Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Harbor's CVSS 9.4 Default Password: How to Tell If Your Registry Is Exposed, and the First-Boot Rule That Prevents the Next One
·Dora Noda·9 min

Harbor's CVSS 9.4 Default Password: How to Tell If Your Registry Is Exposed, and the First-Boot Rule That Prevents the Next One

Harbor 2.15.0 and below ships with a working admin/Harbor12345 default worth CVSS 9.4. A five-minute exposure audit, the rotate-first fix order, what to hunt if it was reachable, and the first-boot rule your own platform should steal.

security
self-hosting
infrastructure
guide
SEP-835 Scopes: Least-Privilege MCP Tokens for Agents That Hold Deploy Keys
·Dora Noda·9 min

SEP-835 Scopes: Least-Privilege MCP Tokens for Agents That Hold Deploy Keys

MCP's SEP-835 adds native per-tool scopes and RFC 8707 audience binding, so a status-check agent holds read-only scopes while deploy and rollback stay behind explicit step-up — and a compromised tool call fails closed instead of shipping an unauthorized deploy.

AI
security
identity
engineering
Render's CLI Now Phones Home by Default: What Opt-Out Telemetry Means for Trusting Your Deploy Tool
·Dora Noda·9 min

Render's CLI Now Phones Home by Default: What Opt-Out Telemetry Means for Trusting Your Deploy Tool

Render CLI v2.26.0 collects usage telemetry by default. This breakdown covers exactly what it sends, how to opt out, the CI disclosure gap in its notice design, and the standard credential-holding CLIs should meet.

security
privacy
developer tools
PaaS
Stop Passing Service Account Tokens to CSI Drivers in Volume Context: What the v1.35 Token-in-Secrets Fix Means for Your Storage Layer
·Dora Noda·8 min

Stop Passing Service Account Tokens to CSI Drivers in Volume Context: What the v1.35 Token-in-Secrets Fix Means for Your Storage Layer

CSI drivers received workload-identity tokens in a log-visible gRPC map, and two CVEs printed them into driver logs. How the v1.35 secrets-field fix works, the rollout order that avoids breaking mounts, and how to audit your fleet.

security
Kubernetes
infrastructure
self-hosting
Synacktiv's Unpatched Argo CD Repo-Server Flaw: Why Any Pod That Can Reach the gRPC Service Is Equivalent to an Authenticated Attacker
·Dora Noda·10 min

Synacktiv's Unpatched Argo CD Repo-Server Flaw: Why Any Pod That Can Reach the gRPC Service Is Equivalent to an Authenticated Attacker

Argo CD's repo-server exposes an unauthenticated gRPC endpoint that turns any pod with network reachability into a path to cluster takeover. This breakdown covers Synacktiv's exploit chain, which installs are exposed, and the exact NetworkPolicies that close it.

security
Kubernetes
self-hosting
developer tools
A2A Joins MCP Under One Roof: How to Hand an Ops Agent a Deploy Investigation Without Handing Over Deploy Authority
·Dora Noda·10 min

A2A Joins MCP Under One Roof: How to Hand an Ops Agent a Deploy Investigation Without Handing Over Deploy Authority

A2A joining MCP under the Agentic AI Foundation settles which protocol does what: A2A moves the diagnosis between agents, MCP moves capability between an agent and the platform. Here is the handoff design that keeps it that way — a worked deploy-investigation task, a three-tool audited MCP surface, and the identity, approval, and least-privilege invariants mapped to Kubernetes RBAC.

AI agents
Model Context Protocol
Kubernetes
security
Your Agent Can Call 7,000 SaaS APIs. Can It Deploy to a Machine You Own?
·Dora Noda·10 min

Your Agent Can Call 7,000 SaaS APIs. Can It Deploy to a Machine You Own?

Arcade.dev gives agents 7,500+ SaaS tools behind brokered OAuth; Capix MCP gives them 37 tools that deploy models, provision GPUs, and emit signed receipts. Only one of those surfaces operates infrastructure you own — here is the checklist your PaaS MCP server still has to complete.

AI agents
Model Context Protocol
self-hosting
PaaS
+1
A Czech Self-Hosting Hub Gave Claude Shell Access to Its Coolify Fleet: A 130-Line MCP Bridge Teardown
·Dora Noda·12 min

A Czech Self-Hosting Hub Gave Claude Shell Access to Its Coolify Fleet: A 130-Line MCP Bridge Teardown

A Czech self-hosting hub wired Claude to its Coolify fleet through a 133-line MCP bridge — and handed the agent raw SSH instead of scoped deploy tokens. A code-level teardown of all seven tools, plus the five authorization rules a platform-owned MCP server needs.

Model Context Protocol
AI agents
self-hosting
security
+1
Chat Deploys My App: What the Coolify–AnythingLLM MCP Bridge Proves, and the 5 Gaps a Render-Compatible MCP Server Closes
·Dora Noda·12 min

Chat Deploys My App: What the Coolify–AnythingLLM MCP Bridge Proves, and the 5 Gaps a Render-Compatible MCP Server Closes

A community MCP server lets an LLM inspect, restart, and debug apps on a self-hosted Coolify box through AnythingLLM chat — but behind one shared API token sit a docker-socket tap and a root shell over SSH. Here is what the bridge proves, how Render's official MCP server scopes agent power instead, and the five gaps a Render-compatible MCP server still has to close.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Showing 154–162 of 532 posts