<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Appaloft engineering blog</title>
    <link>https://www.appaloft.com/blog</link>
    <description>Engineering articles about agent application delivery, deployment evidence, Blueprints, control-plane design, and TypeScript DDD.</description>
    <language>en-US</language>
    <lastBuildDate>Sat, 29 Aug 2026 07:44:55 GMT</lastBuildDate>
    <atom:link href="https://www.appaloft.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Appaloft plugin for Grok Bot</title>
      <link>https://www.appaloft.com/blog/appaloft-plugin-for-grok-bot</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/appaloft-plugin-for-grok-bot</guid>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <description>Add Appaloft from Grok Bot&apos;s plugin directory, Authenticate with OAuth, and get the existing skill plus hosted MCP in one plugin.</description>
      <category>AI</category>
      <category>Agents</category>
      <category>MCP</category>
      <category>Grok</category>
    </item>
    <item>
      <title>Teach Cursor and OpenCode how to deploy</title>
      <link>https://www.appaloft.com/blog/teach-cursor-opencode-appaloft-setup-agent</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/teach-cursor-opencode-appaloft-setup-agent</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description>How appaloft setup agent installs a skill and MCP locally while keeping login, approval, deployment, and readback as explicit boundaries.</description>
      <category>AI</category>
      <category>Agents</category>
      <category>MCP</category>
      <category>CLI</category>
    </item>
    <item>
      <title>Remote agent workspaces that outlive your laptop</title>
      <link>https://www.appaloft.com/blog/agent-workspace-architecture</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/agent-workspace-architecture</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <description>Appaloft 1.4 turns Agent Workspace into a public Sandbox entry workflow: remote harnesses, collaboration leases, hibernation, and an evidence-gated path to ship. Here is the architecture, how it compares to OpenSandbox and peers, and what we are still finishing.</description>
      <category>AI</category>
      <category>Agents</category>
      <category>Sandbox</category>
      <category>Architecture</category>
      <category>Agent Workspace</category>
    </item>
    <item>
      <title>The agent that builds your app should not publish it</title>
      <link>https://www.appaloft.com/blog/agents-should-not-publish-their-own-work</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/agents-should-not-publish-their-own-work</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
      <description>Appaloft&apos;s new sandbox agent runtime lets coding agents build inside isolated, expiring sandboxes, then freezes their work into immutable artifacts that only an external actor can promote. Here is where we drew the boundary.</description>
      <category>AI</category>
      <category>Agents</category>
      <category>Sandbox</category>
      <category>Deployment</category>
    </item>
    <item>
      <title>How we built the delivery evidence chain</title>
      <link>https://www.appaloft.com/blog/delivery-evidence-chain</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/delivery-evidence-chain</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
      <description>AI agents can write an app in ten minutes. Proving what actually shipped is a harder, older problem. This is how we built Appaloft&apos;s evidence chain — and where we deliberately stopped.</description>
      <category>Deployment control</category>
      <category>Runtime verification</category>
      <category>AI</category>
      <category>Agents</category>
    </item>
    <item>
      <title>Control-Plane Key Rotation: From Key Custody to Recovery</title>
      <link>https://www.appaloft.com/blog/control-plane-key-rotation</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/control-plane-key-rotation</guid>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft combines a versioned keyring, short-lived OIDC credentials, plan digests, atomic migration, and an independent restore rehearsal.</description>
      <category>Security</category>
      <category>Key rotation</category>
      <category>Postgres</category>
      <category>GitHub Actions</category>
    </item>
    <item>
      <title>&quot;Deployed&quot; is not a health check</title>
      <link>https://www.appaloft.com/blog/deployment-proof-running-workload-changed</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/deployment-proof-running-workload-changed</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
      <description>A deployment needs evidence that its artifact, process, service, and public route all belong to the intended release.</description>
      <category>Deployment control</category>
      <category>Runtime verification</category>
      <category>Docker</category>
      <category>AI</category>
    </item>
    <item>
      <title>A rollback button is not a recovery plan</title>
      <link>https://www.appaloft.com/blog/compose-rollback-contract</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/compose-rollback-contract</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Five invariants for safer single-host Docker Compose updates: image preflight, candidate verification, scoped cleanup, and explicit data boundaries.</description>
      <category>Docker Compose</category>
      <category>Deployment</category>
      <category>Rollback</category>
      <category>Self-hosting</category>
    </item>
    <item>
      <title>Who owns the deploy? Dividing Git, CI, servers, and release state</title>
      <link>https://www.appaloft.com/blog/who-owns-the-deploy</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/who-owns-the-deploy</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
      <description>Separate repository, CI runner, server, and deployment-state ownership—and see where Appaloft fits without pretending to manage every layer.</description>
      <category>Deployment control</category>
      <category>Docker Compose</category>
      <category>Self-hosting</category>
      <category>CI/CD</category>
    </item>
    <item>
      <title>A deployment platform should not assume every app runs on port 3000</title>
      <link>https://www.appaloft.com/blog/one-repo-many-runtime-shapes</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/one-repo-many-runtime-shapes</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft examples use explicit deployment contracts for Vite, Python, Go, and Docker Compose instead of making the platform guess.</description>
      <category>Deployment control</category>
      <category>Runtime</category>
      <category>Docker</category>
      <category>Examples</category>
    </item>
    <item>
      <title>Copy the environment shape, not the production secrets</title>
      <link>https://www.appaloft.com/blog/copy-the-environment-shape-not-the-secrets</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/copy-the-environment-shape-not-the-secrets</guid>
      <pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft turns environment copy into a plan-first workflow: topology and intent travel; databases, domains, volume data, and secret values stay behind decisions.</description>
      <category>Environments</category>
      <category>Deployment control</category>
      <category>CLI</category>
      <category>Safety</category>
    </item>
    <item>
      <title>Deployment failures should leave a recovery path</title>
      <link>https://www.appaloft.com/blog/deployment-failure-should-leave-a-recovery-path</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/deployment-failure-should-leave-a-recovery-path</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
      <description>A failed deployment should explain where it stopped, what already happened, which actions are safe, and what verified target can be restored.</description>
      <category>Deployment control</category>
      <category>Recovery</category>
      <category>Rollback</category>
      <category>AI</category>
    </item>
    <item>
      <title>How a custom domain gets connected to Appaloft</title>
      <link>https://www.appaloft.com/blog/custom-domain-onboarding-flow</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/custom-domain-onboarding-flow</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate>
      <description>From hostname input to DNS authorization, readback, TLS, routing, and failure handling, this is how Appaloft treats custom domains as a checkable deployment workflow.</description>
      <category>Custom Domains</category>
      <category>DNS</category>
      <category>Routing</category>
      <category>Deployment control</category>
    </item>
    <item>
      <title>MCP tools are product APIs, not demo endpoints</title>
      <link>https://www.appaloft.com/blog/mcp-tools-are-product-apis</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/mcp-tools-are-product-apis</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
      <description>Why Appaloft generates MCP tools from the operation catalog and routes them back through the same CommandBus, QueryBus, authz, audit, and readback boundaries.</description>
      <category>AI</category>
      <category>MCP</category>
      <category>API</category>
      <category>Deployment control</category>
      <category>Agents</category>
    </item>
    <item>
      <title>What a deploy URL should promise</title>
      <link>https://www.appaloft.com/blog/what-a-deploy-url-should-promise</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/what-a-deploy-url-should-promise</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
      <description>A deploy URL is part of the deployment contract: some links should never move, some aliases can move with audit, and custom domains need ownership proof.</description>
      <category>Deployment control</category>
      <category>Routing</category>
      <category>Rollback</category>
      <category>AI</category>
    </item>
    <item>
      <title>Install progress should not be a pile of disconnected logs</title>
      <link>https://www.appaloft.com/blog/install-progress-should-not-be-disconnected-logs</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/install-progress-should-not-be-disconnected-logs</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate>
      <description>Why Appaloft shows Blueprint installs as one readable application progress experience instead of asking users to stitch together component logs and support details.</description>
      <category>Blueprint</category>
      <category>Marketplace</category>
      <category>Product Experience</category>
    </item>
    <item>
      <title>From GitHub Actions to Appaloft: what evidence a deployment should leave behind</title>
      <link>https://www.appaloft.com/blog/github-actions-appaloft-deployment-evidence</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/github-actions-appaloft-deployment-evidence</guid>
      <pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft thinks about GitHub Actions deployments as auditable evidence: commit SHA, image digest, config snapshot, provenance, readback, and rollback.</description>
      <category>GitHub Actions</category>
      <category>Deployment control</category>
      <category>Provenance</category>
      <category>AI</category>
    </item>
    <item>
      <title>When an AI agent builds a static site, deployment should still be a workflow</title>
      <link>https://www.appaloft.com/blog/ai-agent-static-site-deployment</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/ai-agent-static-site-deployment</guid>
      <pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft turns an agent-produced dist directory into an auditable static artifact publication instead of handing an AI broad cloud credentials.</description>
      <category>AI</category>
      <category>Static Artifacts</category>
      <category>Deployment control</category>
      <category>Agents</category>
    </item>
    <item>
      <title>DDD in Appaloft TypeScript, Part 4: specifications</title>
      <link>https://www.appaloft.com/blog/ddd-specification-appaloft-typescript</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/ddd-specification-appaloft-typescript</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
      <description>Appaloft&apos;s lightweight Specification style in TypeScript, from selection specs to readiness gates and drift reports.</description>
      <category>DDD</category>
      <category>Specification</category>
      <category>TypeScript</category>
    </item>
    <item>
      <title>AI agents should not log in by copying cookies</title>
      <link>https://www.appaloft.com/blog/ai-agent-cli-auth-token-handoff</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/ai-agent-cli-auth-token-handoff</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>Why Appaloft separates human browser login, CI tokens, and AI agent token handoff instead of letting agents impersonate users.</description>
      <category>AI</category>
      <category>CLI</category>
      <category>Auth</category>
      <category>Agents</category>
    </item>
    <item>
      <title>Skills are not MCP: how AI agents should call a deployment control plane</title>
      <link>https://www.appaloft.com/blog/skills-are-not-mcp-ai-deployment-control-plane</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/skills-are-not-mcp-ai-deployment-control-plane</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <description>Why Appaloft keeps AI skills, MCP tools, CLI commands, and the operation catalog in separate roles instead of creating an agent-only deployment path.</description>
      <category>AI</category>
      <category>MCP</category>
      <category>Deployment control</category>
      <category>Agents</category>
    </item>
    <item>
      <title>Blueprints are not marketplace cards</title>
      <link>https://www.appaloft.com/blog/blueprints-are-not-marketplace-cards</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/blueprints-are-not-marketplace-cards</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft models Blueprints as versioned application topology definitions, then turns one-click deploys into reviewable dry-run install plans.</description>
      <category>Blueprint</category>
      <category>Deployment control</category>
      <category>Marketplace</category>
      <category>AI</category>
    </item>
    <item>
      <title>DDD in Appaloft TypeScript, Part 3: value objects</title>
      <link>https://www.appaloft.com/blog/ddd-value-objects-appaloft-typescript</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/ddd-value-objects-appaloft-typescript</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft uses practical TypeScript value objects: schema versions, literal unions, ids, secret references, masked connections, and provider boundary aliases.</description>
      <category>DDD</category>
      <category>Value Object</category>
      <category>TypeScript</category>
    </item>
    <item>
      <title>DDD in Appaloft TypeScript, Part 2: aggregate roots</title>
      <link>https://www.appaloft.com/blog/ddd-aggregate-root-appaloft-typescript</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/ddd-aggregate-root-appaloft-typescript</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft models InstalledApplication as an aggregate root in TypeScript, with plan acceptance, readback, failure, and rollback transitions.</description>
      <category>DDD</category>
      <category>Aggregate Root</category>
      <category>TypeScript</category>
    </item>
    <item>
      <title>DDD in Appaloft TypeScript, Part 1: start with boundaries, not folders</title>
      <link>https://www.appaloft.com/blog/ddd-in-appaloft-typescript-architecture</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/ddd-in-appaloft-typescript-architecture</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft applies domain-driven design in TypeScript through Blueprint planning, installed applications, dependency resources, and runtime composition.</description>
      <category>DDD</category>
      <category>TypeScript</category>
      <category>Architecture</category>
    </item>
    <item>
      <title>A deployment control plane for the AI era</title>
      <link>https://www.appaloft.com/blog/ai-native-deployment-control-plane</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/ai-native-deployment-control-plane</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <description>How Appaloft models deployment as an auditable operating path shared by CLI, GitHub, AI tools, Blueprints, and Cloud.</description>
      <category>AI</category>
      <category>Deployment control</category>
      <category>Cloud</category>
    </item>
    <item>
      <title>We built Appaloft with Bun: what worked, what surprised us, and where it still hurts</title>
      <link>https://www.appaloft.com/blog/we-built-appaloft-with-bun</link>
      <guid isPermaLink="true">https://www.appaloft.com/blog/we-built-appaloft-with-bun</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <description>A practical look at how Appaloft uses Bun for TypeScript scripts, compiled binaries, embedded Web/docs assets, PGlite, and multi-target release packaging.</description>
      <category>Bun</category>
      <category>Self-hosting</category>
      <category>Engineering</category>
    </item>
  </channel>
</rss>
