Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority
·Dora Noda·12 min

Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority

A community MCP server turns Coolify into agent-callable deploy tools for about 13 dollars a month — but the agent holds a deploy-level API token with nothing between it and delete. Scoped, audited agent credentials are the missing primitive.

AI agents
Model Context Protocol
security
PaaS
+1
Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?
·Dora Noda·11 min

Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?

Daytona boots sandboxes in under 90ms while E2B's Firecracker microVMs take about 150ms — but model latency dwarfs both in real agent loops. A numbers-first look at when the gap matters, how the two pricing shapes compare, and what a self-hosted sandbox should copy from each.

AI agents
self-hosting
PaaS
cost-optimization
+1
Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet
·Dora Noda·9 min

Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet

Railway's May 2026 changelog lets enterprise workspaces restrict deployments to approved GitHub orgs. Here is what the guardrail enforces and how to rebuild it on your own fleet with ArgoCD source pinning, Kyverno admission policy, and pipeline owner checks.

PaaS
self-hosting
Kubernetes
security
+1
Your API Server Still Proxies Every kubectl exec in 1.36: What ExtendWebSocketsToKubelet Really Moves and the 4 Checks Before You Upgrade
·Dora Noda·9 min

Your API Server Still Proxies Every kubectl exec in 1.36: What ExtendWebSocketsToKubelet Really Moves and the 4 Checks Before You Upgrade

Kubernetes 1.36 did not cut the API server out of the exec path — it turned it into a pass-through proxy. What really moved to the kubelet, the RBAC change that actually matters, and four checks to run before you upgrade.

Kubernetes
security
self-hosting
infrastructure
MCP's 10,000-Server Problem: Building an Allowlisted, Audited Tool Catalog Before an Agent Can Deploy to Your Fleet
·Dora Noda·10 min

MCP's 10,000-Server Problem: Building an Allowlisted, Audited Tool Catalog Before an Agent Can Deploy to Your Fleet

With 10,000+ public MCP servers and most scanned servers needing security review, connecting an agent to a tool is now a governance problem. A tiered, allowlisted tool catalog design — plus a deploy-from-chat walkthrough — for teams running agents against production.

Model Context Protocol
AI agents
security
self-hosting
450+ MCP Servers Catalogued and Quality-Scored Daily: What the Ecosystem Census Says About the Tool Sprawl Your Deploy Platform Inherits
·Dora Noda·12 min

450+ MCP Servers Catalogued and Quality-Scored Daily: What the Ecosystem Census Says About the Tool Sprawl Your Deploy Platform Inherits

A daily census grades 453 MCP servers an average of 16.3 out of 100. Here is what that number means for platform teams, the security gap the score does not cover, and a bless-or-block rubric for governing tenant agent tools.

Model Context Protocol
AI agents
security
self-hosting
MCP Bets H2 2026 on Server Cards: What Your Registry-Less Server Must Hand-Roll Today
·Dora Noda·10 min

MCP Bets H2 2026 on Server Cards: What Your Registry-Less Server Must Hand-Roll Today

The July 2026 MCP spec shipped stateless transport and a mandatory server/discover RPC but left pre-connect Server Cards experimental. Here is the concrete manifest, capability advertisement, and trust signaling a registry-less deploy-from-chat server builds today so the eventual card format is a migration, not a rewrite.

Model Context Protocol
AI agents
self-hosting
security
Your Agent Doesn't Need Your API Key: What Qovery's Infrastructure-MCP Play Proves About Governed Tool Interfaces
·Dora Noda·11 min

Your Agent Doesn't Need Your API Key: What Qovery's Infrastructure-MCP Play Proves About Governed Tool Interfaces

Qovery's infrastructure-MCP writeup defines the governed alternative to pasting API keys into agents: scoped per-tool authority, server-side budget caps, and a per-call audit trail. What that boundary contains, why it became a product category in 2026, and what self-hosting it on your own machines requires.

AI agents
Model Context Protocol
security
self-hosting
+1
Deploy From Chat: What Coolify, Arcade, and Azure APIM Prove About MCP Servers for PaaS Ops
·Dora Noda·13 min

Deploy From Chat: What Coolify, Arcade, and Azure APIM Prove About MCP Servers for PaaS Ops

Coolify's community MCP bridge, Arcade's 8,000-tool OAuth runtime, and Azure APIM's REST-to-MCP exposure prove agents can deploy, roll back, and tail logs from chat. The protocol is the easy part — discovery, scoped credentials, and confused-deputy hardening decide whether an agent gets real authority.

AI agents
Model Context Protocol
PaaS
security
+1
Showing 109–117 of 532 posts