532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Your Buildpack Already Wrote the SBOM — Your Cluster Just Isn't Reading It
Cloud Native Buildpacks already emit a per-layer SBOM with every image, but most fleets never enforce it. Attaching that SBOM as a signed Sigstore attestation and verifying it with an admission controller turns scan-after-deploy into a deny decision before an unapproved image ever shares a node with other tenants.

Let's Encrypt Did the Math for You: What ARI Renewal Exemptions Actually Buy a Self-Hosted PaaS at Tenant Scale
Let's Encrypt caps per-subdomain certificates at 50 per domain a week, but renewals coordinated through ARI are exempt from every rate limit. We work out the onboarding and renewal math for a self-hosted PaaS and what enabling ARI in cert-manager takes.

Michelin Deleted Its Second CNI: What 70-Plus Clusters With Zero Network Visibility Teach a Self-Hosted PaaS About Day One
Michelin ran 70-plus Kubernetes clusters on two CNIs with no network visibility, then consolidated onto Cilium in two months with zero outages. What the blindness cost, how the migration worked, and a five-item checklist for getting the CNI decision right on day one.

Northflank Killed Its microVM Init Container: What One Deleted Startup Step Reveals About PaaS Isolation Overhead
Northflank quietly removed the default init container from its microVM secure runtime. A concrete look at what that per-pod isolation scaffolding cost, and why a fleet that owns its machines pays for isolation once per node pool instead of on every pod start.

One Team Membership Was Enough: How Rancher CVE-2026-41053 Handed Every GitHub Org Member Every Team's RBAC Grants
Rancher CVE-2026-41053 (CVSS 8.8) let any user with one GitHub team membership inherit every team's Rancher permissions. Affected versions, the broken expansion loop, and the remediation checklist.

No SSH? No Problem: Talos Linux's talosctl debug Is a Privileged Escape Hatch That Cleans Up After Itself
Talos v1.13's talosctl debug runs a privileged container in the host's own namespaces — with registry-pull and offline tarball-push image paths — and deletes it on exit. We walk through a real pwru diagnosis and the audit rules for using it safely.

Buildpacks RFC 331: Getting the Extend Phase Off Vendored Kaniko
A Dockerfile hides inside every Dockerfile-free buildpack build — applied by a kaniko copy baked into the lifecycle image. RFC 331 would pull the extender out behind a configurable URI; Chainguard's kaniko fork bought time but didn't fix the coupling. The before/after table and the six-item operator checklist.

containerd 2.1 Is Dead and the CVE Has No Patch: Rolling a Forced Runtime Upgrade Across a Cluster API Fleet
containerd 2.1 went end-of-life with no patch for Critical CVE-2026-46680, a runAsNonRoot bypass. Which versions are safe, how to pick a landing zone, and the five-step Cluster API runbook: audit, image, template, roll, verify.

Dokploy's One-Click Templates Deploy Over HTTP: The TLS Gap in the Catalog and the One-Field Fix
Dokploy's template format has no way to request a TLS certificate, so every app installed from the one-click catalog lands on HTTP until someone hand-wires HTTPS. What that costs a team at catalog scale, how Coolify and Render handle the same moment, and the one optional field that would close the gap.