532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Kubernetes 1.37 Made Pod Certificates GA: The 4-Test Signer Harness to Run Before You Kill Static Credentials
Kubernetes 1.37 promotes Pod Certificates and Cluster Trust Bundles to stable, with 24-hour X.509 certs issued via PodCertificateRequest. A four-test harness for signer authorization, trust-bundle selection, lifetime refresh, and reload behavior that a self-hosted PaaS should pass before retiring static service-account tokens.

Kyverno 1.17's CEL Policies Hit v1: What One Policy Language From Admission to Audit Buys a Multi-Tenant Fleet Over Gatekeeper's Rego
Kyverno 1.17 promotes its CEL policy engine to v1 and starts a removal clock on legacy ClusterPolicy, with deletion planned for v1.20 in October 2026. A side-by-side of validation, tenant defaulting, and image verification in CEL versus Rego, plus an eight-step migration checklist for multi-tenant fleets.

Let's Encrypt Won't Make 6-Day Certificates the Default: the 6-Question Automation Exam Before You Opt In
Let's Encrypt's 160-hour certificates are GA but staying opt-in because most renewal automation can't hold a six-day clock. The per-cert slack math, a six-question pass/fail exam with a cert-manager example, and why a PaaS that owns its whole TLS path can go first.

Harvest Now, Decrypt Later Comes for Your MCP Server: Why Agent Deploy Calls Are Worth Storing
A June 2026 executive order made harvest-now-decrypt-later federal policy — and the ciphertext most worth storing is your agent's deploy calls. A three-layer exposure audit plus a concrete checklist for hybrid post-quantum key exchange on an infra MCP server's own transport.

SOPS with Age vs Sealed Secrets: What GitOps Secrets Cost to Rotate on a Cluster API Fleet
Committing encrypted secrets to Git is the easy part. A fleet-scale comparison of SOPS with age versus Bitnami Sealed Secrets on what each costs to rotate, audit, and recover after the management cluster dies — with runbooks and the February 2026 rotation CVE that settles it.

When the Grid Itself Is the Threat Model: What Berlin's Four-Day Blackout Teaches About Fleet Placement
A January 2026 arson attack naming AI data centers left 45,000 Berlin households dark for four days. Why concentrated compute is now an explicit target — and why a distributed self-hosted fleet is the cheapest hedge.

No Human Typed This Deploy: What Claude's Cron-Triggered Agents Demand From Your MCP Auth Story
Anthropic's June 2026 scheduled deployments let agents wake on a cron schedule, pull vault credentials, and ship with no human watching. Here is the six-rule auth checklist — scoped per-run grants, platform-written audit trails, blast-radius limits — a deploy-from-chat MCP surface needs before a timer gets deploy rights.

Keep Secrets Out of Your AI Agents: Credential Gateways, Short-Lived Tokens, and the Leak That Should Be Impossible
A prompt-injected agent leaks whatever secrets it can see — so stop letting it see them. How credential gateways, short-lived OIDC tokens, and Vault-backed brokers make agent access provable and revocable.

No Account, 60 Minutes, Zero Trust: The Abuse Controls Behind Anonymous Deploys
Railway's no-account 60-minute deploys show what instant agent-to-preview loops need — and what stops them from becoming free cryptominers. A hostile-user checklist for quotas, network cages, build scanning, and timed teardown on your own Kubernetes fleet.