Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Your Buildpack Already Wrote the SBOM — Your Cluster Just Isn't Reading It
·Dora Noda·9 min

Your Buildpack Already Wrote the SBOM — Your Cluster Just Isn't Reading It

Cloud Native Buildpacks already emit a per-layer SBOM with every image, but most fleets never enforce it. Attaching that SBOM as a signed Sigstore attestation and verifying it with an admission controller turns scan-after-deploy into a deny decision before an unapproved image ever shares a node with other tenants.

self-hosting
PaaS
Kubernetes
security
+1
Let's Encrypt Did the Math for You: What ARI Renewal Exemptions Actually Buy a Self-Hosted PaaS at Tenant Scale
·Dora Noda·10 min

Let's Encrypt Did the Math for You: What ARI Renewal Exemptions Actually Buy a Self-Hosted PaaS at Tenant Scale

Let's Encrypt caps per-subdomain certificates at 50 per domain a week, but renewals coordinated through ARI are exempt from every rate limit. We work out the onboarding and renewal math for a self-hosted PaaS and what enabling ARI in cert-manager takes.

self-hosting
PaaS
security
Kubernetes
Michelin Deleted Its Second CNI: What 70-Plus Clusters With Zero Network Visibility Teach a Self-Hosted PaaS About Day One
·Dora Noda·10 min

Michelin Deleted Its Second CNI: What 70-Plus Clusters With Zero Network Visibility Teach a Self-Hosted PaaS About Day One

Michelin ran 70-plus Kubernetes clusters on two CNIs with no network visibility, then consolidated onto Cilium in two months with zero outages. What the blindness cost, how the migration worked, and a five-item checklist for getting the CNI decision right on day one.

Kubernetes
self-hosting
PaaS
infrastructure
+1
Northflank Killed Its microVM Init Container: What One Deleted Startup Step Reveals About PaaS Isolation Overhead
·Dora Noda·9 min

Northflank Killed Its microVM Init Container: What One Deleted Startup Step Reveals About PaaS Isolation Overhead

Northflank quietly removed the default init container from its microVM secure runtime. A concrete look at what that per-pod isolation scaffolding cost, and why a fleet that owns its machines pays for isolation once per node pool instead of on every pod start.

PaaS
self-hosting
Kubernetes
security
One Team Membership Was Enough: How Rancher CVE-2026-41053 Handed Every GitHub Org Member Every Team's RBAC Grants
·Dora Noda·8 min

One Team Membership Was Enough: How Rancher CVE-2026-41053 Handed Every GitHub Org Member Every Team's RBAC Grants

Rancher CVE-2026-41053 (CVSS 8.8) let any user with one GitHub team membership inherit every team's Rancher permissions. Affected versions, the broken expansion loop, and the remediation checklist.

security
infrastructure
self-hosting
engineering
No SSH? No Problem: Talos Linux's talosctl debug Is a Privileged Escape Hatch That Cleans Up After Itself
·Dora Noda·10 min

No SSH? No Problem: Talos Linux's talosctl debug Is a Privileged Escape Hatch That Cleans Up After Itself

Talos v1.13's talosctl debug runs a privileged container in the host's own namespaces — with registry-pull and offline tarball-push image paths — and deletes it on exit. We walk through a real pwru diagnosis and the audit rules for using it safely.

self-hosting
Kubernetes
security
tutorial
Buildpacks RFC 331: Getting the Extend Phase Off Vendored Kaniko
·Dora Noda·11 min

Buildpacks RFC 331: Getting the Extend Phase Off Vendored Kaniko

A Dockerfile hides inside every Dockerfile-free buildpack build — applied by a kaniko copy baked into the lifecycle image. RFC 331 would pull the extender out behind a configurable URI; Chainguard's kaniko fork bought time but didn't fix the coupling. The before/after table and the six-item operator checklist.

self-hosting
PaaS
Kubernetes
security
containerd 2.1 Is Dead and the CVE Has No Patch: Rolling a Forced Runtime Upgrade Across a Cluster API Fleet
·Dora Noda·9 min

containerd 2.1 Is Dead and the CVE Has No Patch: Rolling a Forced Runtime Upgrade Across a Cluster API Fleet

containerd 2.1 went end-of-life with no patch for Critical CVE-2026-46680, a runAsNonRoot bypass. Which versions are safe, how to pick a landing zone, and the five-step Cluster API runbook: audit, image, template, roll, verify.

Kubernetes
security
self-hosting
guide
Dokploy's One-Click Templates Deploy Over HTTP: The TLS Gap in the Catalog and the One-Field Fix
·Dora Noda·9 min

Dokploy's One-Click Templates Deploy Over HTTP: The TLS Gap in the Catalog and the One-Field Fix

Dokploy's template format has no way to request a TLS certificate, so every app installed from the one-click catalog lands on HTTP until someone hand-wires HTTPS. What that costs a team at catalog scale, how Coolify and Render handle the same moment, and the one optional field that would close the gap.

self-hosting
PaaS
security
Showing 208–216 of 532 posts