Skip to main content

531 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Your Kubernetes Cluster Already Negotiates Post-Quantum TLS. Your Edge Probably Doesn't
·Dora Noda·12 min

Your Kubernetes Cluster Already Negotiates Post-Quantum TLS. Your Edge Probably Doesn't

Kubernetes v1.33 already negotiates hybrid post-quantum TLS on the control plane — but your ingress, tenant certificates, and secrets layer each need their own verdict. A layer-by-layer readiness inventory with the CNSA 2.0 deadlines that set the pace.

Kubernetes
cryptography
security
self-hosting
+1
Railway's Dotenv Diff Review: What Confirm-Before-Apply Env Changes Teach Agent-Driven Deploy Pipelines
·Dora Noda·10 min

Railway's Dotenv Diff Review: What Confirm-Before-Apply Env Changes Teach Agent-Driven Deploy Pipelines

Railway's variable edit flow batches env changes, shows a redacted diff, and applies only on confirm. That shape is the governance primitive agent-driven deploy pipelines need before AI agents get write access to production config.

AI agents
Model Context Protocol
security
PaaS
+1
Self-Hosted GitHub Actions Runners vs Depot vs GitHub: The Real Math for Teams That Own Their Machines
·Dora Noda·12 min

Self-Hosted GitHub Actions Runners vs Depot vs GitHub: The Real Math for Teams That Own Their Machines

GitHub charges $0.006 per CI minute, Depot charges $0.004, and a $60 dedicated server charges nothing per minute. The breakeven math at three team sizes, plus the security and maintenance costs the rate card hides.

self-hosting
cost-optimization
Kubernetes
PaaS
+1
Every Deploy Surface Is Shipping an MCP Server: What a PaaS's Agent Interface Must Expose (and What Keeps It Safe)
·Dora Noda·12 min

Every Deploy Surface Is Shipping an MCP Server: What a PaaS's Agent Interface Must Expose (and What Keeps It Safe)

TeamCity, Dooor OS, and the PaaS scoreboard all converged on the same contract: a typed MCP tool surface over deploy, rollback, logs, and status. The minimum inventory a git-push PaaS must expose, and the four controls that make it production-safe.

Model Context Protocol
AI agents
PaaS
self-hosting
+1
Januscape: A 16-Year-Old KVM Escape, the Two CVEs That Fix It, and the One Kernel Flag Your Fleet Should Audit
·Dora Noda·9 min

Januscape: A 16-Year-Old KVM Escape, the Two CVEs That Fix It, and the One Kernel Flag Your Fleet Should Audit

Januscape (CVE-2026-53359) is a 16-year-old KVM shadow-MMU bug giving guest root a host escape on Intel and AMD — closed by two CVEs and mitigated by one kernel flag. What it means for hypervisor-backed tenant isolation, and the fleet audit that verifies the fix.

security
Kubernetes
self-hosting
infrastructure
10,000 MCP Servers and 97M Downloads Later, the Bottleneck Is Discovery
·Dora Noda·9 min

10,000 MCP Servers and 97M Downloads Later, the Bottleneck Is Discovery

MCP passed 10,000 public servers and 97M monthly SDK downloads, so the hard problem is no longer the protocol — it is discovery and trust. What Arcade's brokered runtime and the Coolify agent bridges teach a self-hosted PaaS about shipping a deploy, rollback, and logs server that agents can find and be trusted with.

Model Context Protocol
AI agents
PaaS
security
Half a Billion Downloads Get a Diploma: What MCP's First Certification (MCPA) Signals for Platform Teams
·Dora Noda·9 min

Half a Billion Downloads Get a Diploma: What MCP's First Certification (MCPA) Signals for Platform Teams

The Agentic AI Foundation's MCPA exam arrives as MCP SDK downloads near half a billion a month. What the blueprint's 50% ops-and-security weighting tells platform teams, what the credential doesn't prove, and three moves to make this quarter.

Model Context Protocol
AI agents
Careers
PaaS
+1
My Server Started Mining Monero: What a 606-Point Cryptojacking Postmortem Teaches About Hardening Self-Hosted PaaS Nodes
·Dora Noda·11 min

My Server Started Mining Monero: What a 606-Point Cryptojacking Postmortem Teaches About Hardening Self-Hosted PaaS Nodes

A Hetzner box mined Monero for ten days before anyone noticed — here is the kill chain link by link, and the node-hardening checklist (key-only SSH, egress policy, resource alerts) a self-hosted PaaS should ship by default.

security
self-hosting
PaaS
cybersecurity
1 Million Agents in 3 Months: What Notion's Enterprise Agent Surge Means for a PaaS Whose Deploy API Is the Agent's Next Tool Call
·Dora Noda·11 min

1 Million Agents in 3 Months: What Notion's Enterprise Agent Surge Means for a PaaS Whose Deploy API Is the Agent's Next Tool Call

Notion customers built 1 million AI agents in three months, yet 69% of enterprises still share credentials across agents. This is the five-item checklist — per-agent identity, scoped tokens, agent-aware quotas, audit attribution, MCP deploy tools — a PaaS deploy API needs before agents become its callers.

AI agents
Model Context Protocol
security
PaaS
+1
Showing 82–90 of 531 posts