Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Hard Multi-Tenancy for Agent Workloads: What Apple's Kata plus VirtualClusters Recipe Costs
·Dora Noda·11 min

Hard Multi-Tenancy for Agent Workloads: What Apple's Kata plus VirtualClusters Recipe Costs

Apple's KubeCon recipe pairs per-tenant virtual control planes with Kata microVMs so untrusted agent code never shares a kernel with production tenants. The bill: about a second of cold start and 30-100 MB per sandbox, plus one small control plane per tenant.

Kubernetes
PaaS
self-hosting
AI agents
+1
Heroku Killed 12 TLS Ciphers: The Legacy-Client Audit Your Self-Hosted PaaS Needs Too
·Dora Noda·9 min

Heroku Killed 12 TLS Ciphers: The Legacy-Client Audit Your Self-Hosted PaaS Needs Too

Heroku removed 12 legacy TLS cipher suites and enabled TLS 1.3 with HTTP/2 on August 24, 2026. Here is which clients break, a reproducible openssl/sslyze/testssl.sh audit for your own domains, and the cert-manager plus Gateway API baseline to match it.

security
self-hosting
PaaS
infrastructure
+1
Your Coding Agent Needs a Sandbox, Not a StatefulSet: gVisor vs Kata Under Kubernetes' New Sandbox Controller
·Dora Noda·10 min

Your Coding Agent Needs a Sandbox, Not a StatefulSet: gVisor vs Kata Under Kubernetes' New Sandbox Controller

Kubernetes SIG Apps shipped an upstream Sandbox controller for running untrusted agent code. A practical decision guide: what it replaces, whether gVisor or Kata fits your tenants, and what warm pools cost in idle capacity.

AI agents
Kubernetes
self-hosting
security
+1
10,000 MCP Servers and No Human Wiring Them Up: What Server Cards and Stateless Operation Mean for Agents That Deploy Your Apps
·Dora Noda·10 min

10,000 MCP Servers and No Human Wiring Them Up: What Server Cards and Stateless Operation Mean for Agents That Deploy Your Apps

MCP passed 10,000 public servers and is going stateless and self-describing, so agents will soon reach your deploy tools with no human wiring anything up. Here is the three-tier tool surface — observe freely, gate mutation, deny destruction — that survives contact with autonomous callers.

Model Context Protocol
AI agents
security
self-hosting
+1
Railway Cloud Agents Promote Your Dev VM Straight to Prod: What Skipping the Build Actually Costs
·Dora Noda·10 min

Railway Cloud Agents Promote Your Dev VM Straight to Prod: What Skipping the Build Actually Costs

Railway's Cloud Agents Beta promotes the agent's lived-in VM straight to production via a VM daemon, skipping git push and CI as too slow. A five-row ledger of what the build step was quietly doing — drift, secrets, approvals, rollback, provenance — and how to keep the fast loop without shipping a mutable machine.

PaaS
self-hosting
AI agents
security
+1
Your Sandbox Is Not a Home: Where Vibe-Coded Apps Actually Live After Day One
·Dora Noda·11 min

Your Sandbox Is Not a Home: Where Vibe-Coded Apps Actually Live After Day One

Every 2026 guide to shipping vibe-coded apps ends at 'deploy behind a sandbox' — without saying where the app lives long-term. The missing fifth stage: a permanent git-backed home with a redeploy loop, the sandbox-vs-home checklist, and the cost crossover between execution meters and flat hardware.

PaaS
self-hosting
AI agents
security
+1
SmolVM vs. Firecracker: Which MicroVM Should Actually Isolate Your AI Agent's Code?
·Dora Noda·10 min

SmolVM vs. Firecracker: Which MicroVM Should Actually Isolate Your AI Agent's Code?

SmolVM's sub-200ms boot challenges Firecracker's two-year default. A measured comparison of boot time, memory density, and what actually isolates untrusted agent code from the host kernel across SmolVM, Firecracker, OpenSandbox, and Docker Sandboxes.

AI agents
self-hosting
PaaS
infrastructure
+1
Run a Claude Fable Security Scan with Bex Security
·Dora Noda·9 min

Run a Claude Fable Security Scan with Bex Security

Run a Claude Fable security scan with Claude Code and Bex Security. The exact command, the model row that actually runs, and the sandbox policy Bex enforces around Claude.

changelog
product
security
AI agents
+3
Coolify's 11 Critical CVEs and 52,890 Exposed Dashboards: What a Single Root Daemon's Blast Radius Actually Looks Like
·Dora Noda·10 min

Coolify's 11 Critical CVEs and 52,890 Exposed Dashboards: What a Single Root Daemon's Blast Radius Actually Looks Like

Coolify disclosed 11 critical CVEs in January 2026 — five rated CVSS 10.0 — with 52,890 dashboards exposed online. Eight months later, here is what changed, what didn't, and why blast radius per CVE is the number that should drive self-hosted PaaS architecture choices.

self-hosting
PaaS
security
Kubernetes
Showing 226–234 of 532 posts