527 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

AWS Now Runs an ACME Server: Why Your Self-Hosted cert-manager Never Needed It
AWS Certificate Manager now speaks ACME, issuing 45-day certificates with IAM governance and per-domain pricing. Here is how it compares to running cert-manager against Let's Encrypt directly, and the renewal-margin checklist short-lived certificates actually demand.

The Vendor Ships the Protocol, the Community Ships the Policy: What Coolify's Governed MCP Servers Teach About Agent Interfaces
Coolify's built-in MCP server covers reads while community servers add operation modes, scoped tokens, approval gates, and audit logging — a field guide to the seven governance controls every self-hosted PaaS agent interface should launch with.

CNCF Says MCP Gateways Belong in the Platform. Here's What That Actually Requires
MCP gateways are now a CNCF Platform Engineering 2.0 pillar. Here's what a gateway does that an ad-hoc MCP server doesn't — OAuth 2.1 auth, per-caller rate limits, deny-by-default tool scoping, poisoning detection — and how much of it a self-hosted PaaS control plane already absorbs.

Stop Copying Registry Passwords Into Every Namespace: Kubernetes 1.34 ServiceAccount Image Pulls in Practice
Kubernetes 1.34's beta ServiceAccount token flow replaces per-namespace imagePullSecrets with short-lived, workload-bound pull credentials — how to wire the registry side, bind ServiceAccounts, handle rotation, and test the failure modes before deleting static secrets.

Coolify v4 Is a Rolling Beta: What Pinning the Platform Underneath Your Apps Actually Requires
Coolify v4.3.1 was 'latest patched' on August 12 and four releases behind by August 16 — inside a CVE cluster with RCE to host root. How to run a rolling-beta PaaS panel safely: version-pinned installs, a staging canary box, and advisory-feed monitoring.

Buildpacks Is Cutting Kaniko Out of Your git-push Pipeline
Cloud Native Buildpacks compiles kaniko's executor into the lifecycle binary behind every git-push build — and the plan to cut it out runs through a fork-hop, grype reachability triage, and a separate extender binary. What the extraction means for your builder's CVE surface and provenance story.

Your Secret Scanner's CI Broke Overnight: Gitleaks' Org License Gate, Porsche's TruffleHog Swap, and What a Git-Push Pipeline Should Standardize On
Gitleaks' GitHub Action now fails org repos without a license key while the CLI stays MIT. Compare the three fixes — license, vendored CLI, or TruffleHog verified mode — with Porsche's ADR-0011 as the worked case study and a pinned baseline for git-push build pipelines.

Kubernetes Rewrote Its Image Promoter and Deleted 20% of It: A 7-Phase Registry Lesson for Self-Hosted PaaS
Kubernetes rewrote kpromo, its registry.k8s.io image promoter, deleting 20% of the code while cutting plan time from 20 minutes to 2 and signature replication from 17 hours to 15 minutes. A close read of the 7-phase pipeline — and what a self-hosted PaaS should copy and skip.

Your TLS Renewals Have an Expiration Date Too: Auditing cert-manager for Let's Encrypt's 45-Day Countdown
Let's Encrypt drops to 45-day certificates by 2028 — run this four-step cert-manager audit on versions, hardcoded renewBefore windows, the ARI gate, and expiry alerting before fixed renewal intervals start breaking.