Skip to main content

529 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Your Scanner Said Clean. The Kubernetes CVE Record Was Wrong.
·Dora Noda·10 min

Your Scanner Said Clean. The Kubernetes CVE Record Was Wrong.

Kubernetes corrected four CVE records to 'affects all versions' on June 1, 2026 — three were never fixed and never will be. The five-check audit a self-hosted fleet operator should run before trusting the next automated patch decision.

Kubernetes
security
self-hosting
infrastructure
SNCF Ships Its Cluster API Providers as OCI Artifacts: What an ORAS-Based Provider Supply Chain Buys a Self-Hosted Fleet
·Dora Noda·9 min

SNCF Ships Its Cluster API Providers as OCI Artifacts: What an ORAS-Based Provider Supply Chain Buys a Self-Hosted Fleet

SNCF manages its Cluster API providers as versioned OCI artifacts via ORAS instead of pulling YAML from GitHub releases. How the pattern works mechanically, how it compares to clusterctl's documented air-gap paths, and when a small Hetzner fleet should copy it.

Kubernetes
self-hosting
PaaS
infrastructure
+1
Stop Guessing When to Renew: cert-manager 1.21 Lets Let's Encrypt Tell Your Fleet When
·Dora Noda·9 min

Stop Guessing When to Renew: cert-manager 1.21 Lets Let's Encrypt Tell Your Fleet When

cert-manager 1.21 adds experimental support for ACME Renewal Information, letting Let's Encrypt tell each certificate when to renew instead of clients guessing at two-thirds lifetime — plus the safe upgrade order for its breaking RBAC changes.

Kubernetes
security
self-hosting
guide
CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools
·Dora Noda·10 min

CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools

CIS released the first consensus hardening baseline for MCP servers on September 16, 2026: 55 recommendations across 10 domains. Here is how each domain maps onto MCP tools that deploy, roll back, and read secrets — what a sane self-hosted surface already passes, and what still needs building.

Model Context Protocol
AI agents
security
self-hosting
+1
The Deploy Exists Before the Account Does: What Cloudflare Drop's 60-Minute Anonymous Preview Means for Git-Push PaaS Onboarding
·Dora Noda·11 min

The Deploy Exists Before the Account Does: What Cloudflare Drop's 60-Minute Anonymous Preview Means for Git-Push PaaS Onboarding

Cloudflare Drop inverts PaaS onboarding: drag a folder into the browser, get a live URL for 60 minutes, and only sign up if you claim it. Here is the four-part blueprint for bringing signup-last deploys to a git-push platform — and the state boundary where the pattern breaks.

PaaS
self-hosting
AI agents
security
The Dutch Government Is Building a Microsoft Alternative on NixOS: What National-Scale Self-Hosting Signals for Teams Who Own Their Stack
·Dora Noda·11 min

The Dutch Government Is Building a Microsoft Alternative on NixOS: What National-Scale Self-Hosting Signals for Teams Who Own Their Stack

The Dutch government's DAWO project is building a Microsoft-independent workplace on NixOS — here is what the mandate, pilots, and technology amount to, and what 'the whole system is declared in config' means for a self-hosted PaaS fleet choosing between NixOS and Talos for its node images.

self-hosting
PaaS
Kubernetes
security
What an E2B-Style Sandbox Actually Needs Before an Agent Touches Production
·Dora Noda·10 min

What an E2B-Style Sandbox Actually Needs Before an Agent Touches Production

Sandbox isolation is a solved purchase — E2B, Daytona, and Modal all sell it. The pre-deploy gate around execution (substrate parity, artifact promotion, teardown-on-reject, credential scoping, and a tested-vs-shipped audit trail) is the harder infrastructure you still have to build, priced here against September 2026 vendor primitives.

PaaS
AI agents
self-hosting
security
External Secrets Operator Won the Kubernetes Secrets War: A Self-Hosted PaaS Playbook
·Dora Noda·8 min

External Secrets Operator Won the Kubernetes Secrets War: A Self-Hosted PaaS Playbook

ESO passed 45M downloads and GA'd its v1 APIs, making it the default sync layer between external secret stores and Kubernetes. Here is the concrete buy-vs-cost case for adopting it as a fleet add-on — tenant-scoped stores, rotation semantics, and what it still doesn't solve.

Kubernetes
PaaS
self-hosting
security
Five Surprising Ingress-NGINX Behaviors to Audit Before Migrating to Gateway API
·Dora Noda·9 min

Five Surprising Ingress-NGINX Behaviors to Audit Before Migrating to Gateway API

Ingress-NGINX retired in March 2026, and a clean converter run is not a correct migration. Audit these five behaviors — regex quirks, vanishing redirects, and untranslatable annotations — before flipping traffic to Gateway API routes.

Kubernetes
migration
self-hosting
security
Showing 19–27 of 529 posts