Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

The Tenant Domain That Didn't Renew: cert-manager vs Gardener vs certctl for Per-Tenant TLS
·Dora Noda·10 min

The Tenant Domain That Didn't Renew: cert-manager vs Gardener vs certctl for Per-Tenant TLS

One certificate per tenant collides with Let's Encrypt's 50-per-week ceiling fast. A concrete comparison of cert-manager, Gardener cert-management, and certctl on challenges, secret distribution, and renewal failure modes — plus which one a self-hosted PaaS should default to.

self-hosting
PaaS
Kubernetes
security
+1
ClawBleed: How One Clicked Link Turned 40,000 Self-Hosted Agent Gateways Into Remote Shells
·Dora Noda·9 min

ClawBleed: How One Clicked Link Turned 40,000 Self-Hosted Agent Gateways Into Remote Shells

CVE-2026-25253 let one malicious link steal an OpenClaw gateway token and take over the host. The kill chain, the 40,000 exposed instances, and the gateway-auth checklist for anything an agent can deploy through.

security
self-hosting
AI agents
infrastructure
Coolify's MCP Server Just Made Deploy-From-Chat Table Stakes: What 'Ask Claude to Ship It' Really Covers (and What It Doesn't)
·Dora Noda·10 min

Coolify's MCP Server Just Made Deploy-From-Chat Table Stakes: What 'Ask Claude to Ship It' Really Covers (and What It Doesn't)

Coolify's native read-only MCP endpoint plus 42-tool community servers let agents deploy to self-hosted infrastructure from chat. A labeled walkthrough of the Postgres-to-FastAPI loop, and the five governance controls a fast follower needs.

PaaS
self-hosting
AI agents
infrastructure
+1
Coolify Fixed 11 Critical CVEs in v4.0.0 — How to Audit Any Self-Hosted PaaS Before Trusting It With Secrets
·Dora Noda·10 min

Coolify Fixed 11 Critical CVEs in v4.0.0 — How to Audit Any Self-Hosted PaaS Before Trusting It With Secrets

Coolify's v4.0.0 release rolled up fixes for 11 critical CVEs, several scoring CVSS 10.0. A breakdown of what the flaws allowed, the patterns they share, and a six-point checklist for auditing any self-hosted platform before it holds your secrets.

security
self-hosting
PaaS
Your Ingress-Nginx Has an Expiry Date: What Moving to Gateway API Actually Takes
·Dora Noda·11 min

Your Ingress-Nginx Has an Expiry Date: What Moving to Gateway API Actually Takes

ingress-nginx maintenance ended in March 2026 and the last vendor patch bridge runs out in November 2026. A before/after resource map, a four-phase migration with no flag day, and the full TLS story for self-hosted fleets.

Kubernetes
PaaS
self-hosting
infrastructure
+1
kuberc Is On by Default: Your kubectl Habits Finally Move Out of the Kubeconfig
·Dora Noda·8 min

kuberc Is On by Default: Your kubectl Habits Finally Move Out of the Kubeconfig

Kubernetes 1.36 keeps kuberc beta and on by default, adds a real management CLI, and turns the credential-plugin allowlist rename into a hard error. What the preferences/kubeconfig split means for a shared ops box.

Kubernetes
security
self-hosting
PaaS
Six Days to Renew: What Let's Encrypt's Short-Lived Certificates Do to Your Renewal Margin
·Dora Noda·10 min

Six Days to Renew: What Let's Encrypt's Short-Lived Certificates Do to Your Renewal Margin

Let's Encrypt's 160-hour shortlived certificates cut renewal slack from 30 days to about 53 hours. The before/after margin math, plus the automation, monitoring, and default-or-opt-in checklist a self-hosted platform needs first.

security
self-hosting
PaaS
Kubernetes
The Gate That Wasn't There: What Nomad's CVE-2026-14891 Teaches About Scheduler Isolation
·Dora Noda·10 min

The Gate That Wasn't There: What Nomad's CVE-2026-14891 Teaches About Scheduler Isolation

Nomad 2.0.4 fixed a CVE that let any job submitter land a container in the host's PID, network, or IPC namespaces — because the allow_privileged check was never evaluated. What the bug, its two sibling fixes, and Kubernetes' admission-time enforcement say about choosing a scheduler for untrusting tenants.

self-hosting
PaaS
Kubernetes
security
+1
Your npm Token Is the Next Supply-Chain Incident: A Tokenless Publishing Playbook for Git-Push Pipelines
·Dora Noda·10 min

Your npm Token Is the Next Supply-Chain Incident: A Tokenless Publishing Playbook for Git-Push Pipelines

npm's OIDC trusted publishing replaces the long-lived NPM_TOKEN with per-run workload identity and automatic provenance. A six-step migration checklist with version floors and failure modes, the 2026 enforcement timeline through January 2027, and what the pattern means for a self-hosted build pipeline.

security
self-hosting
PaaS
tutorial
+1
Showing 199–207 of 532 posts