Skip to main content

529 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Kubernetes Rewrote Its Image Promoter and Deleted 20% of It: A 7-Phase Registry Lesson for Self-Hosted PaaS
·Dora Noda·10 min

Kubernetes Rewrote Its Image Promoter and Deleted 20% of It: A 7-Phase Registry Lesson for Self-Hosted PaaS

Kubernetes rewrote kpromo, its registry.k8s.io image promoter, deleting 20% of the code while cutting plan time from 20 minutes to 2 and signature replication from 17 hours to 15 minutes. A close read of the 7-phase pipeline — and what a self-hosted PaaS should copy and skip.

Kubernetes
self-hosting
PaaS
security
Your TLS Renewals Have an Expiration Date Too: Auditing cert-manager for Let's Encrypt's 45-Day Countdown
·Dora Noda·9 min

Your TLS Renewals Have an Expiration Date Too: Auditing cert-manager for Let's Encrypt's 45-Day Countdown

Let's Encrypt drops to 45-day certificates by 2028 — run this four-step cert-manager audit on versions, hardcoded renewBefore windows, the ARI gate, and expiry alerting before fixed renewal intervals start breaking.

security
Kubernetes
self-hosting
guide
Whose Token Is It? Solving the MCP and OAuth2 Identity Problem for AI Agent Deploys
·Dora Noda·9 min

Whose Token Is It? Solving the MCP and OAuth2 Identity Problem for AI Agent Deploys

Every deploy, rollback, or scale call an AI agent makes must answer who authorized it: the developer, the agent, or the tenant. This post maps the three-identity model, the July 2026 MCP authorization rules, and the token-exchange pattern that keeps deploy-from-chat auditable.

Model Context Protocol
AI agents
security
identity
Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec
·Dora Noda·13 min

Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec

A production design for a deploy-capable remote MCP server under the 2026-07-28 spec: OAuth discovery via protected-resource metadata, audience-bound tokens, narrow per-environment scopes, human approval gates for destructive tools, and chain-complete audit logs.

Model Context Protocol
AI agents
security
engineering
Vercel Made Blocked Traffic Free — Here's What That Costs to Build Yourself
·Dora Noda·10 min

Vercel Made Blocked Traffic Free — Here's What That Costs to Build Yourself

Vercel's May 2026 Firewall change made WAF-blocked traffic free on every plan — this post prices each layer of that bundle for a self-hosted fleet and gives the five-item checklist a PaaS control plane must ship to match it.

security
self-hosting
PaaS
cost-optimization
Sealed Secrets vs External Secrets Operator in 2026: What Git-Stored Ciphertext Really Costs a Three-Person Platform Team Against Vault Sync
·Dora Noda·9 min

Sealed Secrets vs External Secrets Operator in 2026: What Git-Stored Ciphertext Really Costs a Three-Person Platform Team Against Vault Sync

Sealed Secrets vs External Secrets Operator for tenant secrets on a self-hosted multi-tenant fleet: a grounded cost comparison of vault sync against git-stored ciphertext, with tenant-isolation recipes and the thresholds for switching.

Kubernetes
security
self-hosting
engineering
Rootless Kubelet Goes Beta in Kubernetes 1.37: A Hardening Checklist for Self-Hosted Fleets
·Dora Noda·10 min

Rootless Kubelet Goes Beta in Kubernetes 1.37: A Hardening Checklist for Self-Hosted Fleets

Kubernetes 1.37 promotes KubeletInUserNamespace to beta, letting the kubelet and node components run as an unprivileged user so container breakouts stop at a UID instead of host root — plus the nine-item cgroup, runtime, CNI, and storage checklist for making rootless your node-image default.

Kubernetes
security
self-hosting
infrastructure
OpenAI Built Codex a Windows Sandbox Out of SIDs and Firewall Rules: What It Teaches a Linux-First PaaS About Isolating Agent Code
·Dora Noda·11 min

OpenAI Built Codex a Windows Sandbox Out of SIDs and Firewall Rules: What It Teaches a Linux-First PaaS About Isolating Agent Code

OpenAI's May 2026 write-up shows how Codex sandboxes agent commands on Windows with synthetic SIDs, write-restricted tokens, dedicated sandbox users, and firewall rules — here is the two-tier design, the three isolation lessons a Linux-first PaaS should take from it, and an explicit verdict on whether it needs a Windows tier.

Codex
AI agents
security
self-hosting
Pangolin Puts SSO and WireGuard in Front of LLM Access Instead of API Keys: What Tunnel-Based Identity Means for Agent Credential Hygiene
·Dora Noda·10 min

Pangolin Puts SSO and WireGuard in Front of LLM Access Instead of API Keys: What Tunnel-Based Identity Means for Agent Credential Hygiene

Pangolin's AI Gateway authenticates LLM access with SSO-backed WireGuard tunnels instead of static API keys, and joins self-hosted models to the same gateway as public ones. Here's how the mechanism works, how it compares to Tailscale Aperture, and what it changes in your threat model.

security
AI agents
LLM
self-hosting
+1
Showing 10–18 of 529 posts