532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

pedit COW: A Packet-Editor Bug Is the Fifth Linux Kernel Escape in Ten Weeks — and It Lives in Code Your CNI Already Loads
CVE-2026-46331 (pedit COW) is the fifth independent Linux kernel escape disclosed in ten weeks — and it lives in traffic-control code your CNI loads on every node. What the five-escape window means for self-hosted Kubernetes fleets, and the patch checklist that closes it.

No More AI API Keys in Env Vars: Reproducing Render's Short-Lived Anthropic and OpenAI Credentials on Your Own Kubernetes
Render's July 2026 Managed OIDC trades long-lived Anthropic and OpenAI API keys for short-lived tokens minted from platform identity — and the same exchange runs on any Kubernetes cluster via projected service-account tokens, issuer registration, and a JWKS upload. The concrete recipe plus what Render still operates for you.

Telepresence Intercepts vs a Preview Environment Per PR: Debugging Live Cluster Traffic From Your Laptop
Routing live cluster traffic to a laptop beats booting a preview per developer on fixed hardware — until it doesn't. A worked cost comparison, the traffic-manager's RBAC trust price, and the golden path that stacks both.

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers
CNCF's Platform Engineering 2.0 names AI agents as platform consumers with their own access, scope, and governance needs. Here is the concrete design that follows: per-agent identity, least-privilege roles, machine-speed quotas — and why MCP auth must be agent-first from day one.

Gateway API 1.4 Stabilizes BackendTLSPolicy: Encrypting the Gateway-to-Pod Hop Without a Service Mesh
Gateway API 1.4 graduates BackendTLSPolicy to stable, giving shared clusters a portable way to encrypt gateway-to-Pod traffic with fail-closed validation — here is the complete YAML and the rollout checklist for multi-tenant platforms.

Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes
CNCF's Q1 2026 radar put Backstage in 'Adopt' while its agentic-enterprise commentary demands machine-consumable platform interfaces. The official MCP plugin, read-through sync, and four hard parts — auth, writes, refresh, drift — decide whether the pairing holds.

Buildpacks RFC 0130: Zero-Config OCI Provenance Your SOC 2 Auditor Can Actually Read
Cloud Native Buildpacks approved RFC 0130, stamping buildpack images with source, commit, and version metadata automatically. What that buys a SOC 2 or FedRAMP audit, what unsigned annotations can't prove, and the SBOM plus signed-attestation checklist that closes the gap.

Your Admission Webhook Never Saw That Container: Runtime Supply-Chain Verification With containerd's NRI
Static pods, direct node access, and webhook outages all bypass API-layer image checks. A CNCF-backed NRI plugin moves SLSA, VEX, and VSA verification into the container runtime itself — here is how it works and what it costs to run across a fleet.