Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain
·Dora Noda·9 min

The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain

The OpenClaw Kubernetes operator packs non-root pods, dropped capabilities, and a default-deny NetworkPolicy into one install — a solid floor for running AI agents in-cluster. But Pod hardening stops at the process boundary: prompt injection, over-broad MCP credentials, and destructive-tool authorization need a governance layer no CRD provides.

AI agents
security
Kubernetes
Model Context Protocol
+1
Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.
·Dora Noda·11 min

Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.

Refuse is an open-source, self-hostable gate that blocks known-vulnerable package installs across 18 package managers before anything hits disk — including installs your coding agent runs. Here is how it works, where it belongs in a PaaS build pipeline, and what it cannot catch.

security
PaaS
self-hosting
AI agents
+1
Rootless Kubelet Hits Beta in Kubernetes 1.37: What Dropping Host Root Changes for Multi-Tenant Nodes (and What Still Needs It)
·Dora Noda·11 min

Rootless Kubelet Hits Beta in Kubernetes 1.37: What Dropping Host Root Changes for Multi-Tenant Nodes (and What Still Needs It)

Kubernetes 1.37 promotes rootless kubelet mode to beta, so node components run as a non-root host user and breakouts stay confined to one account. Here is the blast-radius accounting, the full compatibility inventory, and a one-pool pilot playbook for Hetzner fleets.

Kubernetes
security
self-hosting
infrastructure
The Self-Hosted Governance Gap: Why Your Compliance Team Says No to Coolify, Dokku, CapRover, and Dokploy
·Dora Noda·11 min

The Self-Hosted Governance Gap: Why Your Compliance Team Says No to Coolify, Dokku, CapRover, and Dokploy

Coolify, Dokku, CapRover, and Dokploy win engineering evaluations and lose security reviews: no enterprise SSO, no audit trail. A capability-by-capability look at what compliance-bound teams need and what a self-hosted PaaS must build to win them.

self-hosting
PaaS
governance
compliance
+1
What AI Agents Actually Deploy: Vercel's Ship 2026 Numbers and the PaaS Defaults They Break
·Dora Noda·11 min

What AI Agents Actually Deploy: Vercel's Ship 2026 Numbers and the PaaS Defaults They Break

Vercel's Ship 2026 numbers show agent-triggered deployments passing 50% while AI Gateway tokens grew 10x to 20 trillion a month. What the shift toward inference-calling apps means for PaaS egress, secrets, and metering defaults — and a scorecard for self-hosted platforms.

PaaS
AI agents
self-hosting
security
+1
Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access
·Dora Noda·11 min

Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access

40% of reachable MCP servers need no authentication and tool-poisoning fools flagship models. A concrete blueprint — scoped credential exchange, an OPA default-deny policy, ephemeral runners — that makes the gateway, not the model, the enforcement point.

AI agents
Model Context Protocol
security
PaaS
Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat
·Dora Noda·9 min

Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat

Deploy-from-chat dies the moment the agent asks for your API key. Arcade.dev's MCP runtime — Engine-vaulted OAuth, URL elicitation co-built with Anthropic, per-call scoped credentials — shows how agents deploy without holding tokens, with the deny, revoke, and re-scope paths spelled out.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Daytona Went Closed-Source: What It Costs to Build Agent Sandboxes on Borrowed Open Source
·Dora Noda·9 min

Daytona Went Closed-Source: What It Costs to Build Agent Sandboxes on Borrowed Open Source

Daytona moved its core to a private codebase in June 2026, freezing the open repo at v0.190.0 with no security patches. What that costs self-hosters in CVE backports, API drift, and AGPL obligations — plus a five-way comparison of Microsandbox, E2B self-hosted, Beam, CubeSandbox, and the SIG-governed agent-sandbox.

AI agents
self-hosting
infrastructure
security
Your Deploy Agent Is a Script With an API Key: What Agent Lifecycle Managers Actually Gate
·Dora Noda·9 min

Your Deploy Agent Is a Script With an API Key: What Agent Lifecycle Managers Actually Gate

A deploy agent with a scoped API key is a script with credentials that can improvise. How SPIFFE identity, RFC 8693 delegation, and Kagenti's agent registry gate every deploy call — and what scoped-keys-plus-audit-logs can't see.

Model Context Protocol
AI agents
security
self-hosting
+1
Showing 181–189 of 532 posts