Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Railway Turned Its CLI MCP Server Into a Proxy: One Credential for Every Agent, and an Audit Trail You Can No Longer See
·Dora Noda·12 min

Railway Turned Its CLI MCP Server Into a Proxy: One Credential for Every Agent, and an Audit Trail You Can No Longer See

Railway's September 2026 changelog flips railway mcp from a bundled local server to a proxy for its hosted MCP endpoint. Here is the three-way tradeoff — local vs proxy-to-hosted vs self-hosted — across credentials, logging, scope enforcement, and audit ownership, plus a decision rule for production agent access.

Model Context Protocol
AI agents
security
self-hosting
+1
Six Coding Agents on a Private Network: Threat-Model the Credential Blast Radius Before You Copy Railway's Sandbox
·Dora Noda·12 min

Six Coding Agents on a Private Network: Threat-Model the Credential Blast Radius Before You Copy Railway's Sandbox

Railway's June 2026 sandboxes preinstall six coding agents with private-network reach to production data. Four Kubernetes controls — per-session identities, default-deny egress, approval-gated mutations, and auditable teardown — keep the convenience without the nine-second-wipe blast radius.

AI agents
security
Kubernetes
self-hosting
+1
Agents Will Operate Your Platform With or Without You: What Frigade's Show HN Proves About Agent APIs
·Dora Noda·9 min

Agents Will Operate Your Platform With or Without You: What Frigade's Show HN Proves About Agent APIs

A 96-point Show HN turned observed web traffic into agent tools. That demand signal leaves platforms one choice: ship a versioned, scoped, auditable agent interface, or inherit reverse-engineered traffic with none of those properties.

AI agents
Model Context Protocol
API
security
Your CI Server Just Became an Agent Tool: What TeamCity's MCP Server Means for Deploy-From-Chat
·Dora Noda·10 min

Your CI Server Just Became an Agent Tool: What TeamCity's MCP Server Means for Deploy-From-Chat

TeamCity's MCP servers — the community's 87-tool Full Mode and JetBrains' official 2026.1 endpoint — turn builds, tests, and agent pools into agent-callable tools. The CI half of deploy-from-chat is here; per-tool scoping and human approval decide whether it is safe to use.

AI agents
Model Context Protocol
security
PaaS
X Ships a Hosted MCP Server, and Agent Access Is Now Table Stakes
·Dora Noda·8 min

X Ships a Hosted MCP Server, and Agent Access Is Now Table Stakes

X's hosted MCP server joins Slack, Notion, GitHub, and Stripe in making first-party agent access the default. Here is the concrete production-grade bar — auth, transport, scoping, rate limits — and how it re-sequences your own MCP roadmap.

Model Context Protocol
AI agents
API
security
Who Sent This Agent, and Whose Authority Is It Spending? What the IETF's AIMS Draft Means for MCP Server Auth
·Dora Noda·12 min

Who Sent This Agent, and Whose Authority Is It Spending? What the IETF's AIMS Draft Means for MCP Server Auth

The IETF's AIMS draft composes WIMSE, SPIFFE, and OAuth 2.0 into one agent identity model. Here is what a deploy-from-chat MCP server should borrow — and how to prove which agent called and whose authority it spent.

AI agents
Model Context Protocol
security
identity
Automatic TLS on Owned Hardware: Caddy vs cert-manager After Hetzner's July Load Balancer Disruption
·Dora Noda·11 min

Automatic TLS on Owned Hardware: Caddy vs cert-manager After Hetzner's July Load Balancer Disruption

Hetzner's July 2026 Ashburn load balancer disruption showed what happens when TLS renewal shares fate with a provider's data plane. A comparison of managed LB certificates, Caddy automatic HTTPS, and cert-manager plus Gateway API — and why self-hosted platforms should own the certificate path as Let's Encrypt lifetimes shrink.

self-hosting
security
infrastructure
Kubernetes
Bare-IP TLS Is GA: Instant HTTPS for Preview URLs Without a DNS Round-Trip
·Dora Noda·10 min

Bare-IP TLS Is GA: Instant HTTPS for Preview URLs Without a DNS Round-Trip

Let's Encrypt's generally available 160-hour IP certificates let a preview environment serve valid HTTPS on a bare node IP with no DNS records. Here is the cert-manager plus Gateway API wiring, the renewal math, and when a subdomain still wins.

Kubernetes
self-hosting
PaaS
security
+1
Bottlerocket Killed Bare-Metal Kubernetes After 1.28: Picking a Node OS for Your CAPH Fleet
·Dora Noda·9 min

Bottlerocket Killed Bare-Metal Kubernetes After 1.28: Picking a Node OS for Your CAPH Fleet

Bottlerocket's bare-metal Kubernetes variants ended at 1.28, and the last patches expired with Kubernetes 1.28's end-of-life. Here is how Talos Linux, Flatcar Container Linux, and Kairos compare as the node OS for a Cluster API fleet on owned hardware — and which one fits your team.

Kubernetes
self-hosting
infrastructure
security
Showing 118–126 of 532 posts