Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

pedit COW: A Packet-Editor Bug Is the Fifth Linux Kernel Escape in Ten Weeks — and It Lives in Code Your CNI Already Loads
·Dora Noda·9 min

pedit COW: A Packet-Editor Bug Is the Fifth Linux Kernel Escape in Ten Weeks — and It Lives in Code Your CNI Already Loads

CVE-2026-46331 (pedit COW) is the fifth independent Linux kernel escape disclosed in ten weeks — and it lives in traffic-control code your CNI loads on every node. What the five-escape window means for self-hosted Kubernetes fleets, and the patch checklist that closes it.

security
Kubernetes
self-hosting
infrastructure
No More AI API Keys in Env Vars: Reproducing Render's Short-Lived Anthropic and OpenAI Credentials on Your Own Kubernetes
·Dora Noda·9 min

No More AI API Keys in Env Vars: Reproducing Render's Short-Lived Anthropic and OpenAI Credentials on Your Own Kubernetes

Render's July 2026 Managed OIDC trades long-lived Anthropic and OpenAI API keys for short-lived tokens minted from platform identity — and the same exchange runs on any Kubernetes cluster via projected service-account tokens, issuer registration, and a JWKS upload. The concrete recipe plus what Render still operates for you.

identity
security
self-hosting
Kubernetes
+1
Telepresence Intercepts vs a Preview Environment Per PR: Debugging Live Cluster Traffic From Your Laptop
·Dora Noda·12 min

Telepresence Intercepts vs a Preview Environment Per PR: Debugging Live Cluster Traffic From Your Laptop

Routing live cluster traffic to a laptop beats booting a preview per developer on fixed hardware — until it doesn't. A worked cost comparison, the traffic-manager's RBAC trust price, and the golden path that stacks both.

Kubernetes
self-hosting
developer tools
cost-optimization
+1
An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
·Dora Noda·11 min

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands

Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

AI agents
security
Model Context Protocol
identity
+1
Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers
·Dora Noda·11 min

Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers

CNCF's Platform Engineering 2.0 names AI agents as platform consumers with their own access, scope, and governance needs. Here is the concrete design that follows: per-agent identity, least-privilege roles, machine-speed quotas — and why MCP auth must be agent-first from day one.

AI agents
Model Context Protocol
security
Kubernetes
Gateway API 1.4 Stabilizes BackendTLSPolicy: Encrypting the Gateway-to-Pod Hop Without a Service Mesh
·Dora Noda·10 min

Gateway API 1.4 Stabilizes BackendTLSPolicy: Encrypting the Gateway-to-Pod Hop Without a Service Mesh

Gateway API 1.4 graduates BackendTLSPolicy to stable, giving shared clusters a portable way to encrypt gateway-to-Pod traffic with fail-closed validation — here is the complete YAML and the rollout checklist for multi-tenant platforms.

Kubernetes
PaaS
self-hosting
security
Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes
·Dora Noda·10 min

Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes

CNCF's Q1 2026 radar put Backstage in 'Adopt' while its agentic-enterprise commentary demands machine-consumable platform interfaces. The official MCP plugin, read-through sync, and four hard parts — auth, writes, refresh, drift — decide whether the pairing holds.

AI agents
Model Context Protocol
PaaS
security
+1
Buildpacks RFC 0130: Zero-Config OCI Provenance Your SOC 2 Auditor Can Actually Read
·Dora Noda·11 min

Buildpacks RFC 0130: Zero-Config OCI Provenance Your SOC 2 Auditor Can Actually Read

Cloud Native Buildpacks approved RFC 0130, stamping buildpack images with source, commit, and version metadata automatically. What that buys a SOC 2 or FedRAMP audit, what unsigned annotations can't prove, and the SBOM plus signed-attestation checklist that closes the gap.

PaaS
compliance
security
self-hosting
Your Admission Webhook Never Saw That Container: Runtime Supply-Chain Verification With containerd's NRI
·Dora Noda·12 min

Your Admission Webhook Never Saw That Container: Runtime Supply-Chain Verification With containerd's NRI

Static pods, direct node access, and webhook outages all bypass API-layer image checks. A CNCF-backed NRI plugin moves SLSA, VEX, and VSA verification into the container runtime itself — here is how it works and what it costs to run across a fleet.

Kubernetes
security
self-hosting
PaaS
Showing 100–108 of 532 posts