Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

MCP’s Ecosystem Is Big Enough to Be an Attack Surface: Scope a Deploy-from-Chat Server
·Dora Noda·10 min

MCP’s Ecosystem Is Big Enough to Be an Attack Surface: Scope a Deploy-from-Chat Server

A practical permission, approval, and audit design for an MCP deploy server that keeps untrusted tool context from becoming a production action.

AI agents
Model Context Protocol
security
infrastructure
Platform Engineering 2.0 Has Five Good Ideas—and an Implementation Gap
·Dora Noda·10 min

Platform Engineering 2.0 Has Five Good Ideas—and an Implementation Gap

A practical readiness matrix for turning Platform Engineering 2.0’s AI, agent, FinOps, security, and composability pillars into operating designs a Kubernetes PaaS can verify.

AI
AI agents
Kubernetes
PaaS
+1
Railway’s ChatGPT and Grok Plugins Show Why Deploy-From-Chat Needs an Open Control Plane
·Dora Noda·11 min

Railway’s ChatGPT and Grok Plugins Show Why Deploy-From-Chat Needs an Open Control Plane

Railway’s ChatGPT and Grok plugins point to a host-neutral control-plane design for safely deploying and operating a PaaS from any chat client.

PaaS
AI agents
Model Context Protocol
security
The .self TLD Bid: What a Human-First Domain Would—and Wouldn't—Change for Self-Hosted Apps
·Dora Noda·9 min

The .self TLD Bid: What a Human-First Domain Would—and Wouldn't—Change for Self-Hosted Apps

What the proposed .self TLD could change for self-hosted apps, what still requires portable DNS and TLS automation, and the policy questions a public-good registry must answer.

infrastructure
security
privacy
engineering
SELinux Volume Labels in Kubernetes 1.36: Audit Your Multi-Tenant Storage Before 1.37
·Dora Noda·9 min

SELinux Volume Labels in Kubernetes 1.36: Audit Your Multi-Tenant Storage Before 1.37

Kubernetes 1.37 makes SELinux context mounts the default for eligible volumes. Audit CSI drivers, shared PVCs, and label conflicts before the upgrade leaves a Pod stuck in ContainerCreating.

Kubernetes
security
infrastructure
PaaS
+1
Kubernetes v1.36 Deprecated Service ExternalIPs: A Bare-Metal PaaS Migration Plan Before v1.40
·Dora Noda·10 min

Kubernetes v1.36 Deprecated Service ExternalIPs: A Bare-Metal PaaS Migration Plan Before v1.40

Kubernetes v1.36 deprecated Service externalIPs ahead of planned kube-proxy disablement in v1.40. Use this migration plan to replace insecure tenant-selected addresses with MetalLB, Gateway API, controlled routing, and tested rollback.

Kubernetes
self-hosting
PaaS
security
Four npm Compromises in 77 Days: A Build-Sandbox Blueprint for Self-Hosted PaaS
·Dora Noda·12 min

Four npm Compromises in 77 Days: A Build-Sandbox Blueprint for Self-Hosted PaaS

Axios, node-ipc, Red Hat, and Mastra expose why lockfiles alone fail—and how isolated builds, denied egress, script policy, and SBOMs contain poisoned dependencies.

security
cybersecurity
self-hosting
PaaS
+1
Run GLM and Kimi Security Scans with Bex Security
·Dora Noda·11 min

Run GLM and Kimi Security Scans with Bex Security

Run GLM and Kimi security scans on a real codebase with Bex Security. Use one evidence-driven workflow for discovery, validation, remediation, and review.

changelog
product
security
AI agents
+2
NocoDB's Enterprise Gate Is the Third Warning: How to Vet a Self-Hosted Platform's License Before It Vets You
·Dora Noda·12 min

NocoDB's Enterprise Gate Is the Third Warning: How to Vet a Self-Hosted Platform's License Before It Vets You

NocoDB gated Calendar Sync and Image Annotations behind Enterprise in July 2026 — after Plex paywalled remote streaming and MinIO stripped its admin console. Three moves, one pattern, and a five-question checklist to tell Apache-2.0 from open-core before you build on it.

self-hosting
PaaS
infrastructure
security
Showing 244–252 of 532 posts