Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Cloud Native Buildpacks Win on CVE Day, Not Day One
·Dora Noda·10 min

Cloud Native Buildpacks Win on CVE Day, Not Day One

A base-image CVE across 17 Dockerfile-based services costs three days of edits, rebuilds, and retests. With one shared buildpack builder, it is a single bump and a rebase — here is the itemized ledger.

security
PaaS
self-hosting
developer tools
Cilium 1.20: Default to Portable Policy, Go Cilium-Native Only Where It Earns It
·Dora Noda·10 min

Cilium 1.20: Default to Portable Policy, Go Cilium-Native Only Where It Earns It

Cilium 1.20 implements upstream ClusterNetworkPolicy and promotes MCS to stable. A decision table for writing tenant-isolation policy in portable Kubernetes APIs — and the four things that still need Cilium-native rules.

Kubernetes
self-hosting
PaaS
security
Cilium 1.20 Puts Tenant Auth in the CNI: What ExternalAuth Means for Fleets Still on ingress-nginx
·Dora Noda·9 min

Cilium 1.20 Puts Tenant Auth in the CNI: What ExternalAuth Means for Fleets Still on ingress-nginx

Cilium 1.20 adds the ExternalAuth filter to Gateway API, moving per-route authorization into the CNI you already run. A before/after of tenant auth on ingress-nginx versus HTTPRoute filters, plus an itemized migration bill for fleets facing the retired controller.

Kubernetes
self-hosting
migration
security
Codex Deploys End-to-End Without Leaving Chat: What That Means for Your Deploy API's Trust Boundary
·Dora Noda·10 min

Codex Deploys End-to-End Without Leaving Chat: What That Means for Your Deploy API's Trust Boundary

OpenAI's Codex can now generate code, push to GitHub, create a Vercel project, attach a domain, and deploy — all inside one chat session. Here is the five-item trust-boundary checklist a deploy API must meet before an unattended agent should touch production.

Codex
AI agents
PaaS
security
Fail Closed Before the Agent Acts: What Conduct's Guard-Before-Every-Tool-Call Model Means for Governing Deploy Agents
·Dora Noda·10 min

Fail Closed Before the Agent Acts: What Conduct's Guard-Before-Every-Tool-Call Model Means for Governing Deploy Agents

Conduct puts a fail-closed policy gate — block, warn, audit, or inject — in front of every MCP and shell action an agent takes. A decision table for deploy, rollback, and secret-read tools, plus which production actions still need a human.

Model Context Protocol
AI agents
self-hosting
security
Copy Fail: 4 Bytes in the Page Cache Break Container Isolation on Every Major Distro
·Dora Noda·11 min

Copy Fail: 4 Bytes in the Page Cache Break Container Isolation on Every Major Distro

A 732-byte script turns an unprivileged user into root on every major distro — and the shared page cache carries the corruption across containers. What stops it, what doesn't, and the patch-and-isolate playbook for your fleet.

security
Kubernetes
self-hosting
infrastructure
Gartner Says 40% of Agentic AI Projects Will Die by 2027 — the Deploy Target Is the Governance Gap
·Dora Noda·11 min

Gartner Says 40% of Agentic AI Projects Will Die by 2027 — the Deploy Target Is the Governance Gap

Gartner predicts over 40% of agentic AI projects will be canceled by end of 2027 on cost and weak risk controls. These are the five governance controls — agent identity, audit trails, sandboxed execution, PR gates, and cost guardrails — your deploy target needs before background coding agents touch production.

AI agents
governance
security
self-hosting
Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself
·Dora Noda·9 min

Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself

Kubernetes 1.36 graduates fine-grained kubelet authorization to GA, replacing the over-broad nodes/proxy grant that lets read-only agents execute code in any pod. This playbook maps every kubelet endpoint to its least-privilege subresource and walks through the five-step migration for fleets running untrusted tenant workloads.

Kubernetes
security
self-hosting
infrastructure
Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS
·Dora Noda·10 min

Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS

Kubernetes signs its releases with Sigstore — but a signature nobody verifies is theater. How to wire Cosign keyless signing into a git-push pipeline and enforce it with a Kyverno admission policy before unsigned images reach your nodes.

security
Kubernetes
self-hosting
PaaS
Showing 127–135 of 532 posts