Skip to main content
Dora Noda

Dora Noda

Software Engineer

2322 posts · View all authors

Your Post-Quantum TLS Migration Isn't a Second Certificate Format — It's the Same Freshness Problem You Already Solved for 6-Day Certs
·Dora Noda·8 min

Your Post-Quantum TLS Migration Isn't a Second Certificate Format — It's the Same Freshness Problem You Already Solved for 6-Day Certs

Let's Encrypt is skipping a direct ML-DSA swap for Merkle Tree Certificates because the naive post-quantum handshake blows past 14,700 bytes. Here's the actual byte math, the late-2026 staging timeline, and what a self-hosted PaaS's ACME automation needs to track before production MTCs land in 2027.

self-hosting
PaaS
security
infrastructure
+1
From 3 Days to 11 Minutes: What the Widely-Cited MCP Deploy Speedup Stat Actually Measures
·Dora Noda·8 min

From 3 Days to 11 Minutes: What the Widely-Cited MCP Deploy Speedup Stat Actually Measures

The '3 days to 11 minutes' MCP integration stat traces to one unverified blog testimonial, not a benchmark. Here's what it actually measures, and what a fair before/after would require.

AI
self-hosting
PaaS
engineering
MCP's Enterprise Readiness Push: Why Audit Trails and SSO Matter More When Your MCP Server Can Delete a Database
·Dora Noda·9 min

MCP's Enterprise Readiness Push: Why Audit Trails and SSO Matter More When Your MCP Server Can Delete a Database

MCP's 2026 roadmap treats audit trails and SSO as a security-review checkbox. For a deploy-authority MCP server, they're what turns an agent's nine-second production wipeout into a reconstructable incident instead of a lost weekend.

security
AI
self-hosting
PaaS
+1
Three JavaScript Quirks, One CVSS 10.0 RCE: What n8n's Sandbox-Escape Chain Means for Every Agent Tool Wired to Your Cluster
·Dora Noda·9 min

Three JavaScript Quirks, One CVSS 10.0 RCE: What n8n's Sandbox-Escape Chain Means for Every Agent Tool Wired to Your Cluster

Three individually-harmless gaps in n8n's JavaScript sandbox chained into a CVSS 10.0 RCE that reached every stored credential and, on shared instances, the Kubernetes cluster underneath. Here's the exploit chain and what it means for any tool that hands an agent a general-purpose sandbox.

cybersecurity
AI agents
Kubernetes
self-hosting
+1
New York Froze 50MW+ Data Centers. The Math Shows Self-Hosted PaaS Was Never in That Weight Class
·Dora Noda·8 min

New York Froze 50MW+ Data Centers. The Math Shows Self-Hosted PaaS Was Never in That Weight Class

New York's Executive Order 62 freezes new 50MW-plus data centers — but every self-hosted colocation campus in Europe tops out under that line. Here's the megawatt math, and what the freeze means for hosted PaaS vendors riding on hyperscaler capacity.

self-hosting
PaaS
infrastructure
regulation
+1
Northflank Has Four Kubernetes Modes. Only One Puts You in the Driver's Seat
·Dora Noda·9 min

Northflank Has Four Kubernetes Modes. Only One Puts You in the Driver's Seat

Northflank markets four ways to run Kubernetes under its platform. Three of them mean Northflank's software still operates the control plane — only one hands that job to you. Here's the breakdown, with real numbers.

self-hosting
PaaS
cost-optimization
infrastructure
+1
npm v12 Turns Off 16 Years of Automatic Code Execution: The Exact Packages You Need to Re-Approve Before Your Build Breaks
·Dora Noda·9 min

npm v12 Turns Off 16 Years of Automatic Code Execution: The Exact Packages You Need to Re-Approve Before Your Build Breaks

npm v12 flipped install scripts, Git dependencies, and remote tarballs to off by default after a year of worm-driven supply chain attacks — here's the exact audit of which packages need re-approving and what it means for a git-push PaaS's Node buildpack.

security
self-hosting
PaaS
infrastructure
+1
The NSA Just Published a Threat Model for MCP: What It Means for Your Deploy Agent
·Dora Noda·9 min

The NSA Just Published a Threat Model for MCP: What It Means for Your Deploy Agent

The NSA's AI Security Center named four structural risks in MCP's design — and every one already has a real 2026 incident behind it. Here's what each means concretely for a self-hosted MCP server with deploy and rollback authority.

Model Context Protocol
AI agents
security
self-hosting
+1
Gitpod Bet the Company on Self-Hosted Agent Infra — Then OpenAI Bought It
·Dora Noda·8 min

Gitpod Bet the Company on Self-Hosted Agent Infra — Then OpenAI Bought It

Gitpod rebranded to Ona and went self-hosted-only in September 2025. Nine months later OpenAI bought it for Codex. Here's what a hyperscaler choosing to buy customer-owned execution instead of building it actually signals.

AI agents
self-hosting
openai
acquisitions
+1
Showing 316–324 of 2322 posts
Prev36 / 258Next