Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway
·Dora Noda·10 min

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway

Hand-writing an MCP server means maintaining a second governed interface. What projecting your REST API through a gateway gives you for free — OpenAPI-derived tools, OAuth 2.1 auth, rate limits — and the write-scoping, approval, and rollback semantics a deploy API still has to build itself.

Model Context Protocol
AI agents
API
security
AI-Assisted Commits Leak Secrets at Twice the Baseline Rate — Why Your PaaS Should Scan Every Push
·Dora Noda·9 min

AI-Assisted Commits Leak Secrets at Twice the Baseline Rate — Why Your PaaS Should Scan Every Push

GitGuardian counted 28.65 million new hardcoded secrets on public GitHub in 2025, with AI-assisted commits leaking at 3.2% against a 1.5% baseline. Why a default-on push-time scan catches what Vault, OpenBao, and Infisical never see, and what the gate should look like.

security
AI agents
developer tools
PaaS
Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production
·Dora Noda·12 min

Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production

An MCP server that can redeploy production is a deploy pipeline with natural-language input. A seven-control hardening checklist — TLS, per-tool scopes, short-lived credentials, schema validation, rate limits, and audit logging — mapped to the three attacks that actually happen.

Model Context Protocol
AI agents
security
infrastructure
+1
MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish
·Dora Noda·10 min

MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish

The final MCP spec deprecates Dynamic Client Registration in favor of Client ID Metadata Documents, with removal eligible after July 2027. Here is the ordered checklist for migrating a self-hosted MCP server, plus the two companion hardenings to ship in the same window.

Model Context Protocol
AI agents
security
self-hosting
One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server
·Dora Noda·11 min

One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server

nginx-ui shipped an MCP endpoint without its AuthRequired check — a CVSS 9.8 that left roughly 2,689 servers open to unauthenticated takeover. The full MCPwn timeline, the two-route bug, and a seven-item audit checklist for anyone shipping an MCP server.

security
Model Context Protocol
self-hosting
AI agents
SmolVM Packs a MicroVM Into a Single Binary That Boots in Under 200ms — What It Changes for a Firecracker-Only Agent Sandbox
·Dora Noda·9 min

SmolVM Packs a MicroVM Into a Single Binary That Boots in Under 200ms — What It Changes for a Firecracker-Only Agent Sandbox

SmolVM boots any OCI image as a hardware-isolated microVM from a single binary in under 200ms, with pack and branch primitives Firecracker never shipped. Here is how it compares head-to-head and what to verify before adding it to a self-hosted agent-sandbox stack.

AI agents
self-hosting
security
infrastructure
Tailscale Went Seat-Based: What Self-Hosting Your Admin VPN With NetBird or Headscale Actually Costs
·Dora Noda·12 min

Tailscale Went Seat-Based: What Self-Hosting Your Admin VPN With NetBird or Headscale Actually Costs

Tailscale's 2026 move to 8 to 18 dollar per-seat pricing turned the admin VPN into a headcount tax. What a self-hosted NetBird or Headscale control plane costs in infrastructure and ops hours, the exact seat counts where each crosses over, and when to just pay the SaaS bill.

self-hosting
cost-optimization
infrastructure
security
Toward a World Where Builds Don't Exist: What Railway's VM-Powered Thesis Gives Up in Provenance
·Dora Noda·9 min

Toward a World Where Builds Don't Exist: What Railway's VM-Powered Thesis Gives Up in Provenance

Railway wants a world where builds don't exist and your app is just live. But the build produces the digest, SBOM, provenance, and rollback artifact that incident response and the EU's new reporting rules depend on — here is the full inventory of what disappears with it.

PaaS
self-hosting
security
compliance
cert-manager vs Gardener vs certctl: What Tenant TLS Really Costs at 10, 100, and 1,000 Custom Domains
·Dora Noda·13 min

cert-manager vs Gardener vs certctl: What Tenant TLS Really Costs at 10, 100, and 1,000 Custom Domains

A head-to-head comparison of cert-manager, Gardener cert-management, and certctl for per-tenant custom-domain TLS, with the rate-limit math and renewal checklist for fleets from 10 to 1,000 domains.

self-hosting
Kubernetes
security
PaaS
Showing 163–171 of 532 posts