Skip to main content

688 posts tagged with "Self-Hosting"

Running your own PaaS and infrastructure on machines you own

View all tags

Read the Self-hosted PaaS guide

Kubernetes 1.36 Just Removed gitRepo Volumes and IPVS kube-proxy — Here's the Audit Your Cluster API Fleet Needs Before You Upgrade
·Dora Noda·9 min

Kubernetes 1.36 Just Removed gitRepo Volumes and IPVS kube-proxy — Here's the Audit Your Cluster API Fleet Needs Before You Upgrade

Kubernetes 1.36 permanently kills gitRepo volumes (closing a CVE-2024-10220-class RCE) and removes IPVS kube-proxy mode as hard failures, not warnings. Here are the exact audit commands a Cluster API fleet needs before upgrading, including the CAPI config gap that hides IPVS on Hetzner clusters.

self-hosting
PaaS
security
infrastructure
+1
Kubernetes Dashboard Is Officially Dead: What Breaks When You Move to Headlamp
·Dora Noda·9 min

Kubernetes Dashboard Is Officially Dead: What Breaks When You Move to Headlamp

Kubernetes Dashboard is archived for good. Here's exactly what breaks in a kubectl proxy workflow when you move to Headlamp, what RBAC setup transfers untouched, and what the Cluster API plugin gives a fleet operator that Dashboard never could.

self-hosting
PaaS
infrastructure
engineering
Your Monitoring Stack Was a Root Shell: What Kubernetes v1.36's Kubelet Authorization GA Actually Fixes
·Dora Noda·8 min

Your Monitoring Stack Was a Root Shell: What Kubernetes v1.36's Kubelet Authorization GA Actually Fixes

Kubernetes v1.36 closes a real RCE hiding in nodes/proxy, but its GA authorization split is scoped by operation type, not by tenant — here's what it actually fixes and where pod-level break-glass access still has to live.

security
self-hosting
PaaS
infrastructure
A 'Medium' CVE Popped a Full Reverse Shell: What ms-agent's Six-Layer Regex Bypass Teaches About Agent Sandboxing
·Dora Noda·8 min

A 'Medium' CVE Popped a Full Reverse Shell: What ms-agent's Six-Layer Regex Bypass Teaches About Agent Sandboxing

CVE-2026-2256 scored a 'Medium' 6.5 on CVSS, but its proof-of-concept is a full reverse shell through an AI agent's own shell tool. Here's exactly how a six-layer regex denylist got bypassed, and why only a real sandbox boundary — not command validation — closes the gap.

AI agents
security
cybersecurity
self-hosting
Next.js 16.2 Ships a Stable Adapter API — Vercel's Build Contract Is Now Public
·Dora Noda·9 min

Next.js 16.2 Ships a Stable Adapter API — Vercel's Build Contract Is Now Public

Next.js 16.2's stable Adapter API turns Vercel's once-private build output into a public, testable contract. Here's what the NextAdapter interface actually exposes, and what it takes for a self-hosted platform to build a native adapter instead of guessing.

PaaS
self-hosting
API
infrastructure
The State of Platform Engineering Vol 4: 29.6% of Platform Teams Don't Measure Success at All
·Dora Noda·9 min

The State of Platform Engineering Vol 4: 29.6% of Platform Teams Don't Measure Success at All

A 2026 survey of 518 platform engineers found nearly a third don't measure success at all. Here's what the budget and adoption data actually show — and three cheap metrics to instrument instead so your platform isn't next year's defunded line item.

self-hosting
PaaS
engineering
AI agents
Your Files Never Moved: What Plex's July 2026 Outage Reveals About Fake Self-Hosting
·Dora Noda·8 min

Your Files Never Moved: What Plex's July 2026 Outage Reveals About Fake Self-Hosting

Plex's July 14, 2026 outage never touched a single self-hosted file — but users still got locked out, because auth and discovery route through Plex's cloud by default. Here's what that reveals about the gap between owning your disk and owning your infrastructure.

self-hosting
PaaS
infrastructure
engineering
PowerDNS Operator: The Last Layer a Self-Hosted PaaS Still Outsources
·Dora Noda·9 min

PowerDNS Operator: The Last Layer a Self-Hosted PaaS Still Outsources

PowerDNS Operator turns DNS zones and records into Kubernetes Custom Resources so tenants can self-serve custom domains via RBAC instead of a shared API credential — here's the CRD model, the win over external-dns, and the anycast tradeoff it doesn't solve.

self-hosting
PaaS
Domain
infrastructure
Your Namespace-Scoped Sealed Secret Wasn't: What CVE-2026-22728's Rotation Bug Actually Broke
·Dora Noda·9 min

Your Namespace-Scoped Sealed Secret Wasn't: What CVE-2026-22728's Rotation Bug Actually Broke

A rotation-endpoint bug in Bitnami's Sealed Secrets let attacker-controlled annotations turn a namespace-scoped secret cluster-wide — without touching Kubernetes RBAC at all. Here's the attack, and the NetworkPolicy audit every shared cluster needs to run.

security
self-hosting
PaaS
infrastructure
+1
Showing 352–360 of 688 posts
Prev40 / 77Next