532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Cloud Native Buildpacks Win on CVE Day, Not Day One
A base-image CVE across 17 Dockerfile-based services costs three days of edits, rebuilds, and retests. With one shared buildpack builder, it is a single bump and a rebase — here is the itemized ledger.

Cilium 1.20: Default to Portable Policy, Go Cilium-Native Only Where It Earns It
Cilium 1.20 implements upstream ClusterNetworkPolicy and promotes MCS to stable. A decision table for writing tenant-isolation policy in portable Kubernetes APIs — and the four things that still need Cilium-native rules.

Cilium 1.20 Puts Tenant Auth in the CNI: What ExternalAuth Means for Fleets Still on ingress-nginx
Cilium 1.20 adds the ExternalAuth filter to Gateway API, moving per-route authorization into the CNI you already run. A before/after of tenant auth on ingress-nginx versus HTTPRoute filters, plus an itemized migration bill for fleets facing the retired controller.

Codex Deploys End-to-End Without Leaving Chat: What That Means for Your Deploy API's Trust Boundary
OpenAI's Codex can now generate code, push to GitHub, create a Vercel project, attach a domain, and deploy — all inside one chat session. Here is the five-item trust-boundary checklist a deploy API must meet before an unattended agent should touch production.

Fail Closed Before the Agent Acts: What Conduct's Guard-Before-Every-Tool-Call Model Means for Governing Deploy Agents
Conduct puts a fail-closed policy gate — block, warn, audit, or inject — in front of every MCP and shell action an agent takes. A decision table for deploy, rollback, and secret-read tools, plus which production actions still need a human.

Copy Fail: 4 Bytes in the Page Cache Break Container Isolation on Every Major Distro
A 732-byte script turns an unprivileged user into root on every major distro — and the shared page cache carries the corruption across containers. What stops it, what doesn't, and the patch-and-isolate playbook for your fleet.

Gartner Says 40% of Agentic AI Projects Will Die by 2027 — the Deploy Target Is the Governance Gap
Gartner predicts over 40% of agentic AI projects will be canceled by end of 2027 on cost and weak risk controls. These are the five governance controls — agent identity, audit trails, sandboxed execution, PR gates, and cost guardrails — your deploy target needs before background coding agents touch production.

Kubernetes 1.36 Locks On Fine-Grained Kubelet Authorization: The nodes/proxy Migration Your Multi-Tenant Fleet Owes Itself
Kubernetes 1.36 graduates fine-grained kubelet authorization to GA, replacing the over-broad nodes/proxy grant that lets read-only agents execute code in any pod. This playbook maps every kubelet endpoint to its least-privilege subresource and walks through the five-step migration for fleets running untrusted tenant workloads.

Signing Every Build Means Nothing If Nothing Checks: Wiring Cosign Into a Git-Push PaaS
Kubernetes signs its releases with Sigstore — but a signature nobody verifies is theater. How to wire Cosign keyless signing into a git-push pipeline and enforce it with a Kyverno admission policy before unsigned images reach your nodes.