532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority
A community MCP server turns Coolify into agent-callable deploy tools for about 13 dollars a month — but the agent holds a deploy-level API token with nothing between it and delete. Scoped, audited agent credentials are the missing primitive.

Daytona's Sub-90ms vs E2B's 150ms: Does Sandbox Cold Start Matter for AI Agent Loops?
Daytona boots sandboxes in under 90ms while E2B's Firecracker microVMs take about 150ms — but model latency dwarfs both in real agent loops. A numbers-first look at when the gap matters, how the two pricing shapes compare, and what a self-hosted sandbox should copy from each.

Railway Locked Enterprise Deploys to a GitHub Org Allowlist: Build the Same Guardrail on Your Own Fleet
Railway's May 2026 changelog lets enterprise workspaces restrict deployments to approved GitHub orgs. Here is what the guardrail enforces and how to rebuild it on your own fleet with ArgoCD source pinning, Kyverno admission policy, and pipeline owner checks.

Your API Server Still Proxies Every kubectl exec in 1.36: What ExtendWebSocketsToKubelet Really Moves and the 4 Checks Before You Upgrade
Kubernetes 1.36 did not cut the API server out of the exec path — it turned it into a pass-through proxy. What really moved to the kubelet, the RBAC change that actually matters, and four checks to run before you upgrade.

MCP's 10,000-Server Problem: Building an Allowlisted, Audited Tool Catalog Before an Agent Can Deploy to Your Fleet
With 10,000+ public MCP servers and most scanned servers needing security review, connecting an agent to a tool is now a governance problem. A tiered, allowlisted tool catalog design — plus a deploy-from-chat walkthrough — for teams running agents against production.

450+ MCP Servers Catalogued and Quality-Scored Daily: What the Ecosystem Census Says About the Tool Sprawl Your Deploy Platform Inherits
A daily census grades 453 MCP servers an average of 16.3 out of 100. Here is what that number means for platform teams, the security gap the score does not cover, and a bless-or-block rubric for governing tenant agent tools.

MCP Bets H2 2026 on Server Cards: What Your Registry-Less Server Must Hand-Roll Today
The July 2026 MCP spec shipped stateless transport and a mandatory server/discover RPC but left pre-connect Server Cards experimental. Here is the concrete manifest, capability advertisement, and trust signaling a registry-less deploy-from-chat server builds today so the eventual card format is a migration, not a rewrite.

Your Agent Doesn't Need Your API Key: What Qovery's Infrastructure-MCP Play Proves About Governed Tool Interfaces
Qovery's infrastructure-MCP writeup defines the governed alternative to pasting API keys into agents: scoped per-tool authority, server-side budget caps, and a per-call audit trail. What that boundary contains, why it became a product category in 2026, and what self-hosting it on your own machines requires.

Deploy From Chat: What Coolify, Arcade, and Azure APIM Prove About MCP Servers for PaaS Ops
Coolify's community MCP bridge, Arcade's 8,000-tool OAuth runtime, and Azure APIM's REST-to-MCP exposure prove agents can deploy, roll back, and tail logs from chat. The protocol is the easy part — discovery, scoped credentials, and confused-deputy hardening decide whether an agent gets real authority.