529 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Your Scanner Said Clean. The Kubernetes CVE Record Was Wrong.
Kubernetes corrected four CVE records to 'affects all versions' on June 1, 2026 — three were never fixed and never will be. The five-check audit a self-hosted fleet operator should run before trusting the next automated patch decision.

SNCF Ships Its Cluster API Providers as OCI Artifacts: What an ORAS-Based Provider Supply Chain Buys a Self-Hosted Fleet
SNCF manages its Cluster API providers as versioned OCI artifacts via ORAS instead of pulling YAML from GitHub releases. How the pattern works mechanically, how it compares to clusterctl's documented air-gap paths, and when a small Hetzner fleet should copy it.

Stop Guessing When to Renew: cert-manager 1.21 Lets Let's Encrypt Tell Your Fleet When
cert-manager 1.21 adds experimental support for ACME Renewal Information, letting Let's Encrypt tell each certificate when to renew instead of clients guessing at two-thirds lifetime — plus the safe upgrade order for its breaking RBAC changes.

CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools
CIS released the first consensus hardening baseline for MCP servers on September 16, 2026: 55 recommendations across 10 domains. Here is how each domain maps onto MCP tools that deploy, roll back, and read secrets — what a sane self-hosted surface already passes, and what still needs building.

The Deploy Exists Before the Account Does: What Cloudflare Drop's 60-Minute Anonymous Preview Means for Git-Push PaaS Onboarding
Cloudflare Drop inverts PaaS onboarding: drag a folder into the browser, get a live URL for 60 minutes, and only sign up if you claim it. Here is the four-part blueprint for bringing signup-last deploys to a git-push platform — and the state boundary where the pattern breaks.

The Dutch Government Is Building a Microsoft Alternative on NixOS: What National-Scale Self-Hosting Signals for Teams Who Own Their Stack
The Dutch government's DAWO project is building a Microsoft-independent workplace on NixOS — here is what the mandate, pilots, and technology amount to, and what 'the whole system is declared in config' means for a self-hosted PaaS fleet choosing between NixOS and Talos for its node images.

What an E2B-Style Sandbox Actually Needs Before an Agent Touches Production
Sandbox isolation is a solved purchase — E2B, Daytona, and Modal all sell it. The pre-deploy gate around execution (substrate parity, artifact promotion, teardown-on-reject, credential scoping, and a tested-vs-shipped audit trail) is the harder infrastructure you still have to build, priced here against September 2026 vendor primitives.

External Secrets Operator Won the Kubernetes Secrets War: A Self-Hosted PaaS Playbook
ESO passed 45M downloads and GA'd its v1 APIs, making it the default sync layer between external secret stores and Kubernetes. Here is the concrete buy-vs-cost case for adopting it as a fleet add-on — tenant-scoped stores, rotation semantics, and what it still doesn't solve.

Five Surprising Ingress-NGINX Behaviors to Audit Before Migrating to Gateway API
Ingress-NGINX retired in March 2026, and a clean converter run is not a correct migration. Audit these five behaviors — regex quirks, vanishing redirects, and untranslatable annotations — before flipping traffic to Gateway API routes.