Skip to main content

527 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

AWS Now Runs an ACME Server: Why Your Self-Hosted cert-manager Never Needed It
·Dora Noda·10 min

AWS Now Runs an ACME Server: Why Your Self-Hosted cert-manager Never Needed It

AWS Certificate Manager now speaks ACME, issuing 45-day certificates with IAM governance and per-domain pricing. Here is how it compares to running cert-manager against Let's Encrypt directly, and the renewal-margin checklist short-lived certificates actually demand.

security
self-hosting
PaaS
Kubernetes
+1
The Vendor Ships the Protocol, the Community Ships the Policy: What Coolify's Governed MCP Servers Teach About Agent Interfaces
·Dora Noda·9 min

The Vendor Ships the Protocol, the Community Ships the Policy: What Coolify's Governed MCP Servers Teach About Agent Interfaces

Coolify's built-in MCP server covers reads while community servers add operation modes, scoped tokens, approval gates, and audit logging — a field guide to the seven governance controls every self-hosted PaaS agent interface should launch with.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
CNCF Says MCP Gateways Belong in the Platform. Here's What That Actually Requires
·Dora Noda·12 min

CNCF Says MCP Gateways Belong in the Platform. Here's What That Actually Requires

MCP gateways are now a CNCF Platform Engineering 2.0 pillar. Here's what a gateway does that an ad-hoc MCP server doesn't — OAuth 2.1 auth, per-caller rate limits, deny-by-default tool scoping, poisoning detection — and how much of it a self-hosted PaaS control plane already absorbs.

Model Context Protocol
AI agents
security
PaaS
Stop Copying Registry Passwords Into Every Namespace: Kubernetes 1.34 ServiceAccount Image Pulls in Practice
·Dora Noda·12 min

Stop Copying Registry Passwords Into Every Namespace: Kubernetes 1.34 ServiceAccount Image Pulls in Practice

Kubernetes 1.34's beta ServiceAccount token flow replaces per-namespace imagePullSecrets with short-lived, workload-bound pull credentials — how to wire the registry side, bind ServiceAccounts, handle rotation, and test the failure modes before deleting static secrets.

Kubernetes
security
self-hosting
PaaS
+1
Coolify v4 Is a Rolling Beta: What Pinning the Platform Underneath Your Apps Actually Requires
·Dora Noda·8 min

Coolify v4 Is a Rolling Beta: What Pinning the Platform Underneath Your Apps Actually Requires

Coolify v4.3.1 was 'latest patched' on August 12 and four releases behind by August 16 — inside a CVE cluster with RCE to host root. How to run a rolling-beta PaaS panel safely: version-pinned installs, a staging canary box, and advisory-feed monitoring.

self-hosting
PaaS
security
guide
Buildpacks Is Cutting Kaniko Out of Your git-push Pipeline
·Dora Noda·9 min

Buildpacks Is Cutting Kaniko Out of Your git-push Pipeline

Cloud Native Buildpacks compiles kaniko's executor into the lifecycle binary behind every git-push build — and the plan to cut it out runs through a fork-hop, grype reachability triage, and a separate extender binary. What the extraction means for your builder's CVE surface and provenance story.

security
self-hosting
PaaS
engineering
Your Secret Scanner's CI Broke Overnight: Gitleaks' Org License Gate, Porsche's TruffleHog Swap, and What a Git-Push Pipeline Should Standardize On
·Dora Noda·10 min

Your Secret Scanner's CI Broke Overnight: Gitleaks' Org License Gate, Porsche's TruffleHog Swap, and What a Git-Push Pipeline Should Standardize On

Gitleaks' GitHub Action now fails org repos without a license key while the CLI stays MIT. Compare the three fixes — license, vendored CLI, or TruffleHog verified mode — with Porsche's ADR-0011 as the worked case study and a pinned baseline for git-push build pipelines.

security
self-hosting
PaaS
engineering
Kubernetes Rewrote Its Image Promoter and Deleted 20% of It: A 7-Phase Registry Lesson for Self-Hosted PaaS
·Dora Noda·10 min

Kubernetes Rewrote Its Image Promoter and Deleted 20% of It: A 7-Phase Registry Lesson for Self-Hosted PaaS

Kubernetes rewrote kpromo, its registry.k8s.io image promoter, deleting 20% of the code while cutting plan time from 20 minutes to 2 and signature replication from 17 hours to 15 minutes. A close read of the 7-phase pipeline — and what a self-hosted PaaS should copy and skip.

Kubernetes
self-hosting
PaaS
security
Your TLS Renewals Have an Expiration Date Too: Auditing cert-manager for Let's Encrypt's 45-Day Countdown
·Dora Noda·9 min

Your TLS Renewals Have an Expiration Date Too: Auditing cert-manager for Let's Encrypt's 45-Day Countdown

Let's Encrypt drops to 45-day certificates by 2028 — run this four-step cert-manager audit on versions, hardcoded renewBefore windows, the ARI gate, and expiry alerting before fixed renewal intervals start breaking.

security
Kubernetes
self-hosting
guide
Showing 1–9 of 527 posts