Deal Sheet","excerpt":"Hot deals from Korean communities, collected every few minutes and normalized into one clean, sortable sheet.","href":"/tools/hotdealsheet","category":"Tool","date":"Live","reading":"Korean deal aggregator","body":"Korean shopping communities like Ppomppu, Ruliweb, and Quasarzone surface some of the best deals in the country — but they live in fast moving forum threads with inconsistent titles, buried shipping costs, and no way to filter or sort. Hot Deal Sheet watches those communities around the clock, extracts each deal, and normalizes it into structured data: price, shipping fee, shopping mall, category, and source. The result is one spreadsheet style view where a deal is a row, not a forum post. How it works 1. Open the sheet. No sign up, no app — hotdealsheet.com shows the latest deals the moment you land. 2. Narrow it down. Filter by category, shopping mall, or source community, and sort any column. A dedicated view lists everything under ₩10,000. 3. Click through. Each row links to the original community post, so you can check comments and stock before buying. Features Always fresh — collectors run every few minutes, and each deal shows how long ago it was posted. Board view — the same deals grouped into category columns for scanning by interest instead of by time. Date archive — every collected day is browsable, so a deal you half remember from last Tuesday is still findable. A URL f"},{"title":"QR Code Generator","excerpt":"Turn a link, Wi-Fi login, or contact card into a QR code without the data ever leaving your browser.","href":"/tools/qr-code","category":"Tool","date":"Live","reading":"Browser-only QR encoder","body":"Why this one exists Most QR generators ask you to type a Wi Fi password into a stranger's server, then hand back an image that stops working the day their trial expires. The encoding itself is a solved problem that runs fine on the device already in front of you. So this one does the whole job in the browser tab above. What you type is never uploaded, and the code you download keeps pointing wherever you told it to point, because there is no redirect service in the middle that could go away. How it works 1. Pick what goes in the code: a website address, plain text, a Wi Fi network, an email, a phone number, an SMS, or a contact card. 2. Fill in the fields. The code redraws as you type, and the line underneath tells you which QR version you ended up on and how many characters fit. 3. Download it as a PNG at up to 2048 px, or as an SVG for print. You can also copy the image straight to your clipboard. Features What you type is not sent anywhere. The encoder runs on your device. Wi Fi passwords and phone numbers stay in the tab, which is the main reason this exists. It warns you before you print. Low contrast is the usual reason a QR code fails, so the colour pair gets checked and fla"},{"title":"Fasting Tracker","excerpt":"A fasting notebook that tracks weight, blood pressure, heart rate and blood sugar, and says when a reading falls outside the usual range.","href":"/tools/fasting-tracker","category":"Tool","date":"Live","reading":"Korean-only Toss Mini App","body":"Going a day or more without food moves your body faster than memory keeps up with. Weight, blood pressure, resting heart rate and blood sugar all shift, and by the second morning what you think you measured yesterday is not worth trusting. Most people fasting on their own end up with a few numbers in a memo app and no sense of which one mattered. Fasting Tracker is a notebook for that stretch, running as a Toss Mini App. You log a reading when you actually take one, add a line about how you feel, and the app keeps the running clock, the change since you started, and a chart per metric. When a value lands outside the usual reference range, it says so in plain words, gives the range it is comparing against, and tells you what would be worth doing about it. How it works 1. Start a fast. Choose the kind (water fast, intermittent, other), when it began, and how long you are aiming for. The clock on the home screen runs from there. 2. Log what you measured. Weight, blood pressure, resting heart rate, blood sugar, a memo. Only the fields you actually took, and previous values are never pre filled, so yesterday's number cannot be saved as this morning's. 3. Watch it move. The history tab k"},{"title":"Snip","excerpt":"Paste a long URL, get a short snipp.cc link back, with a key that lets you take it down later.","href":"/tools/snip","category":"Tool","date":"Live","reading":"URL shortener","body":"Some links are longer than the message you want to wrap around them: a path five levels deep, a slug that repeats the title, a tail of tracking parameters. Sent in a chat window or read out from a slide, that link becomes the whole message. Snip trades it for a short one. Paste the URL, press the button, and a snipp.cc address comes back on the same screen. No account, nothing to install. How it works 1. Paste the link. Drop the long URL into the box on snipp.cc. Web addresses starting with or are accepted; anything else is turned away. 2. Press Shorten. The short address appears where the box was, with a copy button next to it. 3. Keep the delete key. It shows up once, under the link. Paste it back into the Take a link down box further down the page whenever you want the link gone. Lose the key and nobody can take the link down, so copy it somewhere before you close the tab. Features Nothing to sign up for — no account to make, and no cookie left in your browser. A key that undoes it — every link comes with one, and a box on the same page takes the link down when you paste the key back. Nothing to install and no request to hand write, though the short link doubles as an API endpoi"},{"title":"PDF Merger","excerpt":"Join several PDFs into one file. The pages are copied in the tab in front of you, so nothing is uploaded.","href":"/tools/merge-pdf","category":"Tool","date":"Live","reading":"Browser-only PDF joiner","body":"The usual way to merge two PDFs is to hand them to a stranger's server, wait for a queue, download the result, and then go looking for the sentence that says how long the copies are kept. For a signed contract, a bank statement, or a scan of your passport, that is a lot to give away for a job that is mostly copying pages from one file into another. The tab above does that copying on your device. The browser reads each file, writes the pages into a new document in memory, and hands you the result from the same tab. Nothing is uploaded, so there is nothing to delete afterwards. The quickest way to check that claim is to open your browser's network panel and watch it while you merge: the pages go nowhere. How it works 1. Drop your PDFs onto the box, or press Choose files . Each one is read on the spot, so its first page and page count show up before you commit to anything. 2. Put them in the order you want. Drag a row, or use the arrows. The number on the left is where that file lands in the finished document. 3. Press Merge into one PDF . The joined file arrives in your downloads as . Features The files stay on your device. There is no upload step and no server to send them to. That "},{"title":"PDF to PNG Converter","excerpt":"Turn the pages of a PDF into PNG images. The pages are drawn in the tab in front of you, so nothing is uploaded.","href":"/tools/pdf-to-png","category":"Tool","date":"Live","reading":"Browser-only PDF page exporter","body":"Getting a picture of a PDF page is one of those jobs that looks trivial until you try it. Screenshotting loses half the resolution, the print dialog wants a printer, and the sites that offer to do it properly ask you to hand over the document first. For a contract, an invoice, or a scan of something with your address on it, that is a strange trade for what amounts to redrawing a page you already have. The tab above redraws it on your device. The browser opens the file, paints each page you asked for onto a canvas at the resolution you picked, and hands the images back from the same tab. Nothing is uploaded, so there is nothing to delete afterwards. The quickest way to check that is to open your browser's network panel while you convert: the pages go nowhere. How it works 1. Drop a PDF onto the box, or press Choose a file . Its first page and page count show up straight away, so you can see you picked the right document. 2. Pick a resolution, and a page range if you do not want all of them. The line under the resolution tells you how many pixels page one will come out at. 3. Press Convert to PNG . One page arrives as a PNG. Several arrive as a single zip, because browsers block a do"},{"title":"PDF Page Organizer","excerpt":"Delete, rotate, reorder and extract pages from one PDF. The file is rewritten in the tab in front of you, so nothing is uploaded.","href":"/tools/pdf-pages","category":"Tool","date":"Live","reading":"Browser-only page editor","body":"A scan comes back with the cover page you did not want, three sheets sideways, and page 12 where page 2 should be. Fixing that usually means uploading the whole document to a stranger's server, which is an odd trade for a contract, a payslip, or a passport scan — the pages you least want to hand over are the ones that need the most tidying. The tab above lays every page of one file out as a picture. You pick the ones you want gone, turn the ones lying on their side, drag any of them into a different position, and save. The reading and the rewriting both happen on your device, so there is nothing to upload and nothing to delete afterwards. The quickest way to check that is to open your browser's network panel and watch it while you work: the pages go nowhere. How it works 1. Drop a PDF onto the box, or press Choose a file . Every page turns up as a tile, and the number on each tile is where that page will land in the saved file. 2. Tick the pages you want to act on and use the buttons — turn them, delete them, or keep only those and drop the rest. Single pages have their own buttons, and you can drag a tile or use the arrows to move it. 3. Press Save PDF . The rewritten document arr"},{"title":"Image to PDF Converter","excerpt":"Turn photos and screenshots into one PDF. The pages are built in the tab in front of you, so nothing is uploaded.","href":"/tools/image-to-pdf","category":"Tool","date":"Live","reading":"Browser-only image to PDF builder","body":"Someone asks for a receipt, a signed form, or a passport page as a PDF, and what you have is three photos on your phone. The usual fix is to hand those photos to a stranger's server, wait for a queue, download the result, and then go looking for the sentence that says how long the copies are kept. The tab above does that on your device. The browser reads each image, writes it onto a page in a new document in memory, and hands you the result from the same tab. Nothing is uploaded, so there is nothing to delete afterwards. The quickest way to check that claim is to open your browser's network panel and watch it while you build the file: the photos go nowhere. How it works 1. Drop your images onto the box, or press Choose images . Each one is read on the spot, so its thumbnail and pixel size show up before you commit to anything. 2. Put them in the order you want and pick a page size. Drag a row, or use the arrows. The number on the left is the page that image becomes. 3. Press Create PDF . The finished file arrives in your downloads. Features The images stay on your device. There is no upload step and no server to send them to. That is the whole reason this exists, and it is the one "},{"title":"Cloudflare Free Plan Rate Limiting Cannot Guard 1,000 KV Writes a Day","excerpt":"The Workers free plan allows 1,000 KV writes a day, shared by everyone. The rate limiting binding let 82 percent of a burst through, WAF rate limiting rules on a free zone are stuck at a 10 second window, and neither can express a daily cap. A per address Durable Object can.","href":"/blog/2026/08/cloudflare-free-plan-rate-limiting-daily-quota","category":"Build log","date":"Aug 24, 2026","reading":"8 min read","body":"Snip is a URL shortener I put on snipp.cc this month. It runs on the Cloudflare Workers free plan, and most of the design is a negotiation with a single number. The free plan allows 1,000 KV writes per day. Creating a link is exactly one write. So a thousand new links a day is the ceiling for the whole service, and it is one pool that everybody shares. The last limit on this plan that caught me out was 10 ms of CPU per invocation. This one is quieter. That ceiling has a sharp edge. Going over does not produce a bill, because the free plan does not upgrade itself. It produces a failure: the write is rejected and the person in front of the box gets nothing. The limits reset at 00:00 UTC, so the worst case is that link creation is dead until midnight while every link that already exists keeps redirecting, since redirects are reads. Cloudflare limits and doc tables quoted below were read on 24 August 2026. Which means the interesting question is not how to survive a flood. It is how to stop one address from quietly spending everyone else's day. The limiter I shipped let 82 percent through I used the Workers rate limiting binding, keyed on , at five creations per sixty seconds. The docs"},{"title":"URL Shorteners 2026: What the Free Plans Let You Do Without an Account","excerpt":"Six shorteners, side by side, on the things that decide a free link: whether you have to sign up, how many links you get, whether you can pick the ending, whether you can take one down afterwards, and whether anything is counted. Two of the six will not let you delete a link you made.","href":"/blog/2026/08/url-shortener-free-plans-2026-without-an-account","category":"Build log","date":"Aug 24, 2026","reading":"6 min read","body":"The roundup I would hand somebody is Zapier's. It says how it was made, the writer spent time with close to fifty tools, and Zapier has no shortener of its own to sell you. Like most of them, it is built for somebody picking a paid plan: branded domains, retargeting, attribution, seats. That is not the question most people arrive with. The question is whether you can paste a long link into a box and get a short one back, right now, without making an account, and what that costs you later. I built one of these this month, so I went and read the free column on every vendor page. Everything below came off those pages, a vendor help article, or a response header I pulled myself, on 24 August 2026. The free column, side by side Sign up? Free links Pick your own ending Take one down later Click stats Snip No 50 a day per address No Yes, with a key No is.gd No 200 an hour per address Yes No, ever Opt in per link TinyURL Not to shorten 30 a month Yes No, not on Free No Bitly Yes 5 a month 3 a month Only if never edited Yes Short.io Yes 1,000 total Yes Yes 50,000 clicks a month Dub Yes 25 a month Yes Yes 1,000 events a month Two of those cells need a note. Bitly states its free quotas by th"},{"title":"Ten Milliseconds of CPU: I Broke the Cron by Making It Run More Often","excerpt":"The Workers free plan gives each invocation 10 ms of CPU, and an isolate tolerates going over as long as you do not do it often. I changed a cron from every ten minutes to every minute and it died an hour later. Then the profiler disagreed with all three of my guesses.","href":"/blog/2026/08/workers-free-tier-10ms-cpu-limit","category":"Build log","date":"Aug 23, 2026","reading":"9 min read","body":"Hot Deal Sheet collects deal posts from Korean forums on a schedule and serves them as pages. It runs on the Cloudflare Workers free plan, and staying inside that plan is most of the design. On 19 August 2026 I changed the collection cron from every ten minutes to every minute, because fresher is better. An hour later every run was ending in , and I did not find out for about two hours. Nothing about the work per run had changed. Each run still fetched one forum, parsed it, and wrote the changed rows. The only thing I touched was how often it happened. The free plan allows 10 ms of CPU per invocation, and that applies to cron triggers exactly as it applies to HTTP requests. Waiting on the network does not count, so and D1 queries are free. Parsing, hashing, and rendering are not. On the paid plan the same number is 30 seconds by default. Cloudflare's own docs say the average Worker uses about 2.2 ms, and that \"heavier workloads that handle authentication, server side rendering, or parse large payloads typically use 10 20 ms.\" Read that twice if you are serving rendered HTML from the free plan. The band the vendor calls normal for server side rendering starts above the free limit. T"},{"title":"Django 4.2 Is Past End of Life: The 5.2 LTS Upgrade","excerpt":"Django 4.2 lost security support on 7 April 2026. On 4 August the security team patched four issues in 5.2 and 6.0 and nothing older, so the gap stopped being hypothetical. 5.2 LTS is the target, and the Python floor is where the time goes.","href":"/blog/2026/08/django-4-2-end-of-life-upgrade-5-2-lts-guide-2026","category":"Tooling","date":"Aug 5, 2026","reading":"8 min read","body":"Django 4.2's extended support ended on 7 April 2026. The download page still lists it, in the unsupported table, frozen at 4.2.30. For four months after that date nothing happened. No CVE, no advisory, no reason for anyone to move. \"Unpatched\" stayed a line on a scanner report rather than something you could point at. Then on 4 August the security team shipped 6.0.8 and 5.2.17, fixing four issues. The patches went to main, 6.1, 6.0, and 5.2. That is the entire list. There was no 4.2.31, and there will not be one. CVE Severity What it touches CVE 2026 15307 High Spatial lookups accepting and values into CVE 2026 15830 Moderate Geometry collections CVE 2026 15920 Moderate Admin display CVE 2026 15337 Low Translation utility Two of the four are GeoDjango. If you have never imported , those are somebody else's problem. The admin one is not: a rendered in the admin is about as close to a default as this framework has. Django's advisories describe the branches that got fixes and say nothing about the ones that did not. That silence is the actual change at end of life. Whether a given CVE reaches the code you are running is now your question to answer, every time, with the patch diff open"},{"title":"Structured Outputs in 2026: OpenAI vs Claude vs Gemini","excerpt":"Schema-constrained decoding is real on all three providers now, and the parameter you reach for is different on each. What each one guarantees, and what it still cannot.","href":"/blog/2026/08/structured-outputs-2026-json-schema-openai-claude-gemini","category":"Tooling","date":"Aug 4, 2026","reading":"9 min read","body":"If you are still prompting \"respond only in valid JSON\" and hoping, you are carrying debt you no longer need to carry. All three major providers constrain generation against a schema now. Not pleading in the system prompt: the decoder itself refuses to emit a token that would break the shape. The catch is that \"structured output\" means three different things depending on which API you are holding, and the parameter names moved recently on at least two of them. Checked against the provider docs on 21 August 2026. Two different failures, one of which is silent Prompting for JSON fails in two ways and it is worth separating them, because the fixes are not the same. The first is a syntax failure. A dangling comma, an unclosed brace, a markdown fence wrapped around the answer even though you asked for none. Annoying, and cheap to catch: a try/catch around , one retry, move on. The second is worse because nothing throws. The model returns syntactically perfect JSON that is not the shape you asked for. A field you never defined, a string where you wanted a number, an enum value outside your three allowed options. Your downstream code eats it happily until something dereferences a null thr"},{"title":"Browser Use vs Stagehand vs Skyvern: Browser Agents 2026","excerpt":"One architectural choice, read the DOM or look at a screenshot, explains the cost, the failure modes, and which of these three you should be running.","href":"/blog/2026/08/best-open-source-browser-agent-frameworks-2026-browser-use-vs-stagehand-vs-skyvern","category":"Tooling","date":"Aug 3, 2026","reading":"9 min read","body":"The demo always works. You point a browser agent at a site, say \"log in and download last month's invoices,\" and it does exactly that on the first attempt. Then you run it a hundred times against a real portal with a session timeout, a lazy loaded table, and a modal that appears only on Tuesdays, and the success rate settles somewhere around 60%. That gap is what actually separates these frameworks. Not the star count, not the benchmark number in the README. So this is Browser Use, Stagehand, and Skyvern from the angle that matters when you are the one getting paged: how each decides what to click, what that costs per run, and how it fails when the page moves. These are not the same category as the consumer AI browsers. Those are products you use. These are libraries you build on, and they turn up in your dependency file, your token bill, and your incident channel. Repo numbers and prices checked on 21 August 2026. The choice everything else falls out of Every browser agent answers the same question on every page: what is on this screen and what can I do with it. Two ways to understand a page: reading the DOM is cheap and precise but breaks on hostile markup, while looking at a scr"},{"title":"Headless CMS 2026: Both Free On-Ramps Closed This Summer","excerpt":"Strapi deletes every remaining free Cloud project on 1 September, and its cheapest paid tier still sleeps when idle and takes no backups. Payload Cloud stopped accepting new deployments after the Figma acquisition. What is left is a self-hosting decision wearing a comparison table.","href":"/blog/2026/08/headless-cms-2026-contentful-vs-sanity-vs-strapi-vs-payload","category":"Tooling","date":"Aug 2, 2026","reading":"9 min read","body":"If you have a free project on Strapi Cloud, the date that matters is 1 September 2026. Strapi's announcement says the free plan was removed for new signups on 1 July and that \"all existing free projects will be deleted\" on 1 September. That is nine days from when I checked this. Export first, decide after. A timeline across June to October 2026. On 1 July 2026 the Strapi Cloud free plan closed to new signups. On 1 September 2026 all remaining free projects are deleted. A marker at 23 August 2026 shows the point of writing, nine days before the deletion date. The Strapi Cloud free plan, start to finish 1 Jul: closed to new signups 1 Sep: all free projects deleted 23 Aug Jun Jul Aug Sep Oct Dates from Strapi's own announcement post. Self hosted Strapi is unaffected; this is the hosted product only. The reason Strapi gave is worth reading, because it describes the product you are being upgraded into. Most free projects were inactive, they cost infrastructure, and they ran on sleeping containers that made Strapi look slow. Fair enough. Then look at the current Cloud pricing page: the cheapest paid tier, Starter at $35 per project per month, has \"Sleeps when idle\" in its runtime behavio"},{"title":"Debian 11 Dies on 31 August, and It Is Hiding in Your Base Images","excerpt":"The people this deadline catches are not Debian admins. They run python:3.9-slim and have never once thought about what is underneath it. Nine days to find out.","href":"/blog/2026/08/debian-11-bullseye-end-of-life-august-2026-docker-migration-playbook","category":"Infrastructure","date":"Aug 1, 2026","reading":"11 min read","body":"Debian 11 \"bullseye\" stops receiving security updates on 31 August 2026. That is nine days from now. If you administer Debian machines for a living you knew this and finished months ago. The people who get caught are app developers who do not think of themselves as Debian users at all. They run , or a image, or a vendor container pulled three years ago and never opened. Bullseye is what is underneath. Nothing in the Dockerfile says \"debian\" anywhere. The exposure is there regardless. Full support actually ended back in August 2024, when the Debian Security Team handed bullseye to the volunteer LTS team. What runs out this month is that extension. From 1 September, every new CVE in glibc, OpenSSL, systemd, or anything else in the base system is yours to carry, or yours to pay someone to carry. What breaks on 1 September Nothing. That is the trap. Containers keep running, VMs keep booting, there is no license check and no nag screen. What you get instead is slower and more irritating. starts failing. Bullseye packages move off the main mirrors to , so against an untouched sources.list returns 404s, and once the Release file's validity window lapses you get expired signature errors st"},{"title":"Search Pricing in 2026: Four Vendors, Four Different Units","excerpt":"Algolia counts requests and records, Typesense counts RAM-hours, Meilisearch will count either, and Elastic switched to VCU-hours. Off the published rates, a $129.60 Typesense box equals Algolia at 269,000 searches a month.","href":"/blog/2026/07/algolia-vs-meilisearch-vs-typesense-vs-elasticsearch-2026-search-pricing","category":"Infrastructure","date":"Jul 31, 2026","reading":"9 min read","body":"The feature tables for these four have converged. Everyone has typo tolerance, faceting, synonyms and some flavor of vector search. What has not converged is the unit on the invoice, and that is the only thing that decides which one is cheap for you. Algolia charges per search request and per record. Typesense Cloud charges for a box by the hour and does not count searches at all. Meilisearch Cloud will sell you either shape. Elastic changed its unit since most comparison posts were written. Every number below came off the vendor pricing pages, the Typesense Cloud price calculator and the GitHub API on 22 August 2026. A chart comparing monthly cost against monthly search volume. Algolia's Grow plan rises as a straight line from zero at ten thousand searches to 495 dollars at one million searches, because it charges 50 cents per additional thousand search requests. A Typesense Cloud four gigabyte cluster is a flat line at 129 dollars 60 cents regardless of search volume. The two lines cross at about 269 thousand searches per month. Where the per request plan passes the rented box $0 $250 $500 0 250K 500K 750K 1M search requests per month 269K searches: the two cost the same Algolia "},{"title":"Postman Alternatives: Every Free Tier Withholds a Different Thing","excerpt":"Bruno's free tier cannot use a private Git repository, which is the entire point of Bruno. Insomnia's free Git Sync stops at three users. Hoppscotch withholds the least and runs in a browser. What each one costs once the free tier stops fitting.","href":"/blog/2026/07/postman-alternatives-2026-bruno-vs-insomnia-vs-hoppscotch","category":"Tooling","date":"Jul 30, 2026","reading":"7 min read","body":"Postman's Free and Solo plans include exactly one user. That is on their pricing page as a line item, \"Total users included: 1 user,\" and it is why a wave of teams went shopping this year. Team is $19 per user per month billed annually, which is $1,140 a year for five people who used to pay nothing. Three alternatives get named in every thread about this, and all three have free tiers. The useful question is not whether they are free but which part of the product each one holds back, because it is a different part in each case, and in one of them it is the feature the product is famous for. Prices below came off the vendor pricing pages and the GitHub API on 23 August 2026. What each free tier holds back. Postman's free plan includes one user only, so team collaboration requires the paid Team plan. Bruno's open source tier connects only to public Git providers and allows two workspaces, so the git native collaboration it is known for needs the paid Pro tier for private repositories. Insomnia's free Essentials tier gives Git Sync to three users, with cloud and local projects unlimited. Hoppscotch's free tier has unlimited workspaces, collections and runners, and holds back the admin"},{"title":"EWS Retirement: The Value That Keeps It On Is Null, Not True","excerpt":"From 1 October, EWSEnabled=True with an empty allow list blocks every EWS call in the tenant, and Null is the value that keeps EWS running. The end-of-August date is not a registration with Microsoft, and the kiosk block quietly moved to October.","href":"/blog/2026/07/exchange-web-services-ews-retirement-microsoft-graph-migration-guide-2026","category":"Infrastructure","date":"Jul 29, 2026","reading":"8 min read","body":"Every write up about the Exchange Web Services retirement hands you the same two dates: 1 October 2026 and 1 April 2027. Both are right. Neither tells you what your tenant will do, because that is decided by one organization level property with three values, and one of the three reverses meaning on the first date. The property is . It holds True, False, or Null, and Null is the default that most tenants still have. Microsoft's phased disablement post gives the behavior on both sides of October, and the row worth reading twice is the one where is True and the new app allow list is empty. Before October that combination allows everything. From October it blocks everything. Dates and behavior below came off Microsoft's own posts and Learn pages on 22 August 2026. How the EWSEnabled setting and the EWSAllowedAppIDs allow list combine, before and after October 2026. Before October, Null allows all EWS traffic and True with an empty list also allows all traffic. From October, Null gets flipped to False as the rollout reaches the tenant, and True with an empty list blocks all traffic instead of allowing it. True with a populated list allows only the listed app IDs in both periods, and Fal"},{"title":"SharePoint 2016 and 2019: No ESU, and No Staying Put","excerpt":"Support ended 14 July 2026, the same day as SQL Server 2016. SQL Server sells you three more years by the core-hour. SharePoint sells you nothing, and Subscription Edition is not staying put: it is a new farm, a database attach, and a license that exists only while Software Assurance does.","href":"/blog/2026/07/sharepoint-2016-2019-end-of-support-july-2026-spse-vs-sharepoint-online","category":"Infrastructure","date":"Jul 28, 2026","reading":"8 min read","body":"Extended support for SharePoint Server 2016 and 2019 ended on 14 July 2026. Nothing stopped. Your farm serves pages today exactly as it did on the 13th, which is the part that lets a farm sit unpatched for a year while everyone agrees it is a priority. That same date ended extended support for SQL Server 2016, and comparing the two is the fastest way to see what you actually have here. Comparison of two Microsoft products that lost support on 14 July 2026. SQL Server 2016 offers Extended Security Updates until July 2029 billed by the core hour on the same machine. SharePoint 2016 and 2019 have no Extended Security Updates, and Subscription Edition requires a new farm with a database attach and active Software Assurance. Both lost support on 14 July 2026. Only one sells you time. SQL Server 2016 Extended Security Updates to 17 Jul 2029, billed by the core hour. Same machine, same instance. Cancel any time. SharePoint Server 2016 and 2019 No Extended Security Updates. There is nothing to buy. Subscription Edition is a new farm: database attach only, no in place path, and the license exists only while Software Assurance is active. Microsoft Learn upgrade and lifecycle documentation, r"},{"title":"React, Vue, Svelte, Solid: The Clock Is on the Meta-Framework","excerpt":"None of the four publishes an end-of-life date. The layer you actually deploy does, and the two policies could not be further apart: Next.js gives a major two years of maintenance, Nuxt gives six months after the next one ships. Nuxt 3 ended three weeks ago.","href":"/blog/2026/07/svelte-vs-react-vs-vue-vs-solid-2026","category":"Tooling","date":"Jul 27, 2026","reading":"8 min read","body":"Four way framework comparisons turn into taste arguments because the things being compared are close enough that taste is what is left. Bundle sizes are all small, all four are fast enough, and the library gap is a hiring question rather than a technical one. There is a question with an answer, though, and it is one layer down from where the comparison usually happens. You do not deploy React, you deploy Next.js. You do not deploy Vue, you deploy Nuxt. Those two projects publish support policies that are nothing alike, and one of them just expired. A timeline from 2023 to 2028 showing published support windows. Nuxt 3 ran until 31 July 2026 and has already ended. Next.js 15 is in maintenance until 21 October 2026. Next.js 16 is supported until 21 October 2027. A vertical line marks today, 23 August 2026, just past the end of the Nuxt 3 bar. React, Vue, Svelte and Solid publish no end date at all and so have no bar. The only published end dates in this comparison today Nuxt 3 ended 31 Jul 2026 Next.js 15 ends 21 Oct 2026 Next.js 16 ends 21 Oct 2027 2023 2024 2025 2026 2027 The two Next.js dates are the end of Maintenance LTS. React, Vue, Svelte, and Solid publish no end date at all,"},{"title":"Secret Scanning 2026: The Default Tool Stopped Shipping","excerpt":"Gitleaks has 28,909 stars and its last release was five months ago, because its author put a warning in the README and moved to a fork with 1,757. Meanwhile the layer that actually prevents a leak is the one most teams skip, and only one of the four layers is prevention at all.","href":"/blog/2026/07/secret-scanning-2026-gitleaks-betterleaks-trufflehog-github-secret-protection-gitguardian","category":"Tooling","date":"Jul 26, 2026","reading":"9 min read","body":"The most installed open source secret scanner has a warning callout at the top of its own README, written by the person who spent eight years building it. \"Gitleaks is feature complete. I'm not merging new features into Gitleaks. Future releases will be security patches only. I'm shifting my focus to Betterleaks.\" The numbers back it up. On 23 August 2026, Gitleaks has 28,909 stars and its most recent release is v8.30.1 from 21 March 2026, five months back. Commit activity over the last six weeks is zero except for one week with three. Betterleaks has 1,757 stars, shipped v1.8.1 on 18 August, and put out six releases between 27 July and 18 August alone. Both are MIT. That is a 16 to 1 gap in stars pointing one way and every signal of actual maintenance pointing the other. If you picked your scanner from a comparison table sorted by popularity, you picked the frozen one. What Betterleaks actually adds It is a drop in replacement in the sense that matters: same shape of CLI, same idea of a config file. The differences are in the detection engine. Rule filters are written in Expr rather than the old allowlist blocks, so a rule can look at the commit author, the commit message, and the"},{"title":"Content API for Shopping Is Off: Merchant API v1, After the Fact","excerpt":"Google sunset Content API for Shopping on 18 August 2026. The hostname still answers and the discovery document still updates, so a 200 proves nothing. What is left is extended access, a registration step that fails by returning an empty list, and prices in micros.","href":"/blog/2026/07/content-api-for-shopping-shutdown-august-2026-merchant-api-v1-migration","category":"Tooling","date":"Jul 25, 2026","reading":"9 min read","body":"Google's migration overview says it plainly: Content API for Shopping was sunset on 18 August 2026. If a cron job somewhere still POSTs to , the symptom is not a stack trace in your logs. It is a client asking why their products came out of Shopping. Almost everything written about this shutdown was aimed at merchants and amounted to \"contact your feed provider.\" That is no help if you are the feed provider, or if the uploader is a script somebody wrote in 2019 and nobody has opened since. First: a 200 does not mean you are fine On 23 August 2026, five days after the sunset, still returns 200. The document is stamped revision , dated the day after the shutdown, still lists all 28 resources, and carries no deprecation flag on . Do not read anything into that. Discovery documents are static artifacts and the host serves plenty of other things. Enforcement here is per account, not per endpoint, which is exactly why the hostname is still up: Google is granting extended access to accounts that ask for it, and that would be impossible if the service had been switched off wholesale. So check the account, not the host. The API usage report under Merchant Center account settings tells you w"},{"title":"npm v12 Blocks Install Scripts: The Allowlist Migration","excerpt":"Three defaults flipped in npm 12 and the failure mode is silent, not loud. Here is what breaks, how the approve-scripts allowlist works, and why npm still ships its cooldown turned off while pnpm turns it on.","href":"/blog/2026/07/npm-v12-install-scripts-blocked-allowlist-migration-playbook","category":"Tooling","date":"Jul 24, 2026","reading":"10 min read","body":"Your Docker build worked yesterday. Today it pulls a newer Node image, npm 12 comes along for the ride, and throws at runtime with nothing useful in the install log. Or Prisma's client was never generated. Or husky's hooks quietly stopped installing and nobody noticed for a week. npm 12.0.0 shipped on 8 July 2026 and it is the largest default behavior change npm has made in years. Three things that used to just work are now opt in: dependency install scripts, git dependencies, and remote URL dependencies. GitHub announced them on 9 June. The changes are overdue, and the migration still has edges the changelog does not cover. Versions and config defaults below were checked against the npm registry and the npm v12 config docs on 22 August 2026. What changed, precisely Three separate mechanisms that people keep collapsing into one. defaults to off. npm no longer runs , , or from your dependencies, no longer runs for git, file, and link dependencies, and skips the implicit it fires for any package containing a even when that package declares no install script at all. Scripts in your own still run. This is about dependency code. defaults to . Its type is , , or , where permits only the "},{"title":"Your Assistants Threads Do Not Survive 26 August","excerpt":"One part of this migration has a deadline you cannot move, and it is not the code. Thread contents stop being reachable through the API the moment the endpoints go. The rewrite can slip a month. The export gets one chance.","href":"/blog/2026/07/openai-assistants-api-shutdown-august-2026-responses-conversations-migration","category":"Tooling","date":"Jul 23, 2026","reading":"10 min read","body":"On 26 August 2026 the Assistants API endpoints come off. Not deprecated and still answering. Gone. , , , every path your code still calls. I wrote this in July with a month of runway and revised it on 23 August, three days out. The two halves of this work have completely different clocks, and that is the only scheduling decision that matters. The code migration is a week of ordinary engineering, and slipping it to September costs you errors in front of users until you ship. Unpleasant, recoverable. The export is not like that. Once the endpoints stop answering, the thread contents are unreachable through the API whatever OpenAI's internal retention says, and no tool is coming to get them out for you afterward. So if you are reading this before the 26th, read the export section and go run it. If you are reading it after, that section is a list of what you no longer have, and it is worth knowing which parts those are. Nobody is exporting your threads OpenAI is explicit about this in the migration guide: \"We will not provide an automated tool for migrating Threads to Conversations.\" The suggested path is to read messages out of each thread and write them into a conversation yourself. "},{"title":"Oracle JDK 21 Free Updates End: The Deadline Is a Patch Date","excerpt":"Updates to Oracle JDK 21 released after September 2026 move to the paid license, and Oracle ships JDK updates quarterly. The next quarterly update is 20 October 2026. Same bytecode from Temurin or Corretto gets patched for three to five more years, free.","href":"/blog/2026/07/oracle-java-21-free-updates-end-september-2026-cost-decision","category":"Infrastructure","date":"Jul 22, 2026","reading":"9 min read","body":"Oracle's Java SE support roadmap, updated 4 August 2026, says that update releases of Oracle JDK 21 published after September 2026 are planned to ship under the Java SE OTN license, the paid one, same as 8, 11, and 17 today. That sentence has no day attached to it, and people keep inventing one. The date that matters is not on a calendar page, it is on Oracle's patch schedule. Oracle ships JDK updates on the quarterly Critical Patch Update cycle, the third Tuesday of January, April, July, and October. July's landed 21 July 2026 as 21.0.12. The next one is 20 October 2026 . So 21.0.12 is the last Oracle JDK 21 build you can put in production for free. The one after it costs money. The JDK 17 precedent says exactly this. Oracle's roadmap records that 17's permissive updates ran \"through September of 2024,\" and then that \"further update releases of Oracle JDK 17, released as of October 15, 2024\" were OTN. October 15, 2024 was that quarter's patch Tuesday. Free update windows for JDK 21 by distribution. Oracle's no fee window runs from September 2023 to October 2026. Eclipse Temurin runs to December 2029, Amazon Corretto to October 2030, Azul Zulu to September 2031, and BellSoft Liberi"},{"title":"MCP 2026-07-28: The Server Can No Longer Speak First","excerpt":"Sessions, ping, server-initiated requests, resumable streams, and the GET endpoint all went in one release. Roots, Sampling, and Logging are deprecated on top. Every removal moves initiative from the server to the client, and that is the migration.","href":"/blog/2026/07/mcp-2026-07-28-stateless-spec-migration-server-authors","category":"Tooling","date":"Jul 21, 2026","reading":"8 min read","body":"The MCP specification shipped on 28 July 2026. It is usually described as the release that made MCP stateless, which is true and undersells it. Read the removals as a list and one pattern falls out. The handshake and are gone. is gone. is gone. is gone. The HTTP GET endpoint and are gone. SSE stream resumability is gone. Server initiated requests, which is to say , , and , are gone as a mechanism. And Roots, Sampling, and Logging are deprecated outright. Every one of those was a way for the server to start something. After this release there are none. The client asks, the server answers, and if the server needs more it has to say so in an answer and wait to be asked again. The mechanic that replaces server initiated requests Multi Round Trip Requests is the piece worth understanding before anything else, because it is how a server now gets information it did not receive. Instead of the server sending its own request back down the connection, every result carries a required field. Ordinary answers are . When the server needs more, it answers the original call with and an field describing what it wants. The client then retries the same request, carrying . A sequence diagram of the Mu"},{"title":"Zapier vs Make vs n8n 2026: The AI-Agent Pricing Trap","excerpt":"Zapier bills per task, Make per credit, n8n per execution. The same five-step workflow costs wildly different amounts depending on which word your invoice uses.","href":"/blog/2026/07/zapier-vs-make-vs-n8n-2026-ai-agent-pricing-per-task-vs-per-execution","category":"Tooling","date":"Jul 21, 2026","reading":"7 min read","body":"Every automation platform ships an AI agent now. Zapier has Agents, Make has Maia plus an agent builder, n8n put out a 2.0 release with a pile of AI nodes and real agent loops. The pitch on all three landing pages is the same: describe what you want in plain English and the platform assembles the workflow. That part is mostly true. What none of them put on the pricing page is that the billing unit, not the feature list, decides whether you are paying $30 a month or $3,000 a month in a year. Zapier bills per task . Make bills per credit . n8n bills per execution . Those sound interchangeable. They are not, and the gap widens with every step you add. Prices below were checked against the vendor pages on 21 August 2026. The short version Non technical team, low volume, wants it to work without thinking: Zapier . The most expensive per unit, and the catalog and the polish are worth it under a few thousand runs a month. Ops heavy, lots of branching, cost sensitive: Make . Cheapest entry point, and the canvas handles complicated logic without turning into code. Dev team, high volume, or data that cannot leave your servers: n8n , self hosted, where the per execution cost stops mattering e"},{"title":"Managed Database Pricing: The Instance Rate Decides the Least","excerpt":"Four providers meter four different things, and each one hides the pain somewhere else: a per-request I/O charge, a storage tier you cannot shrink, an HA checkbox that doubles the bill, a size you configured once and now pay for forever.","href":"/blog/2026/07/managed-database-pricing-2026-rds-aurora-cloud-sql-azure-sql-hidden-costs","category":"Data","date":"Jul 20, 2026","reading":"8 min read","body":"The instance rate is the number everyone compares, and it is the number that decides the least. It is also the only one the four big managed database services made comparable, which is why so many bills end up somewhere nobody modeled. Managed relational databases are priced on four axes that do not line up between providers: compute, storage, I/O, and high availability. Each vendor hides the pain in a different one. Aurora Standard meters I/O per request. Cloud SQL doubles everything when you tick the HA box. Azure SQL bills you for the size you configured rather than the size you use. RDS is the most conventional of the four and still has a performance cliff people cross without noticing. Rates and rules below came off AWS, Google, and Microsoft documentation on 22 August 2026. Pull your own numbers for your region before you commit to anything, and note that only one of these four publishes figures a script can read. Aurora Standard bills per I/O, and it compounds quietly This is the one that ambushes people, because it is metered rather than provisioned. Aurora Standard charges $0.20 per million I/O requests on top of compute and storage, where storage runs $0.10 per GB month. "},{"title":"AGENTS.md vs CLAUDE.md vs Cursor Rules: Writing One in 2026","excerpt":"Which tool reads which file, how to feed all of them from one source, and the size budget that decides whether the agent actually follows your rules.","href":"/blog/2026/07/agents-md-vs-claude-md-cursor-rules-how-to-write-2026","category":"Tooling","date":"Jul 18, 2026","reading":"11 min read","body":"If you have used Cursor, Claude Code, Copilot, and Codex CLI in the same month, you have probably written the same \"here is how this repo works\" file three times in three formats, then watched the agent ignore half of it. The instruction file is the single biggest lever you have over a coding agent. Most of the ones I read are quietly making the agent worse: too long, too vague, or full of advice the model already has. Checked against the vendor docs on 21 August 2026. Three files, and who reads what AGENTS.md is the closest thing to a standard. It was formalized as an open spec in 2025 with OpenAI leading, and in December 2025 it went to the Linux Foundation's new Agentic AI Foundation alongside Anthropic's MCP and Block's goose. More than 60,000 open source projects use one, and it is read natively by Codex, Cursor, Copilot, Gemini CLI, Windsurf, Cline, Devin, Jules, Factory, and a long tail of others. The spec is roughly \"put a Markdown file at the repo root and write useful things in it.\" CLAUDE.md is Claude Code's file, and here is the catch that trips teams up: Claude Code reads CLAUDE.md and not AGENTS.md. The feature request is one of the most upvoted issues on the repo and"},{"title":"GitHub Models Is Gone, and the Error Message Says Otherwise","excerpt":"The endpoint returns 410 Gone with a body that calls it a temporary brownout. Trust the status code. Then work out what you actually lost, because the thing you are replacing cost zero and every replacement does not.","href":"/blog/2026/07/github-models-retired-july-2026-migration-azure-foundry-openrouter-self-host","category":"Infrastructure","date":"Jul 18, 2026","reading":"7 min read","body":"GitHub Models was retired on 30 July 2026. The changelog is unusually blunt about the scope: \"The playground, model catalog, inference API, and bring your own key (BYOK) are no longer available to any customer, including existing customers with active usage.\" If you still have code pointing at it, here is what that code sees today. I ran this on 23 August 2026: Read those two lines against each other. The status is 410 Gone, which in HTTP means the resource is permanently unavailable and clients should not try again. The message body says \"temporarily unavailable\" and calls it a scheduled brownout, which is left over from the tooling GitHub used for the deliberate outages on 16 and 23 July. Anything that branches on the status code has already given up correctly. Anything that branches on the message string, or that retries on any non 200, is still hammering an endpoint that will never answer. That is a specific bug to go looking for rather than a general worry: grep for , then check what your retry policy does with a 4xx it does not recognize. The number you are replacing is zero Every migration guide for this skips the part that matters. GitHub Models was free. Not a generous tri"},{"title":"Postgres 18: Async I/O, uuidv7, and Whether It Helps You","excerpt":"Postgres 14 stops getting fixes on 12 November, 19 arrives in September, and 18 is the version to land on. What actually changed in the storage layer, and how to tell in advance whether you will feel any of it.","href":"/blog/2026/07/postgresql-18-upgrade-async-io-uuidv7-should-you-upgrade-2026","category":"Data","date":"Jul 16, 2026","reading":"9 min read","body":"Two clocks make this decision for you, and one of them just started ringing. Postgres 13 went end of life on 13 November 2025 and RDS ended standard support for 13.x on 28 February 2026, which means anyone still on it is enrolled in Extended Support and paying for the privilege right now. Postgres 14 is next: community support ends on 12 November 2026, about twelve weeks out. RDS keeps 14 under standard support until 28 February 2027, so the managed calendar gives you a quarter of cover past the community one, and no more. The other clock is 18 itself. It went GA on 25 September 2025 and is on 18.6 as of this month, which is exactly the maturity you want to upgrade into. Postgres 19 is planned for September 2026, with beta 3 out on 13 August. That is a month away, and it is not the version to land a production database on this year. Versions checked on the postgresql.org release pages on 22 August 2026. So the question is not whether to upgrade. It is how far to jump and what breaks when you land. Skip the intermediate versions If you are on 13 or 14, go straight to 18. crosses multiple major versions in one run, so climbing the ladder one rung at a time buys nothing. The cost of a"},{"title":".NET 8 and 9 End of Support: The .NET 10 Migration","excerpt":"Both versions stop getting patches on 10 November 2026, so staying on the LTS bought you nothing. What actually breaks is mostly .NET 9's doing, and the obsolete-API warnings you have been scrolling past are still warnings.","href":"/blog/2026/07/dotnet-8-9-end-of-support-november-2026-net-10-migration-playbook","category":"Tooling","date":"Jul 15, 2026","reading":"8 min read","body":".NET 8 and .NET 9 reach end of support on the same day: 10 November 2026, about eleven weeks from now. If you deliberately stayed on .NET 8 because it was the Long Term Support release, you get exactly as much runway as the teams who chased .NET 9. The reason they land together is a policy detail. LTS releases get three years from GA; Standard Term Support releases get two. .NET 8 shipped 14 November 2023, .NET 9 shipped 12 November 2024, and three years and two years both run out in November 2026. Microsoft's support policy page states it plainly: STS is \"supported for one year after a subsequent release,\" and since releases land every twelve months, that adds up to two years. Support windows for .NET 8, 9, and 10. .NET 8 released November 2023 with three years of LTS support and .NET 9 released November 2024 with two years of STS support; both end on 10 November 2026. .NET 10 released November 2025 and is supported until 14 November 2028. A three year window and a two year window end on the same day Nov 2023 Nov 2026 Nov 2028 .NET 8 & 183; LTS & 183; 36 months .NET 9 & 183; STS & 183; 24 months .NET 10 & 183; LTS & 183; to Nov 2028 10 Nov 2026 both stop here today Picking the LTS"},{"title":"Python 3.10 End of Life: The October 2026 Upgrade Playbook","excerpt":"Security patches stop on 31 October 2026, but Ubuntu 22.04 stays supported until April 2027 and Lambda keeps accepting updates until March. Four deadlines that do not line up, and the two that actually bite.","href":"/blog/2026/07/python-3-10-end-of-life-october-2026-upgrade-playbook","category":"Tooling","date":"Jul 14, 2026","reading":"10 min read","body":"Python 3.10 stops getting security patches on 31 October 2026, about ten weeks out. The reason this EOL matters more than the last few is boring: 3.10 is the default interpreter on Ubuntu 22.04 LTS. Every image, every EC2 instance nobody has touched since 2023, every base goes unpatched on the same day. What makes it confusing is that three other deadlines sit nearby and none of them match. Dates below came off the Python developer guide, the AWS Lambda runtime docs, and Canonical's release cycle page on 21 August 2026. Four deadlines around Python 3.10 end of life. On 31 October 2026 upstream security patches stop and the AWS Lambda python3.10 runtime is deprecated. On 1 February 2027 Lambda blocks creating new functions. On 3 March 2027 Lambda blocks updating existing functions. In April 2027 Ubuntu 22.04 standard support ends. Four deadlines that do not line up today 31 Oct 2026 CPython patches stop Lambda runtime deprecated 1 Feb 2027 Lambda blocks create 3 Mar 2027 Lambda blocks update Apr 2027 Ubuntu 22.04 support ends The gap between the first marker and the last is the trap. Your OS is supported, apt works, nothing looks broken, and the interpreter underneath has no upstrea"},{"title":"Mesh VPN Pricing in 2026: Your Bill Is a Device-to-User Ratio","excerpt":"Tailscale charges per seat, ZeroTier per device, NetBird per active user against a machine allowance, Twingate per person who can request access. The cheapest one flips as your infrastructure grows, and nothing about the products changes.","href":"/blog/2026/07/mesh-vpn-pricing-2026-tailscale-vs-netbird-vs-zerotier-vs-twingate-vs-netmaker","category":"Infrastructure","date":"Jul 13, 2026","reading":"10 min read","body":"The moment teams start shopping for a Tailscale alternative is predictable. You added twelve people, someone ran the annual number, and the thing you adopted because it beat standing up an OpenVPN concentrator is now a line item with a comma in it. Then the comparison goes wrong, because five vendors bill four different units and none of the pricing pages tell you which one your workload is expensive in. Your bill is mostly a function of your device to user ratio. Count both numbers and know which is growing faster before you sign anything. Prices below came off the vendor pricing pages on 22 August 2026. This category re tiers often, so check before you commit to a figure. Two architectures, and the pricing follows from them Two network models. A peer to peer mesh connects every node to every other node directly, so access is restricted only by the ACLs you write. A proxy based zero trust model chains a client through a relay and a connector to one published resource, so nothing is reachable until you publish it. Where the default sits Mesh: routable to everything, minus your ACLs client relay connector Proxy: one published resource at a time Tailscale, NetBird, ZeroTier, and Netm"},{"title":"Feature Flags 2026: LaunchDarkly Stopped Charging for Seats","excerpt":"LaunchDarkly now bills per server-side SDK connection and per client MAU with unlimited seats, which turns the old advice about moving evaluation server-side upside down. Unleash relicensed to AGPL in May and its open-source Edge dies on 31 December.","href":"/blog/2026/07/feature-flag-platforms-2026-launchdarkly-vs-flagsmith-vs-unleash-vs-posthog-vs-growthbook","category":"Tooling","date":"Jul 12, 2026","reading":"9 min read","body":"Three things changed in this category over the past few months, and none of them show up on a comparison grid. LaunchDarkly deleted per seat pricing. Its Developer plan now says \"Unlimited seats. No per seat pricing,\" and the paid Foundation tier says \"No platform or seat fees.\" What it bills instead is $10 per service connection per month, where a service connection is one server side SDK connected to one environment, plus $8.33 per thousand client side monthly active users on annual billing. Five service connections are included, then the meter starts. Read that meter twice if you have ever taken the standard advice about LaunchDarkly bills, which was to move flag evaluation out of the browser and into your backend so the MAU meter stops spinning. That advice is now half a bill. Server side evaluation is exactly what a service connection is, and every environment you evaluate in counts separately. Ten services across dev, staging, and production is thirty connections, $250 a month after the included five, before a single end user shows up. The second change is that Unleash relicensed. The third is that its open source edge proxy has a date on it. Both of those are worth their own"},{"title":"Bitbucket App Passwords Are Gone: Three Usernames, One Token","excerpt":"App passwords were removed on 28 July 2026. The migration is a thirty-minute swap per system, except for the part nobody documents in one place: which username goes with which credential. There are three answers and picking the wrong one returns 401 with a perfectly good token.","href":"/blog/2026/07/bitbucket-app-passwords-removed-july-2026-api-token-migration-playbook","category":"Tooling","date":"Jul 11, 2026","reading":"7 min read","body":"Bitbucket Cloud app passwords were removed on 28 July 2026, at the end of escalating brownouts that ran from 9 June. Creation had already been switched off back in September 2025, so if you went looking for the button recently and could not find it, that is why. If something of yours is still broken, it is probably not the token. It is the username. Three credentials, three usernames App passwords authenticated with your plain Bitbucket username everywhere, for Git and for the REST API alike. Nothing that replaces them does that, and the replacements do not agree with each other either. Credential Git over HTTPS REST API Atlassian API token your Bitbucket username, or your Atlassian account email Repository or workspace access token App password your Bitbucket username your Bitbucket username So a find and replace that swaps the secret value and leaves the username alone gives you a 401, and you will spend an hour convinced the token is bad. It is not. Two details in that table are worth pulling out. If you use your real Bitbucket username with an API token for Git, Atlassian's docs warn that it is case sensitive and has to match your account settings page exactly, which is a fun o"},{"title":"CDN Pricing in 2026: The Rate Card Is Not the Unit","excerpt":"Five providers, three volumes, list prices read off the vendors' own price files. The gap between the cheapest and the most expensive at 50 TB is 18x, and almost none of it comes from the per-GB number.","href":"/blog/2026/07/cdn-pricing-2026-cloudfront-vs-cloudflare-vs-fastly-vs-bunny-vs-akamai","category":"Infrastructure","date":"Jul 10, 2026","reading":"10 min read","body":"Every CDN comparison starts with per GB rates, and per GB rates are the least useful number on the invoice. CloudFront meters bytes and requests separately, with separate allowances. Bunny meters bytes only and charges nothing for requests. Cloudflare meters neither on its self serve plans, and instead restricts what kind of content you are allowed to serve. Fastly meters both but publishes rates for only the first 20 TB. Those are four different units, not four different prices. Comparing the rate cards compares the wrong thing. Below are three volumes costed out against each. Bandwidth and request rates for CloudFront come from the AWS price list file ( ) and the flat rate plan documentation, everything else from the vendors' pricing pages, all read on 22 August 2026. Arithmetic is mine and I have shown it where it matters. What each one counts Bytes Requests Other gate CloudFront pay as you go tiered per GB, per region $0.01 per 10,000 HTTPS none CloudFront flat rate monthly allowance monthly allowance 1 apex domain per plan Cloudflare self serve not metered not metered video and large files need Stream, Images, or the Developer Platform Bunny tiered per GB, per region not bille"},{"title":"Ubuntu 25.10 Is Obsolete and apt Still Reports Success","excerpt":"Launchpad marks 25.10 Obsolete, but the repositories are still on archive.ubuntu.com, frozen since July. So apt update succeeds, unattended-upgrades logs a clean run, and nothing on the machine tells you patches stopped.","href":"/blog/2026/07/ubuntu-25-10-end-of-life-upgrade-26-04-lts-playbook-2026","category":"Infrastructure","date":"Jul 8, 2026","reading":"8 min read","body":"Canonical's own tracker settles the question. Ask Launchpad about the series and it returns with . Ubuntu 25.10 shipped 9 October 2025, interim releases get nine months of updates, and that ran out in July. What did not happen is the thing most end of life advice describes. The repositories did not go away. The failure mode is silence, not errors is still serving today. Not , where dead releases eventually land. The live archive, returning 200, exactly as it did in June. What changed is that nothing is being published into it. Every suite's file carries the timestamp of its last change, which makes this checkable in one request per suite. Read on 23 August 2026: Suite Release file last dated (24.04 LTS) 23 Aug 2026 (26.04 LTS) 23 Aug 2026 (25.10) 20 Jul 2026 (25.10) 17 Jul 2026 (25.04) 19 Jan 2026 The supported releases changed today. 25.10 last changed five weeks ago. And 25.04, dead since January, is still on the live archive seven months later. Flow diagram showing that because the 25.10 repositories remain in place but frozen, apt update succeeds, reports zero upgradable packages, and unattended upgrades logs a clean run, so nothing on the machine signals that patching has stop"},{"title":"Next.js 16 Hydration Errors: One Rule, Seven Causes, and Two Myths","excerpt":"React 19 did not turn hydration warnings into errors. They were always errors. What changed is that you now get one message with a diff instead of five without one, which makes the bug findable.","href":"/blog/2026/07/nextjs-16-hydration-errors-react-19-causes-fixes-2026","category":"Tooling","date":"Jul 7, 2026","reading":"8 min read","body":"You upgraded to Next.js 16, ran the app, and the screen is red: The same code was fine on 15. Two things get repeated about this that are not true, and both send people down the wrong path. React 19 did not promote hydration warnings to errors. React 18 threw on mismatches too, with buried under a pile of duplicate warnings. What React 19 changed is the reporting: one error, with a diff showing which node differed and which side rendered what. The bug is not new. It just became findable. The second myth is that Partial Prerendering is on by default in Next.js 16 and is dragging mismatches into the light. It is not on by default. PPR now ships inside the flag, which you set yourself in , and turning it on removed the old flag and the route segment config. If you have not set , PPR is not what is happening to you. Versions here are Next.js 16.3.2 and React 19.2.8, checked on 22 August 2026. The one rule everything follows from Hydration compares exactly two renders: the markup the server produced, and the very first render on the client. That is the whole comparison window. A sequence showing the hydration comparison window. The server render and the client's first render sit inside "},{"title":"Best LLM Observability Tools in 2026: Langfuse vs LangSmith vs Braintrust vs Arize Phoenix vs Helicone","excerpt":"The category split into three different jobs, and each tool bills for a different thing. Which one is cheapest depends entirely on the shape of your team and your traffic.","href":"/blog/2026/07/best-llm-observability-eval-tools-2026-langfuse-vs-langsmith-vs-braintrust-vs-arize-phoenix-vs-helicone","category":"Infrastructure","date":"Jul 6, 2026","reading":"10 min read","body":"The agent worked in the demo. Then it shipped, someone asked it something slightly sideways, and it called the wrong tool three times before inventing a refund policy. Now you are looking at logs that show the final answer and nothing about how it got there. That is the afternoon people go shopping for an observability tool. The problem is that the category quietly split into three different jobs, and most comparisons are written by one of the vendors and pretend their tool does all three equally well. Prices below came off the vendor pricing pages on 21 August 2026. Three jobs, and why nobody aces all three Tracing is recording every step of a run: prompts, tool calls, retrieved chunks, latency at each hop, so you can replay a failure instead of guessing at it. This is what everyone needs first. Evals are scoring outputs systematically, offline against a dataset before deploy or online against live traffic. This is how you catch \"did my prompt edit make the summarizer worse.\" Hardest job to do well, and the one most teams underuse. Cost and latency is knowing which feature or customer or agent run is burning the tokens. Sounds trivial right up until the bill triples and nobody can"},{"title":"Splunk 9.3 Is Past End of Support: Which 10.x to Land On","excerpt":"9.3 went out on 24 July 2026 and 9.4 follows on 16 December, so the stepping-stone plan is gone. Splunk sells 24 months from a minor's release date, which makes the version you pick a purchase of months. The walls are the CPU, the certificates, and the forwarders.","href":"/blog/2026/07/splunk-enterprise-9-3-end-of-support-july-2026-upgrade-10-0-playbook","category":"Infrastructure","date":"Jul 6, 2026","reading":"8 min read","body":"Splunk Enterprise 9.3 reached end of support on 24 July 2026. No more security patches, no more bug fixes, and TAC will not take the ticket when your indexer cluster wedges at two in the morning. The advice everyone gave before that date was to hop through 9.4 first, on the theory that two small jumps beat one large one. That plan has expired. 9.4 goes out on 16 December 2026, which is under four months away, so the stepping stone now costs a full validation cycle and buys a single quarter before you do the whole thing again. Which leaves one real question, and it is not the one the version numbers suggest. Splunk sells months, and it starts the clock without you Each minor release is supported for 24 months from the date that minor shipped , not from the date you installed it. Splunk publishes both columns in the support policy, and lining them up changes what a version choice means. Support windows for Splunk Enterprise 9.3 through 10.4, drawn against a timeline. 9.3 ended 24 July 2026 and 9.4 ends 16 December 2026, both close to the present. 10.0 runs to July 2027, 10.2 to January 2028, and 10.4 to May 2028. Twenty four months from release, not from install 23 Aug 2026 9.3 24 Ju"},{"title":"ELT Pricing in 2026: The Unit Decides Which Data Is Expensive","excerpt":"Fivetran counts rows that changed and does not charge for the initial load. Estuary counts gigabytes and charges per connector instance in both directions. Airbyte stopped publishing its rate entirely. Five tools, five units, and the one that fits depends on how your biggest table churns.","href":"/blog/2026/07/fivetran-vs-airbyte-vs-stitch-vs-meltano-vs-estuary-elt-pricing-2026","category":"Data","date":"Jul 5, 2026","reading":"8 min read","body":"Every tool here will pull Salesforce, Postgres and Stripe into your warehouse. That is not the decision. The decision is that none of them agree on what they are charging you for, and the unit each one picked determines which shape of data is expensive for you. A 500 GB table where 2% of rows change each month is cheap on a row change meter and expensive on a gigabyte meter. A small table that updates constantly is the reverse. Neither vendor is cheaper; they are cheaper for different data. Prices below came off the vendor pricing pages and the GitHub API on 23 August 2026. What each ELT tool meters and which data pattern that punishes. Fivetran counts monthly active rows, so high churn tables are expensive while the initial load is free. Estuary counts gigabytes moved plus a monthly fee per connector instance, so large tables and wide pipelines are expensive. Stitch counts rows loaded in fixed tiers, so you pay for the tier ceiling rather than usage. Airbyte moved from volume pricing to capacity pricing and no longer publishes a rate. Meltano charges nothing and bills you in operations time. The meter picks the loser before you sync anything Fivetran rows that changed; the first f"},{"title":"containerd 1.7 End of Support: Migrating Kubernetes Nodes to 2.x","excerpt":"Security support for containerd 1.7 stops on 1 September 2026. Go to 2.3 rather than 2.0, convert your registry config before you touch the binary, and let the 1.7 deprecation warnings write your checklist.","href":"/blog/2026/07/containerd-1-7-end-of-support-migrate-containerd-2-kubernetes-2026","category":"Infrastructure","date":"Jul 2, 2026","reading":"8 min read","body":"Security only support for the containerd 1.7 branch ends on 1 September 2026. After that there are no CVE backports for the runtime under every pod on your nodes. If you are on managed Kubernetes, your provider is already handling most of this and has probably nudged you in the console. If you build your own nodes with kubeadm, kops, or a baked AMI, this one is yours. The jump from 1.7 to 2.x is not an . There are removed APIs, a renamed CNI key, and a registry config format whose migration path has a failure mode that takes the CRI plugin offline while the kubelet still reports Ready. Dates and version numbers below came off containerd's RELEASES.md and the GKE deprecation docs on 21 August 2026. Pick 2.3, and know why the others are traps The support table is the whole decision, and it is less forgiving than people assume. Remaining support windows for containerd branches as of 21 August 2026. Version 2.1 is already end of life since 3 July 2026. Version 1.7 ends 1 September 2026, 2.2 ends 6 November 2026, 2.0 ends March 2027, and 2.3 runs until 30 April 2028. Support remaining, from 21 August 2026 today 2.1 EOL ended 3 Jul 2026 1.7 1 Sep 2026, 11 days 2.2 6 Nov 2026 2.0 Mar 2027"},{"title":"RDS MySQL 8.0 Is on the Meter. MariaDB Has No Meter to Get On.","excerpt":"Extended Support for RDS MySQL 8.0 started billing on 1 August 2026 at $0.10 per vCPU-hour, standbys included. RDS for MariaDB was never eligible, which makes 31 December a harder deadline than any invoice.","href":"/blog/2026/07/rds-mysql-8-0-end-of-support-2026-extended-support-cost-upgrade-8-4","category":"Data","date":"Jul 1, 2026","reading":"9 min read","body":"If you run Amazon RDS for MySQL 8.0, the charge already started. RDS end of standard support for MySQL 8.0 was 31 July 2026, and per AWS's release calendar year one Extended Support pricing began the next day. Nothing shut off. A line item appeared. That is the usual shape of these deadlines and it is the easy case, because paying is an option. The harder case is the engine where paying is not an option, and most write ups about RDS deprecation never mention it. Extended Support exists for RDS for MySQL and RDS for PostgreSQL only. MariaDB is not on the list, is not in the price list, and does not get a paid grace period. Prices and dates below came off AWS's own docs and the us east 1 price list file on 22 August 2026. What happens after the RDS end of standard support date, split by engine. RDS for MySQL and PostgreSQL are auto enrolled into paid Extended Support at 0.10 dollars per vCPU hour, and opting out triggers an immediate automatic major version upgrade. RDS for MariaDB has no Extended Support offering, so the automatic upgrade is the only outcome. Past the end of standard support date, the engine decides Nothing shuts off. What differs is whether paying is an option. RDS"},{"title":"Self-Hosted Status Pages: Check the Commit Log First","excerpt":"One of these four has shipped nothing in fourteen months. Another closed multi-region monitoring as not planned. A third dropped its Cloudflare requirement and is now a docker compose file. The comparison tables have not caught up.","href":"/blog/2026/06/self-hosted-status-page-uptime-monitoring-2026-uptime-kuma-vs-gatus-vs-statping-ng-vs-openstatus","category":"Infrastructure","date":"Jun 29, 2026","reading":"7 min read","body":"A public \"are we up\" page plus uptime monitoring is a small enough job that self hosting it makes sense, and there are four tools people keep recommending for it. The recommendations are mostly repeating each other from 2024, and three of the four have moved since. So before any feature table, the check that decides the most: what has each project shipped lately. All figures below came from the GitHub API and each project's own repository on 23 August 2026. License Stars Latest release Commits since 23 May : : Uptime Kuma MIT 90,484 2.5.3, 22 Aug 2026 100+ Gatus Apache 2.0 11,882 v5.36.0, 19 May 2026 10 OpenStatus AGPL 3.0 9,005 untagged, pushed 21 Aug 2026 100+ Statping ng GPL 3.0 1,988 v0.93.0, 4 Jun 2025 0 That last row is the finding. Statping ng was the community continuation of an abandoned project, and the pitch for it was always \"the maintained fork.\" Its last release was fourteen months ago, its last commit to the default branch was the same day, and nothing has landed in the three months I looked at. Whatever it is now, it is not the maintained fork. I would not put a public status page on it, and the rest of this piece treats the choice as three way. A two axis chart. Th"},{"title":"SQL Server 2016 Is Past End of Life: Read the ESU Meter","excerpt":"Support ended 14 July 2026 and Extended Security Updates run to 17 July 2029. The escalating 75/150/300 percent table everyone quotes is not what the Azure meter charges, and waiting to subscribe does not save you a dollar.","href":"/blog/2026/06/sql-server-2016-end-of-life-july-2026-upgrade-azure-esu-cost-decision-guide","category":"Infrastructure","date":"Jun 26, 2026","reading":"8 min read","body":"Extended support for SQL Server 2016 ended on 14 July 2026. Microsoft's own ESU FAQ puts the paid bridge at three years past that, ending 17 July 2029, and the meter started running at midnight UTC on 15 July. Nothing shut off. Your instances still start, still accept connections, still take backups. What changed is that Microsoft ships nothing for them now, and that you can no longer open a support ticket at all, even with a paid support plan. Most of what is written about this decision quotes a table of escalating percentages: 75 percent of your license cost in year one, 150 in year two, 300 in year three. That table describes the Volume Licensing program. It is not what the Azure meter charges, and if you plan a budget from it you will be wrong in both directions. What the meter actually says Prices below came off the Azure retail price API on 23 August 2026, which is the same feed the pricing page renders from. Meter Rate Per core, per month (730 hours) : : $0.74 / hour $540.20 $0.19 / hour $138.70 Two things follow from that. The first is the minimum: ESU usage is metered on every core visible to the operating system environment, with a floor of four cores per OSE. So the smal"},{"title":"Passkeys in Production: Two Fields Say Who Needs a Second One","excerpt":"Your registration response already tells you whether the passkey the user just made will survive their next laptop. credentialDeviceType and credentialBackedUp turn the blanket advice to register two devices into a prompt for the people who actually need it.","href":"/blog/2026/06/passkeys-in-production-2026-webauthn-implementation-playbook-rp-id-account-recovery-windows-hello","category":"Tooling","date":"Jun 25, 2026","reading":"9 min read","body":"The WebAuthn ceremony is the easy part. You can wire registration and login in an afternoon. What eats two sprints is everything around it: getting the RP ID right, designing recovery that does not quietly reopen the phishing hole you just closed, and explaining to a user why the passkey from their old laptop is not on the new one. That last problem has a server side answer that most implementations throw away. returns two fields alongside the credential, and the package's own type documentation shouts about both of them in bold: , which is or , and , a boolean. Together they say whether the thing you just saved is going to exist after the user replaces the hardware. Three combinations of credentialDeviceType and credentialBackedUp from a WebAuthn registration response. singleDevice with backedUp false means the credential is bound to that device, so ask for a second one now. multiDevice with backedUp false means it is syncable but not yet synced, so nudge without blocking. multiDevice with backedUp true means it survives a new laptop, so leave the user alone. What the registration response already told you Two fields on registrationInfo, and what each combination means for recover"},{"title":"The Azure DevOps Issuer Is Deprecated: Find Yours Before 2027","excerpt":"Deprecation started 1 July 2026 and the issuer dies 1 July 2027. Nothing breaks in between, which is the problem. The issuer is not a documented field on the service connection, so finding every affected one means grepping the raw REST response.","href":"/blog/2026/06/azure-devops-issuer-retirement-2026-entra-issuer-migration-playbook","category":"Tooling","date":"Jun 23, 2026","reading":"7 min read","body":"If a pipeline run showed you a yellow banner on an Azure service connection sometime after 1 July, this is what it was about. Microsoft is retiring the Azure DevOps issuer for workload identity federation, and the published timeline is deprecation on 1 July 2026 and end of life on 1 July 2027. Nothing breaks on either of those dates except the second one. That is the entire difficulty. A year of warnings is long enough for the banner to become wallpaper, and the failure at the end is a pipeline that cannot authenticate to Azure, discovered by whoever is on call. What is changing, precisely Workload identity federation is how a pipeline authenticates to Azure without a stored secret: it presents a short lived OIDC token, and Azure trusts it because a federated credential on the identity says to. That credential pins two strings, an issuer and a subject, and both are changing. Comparison of the two issuers. The Azure DevOps issuer builds the federation subject from the organization, project, and connection names, so renaming any of them breaks the match. The Entra issuer builds it from immutable organization and service connection identifiers instead. The subject stops being a path m"},{"title":"Transactional Email 2026: SES Changed What Happens by Default","excerpt":"Amazon SES is the $0.10 per thousand everyone quotes. From 21 July 2026, new accounts start on a plan that charges $0.16, and the cheap number is something you opt into. Meanwhile the break-even against a managed provider is roughly ten times higher than the usual advice says.","href":"/blog/2026/06/best-transactional-email-api-2026-resend-vs-sendgrid-vs-postmark-vs-ses-vs-mailgun","category":"Infrastructure","date":"Jun 22, 2026","reading":"8 min read","body":"Every comparison of transactional email providers has the same first row: Amazon SES, $0.10 per thousand emails, cheaper than everything else by an order of magnitude. That number is still on the pricing page. It is no longer what a new account gets. SES now sells three plans. Essentials charges $0.16 per 1,000 emails for the first 10 million, Pro charges $0.22 plus $105 per account per region per month, Enterprise charges $0.23 plus $500. The old pay only for what you use rate is now labeled \"à la carte,\" and the footnote under the plan table says that new SES accounts, and account and region combinations with no metered activity since 1 June 2025, \"will start on the Essentials plan beginning July 21, 2026.\" You can switch to à la carte at any time. You just have to know to do it. Sixty percent is not a large absolute difference at small volume. It is a large difference in what the comparison table means, because the number everyone quotes is now the number you get by acting rather than the number you get by default. What the five actually cost A bar chart of monthly cost at 100,000 emails per month. Amazon SES à la carte is $10. Amazon SES on the Essentials plan is $16. Resend Pr"},{"title":"TypeScript 7 Shipped Without the API Your Tools Use","excerpt":"TypeScript 7.0 went GA on 8 July 2026 and type-checks VS Code in 10.6 seconds instead of 125.7. It also ships no compiler API until 7.1, and typescript-eslint's peer range still stops at 6.x. The upgrade is an install-both, not a swap.","href":"/blog/2026/06/typescript-7-go-native-compiler-tsgo-migration-2026","category":"Tooling","date":"Jun 21, 2026","reading":"7 min read","body":"TypeScript 7.0 is out. It went GA on 8 July 2026, and the first stable build on npm is , published that day. The compiler is written in Go now, and Microsoft's numbers for a full type check are the ones everyone quotes: VS Code from 125.7 seconds to 10.6, Sentry from 139.8 to 15.7, Playwright from 12.8 to 1.47. Memory went down between 6% and 26% depending on the project. That is not the interesting part any more. The interesting part is what happens when you actually run in a repo that lints. The gate is the compiler API, and it is not shipping until 7.1 From the release announcement: \"TypeScript 7.0 does not ship with an API.\" Not a reduced API, not an unstable one. The Go port does not expose the programmatic surface that has exported for a decade, and the plan is for that to arrive in 7.1. Anything that imports and walks the AST or asks the checker a question is built on that surface. You can see the consequence in the package metadata rather than having to guess at it. As of 22 August 2026, 8.67.0 declares its peer as , and 29.4.12 declares . Neither of them accepts TypeScript 7 at all. This is a loud failure at install time, not a subtle degradation later. The announcement na"},{"title":"Lambda vs Containers: The Break-Even Is 46% Duty Cycle, Not 15%","excerpt":"Run the two rate cards against each other and Lambda costs 2.15 times Fargate for the same CPU and memory, so it stays cheaper until the function is busy nearly half the time. Lambda Managed Instances lands within 1% of Fargate, which is not where the announcement pointed.","href":"/blog/2026/06/aws-lambda-vs-containers-cost-break-even-2026-lambda-managed-instances","category":"Infrastructure","date":"Jun 19, 2026","reading":"9 min read","body":"The usual version of this question is \"how many invocations before Lambda gets expensive,\" and it has no answer, because a 40ms function at 128 MB and an 8 second PDF render at 2 GB are the same invocation count and nowhere near the same bill. The question that does have an answer is what fraction of a continuously running machine your functions add up to. There is also a newer problem with the question. Lambda is not one pricing model any more. It is five, and three of them did not exist when most of the comparisons on this topic were written. Every rate below came from the AWS price list files for us east 1 and the Lambda pricing page on 22 August 2026. The five ways AWS Lambda bills as of August 2026. Functions, the default, charges per request plus GB seconds with CPU tied to the memory setting. MicroVMs charge vCPU seconds and GB seconds as separate meters. Managed Instances charge per request plus the EC2 on demand instance price plus a fifteen percent management fee. Durable Functions charge per durable operation, per GB written, and per GB month retained. Tenant isolation charges per GB of each new tenant isolated execution environment. Lambda now has five meters, not one T"},{"title":"Node 20 Is Past End of Life: Two Platforms, Two Clocks","excerpt":"Node 20 stopped getting patches on 30 April 2026. GitHub Actions forced every action onto Node 24 seven weeks later. AWS Lambda pushed its enforcement out to March 2027. Neither date is the one that was announced last year.","href":"/blog/2026/06/github-actions-node-20-deprecation-migrate-node-24-2026","category":"Tooling","date":"Jun 18, 2026","reading":"9 min read","body":"Node.js 20 reached end of life on 30 April 2026. That date comes from the release schedule in the nodejs/Release repo, it has been in there for years, and it is the least interesting date in this post. What matters is what each platform you deploy to decided that date meant. GitHub gave you seven weeks. AWS gave you ten months, after quietly moving its own deadline. Neither of them is running on Node's calendar, and neither of them is running on the calendar they published a year ago. Time from Node 20's end of life to each platform's enforcement date. GitHub Actions forced all actions onto Node 24 on 16 June 2026, 47 days after end of life. AWS Lambda blocks updates to nodejs20.x functions on 3 March 2027, 307 days after end of life. One dead runtime, two enforcement calendars Node 20 EOL, 30 Apr 2026 GitHub Actions 47 days, then every action runs on Node 24 AWS Lambda 307 days, then function updates are blocked today Apr 2026 Apr 2027 Dates from the GitHub Actions changelog and the Lambda runtime table, checked 22 August 2026. Both platforms moved these after first announcing them. GitHub Actions changed two different Node versions, and people keep merging them There are two Node"},{"title":"Free-Threaded Python 3.14: What Actually Decides If You Get Parallelism","excerpt":"I ran the same threaded workload on 3.14 and 3.14t on a 10-core laptop: 1.00x versus 3.53x on four threads. The interesting part is the two things that silently take that away, and neither of them is Python.","href":"/blog/2026/06/python-3-14-free-threaded-gil-removal-production-ready-2026","category":"Tooling","date":"Jun 16, 2026","reading":"9 min read","body":"Python 3.14 shipped on 7 October 2025 with free threading no longer marked experimental. The GIL was not removed. It was made optional, and you opt in by installing a second interpreter: , a separate binary with its own ABI tag and its own wheels. The question that matters is not whether the speedup is real. It is. The question is whether your process gets it, and that turns out to be decided by two things that have nothing to do with your code. I installed both builds and measured, then went looking for why the wins disappear in practice. Version numbers and release dates below were checked on 22 August 2026. What I measured Both builds are CPython 3.14.4 installed with , running on an M1 Pro MacBook Pro with eight performance cores and two efficiency cores. The workload is pure Python arithmetic (Collatz step counting over a 120,000 integer range per thread), best wall time of five runs, threads started with . Threads GIL build Free threaded build 1 0.778s (1.00x) 0.759s (1.00x) 2 1.561s (1.00x) 0.779s (1.95x) 4 3.124s (1.00x) 0.861s (3.53x) 8 6.247s (1.00x) 1.343s (4.52x) The GIL column is the whole argument in one column. Doubling the threads doubles the wall time, every time, "},{"title":"AI SRE Agents 2026: Five Products, Five Different Meters","excerpt":"One bills agent-seconds, one bills AI credits at roughly 6.5 per investigation, two bill seats, and one will not tell you. The word agent got stretched across five product shapes, and the meter is the fastest way to work out which one you are looking at.","href":"/blog/2026/06/ai-sre-agents-2026-aws-devops-agent-vs-datadog-bits-vs-pagerduty-vs-incident-io-vs-resolve-ai","category":"Infrastructure","date":"Jun 15, 2026","reading":"8 min read","body":"Five vendors sell something called an AI SRE. They do not sell the same thing, and the feature grids are built to obscure that. The quickest way through the fog is not the feature list. It is the meter, because what a vendor decided to count tells you what they think they are selling. AWS DevOps Agent counts agent seconds. Datadog counts AI credits, about 6.5 per autonomous investigation. PagerDuty counts seats and hands you a bundle of AI Actions with them. incident.io counts seats and does not meter the AI at all. Resolve AI counts something, but you will need a sales call to find out what. Estimated monthly cost for twenty engineers handling sixty incidents a month. AWS DevOps Agent about $299 assuming ten agent minutes per incident and before support credits. Datadog Bits Investigation $500 for one credit bundle, not counting Datadog ingest. PagerDuty Business $820. incident.io Pro with on call $900. Resolve AI does not publish a price. 20 engineers, 60 incidents a month AWS DevOps Agent $299 Datadog Bits Investigation $500 PagerDuty Business $820 incident.io Pro + on call $900 Resolve AI no published price Seat prices are annual billing rates. The AWS figure assumes ten agent "},{"title":"Best AI for Excel & Google Sheets in 2026: Claude vs Copilot vs ChatGPT vs Julius vs Gemini","excerpt":"Formula correctness, messy-data cleaning, and what leaves your tenant. Which spreadsheet AI to reach for depends mostly on where your data already lives.","href":"/blog/2026/06/best-ai-for-excel-google-sheets-2026-claude-vs-copilot-vs-chatgpt-vs-julius-vs-gemini","category":"Data","date":"Jun 13, 2026","reading":"6 min read","body":"Most knowledge work happens in a spreadsheet, and 2026 is the year the model vendors stopped treating that as somebody else's problem. Anthropic put Claude inside Excel, Word, and PowerPoint and took it to general availability on paid Claude plans, with Outlook added so a single conversation can follow you across all four. Microsoft made its own agentic Word, Excel, and PowerPoint features generally available on 22 April, and opened the model selector so you can put Claude behind Copilot instead of OpenAI. Google shipped a Gemini in Sheets that scores 70.48% on SpreadsheetBench. And the upload based tools, ChatGPT's data analysis and Julius, kept getting sharper at the thing they were always good at. They are not interchangeable. Which one you want depends on whether you care most about formula correctness, staying inside your existing files, or just getting an answer out of a data dump. Checked against vendor pages on 21 August 2026. Pricing in this category changed twice while I was writing. Formula accuracy is the thing that breaks trust This is the widest gap and the one most roundups skip, because testing it is tedious. A formula that is 90% right is worse than no formula. You"},{"title":"Agent Memory in 2026: Four Tools, Four Different Meters","excerpt":"Mem0 bills add and retrieval requests, Zep bills credits, Letta bills active agents and seconds of tool execution, Cognee bills tokens ingested. All four are Apache-2.0, so the meter matters more than the feature list.","href":"/blog/2026/06/ai-agent-memory-2026-mem0-vs-zep-vs-letta-vs-cognee","category":"Data","date":"Jun 12, 2026","reading":"7 min read","body":"Agent projects hit the same wall in week three. The demo works, someone closes the chat, opens a new one, and the agent has no idea who they are. A larger context window does not fix it. Context is what the model can see in this turn; memory is what survives the session ending. So you go looking for a memory layer and end up with four tabs open: Mem0, Zep, Letta, Cognee. They all say \"persistent memory for agents\" and they are not the same product. Two of them are a service you call, one is an agent runtime you build inside, and one is a pipeline that turns documents into a graph. They also bill on four incompatible units, which is the part that decides what this costs you at scale. Prices below came off each vendor's pricing page on 22 August 2026. What a memory layer does, and the part that is hard Three jobs: decide what is worth keeping from a conversation, store it durably, and pull the relevant piece back when it matters. Storage is the easy third. Any vector store holds embeddings. The hard parts are extraction and retrieval. Extraction has to know that \"actually, make it dairy free\" replaces \"add extra cheese\" rather than sitting next to it. Retrieval has to surface that tw"},{"title":"Postgres Connection Pooling in 2026: PgBouncer vs PgCat vs Supavisor vs RDS Proxy vs Pgpool-II","excerpt":"Picking a Postgres pooler is mostly picking a pooling mode and living with what it breaks. Five options, what each one is actually for, and the setting that stopped being a footgun.","href":"/blog/2026/06/postgresql-connection-pooling-pgbouncer-vs-pgcat-vs-supavisor-vs-rds-proxy-vs-pgpool-2026","category":"Data","date":"Jun 12, 2026","reading":"8 min read","body":"If you got here from , the fix is a connection pooler and you already suspect that. The part that costs a weekend is the pooling mode, not the tool. Postgres forks a full OS process per connection. Not a thread, a process, with its own memory before it has run a single query. Several hundred idle connections can hold gigabytes and burn CPU on context switches while doing nothing at all. Managed instances cap you accordingly, usually far lower than people expect, and then a serverless fleet scales to a few hundred concurrent executions that each want their own connection. The connections are not busy. They are just there, holding slots. A pooler breaks the link between \"the app wants a connection\" and \"Postgres spawns a backend.\" Ten thousand clients can share fifty backends, if the workload allows it. Everything below is about that last clause. Versions and defaults here were checked against vendor docs and the GitHub release APIs on 21 August 2026. Modes, and what each one costs you Session pooling hands a client one backend for the life of its connection. Nothing breaks, because nothing is shared. It also barely helps, since an idle client still squats on a backend. Transaction p"},{"title":"Amazon Linux 2 Is Past End of Life: The AL2023 Migration in Practice","excerpt":"AL2 stopped getting security updates on 30 June 2026. The upgrade is not a version bump, it is a different distribution, and these are the specific pieces that break.","href":"/blog/2026/06/amazon-linux-2-end-of-life-al2023-migration-2026","category":"Infrastructure","date":"Jun 11, 2026","reading":"4 min read","body":"Amazon Linux 2 reached end of support on 30 June 2026. Instances still boot, workloads still run, and nothing about that changed on 1 July. What changed is that the next kernel or OpenSSL advisory will not arrive as a package for you. The awkward part is that AL2023 is not AL2 with newer packages. It is built from a different upstream lineage, uses a different package manager, a different init story for several services, and a different set of defaults. Treating it as a version bump is how migrations end up half finished in a stuck Auto Scaling group. Details below were checked against AWS documentation on 21 August 2026. What you get for the work AL2023 is supported for five years, which puts the next deadline in 2029, and it has the modern package versions and a FIPS certification story that AL2 does not. The more useful difference for day to day operations is deterministic upgrades. AL2023 pins to a specific repository version at launch, so two instances launched from the same template a month apart get the same packages unless you deliberately move the version. AL2's behavior of installing security updates at boot meant that a scaling event could introduce a package change nobo"},{"title":"Terraform: Error Acquiring the State Lock, and the Config That Silently Takes No Lock","excerpt":"How to read the lock block before you break it, when to clear a DynamoDB record by hand, and the migration to S3-native locking that has one combination which locks nothing and warns about nothing.","href":"/blog/2026/06/fix-terraform-error-acquiring-state-lock-force-unlock-s3-lockfile","category":"Infrastructure","date":"Jun 10, 2026","reading":"9 min read","body":"A CI job dies partway through an apply, and every run after it stops at the same wall of text. Nothing is broken. Terraform is refusing to let two processes write the same state file, which is its job. The process holding the lock died without cleaning up, so the lock sits there blocking everyone. There is a safe way out and an unsafe one, and the unsafe one can leave you with a half merged state file. Behavior below was read from the S3 backend documentation and the backend source in on 22 August 2026. Read the lock block before you touch it That block is not boilerplate. Four fields decide whether this lock is safe to break. is what you feed to , copied exactly. is the user and host that took it, so a from a job your dashboard shows as dead is a stale lock, and your coworker's laptop while they are online is not. matters because means resources may have changed without state being written back, while is harmless to break. is the field people skip and the one that decides it. Compare it to now. Four hours old against a ninety second apply means the process is gone. Forty seconds old means slow down, because something may genuinely be running and breaking a live lock is how state g"},{"title":"Spring Boot 3.5 Is Past End of Life: What the 4.0 Migration Actually Breaks","excerpt":"The last open source 3.5 release shipped in June and nothing has followed it. Here is the real list of what changes on the way to 4.x, in the order it will bite you.","href":"/blog/2026/06/spring-boot-3-5-end-of-life-spring-boot-4-migration-what-breaks-2026","category":"Tooling","date":"Jun 7, 2026","reading":"4 min read","body":"Spring Boot 3.5 reached the end of its open source support window on 30 June 2026. The last community release was 3.5.16 on 25 June, and the release feed has carried nothing for the 3.5 line since. If you are still on it, you are running a version that will not receive a fix for the next CVE unless you are paying for commercial support. That changes the shape of the decision. This was a scheduling problem in the spring and it is a risk problem now, which usually means it stops competing with feature work for attention and starts competing with incidents. Release information here was checked against the Spring Boot release feed and the project's migration guide on 21 August 2026. The current line is 4.1.x, with 4.0.x still receiving patches. Decide between 4.0 and 4.1 first There are two supported targets, and picking the wrong one adds a second migration. 4.0 is the version that carries every breaking change described below. 4.1 builds on it and is where the ongoing work is happening. If you are starting the migration now rather than in April, going straight to 4.1 is usually right: the breaking changes are identical, and you land on the line that will keep receiving features rathe"},{"title":"Cloud GPU Pricing in 2026: What an H100 Hour Actually Costs","excerpt":"Per-GPU hourly rates off the vendor pages, and the thing the rate sheet gives away: the cheap-to-expensive order is not the same on Blackwell as it is on Hopper.","href":"/blog/2026/06/cloud-gpu-pricing-2026-runpod-lambda-coreweave-vast-vs-aws-gcp-azure","category":"Infrastructure","date":"Jun 6, 2026","reading":"9 min read","body":"Here is the number you came for, per GPU per hour, taken off each vendor's own pricing page on 22 August 2026. H100 SXM H200 B200 B300 : : : : RunPod Community $2.69 $3.59 $5.98 $6.94 RunPod Secure $3.29 $4.59 $6.79 $7.89 Lambda $3.99 not listed $6.69 not listed AWS Capacity Blocks $5.19 $5.97 $12.36 $14.04 CoreWeave $6.16 $6.31 $8.60 contact sales The AWS column is Capacity Blocks for ML divided by eight, since those are whole node reservations: at $41.528 an hour, at $47.76, at $98.84, at $112.32, all US East. Lambda and CoreWeave are eight GPU instances divided the same way. RunPod rents single GPUs, and its H100 PCIe is cheaper still at $1.99 on Community and $2.89 on Secure, which is a different chip from the SXM part in the table and not a cheaper way to buy the same thing. Now look at the shape of it rather than the digits. The order changes between generations On H100, the ladder runs the way everyone says it does, except at the top. RunPod Community is the floor, CoreWeave is the ceiling, and AWS sits between Lambda and CoreWeave. A hyperscaler reservation is not the most expensive H100 hour on this table. CoreWeave is. On B200, that inverts. AWS Capacity Blocks costs $12."},{"title":"HCP Terraform's Free Tier Ended in March. Now Read the Meter","excerpt":"You are already on the enhanced Free tier, and the question is what happens at 500 resources. The alternatives repriced hard since March, and one of them now starts at $20,000 a year.","href":"/blog/2026/06/hcp-terraform-free-tier-eol-migration-spacelift-scalr-env0-atlantis-opentofu-2026","category":"Infrastructure","date":"Jun 4, 2026","reading":"7 min read","body":"HashiCorp retired the legacy HCP Terraform free plan on 31 March 2026 and moved every organization still on it to the enhanced Free tier. That date is behind us, so this is no longer a deadline post. It is a \"you are already there, now what\" post, and the answer changed over the summer because the alternatives repriced. The enhanced tier flips the model. The legacy plan counted users and capped them. The new one gives you unlimited users and up to 500 managed resources, and it throws in SSO, policy as code with Sentinel and OPA, run tasks, and agents, which the legacy plan did not have. For a homelab or a side project it is a genuine upgrade. The catch is how fast 500 resources goes. A managed resource is anything in state where , counted from the first plan or apply. That is not the EC2 instances you think about. It is every subnet, route table, IAM policy attachment, security group rule, and CloudWatch alarm that came along with them. One moderately complex environment can clear 500 by itself. And the move to the enhanced tier does not reverse. Plans and prices below came off the vendor pricing pages on 22 August 2026. First, pull your state Before you evaluate anything, back up "},{"title":"Two of the Three Secure Boot Certificates Already Expired. The Third Is 19 October.","excerpt":"Nothing bricked in June, because UEFI checks whether a certificate is in the database, not whether it is still valid. What expiry actually took away is the ability to sign, and the Windows boot manager is the last one holding.","href":"/blog/2026/06/secure-boot-certificate-expiration-2026-playbook-windows-linux-vms-ci","category":"Infrastructure","date":"Jun 3, 2026","reading":"8 min read","body":"The Secure Boot certificates that have been in x86 firmware since 2011 came with expiry dates, and two of the three passed in June. Microsoft Corporation KEK CA 2011 expired on 24 June 2026, Microsoft UEFI CA 2011 on 27 June. Nothing bricked. Nobody's laptop refused to POST, and the machines that had not been updated kept booting exactly as before. That was always going to happen, and understanding why is the whole thing. The last of the three, Microsoft Windows Production PCA 2011, expires on 19 October 2026, which is eight weeks out. Dates below came off Microsoft's certificate expiration page and Red Hat's guidance on 22 August 2026. A timeline across 2026. Microsoft Corporation KEK CA 2011 expired on 24 June 2026 and Microsoft UEFI CA 2011 on 27 June 2026, both already in the past as of 22 August 2026. Microsoft Windows Production PCA 2011 expires on 19 October 2026, still ahead. Expiry removes the ability to sign new binaries under the 2011 chain; it does not stop already signed binaries from booting. The 2011 chain, one date at a time 19 Oct 2026 Windows Production PCA 2011 24 + 27 Jun 2026 KEK CA 2011, UEFI CA 2011 today Jan 2026 Jan 2027 Behind you: nothing can be signed un"},{"title":"What Coding Agents Actually Charge You in 2026","excerpt":"Claude Code, Codex, Copilot, Cursor, Gemini CLI, and Grok Build meter your work in four incompatible ways. The meter, not the model, is what decides your bill.","href":"/blog/2026/06/terminal-coding-agents-grok-build-vs-claude-code-vs-codex-cli-vs-gemini-cli-2026","category":"Tooling","date":"Jun 2, 2026","reading":"7 min read","body":"Every comparison of coding agents ranks the models, and every one of those rankings is stale within a quarter. The part that stays true longer is the billing model, because changing it annoys customers and vendors do it rarely. There are four meters in this market right now, and which one you are standing on explains almost everything about how your month goes: an opaque usage multiplier attached to a seat, dollar denominated credits, a free request quota, and raw tokens. All prices below came off vendor pricing pages on 21 August 2026. This category reprices often, so treat the numbers as a snapshot and the structure as the durable part. The four meters The same hour of agent work billed four ways: against an invisible seat allowance, against a dollar denominated credit balance, against a free daily request quota, and against raw token spend One hour of agent work, billed four ways Seat plus a multiplier Dollar credits Free request quota Raw tokens Claude Code, Codex, Cursor GitHub Copilot Gemini CLI Grok Build, or any API key invisible until you hit the end $0.01 a credit 1,000 a day, then it stops priced per million tokens Only two of these four tell you what the task cost while"},{"title":"Kubernetes 1.35 and cgroup v1: What Broke, and What Did Not","excerpt":"The kubelet stopped starting on cgroup v1 in 1.35, and one line of config still turns that off. The code is not gone, no removal release has been named, and the deadline that actually costs you money is somewhere else.","href":"/blog/2026/06/kubernetes-1-35-cgroup-v1-removed-migration-playbook-2026","category":"Infrastructure","date":"Jun 1, 2026","reading":"8 min read","body":"A node comes up, the kubelet exits, the node never goes Ready, and the log line says something about cgroup v1 being deprecated. That is Kubernetes 1.35 doing exactly what it said it would do. What 1.35 changed is one default. The kubelet config field flipped from to , so a kubelet that finds a cgroup v1 hierarchy at refuses to start instead of warning and continuing. The 1.35 changelog files it under ACTION REQUIRED: \"nodes will not start on a cgroup v1 by default. This puts cgroup v1 into a deprecated state.\" Then there is the part that most write ups get wrong, including the one I am rewriting here. Versions, dates and prices below were checked against vendor documentation on 22 August 2026. The cgroup v1 code is still in the kubelet The common claim is that the v1 code paths disappear in the next release, so the override buys you one cycle. That is not what happened. KEP 5573 graduated to beta in 1.35, and its own removal section is still marked unresolved: \"Once all supported releases of Kubernetes have set to true, we can begin the removal of the cgroup v1 support.\" No release is named. Upstream still runs a cgroup v1 test lane and still treats regressions in it as cherry pic"},{"title":"Valkey vs DragonflyDB vs Redis in 2026, and Whether You Need Any of Them","excerpt":"The license fight that started the fork has quietly changed again. Here is where the three engines actually differ, and why a lot of Redis deployments are a cache, a queue, and a channel that Postgres already handles.","href":"/blog/2026/05/valkey-vs-dragonflydb-vs-redis-2026","category":"Data","date":"May 31, 2026","reading":"6 min read","body":"Two years after Redis changed its license and the fork happened, the situation people remember is out of date. It is worth restating what is true now before deciding anything, because the license was the entire reason many teams moved. Everything below was checked against the projects' own license files and release feeds on 21 August 2026. Where the licenses actually stand Redis since version 8 is tri licensed: you may take it under the Redis Source Available License v2, the Server Side Public License v1, or AGPLv3. The AGPL option is an OSI approved open source license, which means the plain claim that Redis is no longer open source stopped being accurate. Current release is 8.10.1. Valkey is BSD 3 Clause, the license Redis had before all this, and is the Linux Foundation stewarded continuation of that lineage. Current release is 9.1.1. DragonflyDB is under the Business Source License 1.1, which is source available rather than open source: free for most uses, with a restriction on offering it as a competing managed service, converting to an open license on a schedule. If your migration off Redis was motivated purely by licensing, the AGPL option may make that migration unnecessary"},{"title":"Agent Frameworks in 2026: LangGraph, CrewAI, Agents SDK, Pydantic AI, Mastra","excerpt":"They have converged on the same loop, so the choice is about the shape of orchestration you want and whether the project is still where its vendor invests. One popular answer has already been superseded.","href":"/blog/2026/05/ai-agent-frameworks-langgraph-crewai-openai-agents-pydantic-mastra-2026","category":"Infrastructure","date":"May 30, 2026","reading":"7 min read","body":"Every one of these frameworks wraps the same loop: send messages, get a tool call, run the tool, send the result back, repeat until the model stops asking. You can write that loop yourself in an afternoon, and for a single agent with three tools you probably should. What the frameworks sell is everything around the loop: state that survives a crash, a way to describe control flow that is not a pile of if statements, retries, streaming, tracing, and human approval steps. Which of those you need is the actual question, and it has more to do with how your agent fails than with which model you call. Repository activity and licenses below were checked on 21 August 2026. Check who is still investing before you check features AutoGen is the cautionary tale of this cycle. It shows up on most recommendation lists, and Microsoft has since folded it and Semantic Kernel into Microsoft Agent Framework, which reached release candidate in February 2026 for both .NET and Python. Microsoft publishes a migration guide from AutoGen, and the AutoGen repository has not seen a push since April. Existing projects keep working; new ones should start on the successor. The rest are all active and permissive"},{"title":"Self-Hosted Observability in 2026: What You Save and What You Pay Instead","excerpt":"Datadog bills per host, Grafana and SigNoz bill per GB, Sentry bills per event. Running it yourself replaces all three with storage and your own time, and the license fine print decides whether you can.","href":"/blog/2026/05/self-hosted-opentelemetry-signoz-grafana-lgtm-openobserve-uptrace-2026","category":"Infrastructure","date":"May 29, 2026","reading":"6 min read","body":"Observability bills grow faster than traffic, and the reason is rarely the vendor. It is that instrumenting more is always the locally correct decision. Every new label, every debug span, every retained log line is defensible on its own, and the aggregate arrives as a surprise once a quarter. Switching vendors changes the slope of that curve. Cutting what you emit changes the curve itself. It is worth being clear about which one you are doing, because most migrations are sold as the second and deliver the first. All prices below came off vendor pricing pages on 21 August 2026. Three units, three different bills Datadog prices infrastructure per host: $15 per host per month on Pro with annual billing, $23 on Enterprise, and APM stacked on top of that starting at $31 per host. Logs split into ingestion at $0.10 per GB and indexing at $1.70 per million events, which is the line that surprises people, because ingestion is cheap and making those logs searchable is not. Grafana Cloud prices by volume instead: a free tier with 50 GB of logs, 50 GB of traces, and 10k active metric series at 14 day retention, then a $19 platform fee and per GB rates for processing, writing, and retention. S"},{"title":"Ingress-NGINX Is Archived: Reading the CVE Log Before You Migrate","excerpt":"The repository was archived on 23 March 2026 with a CVE published the same day as its final release. Seven landed in the ten weeks before that, all the same shape, and that shape is exactly what makes the migration hard.","href":"/blog/2026/05/ingress-nginx-retired-migration-traefik-envoy-gateway-kong-2026","category":"Infrastructure","date":"May 28, 2026","reading":"8 min read","body":"The repository is archived. Not deprecated, not in maintenance mode: archived, read only, on 23 March 2026. The final release, , went out four days earlier. Its own README now describes the project in the past tense and tells you to go pick a Gateway API implementation instead. The usual framing for this is that you are now exposed to some hypothetical future CVE. That framing understates it, and the fix is to read the actual advisory record rather than reason about risk in the abstract. Seven CVEs in ten weeks, and the last one shipped on closing day Searching NVD for on 22 August 2026 returns twenty advisories. Seven of them were published in 2026, all in a ten week stretch ending the day the project shut down. Published CVE CVSS Trigger : 3 Feb 2026 CVE 2026 1580 8.8 annotation 3 Feb 2026 CVE 2026 24512 8.8 field 3 Feb 2026 CVE 2026 24513 3.1 annotation protection bypass 3 Feb 2026 CVE 2026 24514 6.5 validating admission controller 6 Feb 2026 CVE 2025 15566 8.8 annotation 9 Mar 2026 CVE 2026 3288 8.8 annotation 19 Mar 2026 CVE 2026 4342 8.8 a combination of annotations Five of the seven share a description almost word for word: an Ingress annotation can be used to inject configu"},{"title":"Commitment Discounts in 2026: Read the Exclusion List First","excerpt":"Savings Plans, Reserved Instances, and Spot all advertise a percentage. The number that decides your bill is the list of things the discount never touches, and both AWS and Azure moved that line this year.","href":"/blog/2026/05/aws-savings-plans-vs-reserved-instances-vs-spot-2026","category":"Infrastructure","date":"May 26, 2026","reading":"11 min read","body":"Every commitment discount is sold as a percentage. Up to 72%, up to 66%, up to 90%. Those numbers are real and they are also the least useful thing on the page, because they describe the best case for a slice of your bill rather than the bill. The number that decides what you actually pay is the scope. Which services the discount reaches, which ones it silently skips, and which line items sit permanently outside every commitment you can buy. That is where the surprises live, and this year both major providers moved the boundary: Azure stopped selling reservations for a list of VM series on 1 July 2026, and AWS shipped EKS charges that no Savings Plan will ever discount. Prices and policy below came off the vendor documentation on 22 August 2026. Pull your own rates before you commit money. AWS: three instruments, and one of them is not a commitment Savings Plans are a pledge to spend a fixed dollar amount per hour for one or three years. You do not pick instances. You pledge, say, $5 an hour of compute, and AWS applies the discount to whatever eligible compute you run up to that amount. Compute Savings Plans span instance family, size, OS, tenancy, and region. EC2 Instance Savings "},{"title":"Docker Exit Code 137 (OOMKilled): Causes and Real Fixes","excerpt":"137 is 128 plus SIGKILL, and raising the memory limit is the right fix for exactly one of the four things that send it. Two commands tell you which one you have.","href":"/blog/2026/05/fix-docker-exit-code-137-oomkilled-container-killed","category":"Infrastructure","date":"May 25, 2026","reading":"10 min read","body":"The container was running fine, and then it was not. The logs cut off mid sentence. shows exit code 137. No stack trace, no graceful shutdown, nothing in the application logs explaining anything. That abruptness is the clue. Exit code 137 means the process did not decide to quit. Something killed it from outside with SIGKILL, the one signal a process cannot catch or ignore. Nine times in ten that something is the Linux OOM killer. Not always, though, and raising the memory limit without checking which case you are in is how people end up paying for 8GB containers that still die. exit 137 128 + 9, a SIGKILL landed docker inspect .State.OOMKilled true false hit its own limit dmesg grep i oom dies fast, every time sawtooth over hours no cgroup line no oom line at all limit too low right size it memory leak profile it host ran dry limit every container someone killed it stop timeout, probe Two commands split 137 into four causes. Raising the memory limit is the right fix for exactly one of them. Where 137 comes from A process terminated by a signal exits with . SIGKILL is 9, so 128 + 9 = 137. There is no Docker specific magic in it. The decoding works for the whole family. 143 is 128 +"},{"title":"Best AI Code Security Tools in 2026: Snyk vs Semgrep vs Endor Labs vs Socket vs Aikido vs GitHub Advanced Security","excerpt":"Agents ship vulnerabilities faster than anyone can review them. SAST, SCA, and package firewalls compared, plus why the hallucinated dependency is the door people leave open.","href":"/blog/2026/05/best-ai-code-security-tools-2026-snyk-semgrep-endor-labs-socket-aikido","category":"Tooling","date":"May 24, 2026","reading":"7 min read","body":"The uncomfortable arithmetic that landed on security teams this year: developers commit several times more code than they did before agents, and AI generated code carries roughly 2.7 times the vulnerability density of code written by hand. Multiply those and you get a backlog that grows faster than any human review process drains it. That is the problem this category is trying to solve. Not \"is this code readable,\" which is what PR review is for. This is \"did the agent just hand me a SQL injection, a leaked key, or a dependency that does not exist.\" The tools worth paying for are not bolting a model onto a decade old scanner. They changed what gets flagged, what gets suppressed, and what happens before the agent commits. Checked on 21 August 2026. Why the old playbook stopped working Veracode's 2026 GenAI code security testing puts the average security pass rate across models at 56%, essentially flat against 55% the year before. Forty four percent of code generation tasks introduced a real vulnerability. The variance by class is the interesting part: SQL injection passes 83% of the time and cryptographic algorithm choice 87%, while cross site scripting passes 15% and log injection "},{"title":"uv vs Poetry vs pip vs PDM: Python Package Managers in 2026","excerpt":"I timed the same 59-package install four ways: pip takes 15 seconds warm, uv takes half a second. Plus what the OpenAI acquisition actually changes, and the lockfile standard nobody mentions.","href":"/blog/2026/05/uv-vs-poetry-vs-pip-vs-pdm-python-package-manager-2026","category":"Tooling","date":"May 23, 2026","reading":"8 min read","body":"The download counts have stopped being close. On PyPI, uv is pulling about 203 million downloads a month against Poetry's 80 million as of 21 August 2026. Two years ago uv did not exist. People do not switch package managers for entertainment, so a swing that size is reporting something. What it is reporting is mostly speed, so let me put a real measurement up before the opinions. What I measured I timed the same install four ways on an Apple silicon Mac against Python 3.14: 20 top level requirements for an ordinary web service, Django and DRF and Celery and SQLAlchemy and boto3 and pandas and the usual test tooling, which resolve to 59 packages. Each run went into a fresh virtualenv. uv was 0.11.6, pip was 26.0. Measured install times for 59 packages into a fresh virtualenv: pip with no cache 17.4 seconds, pip with a warm cache 15.2 seconds, uv with a cold cache 3.0 seconds, uv with a warm cache 0.5 seconds 59 packages into a fresh virtualenv Apple silicon, Python 3.14, uv 0.11.6, pip 26.0, one run each pip, no cache 17.4s pip, warm cache 15.2s uv, cold cache 3.0s uv, warm cache 0.5s pip barely benefits from its cache here; uv's warm path is 30 times faster than pip's. My own numb"},{"title":"Fix CORS Errors: Where the Wildcard Stops Being a Wildcard","excerpt":"The server already ran your handler. What is left is a permission header, and the star you pasted into it means four different things depending on the request. Next.js, Express, FastAPI and Django defaults compared, plus the failure no header can fix.","href":"/blog/2026/05/fix-cors-error-nextjs-express-fastapi-django","category":"Tooling","date":"May 22, 2026","reading":"9 min read","body":"The console line is specific, and almost nobody reads it as specific: . That is a sentence about a missing response header. It is not a sentence about your request being rejected. The Express package's own README puts it bluntly: your server receives and processes every request, and the headers only decide whether JavaScript gets to read the answer. Which is why the first fix everyone reaches for, pasting into the header, works right up until it does not. The star stops behaving like a star in at least four places, and three of them produce error messages that look identical to the one above. Everything below was checked against the current framework docs and package sources on 22 August 2026. Two failure points in a cross origin request. A simple request such as a GET or a form encoded POST is sent to the server, the handler runs, the server responds, and only then does the browser check the headers and withhold the body from JavaScript, meaning the write already happened. A preflighted request such as one with a JSON body, an Authorization header, or a PUT or DELETE method sends an OPTIONS request first, and if the answer is missing or wrong the real request is never sent and the"},{"title":"Postgres Backup Tools in 2026: Read the Release Log First","excerpt":"pgBackRest nearly lost its maintainer in April and is shipping again. The scare pointed at the two questions worth asking about any of these four tools: who keeps it alive, and who computes the incremental.","href":"/blog/2026/05/postgresql-backup-tools-wal-g-barman-pgbackrest-pg-probackup-2026","category":"Data","date":"May 21, 2026","reading":"9 min read","body":"For about three weeks last spring the most widely deployed PostgreSQL backup tool looked finished. David Steele, pgBackRest's creator and effectively its only maintainer, announced on 27 April 2026 that he was stopping. Crunchy Data had paid for his time for years, the acquisition ended that, and no replacement showed up. Then on 18 May it un ended, with a group of sponsors funding the work instead of one company. The part worth checking is not the announcement. It is whether anything shipped afterward. It did. pgBackRest released 2.59.0 on 20 July 2026 and 2.59.1 on 17 August, after 2.58.0 in January. The sponsor list on pgbackrest.org has grown from the six announced in May to nine: AWS, Supabase, pgEdge, Tiger Data, Percona, Eon, Xata, Dalibo, and Data Egret, with Crunchy Data and Resonate listed as past sponsors. So the answer to \"should I migrate off pgBackRest\" is no, and the migration a lot of people half started in May was solving a problem that stopped existing. What the scare was actually good for is that it made people ask a question they had not asked in years. Repository state below was read from the GitHub API and vendor documentation on 22 August 2026. The release lo"},{"title":"Neon vs PlanetScale vs Turso vs Supabase vs Firebase in 2026","excerpt":"Four of these are not the same product, and the free tiers fail in four different ways. What each one actually charges for, and which shape of application each one fits.","href":"/blog/2026/05/neon-vs-planetscale-vs-turso-vs-supabase-serverless-postgres-2026","category":"Data","date":"May 19, 2026","reading":"5 min read","body":"These get compared as if they were interchangeable databases, and they are not. Two of them sell you a database. Two of them sell you most of a backend. One of them sells you a database that lives close to your users. Picking on price before deciding which of those three you want is how teams end up migrating twice. The prices below came off the vendors' pricing pages on 21 August 2026. What each one is actually selling Neon and PlanetScale sell managed databases and nothing else. You bring your own auth, your own storage, your own API layer. What you get is a Postgres or MySQL endpoint run by people who do that professionally, with branching and scaling behavior that ordinary managed Postgres does not have. Supabase and Firebase sell a backend: database, authentication, object storage, and generated APIs, with client libraries that let a frontend talk to all of it. That saves weeks at the start and is the thing that is hardest to leave later, because the auth and storage layers become load bearing well before the database does. Turso is the odd one, and the interesting one. It is SQLite shaped, sold by rows read and rows written rather than by compute hours, and designed for many "},{"title":"Best AI Image Generators 2026: Midjourney, Flux, Ideogram","excerpt":"There is no single winner left. A use-case-first look at Midjourney, FLUX.2, Ideogram, Recraft, Nano Banana Pro, and Firefly, with the licensing terms that decide it for most companies.","href":"/blog/2026/05/best-ai-image-generators-2026-midjourney-flux-ideogram-recraft-firefly","category":"Tooling","date":"May 18, 2026","reading":"7 min read","body":"Two years ago \"just use Midjourney\" was a fine answer for almost everyone. It stopped being one somewhere in 2025, and the gap between the models has widened since. Midjourney still makes the most arresting hero image. Give it a poster with five lines of copy and the typography falls apart. Give the same brief to Ideogram and you get something you can actually ship. Ask Recraft for a mascot in your brand palette and it holds the palette across forty variations, which Midjourney still cannot really do. Ask FLUX.2 for a product on a marble counter and you will have trouble telling it from a photograph. So this is a guide to picking per job, and for anyone doing this seriously, to picking two or three tools instead of one. Prices and version numbers below were re checked on 21 August 2026. This category moves fast enough that anything here should be treated as stale a quarter from now. The short version Cinematic art, mood boards, concept work: Midjourney Photoreal product and ad imagery, clean commercial terms: FLUX.2 Posters, social cards, anything with text: Ideogram or Nano Banana Pro Vectors, mascots, brand kits, character consistency: Recraft V4 Editing by conversation, and imag"},{"title":"Kong vs Apigee vs Tyk vs APISIX vs KrakenD in 2026","excerpt":"Kong's open source gateway stopped at 3.9 while Enterprise shipped 3.15, and Konnect charges ten times what Apigee does per million requests. Both facts reorder the shortlist.","href":"/blog/2026/05/kong-vs-apigee-vs-tyk-vs-apisix-vs-krakend-2026","category":"Infrastructure","date":"May 18, 2026","reading":"9 min read","body":"The thing that should decide this comparison is not throughput. Every gateway below routes a request, checks a JWT, and enforces a rate limit, and on any hardware you can afford, all of them are faster than the services behind them. What actually separates them is which parts you get to keep without a contract, and what the meter reads when the month closes. On both of those, the answers moved in the last eighteen months, and they moved in a direction that makes the usual recommendation wrong. Kong's open source edition stopped shipping features The repository's newest release is 3.9.3, published 17 June 2026. It is a patch on 3.9.0, which shipped in December 2024. Meanwhile Kong Gateway Enterprise is on 3.15.0.4, dated 20 August 2026, and the Kong changelog is explicitly labeled as covering supported Enterprise versions. The gap is not an accident of release timing. From 3.10 onward, the Enterprise image dropped its free mode: run or later without a valid license and it behaves as an expired Enterprise install, not as a full OSS gateway. Kong staff confirmed this in a repository discussion, and the guidance there is to pin if you want to stay on free builds. So \"use Kong OSS and u"},{"title":"Best AI Meeting Note Takers 2026: Granola vs Fathom vs Otter","excerpt":"Bot or no bot is the first decision, not a vibes question. Granola, Fathom, Otter, and Fireflies compared on coverage model, CRM sync, compliance, and real cost at 5, 25, and 100 seats.","href":"/blog/2026/05/best-ai-meeting-note-takers-2026-granola-fathom-otter-fireflies","category":"Tooling","date":"May 17, 2026","reading":"8 min read","body":"Two years ago picking an AI notetaker was a coin flip between Otter and Fireflies, and most teams defaulted to whatever their video tool summarized for free. That market is gone. The category has split into four lanes, and the right answer depends almost entirely on which lane your workflow lives in. Granola raised $125M at a $1.5B valuation in March and is pushing up into the enterprise. Fathom keeps quietly winning on reviews. Otter is still the only major player offering HIPAA with a BAA. Fireflies pushed past a hundred supported languages. None of them is bad. They are optimized for different jobs. Prices below came off the vendor pricing pages on 21 August 2026, and several of them moved since this was first written. The four lanes Bot free personal capture is Granola: your laptop records the audio, no bot joins the call, the model cleans up the notes you took. Sales teams with a CRM bottleneck want Fathom, where the Business tier pushes structured fields into Salesforce and HubSpot. Searchable archives, live captions, and any workflow touching PHI go to Otter. Distributed teams running calls in languages other than English default to Fireflies, where 100 plus languages is a r"},{"title":"Object Storage in 2026: R2 vs S3 vs B2 vs Wasabi vs Tigris","excerpt":"Store a terabyte, serve five, and S3 bills $464 while R2 bills $15. The egress line is the whole comparison, and two of the cheap options have fine print that undoes it.","href":"/blog/2026/05/cloudflare-r2-vs-s3-vs-backblaze-vs-wasabi-vs-tigris-2026","category":"Infrastructure","date":"May 17, 2026","reading":"9 min read","body":"Storage price per gigabyte is the number every vendor puts on the slide, and it is the number that decides almost nothing. Across the five providers below, storage ranges from $6.95 to $23 per terabyte per month. That spread is real but small. Egress ranges from free to $90 per terabyte, and that is where the bills come from. So here is the comparison in one line: hold a terabyte and serve five terabytes a month to the public internet, and S3 charges about $464 while R2 charges about $15. Everything else in this post is either the arithmetic behind that or the fine print that changes it. All prices below came off the vendor pricing pages on 21 August 2026. The arithmetic Monthly cost of storing one terabyte as egress rises from zero to five terabytes. S3 climbs in a straight line from $23 to $464 while R2, Backblaze B2, and Tigris stay in a band between $15 and $27 across the whole range. 1 TB stored, monthly cost as egress rises $500 $0 0 1 TB 2 TB 3 TB 4 TB 5 TB egress per month R2, B2, Tigris: $15 to $27, flat S3, $464 every dollar of the climb is egress at $0.09/GB S3 Standard at $0.023/GB month plus $0.09/GB egress, against the three zero egress options at list rates. On a $50"},{"title":"AI Agent Payment Protocols 2026: x402, MPP, AgentCore","excerpt":"These protocols are not competing for the same job. Authorization, checkout, and settlement are three different layers, and knowing which one you are shopping for settles most of the argument.","href":"/blog/2026/05/ai-agent-payment-protocols-2026-x402-mpp-agentcore-visa-mastercard","category":"Infrastructure","date":"May 16, 2026","reading":"8 min read","body":"Not long ago, giving an agent the ability to pay for something meant putting a Stripe key in an environment variable, setting a max spend tripwire, and hoping the model would not get stuck in a loop calling a two cent endpoint fifty thousand times overnight. That is no longer the state of the art. The category went from one duct taped pattern to a stack of real protocols in about six months, and the most common mistake now is reading them as competitors when most of them operate at different layers. Checked on 21 August 2026, and the freshest thing here is three days old. Three problems humans do not have Fees. Card payments have a floor, roughly thirty cents plus a few percent, lower at scale and never zero. An agent paying for a $0.001 tool call a million times does not have a payment problem, it has a fee problem, and the infrastructure costs more than the service. That arithmetic kills whole product categories before they ship. Identity. A merchant needs to tell a legitimate agent acting for a customer from a scraper running a stolen card. The fraud tooling built for humans, device fingerprinting and behavioral signals and step up challenges, breaks the moment the actor is head"},{"title":"Best AI Search APIs for Agents 2026: Tavily vs Exa vs Serper","excerpt":"Four different products wear the same label. Which one you need depends on whether you want URLs, passages, or clean text, and the bill is decided by how many pages you fetch, not how many searches you run.","href":"/blog/2026/05/best-ai-search-apis-2026-tavily-exa-serper-firecrawl","category":"Infrastructure","date":"May 15, 2026","reading":"9 min read","body":"The first time you wire an agent to the open web you meet the boring truth: the model is the easy part. Finding clean, recent, citation ready text about whatever the user just asked is where projects stall. Scraping Google yourself is fragile and against the terms. A vector store full of last quarter's PDFs is no help when someone asks about a feature that shipped this morning. And once the agent starts looping, you are paying a frontier model to read a page of SEO sludge on every turn. That gap is why this category exists, and why it split into four quite different products that share one label. Prices below came off the vendor pricing pages on 21 August 2026. Four products, one label Four kinds of AI search API: SERP wrappers return links and snippets, LLM native search returns passages with citations, crawl and extract turns one URL into clean text, and independent indexes return a different set of results entirely SERP WRAPPER Serper, SerpAPI gives you titles, snippets, links LLM NATIVE SEARCH Tavily, Exa, Linkup gives you passages with citations CRAWL + EXTRACT Firecrawl, Jina gives you one URL as clean markdown OWN INDEX Brave, Kagi gives you different results, cleaner licens"},{"title":"Kafka Alternatives in 2026: AutoMQ, WarpStream, Redpanda, NATS","excerpt":"Three replicas on EBS plus cross-AZ traffic is where a Kafka bill actually goes, and at AWS list rates that line is sixteen times what the same data costs on S3. Diskless is now everyone's answer, including Kafka's.","href":"/blog/2026/05/kafka-alternatives-automq-warpstream-redpanda-nats-2026","category":"Infrastructure","date":"May 15, 2026","reading":"10 min read","body":"IBM closed its $11 billion acquisition of Confluent on 17 March 2026, at $31 a share, which delisted Confluent and made WarpStream an IBM product by inheritance. That is the news everyone leads with, and it is the least useful thing to plan around. The useful thing is that the argument diskless streaming was making has been won so completely that the incumbents now sell it too. Confluent has a diskless cluster type on its price list. Redpanda shipped one. Apache Kafka voted to put one in the protocol. If you are still comparing \"Kafka\" against \"the diskless alternatives,\" you are comparing a thing against itself. Here is the arithmetic that caused all of it, and then what each engine is actually for. Prices below came off the AWS price list and the vendor pricing pages on 21 August 2026. Where a Kafka bill goes Take a modest workload: one tebibyte ingested per day, seven day retention, three replicas across three availability zones. Nothing exotic. Classic brokers hold three copies on disk. That is 21 TB of gp3, which lists at $0.08 per GB month in us east 1, so about $1,720 a month. Then every byte the leader accepts crosses an availability zone boundary twice to reach its followe"},{"title":"Best AI Voice Agent Platforms 2026: Vapi vs Retell vs Bland","excerpt":"Voice finally works because the pipeline collapsed. What each platform actually charges per minute once the model passthrough is counted, and the three things that decide whether your agent feels broken.","href":"/blog/2026/05/ai-voice-agent-platforms-2026-vapi-retell-bland-synthflow-elevenlabs-deepgram","category":"Infrastructure","date":"May 14, 2026","reading":"10 min read","body":"Voice is the AI category that took the longest to become usable and is now moving fastest. Text agents had 2024 and 2025. The model layer underneath voice, end to end speech models and sub 200ms synthesis, only collapsed into something workable in the last few quarters, and a real platform tier grew on top of it almost immediately. So: where each platform wins, where it falls over, what it costs once the model passthrough is counted, and which parts you should still build yourself. Prices below came off the vendor pricing pages on 21 August 2026. This category reprices constantly. Why it works now The reason voice agents were uncanny until recently is the pipeline. Speech to text, then a language model, then text to speech, three round trips bolted together. Even at 300ms each you are past a second before the agent starts talking, and a conversation feels broken somewhere north of 800ms. A stacked speech to text, language model and text to speech pipeline lands around a second of latency, past the point a conversation feels broken, while an end to end speech model finishes well under it 0ms 800ms 1200ms the old stack STT LLM TTS 1s end to end speech model listen and speak in one mo"},{"title":"Stripe Managed Payments vs Paddle vs Lemon Squeezy in 2026","excerpt":"Stripe now sells the merchant of record product it also owns a competitor to. Verified rates for six options, and the revenue level where paying the surcharge starts making sense.","href":"/blog/2026/05/stripe-managed-payments-vs-paddle-vs-lemon-squeezy-2026","category":"Infrastructure","date":"May 14, 2026","reading":"7 min read","body":"Selling software to people in other countries means someone has to register for VAT in the EU, GST in Australia, and sales tax in most US states, then file in all of them forever. You can be that someone, or you can pay a merchant of record 3 to 5 percent of revenue to be it instead. That was a stable trade until Stripe entered the category itself, while owning Lemon Squeezy, one of the incumbents. So the question is no longer only about rates. It is about which of these products will still be the recommended path in two years. Every rate below came off the vendor's own pricing page on 21 August 2026. Rates in this category move, so check before you commit. The distinction that decides everything else A payment processor charges the card and sends you the money. You are the legal seller, which means you own tax registration, filing, and audit risk in every jurisdiction where you have customers. A merchant of record buys from you and sells to your customer. They are the legal seller. They register, collect, remit, and take the audit. You get one invoice and one payout instead of a filing calendar. With a payment processor the money passes through and the tax obligation stays with yo"},{"title":"Opsgenie Is Turned Off in April 2027, and One Clock Is Floating","excerpt":"Two of the three dates are fixed and public. The one that catches teams is the 120-day window that starts the day you migrate, and it only applies if you take Atlassian's own exit.","href":"/blog/2026/05/opsgenie-shutdown-migration-pagerduty-incident-io-grafana-2026","category":"Infrastructure","date":"May 13, 2026","reading":"10 min read","body":"Opsgenie is not deprioritized or in maintenance mode. It gets turned off. Atlassian stopped selling new accounts and trials on 4 June 2025, and the REST APIs stop answering on 5 April 2027. After that the service is gone and anything you did not migrate is deleted. That leaves about twenty months, which sounds comfortable and is not, because the technical half of this migration is the small half. Exporting schedules and rebuilding escalation policies is a weekend. Re pointing forty integrations, retraining people on a new mobile app, and getting a line item approved that did not exist in the budget is a quarter. So the question is not which alternative has the best feature list. It is which one you can be live on before your next renewal at a price you can defend. Prices below came off the vendor pricing pages on 22 August 2026. The dates, including the one that floats Opsgenie shutdown timeline. Atlassian stopped selling new accounts on 4 June 2025. Teams using Opsgenie bundled inside Jira Service Management lost the standalone experience around October 2025. The REST APIs stop and data is deleted on 5 April 2027. Separately, a floating 120 day window starts on the day you migrate"},{"title":"Snowflake vs Databricks vs BigQuery vs Redshift: Read the Meter","excerpt":"The four warehouses have converged on features and not on billing units. Warehouse-seconds, bytes scanned, slot-hours, DBUs, and RPU-hours do not convert, and the minimum charge on a short query varies by a factor of sixty.","href":"/blog/2026/05/snowflake-vs-databricks-vs-bigquery-vs-redshift-2026","category":"Data","date":"May 11, 2026","reading":"9 min read","body":"Every one of these four reads and writes Iceberg now. Every one has an MCP server. Every one puts a model behind a SQL function. If you line the feature matrices up they are close enough that the sales engineer stops arguing about capability and starts arguing about total cost of ownership, which is the point where the conversation becomes unfalsifiable. The part that is falsifiable is the meter. Snowflake bills warehouse seconds. BigQuery bills bytes scanned or slot seconds, and you choose which per reservation. Redshift bills RPU seconds or node hours. Databricks bills DBUs plus, on classic compute, the cloud VM underneath. Those units do not convert into each other, which is why every \"X is cheaper than Y\" post is really a statement about one specific workload shape. All numbers below are US East list prices read on 22 August 2026, from Snowflake's Service Consumption Table effective 18 August 2026, Google's BigQuery pricing page, and the AWS Redshift price list for . Unit List price Minimum charge Snowflake Platform credit per warehouse hour $2.00 / $3.00 / $4.00 per credit (Standard / Enterprise / Business Critical, AWS us east 1) 1 minute, then per second BigQuery on demand B"},{"title":"Cloud Cost Tools in 2026: What They Attribute, and What They Can Change","excerpt":"Cost Explorer says EC2 went up. Every tool in this category exists to answer the next question, and they answer it at four different layers, against numbers that are not always what you paid.","href":"/blog/2026/05/cloudzero-vs-vantage-vs-infracost-vs-nops-2026","category":"Infrastructure","date":"May 10, 2026","reading":"9 min read","body":"Spend is up 38% this quarter and someone wants to know which feature did it. You open Cost Explorer. Cost Explorer says EC2 went up. That gap is the entire category. CloudZero, Vantage, Infracost, nOps, OpenCost, Kubecost, CAST AI, ScaleOps: they all exist to answer the next question, and the pitches blur together because they all say \"cloud cost.\" They differ on three things that keep mattering after the pricing pages change. What does the tool attribute against? Does it reconcile to what you actually paid, or to list price? And does it have write access to your infrastructure? Answer those three and the shortlist writes itself. Vendor pricing and project status below were checked on 22 August 2026. The four layers, and why Kubernetes is the hard one Four layers at which cloud cost tools attribute spend. Infracost works on the Terraform plan before a merge. Vantage, CloudZero and nOps work on cloud bill lines. The node you rent is where the cloud bill stops. OpenCost, Kubecost, CAST AI and ScaleOps work on pod requests versus actual usage, below the line the bill can see. Where each tool attaches Terraform plan, before merge Infracost Cloud bill lines Vantage, CloudZero, nOps The "},{"title":"Hyperscaler Agent Platforms in 2026: Bedrock AgentCore vs Agent 365 vs Gemini Enterprise","excerpt":"AWS bills your agents by the vCPU second. Microsoft and Google bill by the person. That single difference decides more about your bill than any model choice.","href":"/blog/2026/05/hyperscaler-agent-platforms-2026-gemini-enterprise-vs-bedrock-agentcore-vs-azure-foundry","category":"Infrastructure","date":"May 9, 2026","reading":"7 min read","body":"The interesting question about agent platforms is not which model they call. You will change models within a year. It is where the agents run, who holds their identity, and what unit shows up on the invoice. On that last point the three hyperscalers have picked genuinely different answers, and the difference is large enough that a fleet that costs a few hundred dollars a month on one can cost six figures on another without either vendor being dishonest about it. All prices below came off vendor pricing pages and product documentation on 21 August 2026. Three billing units AWS meters compute. Bedrock AgentCore charges $0.0895 per vCPU hour and $0.00945 per GB hour for its runtime microVMs, and it does not bill I/O wait. An agent that spends most of a request waiting for a model to answer is not consuming vCPU during the wait, so you are not paying for it. Gateway invocations are $0.005 per thousand, tool search is $0.025 per thousand, and memory has its own per record rates. Microsoft meters people. Agent 365 went generally available on 1 May 2026 at $15 per user per month standalone, or bundled into Microsoft 365 E7. Microsoft's own wording is that a license covers \"an individual w"},{"title":"AI Data Analyst Tools in 2026: Notebooks, Warehouse Agents, and BI Search","excerpt":"Three different products get sold under the same phrase, and the one that decides whether any of them works is a semantic model you probably have not written.","href":"/blog/2026/05/ai-data-analyst-platforms-2026-hex-julius-cortex-genie-thoughtspot","category":"Data","date":"May 8, 2026","reading":"5 min read","body":"\"AI data analyst\" covers three products that fail in different ways. The first is a notebook with a model in it, aimed at people who already write SQL and Python. The second lives inside the warehouse and answers questions against a defined semantic model. The third is a business intelligence tool where the search box got better. Picking between them is really picking who is asking the questions, and whether anyone has told the system what the words in those questions mean. Prices below came off vendor pricing pages on 21 August 2026. The notebook tier Hex is the clearest example: a collaborative notebook with agents attached, free on Community, $36 per editor per month on Professional, and $75 on Team, with per seat credit grants covering the AI features. The agents draft queries and cells, and a human who can read SQL stays in the loop. That last part is the point. A notebook tool assumes the person receiving the answer can check it, which makes the model's mistakes recoverable. It is the right shape for a data team and the wrong shape for handing to a sales director, because the failure mode of a wrong query in a notebook is a person noticing, and that only works if the person c"},{"title":"Durable Execution Pricing: Three Count Steps, One Counts Seconds","excerpt":"Inngest, Temporal and now Lambda all bill per step, and a five-step run costs six of whatever they count. Trigger.dev bills compute-seconds instead. Same workload, four rate cards, and one of them cannot be filled in from public prices.","href":"/blog/2026/05/trigger-dev-vs-inngest-vs-temporal-2026","category":"Infrastructure","date":"May 8, 2026","reading":"8 min read","body":"The engines have converged. Trigger.dev, Inngest and Temporal all give you the same thing now: break one logical job into steps, checkpoint each step's result, retry only what failed, and sleep for days without holding a worker open. AWS shipped the same idea into Lambda itself at re:Invent 2025 as durable functions, which suspend for up to a year and stop charging compute while they wait. So the interesting question is no longer which one has steps. It is what a step costs, and the four answers are not in the same unit. Rates below came off the vendor pricing pages and the AWS price list on 23 August 2026. What one run of a five step workflow costs on each platform's meter. Inngest counts six executions, the run itself plus each of the five steps. Temporal counts six Actions, the workflow start plus five activity executions, with each timer counted separately. AWS Lambda durable functions count six durable operations, the start plus five steps, on top of normal Lambda compute. Trigger.dev counts no steps at all: it bills ten seconds of machine time plus one run invocation. One run, five steps, four meters Three of them charge you six times for one logical job. The fourth never cou"},{"title":"Railway vs Render vs Fly.io vs Koyeb: PaaS Pricing 2026","excerpt":"What a small always-on app actually costs on each, and the specific line item on each platform that turns a $10 bill into a $200 one.","href":"/blog/2026/05/railway-vs-render-vs-fly-vs-koyeb-2026","category":"Infrastructure","date":"May 7, 2026","reading":"8 min read","body":"If you only want the number: a small always on app with a small Postgres runs somewhere between two and fifteen dollars a month on all four of these, and the platform you pick matters far less than the one line item on each that quietly multiplies. Checked against the vendor pricing pages on 21 August 2026. All four have changed pricing inside the last year, so verify before you commit anything. The floor, for a small always on app Fly.io is cheapest at the bottom. A machine with 256MB run continuously is about $1.94 a month in Ashburn and $2.02 in Amsterdam. There is no free tier and no monthly credit; you simply pay very little. Railway has a Free plan at $0 with $1 of monthly usage credit and one vCPU and half a gig per service, plus a 30 day $5 trial that needs no card. Hobby is $5 a month including $5 of credit, and Pro is $20 per workspace including $20. Metering is per second: roughly $0.0139 per GB hour of memory and $0.0278 per vCPU hour. If you have read that Railway has no free tier, that was true and is not any more. Render gives every workspace 750 free instance hours a month, and spun down services do not consume them. As of mid 2026 an always on Starter web service p"},{"title":"AI Inference Providers 2026: Honest Comparison Guide","excerpt":"Custom silicon against GPU platforms, and the question that settles it: what is your user doing while the tokens stream? Speed is worth paying for in exactly two of the four common workloads.","href":"/blog/2026/05/ai-inference-providers-2026-groq-cerebras-together-fireworks-baseten","category":"Infrastructure","date":"May 6, 2026","reading":"7 min read","body":"The inference layer is where the AI bill actually gets paid. You can spend a week choosing a gateway, an observability platform, and a durable orchestrator, and the per token meter still runs against whoever is underneath all of it. Numbers below were re checked on 21 August 2026. Treat any per token price in any post, including this one, as indicative rather than current. The split that explains most arguments Custom silicon. Groq's LPU, Cerebras' wafer scale engine, SambaNova's RDU. Chips designed top down for transformer inference, hitting numbers GPUs do not reach on the workloads they support. Groq runs a 70B class open model around 750 tokens a second; Cerebras runs the same class near 2,100 and has published figures above 2,600 on smaller Llama 4 variants. Independent measurement puts both roughly an order of magnitude ahead of equivalent GPU inference. GPU platforms. Together, Fireworks, Baseten, Modal, DeepInfra, Hyperbolic and the rest. Slower per token, and they host every model anyone publishes, they let you fine tune, they expose batch APIs, and they do not tie you to one chip vendor's roadmap. Once that split is clear, most of the \"which is better\" arguments evaporate"},{"title":"Drizzle vs Prisma vs Kysely: Choosing a TypeScript ORM in 2026","excerpt":"Prisma 7 dropped its Rust engine and Drizzle joined PlanetScale, which killed both of the easy reasons to pick a side. What is left is a question about how much SQL you want to write.","href":"/blog/2026/05/drizzle-vs-prisma-vs-kysely-2026","category":"Data","date":"May 4, 2026","reading":"10 min read","body":"For two years this comparison had a lazy answer: Drizzle, unless your team really wants a file. Prisma's Rust query engine was heavy on serverless, Drizzle's edge story was better, done. Both halves of that stopped being true. Prisma 7 removed the Rust engine entirely and the client is now TypeScript. PlanetScale hired the Drizzle core team on 3 March 2026, which ended the \"it is a side project\" objection. The two arguments people used to settle this both evaporated within a few months of each other. So the question is open again, and it turns out to be a better question: how much of your SQL do you want to write yourself? Versions and numbers below came off npm and the vendor docs on 23 August 2026. Prisma is on 7.9.1, Drizzle on 0.45.2, Kysely on 0.29.5. Two of those three are still pre 1.0, which is worth noticing before you read anyone's stability argument. Drizzle's 1.0 is closer than that version number suggests and has been for a while, which cuts both ways. On npm the tag is , first published 27 June 2026, and the line has been in release candidate since on 30 April. Prerelease builds run to on 12 August. But is still 0.45.2, 's is 0.31.10 from 17 March, and the repository "},{"title":"pgvector vs Pinecone vs Qdrant vs Weaviate: The WHERE Clause Decides","excerpt":"Nobody picks a vector store on unfiltered QPS, because nobody runs unfiltered queries. What separates these four is what happens when you add a tenant filter, and which version you are pinned to.","href":"/blog/2026/05/pgvector-vs-pinecone-vs-qdrant-vs-weaviate-2026","category":"Data","date":"May 2, 2026","reading":"9 min read","body":"Almost every vector database comparison ranks these four by queries per second on a public benchmark, which measures a query nobody ships: top k over the whole collection, no filter, one tenant, static data. Real retrieval queries carry a . Filter by tenant, by conversation, by document set, by whether the thing has been deleted. That is the part where an approximate index stops being a solved problem, and it is the part where these four differ most. Filtering an approximate index is a choice, not a feature pgvector's own README states the problem without hedging: \"With approximate indexes, queries with filtering can return less results since filtering is applied after the index is scanned.\" So an HNSW scan walks the graph, hands back roughly candidates, and then Postgres applies your . Ask for ten results with a filter that matches one row in a thousand and you can get two, or none. The index did its job. The filter ate the answer. Two ways a filtered top k query resolves. In pgvector the HNSW scan returns ef search candidates, the WHERE clause is applied afterward, and fewer than k results can come back unless iterative scan is enabled. In Qdrant a payload index narrows the candi"},{"title":"Linear vs Jira vs Asana in 2026: Price the Exit, Not the Seat","excerpt":"The seat prices are close enough that they should not decide this. Jira Data Center is being retired, Atlassian bills your peak headcount each month, and the MCP gap that looked like Linear's moat a year ago closed on all three.","href":"/blog/2026/05/linear-vs-jira-vs-asana-2026","category":"Tooling","date":"May 1, 2026","reading":"9 min read","body":"Three things changed the shape of this comparison in the last year, and none of them are features. Atlassian announced the end of Data Center. Atlassian also started billing Cloud on your peak user count each month. And the integration gap that looked like Linear's structural advantage in 2025 closed, because all three vendors now ship a generally available MCP server. What is left to decide on is billing shape and exit cost. Prices and dates below came off the vendors' own pricing and licensing pages on 22 August 2026. Self hosting Jira has an end date now This is the biggest item and it gets buried under pricing talk. Atlassian's Data Center end of life notice covers Jira Software, Jira Service Management, Confluence, Bamboo, Crowd, and Marketplace apps. Bitbucket Data Center is the exception and gets a Hybrid License instead. Atlassian Data Center end of life timeline. On 30 March 2026 new customers can no longer purchase Data Center subscriptions. On 30 March 2028 existing customers can no longer buy new subscriptions, expansions, or Marketplace apps. On 28 March 2029 the products reach end of life and instances become read only. The Data Center runway, in three dates 30 Mar 20"},{"title":"AI Code Review in 2026: CodeRabbit vs Greptile vs What You Already Pay For","excerpt":"These tools bill per seat or per review, and that choice decides whether you review every pull request. The harder number is how many comments your team ignores before it stops reading them.","href":"/blog/2026/04/ai-code-review-tools-2026-coderabbit-vs-greptile","category":"Tooling","date":"Apr 30, 2026","reading":"4 min read","body":"An AI reviewer that finds one real bug a week is worth the money. The same reviewer leaving eleven confident comments about naming conventions on every pull request costs you something that does not appear on an invoice: it teaches the team to scroll past review comments, including the ones a human wrote. That is the whole evaluation. Everything else is pricing structure, and pricing structure at least is knowable. Prices below came off vendor pages on 21 August 2026. What each one charges CodeRabbit is $24 per developer per month on Pro with annual billing, $48 on Pro Plus, which adds multi repository analysis, custom pre merge checks, and post merge actions. Public repositories are reviewed for free, which is a genuinely useful way to see the output style before paying. Self hosting exists on Enterprise only. Greptile prices differently: $30 per seat per month on Pro, but seats carry 50 credits and one credit is one standard review, with extra credits at $1 each. The free Starter tier gives a single developer 50 credits a month across unlimited repositories. Self hosting is an Enterprise option. The unit difference matters more than the $6. A per seat plan with unlimited reviews "},{"title":"Cloudflare Containers vs Fargate vs Fly: The Meter You Cannot Turn Off","excerpt":"At half an hour of work a day, all three container meters land within seven cents of each other. What separates them is whatever has to stay awake to receive the request: $5 for a Worker, cents for a stopped Fly machine, $16.43 a month for a load balancer before the container starts.","href":"/blog/2026/04/cloudflare-containers-vs-fargate-vs-flyio","category":"Infrastructure","date":"Apr 29, 2026","reading":"8 min read","body":"The interesting question about these three is not which one runs a container faster. It is what is still on the bill at 4am when nobody has sent a request. All three meter compute by the second or finer, and for intermittent work they land in nearly the same place. The spread is in the parts that never sleep, and in one shape rule that decides how much memory you are allowed to not use. Rates below came off the Cloudflare docs, the Fly pricing page, and the AWS price list on 23 August 2026, all for the US East region. Two panels comparing monthly cost. In the first, for a one vCPU container awake thirty minutes a day with the CPU busy twenty percent of that time, Cloudflare Containers costs 60 cents, AWS Fargate on Arm costs 60 cents, and a Fly performance 1x machine costs 67 cents. In the second panel, the cost of what stays running while nothing happens: a stopped Fly machine costs 15 cents per gigabyte of image, Cloudflare requires the 5 dollar Workers Paid plan, and an AWS Application Load Balancer costs 16 dollars 43 a month, with 32 dollars 85 more if a NAT Gateway sits in the path. The container is the cheap part. Look at what stays awake. Container time: 1 vCPU, awake 30 mi"},{"title":"Best LLM Gateway 2026: Portkey, OpenRouter, LiteLLM","excerpt":"Five gateways took most of the production traffic this year. Routing, cost, and governance compared, plus the honest ops bill behind the cheap option.","href":"/blog/2026/04/llm-gateway-portkey-vs-openrouter-vs-litellm-vs-cloudflare-vs-kong","category":"Infrastructure","date":"Apr 29, 2026","reading":"8 min read","body":"If your agent stack still talks straight to provider SDKs, you will regret it within a quarter. Not because the raw and clients stopped working. They are fine. The problem is everything around the call: failing over when one provider throttles you mid incident, attributing cost across forty agents, redacting PII before it reaches a vendor, keeping an audit trail, and swapping models without a deploy. That is what a gateway does. It sits between your application and however many providers you have, and turns \"which model are we calling\" from a code change into a routing decision. By spring the category had consolidated onto five products. This is what I would pick and why, re checked against vendor docs, the GitHub API, npm, and Docker Hub on 23 August 2026. One of the five had gone quiet since I first wrote this, which is the kind of thing a pricing page never tells you. Why the gateway showed up A year ago you could hit one provider directly and be done. Now a normal stack has Claude Opus 5 for hard reasoning, Sonnet 5 for cheap throughput, GPT 5.5 somewhere, Gemini for the long context jobs, and probably DeepSeek or Qwen doing batch work on an open weights host. That is five prov"},{"title":"Vault vs Doppler vs Infisical: Count Your Machines First","excerpt":"Twelve engineers and forty CI identities run about $252 a month on one of these and about $5,800 on another. The unit printed on the invoice is most of the comparison. The rest is which directory the audit log lives in.","href":"/blog/2026/04/hashicorp-vault-vs-doppler-vs-infisical-2026","category":"Infrastructure","date":"Apr 28, 2026","reading":"8 min read","body":"Three vendors, three units. Doppler bills per human seat and says on its own pricing page that \"AI agents and non human identities ride free.\" Infisical bills per identity, and its pricing page defines that as \"any human or machine that authenticates to Infisical.\" HCP Vault Dedicated bills a cluster by the hour, then bills again for every client that authenticated at any point during the month. Those are not three prices for one product. They are three different questions about your infrastructure, and the answer is a number you already have. Take a team of twelve engineers with forty machine identities: CI runners, a couple of Kubernetes operators, some background workers, a handful of deploy jobs. Fifty two things that authenticate. Here is what each vendor charges for exactly that, using prices I pulled on 23 August 2026. A bar chart comparing monthly cost for the same 12 human users and 40 machine identities across three secrets managers. Doppler Team charges for 12 seats only and costs 252 dollars a month. Infisical Pro charges for all 52 identities and costs 1,040 dollars a month. HCP Vault Dedicated charges for a small Standard cluster plus all 52 clients and costs about 5,"},{"title":"Backstage vs Port vs Cortex: Only One Publishes a Price","excerpt":"Port lists $30 and $40 a seat and caps entities and automation runs on top, and its own two tables disagree about the run limit. Cortex and Spotify publish nothing. The free option ships a minor release every month and backports security fixes for six.","href":"/blog/2026/04/backstage-vs-port-vs-cortex-2026","category":"Tooling","date":"Apr 27, 2026","reading":"7 min read","body":"Every internal developer portal pitch sounds the same, so skip the pitch and go to the part that differs. Try to build a budget for each of these from the public pages. Three of the four routes to a portal will not let you, and the fourth counts three things at once. What that exercise turns up is a better decision input than any feature matrix. Everything below came off the vendors' own pages and repositories on 23 August 2026. The free one has a clock, not an invoice Backstage is Apache 2.0, was accepted into the CNCF in September 2020, and moved to Incubating in March 2022, where it still sits. Nothing about the license will ever cost you money. The cost is in the cadence. Backstage cuts a main release monthly, on the Tuesday before the third Wednesday. Between August 2025 and August 2026 it shipped fourteen minor lines, v1.41 through v1.54. The support statement attached to those releases is narrow: vulnerabilities rated high or critical \"will always be backported to releases for the last 6 months if feasible,\" regular bug fixes land in the next release rather than older ones, and a bug report is only valid if it reproduces on the most recent release. A timeline of Backstage mi"},{"title":"MCP Servers for DevOps: The Install Line Is the Security Boundary","excerpt":"Setup guides tell you to run npx -y @anthropic-ai/github-mcp-server. That package does not exist. The useful part of an MCP setup is not the list of servers, it is how you resolve which artifact is really the vendor's.","href":"/blog/2026/04/best-mcp-servers-devops-setup-guide","category":"Tooling","date":"Apr 25, 2026","reading":"8 min read","body":"Every MCP guide is a list of servers, and every list is stale in a quarter. The part that keeps its value is duller: before you paste a command into your agent config, how do you know that the thing about to run on your laptop, holding a token for your production cluster, is the artifact the vendor actually publishes? That question has a cheap, repeatable answer. It is worth more than any ranking of servers, because it is the step where MCP setups go wrong. Start with a live example. Guides in circulation, including the earlier version of this page, tell you to run this: That package does not exist. returns a 404 from the registry, checked on 23 August 2026. GitHub's actual MCP server is a Go program in , and the way GitHub tells you to use it is a hosted endpoint at with OAuth, or a local binary or container image. There has never been an npm package under that name. A command that installs nothing is the harmless version of this failure. The harmful version is a command that installs something, because resolves a name at the moment you run it and executes whatever is behind it. That is the same mechanism behind the install script problem npm v12 was built to blunt, except here yo"},{"title":"Node vs Deno vs Bun: Pick the Support Window, Not the Benchmark","excerpt":"Node publishes end-of-life dates four years out. Deno maintains one LTS line at a time and has already left a two-month gap between two of them. Bun's security policy lists one supported version: 1.x.","href":"/blog/2026/04/deno-vs-bun-vs-nodejs-javascript-runtime-comparison","category":"Tooling","date":"Apr 24, 2026","reading":"8 min read","body":"Runtime comparisons still open with requests per second, and the number is still mostly irrelevant, because a service that talks to Postgres spends its time waiting on Postgres. There is a question underneath that ages better and takes ten minutes to answer: if you ship this runtime in a container today, how long will somebody publish a security patch for the exact version you shipped? The three answers are not close to each other. All dates below came off the projects' own release schedules and security policies on 23 August 2026. A timeline from 2025 to 2029 comparing support windows. Node.js 22 is supported until April 2027, Node.js 24 until April 2028, and Node.js 26 until April 2029. Deno's LTS channel covers only the 2.9 line, from July 2026 to January 2027, a seven month window. Bun publishes no end date at all; its security policy lists 1.x as the supported version, so the supported build is whatever shipped most recently. How far ahead each project has committed to patching Node 22 ends 30 Apr 2027 Node 24 LTS ends 30 Apr 2028 Node 26 ends 30 Apr 2029 Deno 2.9 LTS ends 31 Jan 2027 Bun 1.x whatever shipped last, no published end date 2025 2026 2027 2028 2029 Node 25 is not "},{"title":"Workers vs Lambda vs Vercel: The Ranking Flips on One Question","excerpt":"Cloudflare bills CPU time, Lambda bills wall-clock, and Vercel splits the difference by pausing CPU billing during I/O while memory keeps running. At 100M requests the cheapest and the most expensive swap places depending on whether your function waits or computes.","href":"/blog/2026/04/cloudflare-workers-vs-aws-lambda-vs-vercel-functions","category":"Infrastructure","date":"Apr 22, 2026","reading":"7 min read","body":"Comparisons of these three usually open with cold starts and end with a table of benchmark numbers somebody else measured. Skip both. The thing that decides your bill is duller and easier to check: each platform meters a different quantity, and one of them is the quantity your function spends most of its time not doing. AWS Lambda bills GB seconds of wall clock time. If your handler awaits a database for 180 milliseconds, you pay for 180 milliseconds. Cloudflare Workers bills CPU time and nothing else, so that same wait is free. Vercel's fluid compute splits the difference, and its docs are refreshingly blunt about it: \"If the request is waiting on I/O, CPU billing pauses but memory billing continues.\" Rates below came off the vendor pricing pages and the AWS price list on 23 August 2026. The same one hundred million requests a month, priced two ways. For an I/O bound function with 200 milliseconds wall clock and 20 milliseconds of CPU, Cloudflare Workers costs 71 dollars, Vercel 190 dollars, and AWS Lambda on Arm 287 dollars. For a CPU bound function where all 200 milliseconds are CPU, Lambda on Arm stays at 287 dollars, Workers rises to 431 dollars, and Vercel rises to 830 dollar"},{"title":"OrbStack vs Podman Desktop vs Rancher Desktop in 2026","excerpt":"Docker Desktop's license threshold is the reason most teams start looking. Here is what the three usual replacements actually cost you in compatibility, security posture, and money.","href":"/blog/2026/04/orbstack-vs-podman-desktop-vs-rancher-desktop","category":"Infrastructure","date":"Apr 20, 2026","reading":"8 min read","body":"Docker Desktop is free until your company is not small anymore. Docker's license terms put the line at fewer than 250 employees and under $10 million in annual revenue. Cross either one and every developer needs a seat. At the current prices, a 50 person engineering team on Team costs $9,000 a year ($15 per user per month on annual billing, $16 monthly). Business is $24. Neither number sinks a budget, but both are large enough that somebody eventually asks whether the laptop container runtime is worth a line item at all. Three replacements are mature enough that the answer is often no. OrbStack rebuilt the macOS virtual machine layer and charges less than Docker for it. Podman Desktop threw out the daemon and is free under Apache 2.0. Rancher Desktop lets you pick your own runtime and is also free under Apache 2.0. They fail in different places, which is the part worth reading about. Prices and versions below came off the vendor pages and the GitHub release APIs on 21 August 2026. The process model is the real difference Everything else in this comparison follows from how each tool arranges processes. Docker Desktop and OrbStack both keep a daemon. The Docker daemon runs inside a L"},{"title":"GitHub Actions Pricing in 2026, and What the Other Three Meter","excerpt":"Hosted runners got cheaper in January and the per-job rounding rule still quietly costs you more than any of it. And before you price a move to GitLab, CircleCI, or Buildkite: none of the four bill the same unit.","href":"/blog/2026/04/github-actions-pricing-2026","category":"Infrastructure","date":"Apr 19, 2026","reading":"9 min read","body":"GitHub restructured Actions pricing at the start of 2026. Hosted runners got cheaper. Then GitHub tried to put a per minute charge on self hosted runners as well, the community objected loudly, and the change was withdrawn inside a day. If you run hosted runners on private repos your bill went down without you doing anything. If you self host, nothing changed. The episode is still worth understanding, because the economics that prompted it have not gone anywhere. Rates below were checked against GitHub's billing docs on 21 August 2026. What the runners cost now Runner Per minute Linux 2 core $0.006 Windows 2 core $0.010 macOS 3 or 4 core $0.062 The restructure cut raw compute by roughly 40% and folded a $0.002 per minute platform charge, covering the orchestration layer, into the per minute rate. You just see a smaller number. Included minutes per month did not change: 2,000 on Free, 3,000 on Pro, 3,000 on Team , and 50,000 on Enterprise Cloud. If you have read somewhere that Team gets 50,000, that is Enterprise Cloud's number and it is a wrong one to budget against. Public repos still get hosted runners for free. Per minute runner rates drawn to scale: Linux at six tenths of a cen"},{"title":"Beyond Kubernetes: 5 Simpler Alternatives for Small Teams","excerpt":"Kubernetes is extraordinary engineering and wildly overbuilt for most teams under fifteen engineers. Five things that are genuinely production-grade and stop one rung earlier.","href":"/blog/2026/04/kubernetes-alternatives-small-teams-2026","category":"Infrastructure","date":"Apr 18, 2026","reading":"7 min read","body":"Kubernetes is an extraordinary piece of engineering. It is also overbuilt for most small teams. Under about fifteen engineers, without hundreds of services, you are paying a complexity tax that buys very little: etcd, RBAC policies, ingress controllers, CRDs, and the hours those consume every month. The alternatives got genuinely viable somewhere in the last two years. Not toy grade, production options that trade infinite flexibility for the thing that is actually scarce at small scale. Checked on 21 August 2026, and one of these five changed status since this was written. Pick the lowest rung that holds A ladder of deployment complexity: one box needs only Kamal, a few boxes suit Docker Swarm, managed containers suit Cloud Run or ECS Express, real mixed workload scheduling suits Nomad, and only fleets of services need Kubernetes Kamal one box, or a few you name yourself Docker Swarm a few nodes, compose files you have Cloud Run / ECS Express no cluster at all, someone else runs it Nomad real scheduling, and everything else Kubernetes many services, many teams, a platform group Most teams are two rungs above where they need to be. Every rung up buys capability you might not need an"},{"title":"AWS DevOps Agent and Security Agent: Read the Second Meter","excerpt":"Both bill by the second, both look cheap, and neither price is the whole bill. The agent-second rate covers the agent; the observability calls it makes to do its job are billed at their own rates, and the support credits that offset the first do not touch the second.","href":"/blog/2026/04/aws-frontier-agents-devops-security","category":"Infrastructure","date":"Apr 17, 2026","reading":"7 min read","body":"AWS ships two agents under the Frontier Agents name that are meant to act rather than suggest. DevOps Agent investigates incidents on its own, starting from a CloudWatch alarm, a PagerDuty alert, a Dynatrace problem, or a webhook. Security Agent runs penetration tests against an application you point it at and validates findings by exploiting them. Both are metered by the second, which makes them easy to try and hard to forecast. The rates are published, so the arithmetic is worth doing before rather than after. DevOps Agent is $0.0083 per agent second, which is $29.88 per agent hour. Security Agent is $50.00 per task hour, also billed per second with partial seconds prorated. Neither has a monthly platform fee. The rate is not the bill The DevOps Agent FAQ says the part that matters and says it quietly: charges for connected services, CloudWatch Logs among them and trace retrievals among them, are billed separately at their own rates and are not included in DevOps Agent pricing. That is the whole design in one line. The agent's job is to query everything at once, so an investigation that spans four data sources is four data sources' worth of read charges on top of the agent second"},{"title":"Tailscale vs Cloudflare Tunnel vs ngrok in 2026","excerpt":"These three get compared as if they do the same job. They don't, and the architecture diagram explains every difference in price, latency, and who can read your traffic.","href":"/blog/2026/04/tailscale-vs-cloudflare-tunnel-vs-ngrok-2026","category":"Infrastructure","date":"Apr 16, 2026","reading":"11 min read","body":"If you have been typing on autopilot for years, the tightened free tier is probably what made you look around. It is worth getting the facts right before you migrate on a rumor, because one of the most repeated complaints about it is not true. ngrok's own free plan limits page says plainly: free endpoints have no timeout and can stay online indefinitely. The widely circulated \"two hour session limit\" is not a thing. What the free plan actually caps is 1 GB of data transfer a month, 20,000 HTTP requests, 5,000 TCP connections, three simultaneous online endpoints, and a rate ceiling of 4,000 requests a minute. Plus an interstitial warning page in front of every visitor, which is the part that actually stings during a client demo. That 1 GB is the real constraint. A typical React app ships a few megabytes per load, so a stakeholder refreshing a demo burns through it faster than you would guess. Webhook payloads, by contrast, are tiny, and 20,000 requests is a lot of Stripe events. Numbers below came off the vendor pricing and docs pages on 21 August 2026. They are not three versions of the same product This is the part that decides everything else, and a feature table hides it. Three "},{"title":"Playwright vs Cypress: Count the Majors, Then Read the Meter","excerpt":"Playwright has been on 1.x since 2020. Cypress has shipped eight majors since 2021, and each one stopped getting releases within weeks of the next. The paid meter is not what most comparisons say it is either.","href":"/blog/2026/04/playwright-vs-cypress","category":"Tooling","date":"Apr 14, 2026","reading":"7 min read","body":"Comparisons of these two open with download counts and close with a benchmark somebody ran on a laptop. The download gap is real and it is one sided: for the week ending 21 August 2026, npm served 82.9 million downloads of and 7.3 million of . That tells you which one is winning. It does not tell you what either will cost you over three years. Two things do, and both are checkable in a few minutes. How often does the tool force you to do a major upgrade, and what does the paid tier actually count. A timeline from 2021 to 2026 comparing major version churn. Playwright is one unbroken bar because it has stayed on version 1.x since May 2020. Cypress is the same span divided into eight segments, one for each major version from 8 to 15, released between July 2021 and August 2025. How many times each tool made you do a major upgrade Playwright 1.x one major, six years Cypress eight majors since July 2021 2021 2022 2023 2024 2025 2026 Each Cypress major stopped getting releases within weeks of the next one shipping. Dates from the npm registry's own publish timestamps. Playwright's bar is clipped at the left; 1.0 shipped in May 2020. The upgrade clock Playwright published on 6 May 2020 an"},{"title":"Google Gemma 4: Run It Locally and Build Your First AI Agent","excerpt":"Picking a Gemma 4 size for the hardware you already own, getting it running under Ollama, and wiring native function calling into a small agent loop.","href":"/blog/2026/04/google-gemma-4-local-setup-ai-agent","category":"Infrastructure","date":"Apr 13, 2026","reading":"7 min read","body":"Google released Gemma 4 in early April: Apache 2.0, multimodal, several sizes from phone to workstation, and native function calling that is good enough to build a real agent on rather than a demo. This is what I would tell someone who wants to run it on hardware they already own, and then have it call tools. Re checked on 21 August 2026. One thing changed since April, and it changed the recommendation, so read the sizes section even if you skimmed this in the spring. What makes it worth the disk space Gemma 4 comes out of the same research line as Google's commercial Gemini models, and the jump from Gemma 3 on the reported benchmarks is large enough to be suspicious: AIME math from 20.8% to 89.2%, LiveCodeBench from 29.1% to 80.0%, GPQA from 42.4% to 84.3%. Those are Google's numbers, not mine, and benchmark scores are the least interesting thing about a local model. Three things matter more. The license is Apache 2.0, so there is no monthly active user cap and no regional carve out to read twice, which is not true of Llama. The models are built for efficient inference on consumer hardware rather than being a server model that technically fits. And tool calling is trained in rathe"},{"title":"Terraform, OpenTofu, Pulumi: The Fork Is in the Registry","excerpt":"The BUSL has an expiry date printed in it, four years per version, and IBM is the licensor. The split that actually changes what you can build is which registry your source address resolves to, and 3,198 provider names sit on only one side of it.","href":"/blog/2026/04/terraform-vs-pulumi-vs-opentofu","category":"Infrastructure","date":"Apr 13, 2026","reading":"9 min read","body":"Most comparisons of these three open with the license and then spend the rest of the article on syntax. The license is the easy part, because the terms are written down with dates attached. What is harder to see, and what decides more of your day, is that the three tools no longer read from the same place and no longer store your state the same way. Start with the file everyone argues about. in the Terraform repository is Business Source License 1.1, and the Licensor line now reads International Business Machines Corporation. The Additional Use Grant permits production use as long as you are not offering Terraform to third parties on a hosted or embedded basis in competition with IBM's paid versions, and it says plainly that \"hosting or using the Licensed Work(s) for internal purposes within an organization is not considered a competitive offering.\" If you run in your own pipeline against your own cloud account, the BUSL has never applied to you and still does not. The part that gets skipped is the two lines under it. Change Date: four years from the date the Licensed Work is published. Change License: MPL 2.0. The BUSL is not permanent, and it expires per version rather than all a"}]