532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Railway Turned Its CLI MCP Server Into a Proxy: One Credential for Every Agent, and an Audit Trail You Can No Longer See
Railway's September 2026 changelog flips railway mcp from a bundled local server to a proxy for its hosted MCP endpoint. Here is the three-way tradeoff — local vs proxy-to-hosted vs self-hosted — across credentials, logging, scope enforcement, and audit ownership, plus a decision rule for production agent access.

Six Coding Agents on a Private Network: Threat-Model the Credential Blast Radius Before You Copy Railway's Sandbox
Railway's June 2026 sandboxes preinstall six coding agents with private-network reach to production data. Four Kubernetes controls — per-session identities, default-deny egress, approval-gated mutations, and auditable teardown — keep the convenience without the nine-second-wipe blast radius.

Agents Will Operate Your Platform With or Without You: What Frigade's Show HN Proves About Agent APIs
A 96-point Show HN turned observed web traffic into agent tools. That demand signal leaves platforms one choice: ship a versioned, scoped, auditable agent interface, or inherit reverse-engineered traffic with none of those properties.

Your CI Server Just Became an Agent Tool: What TeamCity's MCP Server Means for Deploy-From-Chat
TeamCity's MCP servers — the community's 87-tool Full Mode and JetBrains' official 2026.1 endpoint — turn builds, tests, and agent pools into agent-callable tools. The CI half of deploy-from-chat is here; per-tool scoping and human approval decide whether it is safe to use.

X Ships a Hosted MCP Server, and Agent Access Is Now Table Stakes
X's hosted MCP server joins Slack, Notion, GitHub, and Stripe in making first-party agent access the default. Here is the concrete production-grade bar — auth, transport, scoping, rate limits — and how it re-sequences your own MCP roadmap.

Who Sent This Agent, and Whose Authority Is It Spending? What the IETF's AIMS Draft Means for MCP Server Auth
The IETF's AIMS draft composes WIMSE, SPIFFE, and OAuth 2.0 into one agent identity model. Here is what a deploy-from-chat MCP server should borrow — and how to prove which agent called and whose authority it spent.

Automatic TLS on Owned Hardware: Caddy vs cert-manager After Hetzner's July Load Balancer Disruption
Hetzner's July 2026 Ashburn load balancer disruption showed what happens when TLS renewal shares fate with a provider's data plane. A comparison of managed LB certificates, Caddy automatic HTTPS, and cert-manager plus Gateway API — and why self-hosted platforms should own the certificate path as Let's Encrypt lifetimes shrink.

Bare-IP TLS Is GA: Instant HTTPS for Preview URLs Without a DNS Round-Trip
Let's Encrypt's generally available 160-hour IP certificates let a preview environment serve valid HTTPS on a bare node IP with no DNS records. Here is the cert-manager plus Gateway API wiring, the renewal math, and when a subdomain still wins.

Bottlerocket Killed Bare-Metal Kubernetes After 1.28: Picking a Node OS for Your CAPH Fleet
Bottlerocket's bare-metal Kubernetes variants ended at 1.28, and the last patches expired with Kubernetes 1.28's end-of-life. Here is how Talos Linux, Flatcar Container Linux, and Kairos compare as the node OS for a Cluster API fleet on owned hardware — and which one fits your team.