529 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Kubernetes Rewrote Its Image Promoter and Deleted 20% of It: A 7-Phase Registry Lesson for Self-Hosted PaaS
Kubernetes rewrote kpromo, its registry.k8s.io image promoter, deleting 20% of the code while cutting plan time from 20 minutes to 2 and signature replication from 17 hours to 15 minutes. A close read of the 7-phase pipeline — and what a self-hosted PaaS should copy and skip.

Your TLS Renewals Have an Expiration Date Too: Auditing cert-manager for Let's Encrypt's 45-Day Countdown
Let's Encrypt drops to 45-day certificates by 2028 — run this four-step cert-manager audit on versions, hardcoded renewBefore windows, the ARI gate, and expiry alerting before fixed renewal intervals start breaking.

Whose Token Is It? Solving the MCP and OAuth2 Identity Problem for AI Agent Deploys
Every deploy, rollback, or scale call an AI agent makes must answer who authorized it: the developer, the agent, or the tenant. This post maps the three-identity model, the July 2026 MCP authorization rules, and the token-exchange pattern that keeps deploy-from-chat auditable.

Deploy From Chat Without Handing the Agent Your Production Keys: Remote MCP After the 2026-07-28 Spec
A production design for a deploy-capable remote MCP server under the 2026-07-28 spec: OAuth discovery via protected-resource metadata, audience-bound tokens, narrow per-environment scopes, human approval gates for destructive tools, and chain-complete audit logs.

Vercel Made Blocked Traffic Free — Here's What That Costs to Build Yourself
Vercel's May 2026 Firewall change made WAF-blocked traffic free on every plan — this post prices each layer of that bundle for a self-hosted fleet and gives the five-item checklist a PaaS control plane must ship to match it.

Sealed Secrets vs External Secrets Operator in 2026: What Git-Stored Ciphertext Really Costs a Three-Person Platform Team Against Vault Sync
Sealed Secrets vs External Secrets Operator for tenant secrets on a self-hosted multi-tenant fleet: a grounded cost comparison of vault sync against git-stored ciphertext, with tenant-isolation recipes and the thresholds for switching.

Rootless Kubelet Goes Beta in Kubernetes 1.37: A Hardening Checklist for Self-Hosted Fleets
Kubernetes 1.37 promotes KubeletInUserNamespace to beta, letting the kubelet and node components run as an unprivileged user so container breakouts stop at a UID instead of host root — plus the nine-item cgroup, runtime, CNI, and storage checklist for making rootless your node-image default.

OpenAI Built Codex a Windows Sandbox Out of SIDs and Firewall Rules: What It Teaches a Linux-First PaaS About Isolating Agent Code
OpenAI's May 2026 write-up shows how Codex sandboxes agent commands on Windows with synthetic SIDs, write-restricted tokens, dedicated sandbox users, and firewall rules — here is the two-tier design, the three isolation lessons a Linux-first PaaS should take from it, and an explicit verdict on whether it needs a Windows tier.

Pangolin Puts SSO and WireGuard in Front of LLM Access Instead of API Keys: What Tunnel-Based Identity Means for Agent Credential Hygiene
Pangolin's AI Gateway authenticates LLM access with SSO-backed WireGuard tunnels instead of static API keys, and joins self-hosted models to the same gateway as public ones. Here's how the mechanism works, how it compares to Tailscale Aperture, and what it changes in your threat model.