532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

MCP’s Ecosystem Is Big Enough to Be an Attack Surface: Scope a Deploy-from-Chat Server
A practical permission, approval, and audit design for an MCP deploy server that keeps untrusted tool context from becoming a production action.

Platform Engineering 2.0 Has Five Good Ideas—and an Implementation Gap
A practical readiness matrix for turning Platform Engineering 2.0’s AI, agent, FinOps, security, and composability pillars into operating designs a Kubernetes PaaS can verify.

Railway’s ChatGPT and Grok Plugins Show Why Deploy-From-Chat Needs an Open Control Plane
Railway’s ChatGPT and Grok plugins point to a host-neutral control-plane design for safely deploying and operating a PaaS from any chat client.

The .self TLD Bid: What a Human-First Domain Would—and Wouldn't—Change for Self-Hosted Apps
What the proposed .self TLD could change for self-hosted apps, what still requires portable DNS and TLS automation, and the policy questions a public-good registry must answer.

SELinux Volume Labels in Kubernetes 1.36: Audit Your Multi-Tenant Storage Before 1.37
Kubernetes 1.37 makes SELinux context mounts the default for eligible volumes. Audit CSI drivers, shared PVCs, and label conflicts before the upgrade leaves a Pod stuck in ContainerCreating.

Kubernetes v1.36 Deprecated Service ExternalIPs: A Bare-Metal PaaS Migration Plan Before v1.40
Kubernetes v1.36 deprecated Service externalIPs ahead of planned kube-proxy disablement in v1.40. Use this migration plan to replace insecure tenant-selected addresses with MetalLB, Gateway API, controlled routing, and tested rollback.

Four npm Compromises in 77 Days: A Build-Sandbox Blueprint for Self-Hosted PaaS
Axios, node-ipc, Red Hat, and Mastra expose why lockfiles alone fail—and how isolated builds, denied egress, script policy, and SBOMs contain poisoned dependencies.

Run GLM and Kimi Security Scans with Bex Security
Run GLM and Kimi security scans on a real codebase with Bex Security. Use one evidence-driven workflow for discovery, validation, remediation, and review.

NocoDB's Enterprise Gate Is the Third Warning: How to Vet a Self-Hosted Platform's License Before It Vets You
NocoDB gated Calendar Sync and Image Annotations behind Enterprise in July 2026 — after Plex paywalled remote streaming and MinIO stripped its admin console. Three moves, one pattern, and a five-question checklist to tell Apache-2.0 from open-core before you build on it.