531 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

External Secrets Operator Won the Kubernetes Secrets War: A Self-Hosted PaaS Playbook
ESO passed 45M downloads and GA'd its v1 APIs, making it the default sync layer between external secret stores and Kubernetes. Here is the concrete buy-vs-cost case for adopting it as a fleet add-on — tenant-scoped stores, rotation semantics, and what it still doesn't solve.

Five Surprising Ingress-NGINX Behaviors to Audit Before Migrating to Gateway API
Ingress-NGINX retired in March 2026, and a clean converter run is not a correct migration. Audit these five behaviors — regex quirks, vanishing redirects, and untranslatable annotations — before flipping traffic to Gateway API routes.

MCP Lock-In Moves Up the Stack: Why Your Infrastructure MCP Server Belongs on Your Own Fleet
MCP passed 10,000 public servers and 97M monthly downloads under foundation governance — but lock-in moved to registries, client defaults, and trust signals. Why teams running deploy-capable infrastructure servers should self-host the server, the catalog, and the registry surface.

The Agent Wrote the Release Notes. Next It Ships the Release: What ReleasePad's Changelog MCP Server Teaches Deploy-Tool Design
ReleasePad's September 2026 MCP server lets agents draft, publish, and measure changelogs with drafts-by-default and read-only scopes. Its tool catalog is a worked template for deploy-server design — separate the point of no return, make reads plentiful, and enforce gates server-side.

Shadow AI in the Pipeline: What to Audit From Laptop to Kubernetes Before Unvetted AI Becomes a Supply-Chain Bridge
Unmanaged AI tools now sit at every stage from developer laptop to production cluster. A stage-by-stage audit of what to check and which open-source controls clamp each risk on a build fleet you own.

SSH Into a Throwaway Instance: Render's Ephemeral Shell and the New Bar for PaaS Debug Access
Render's June 2026 ephemeral SSH instances plus shell-session audit events define what tenant debug access should look like. Here is how to match it on a self-hosted PaaS with same-digest debug pods, session-scoped RBAC, and an explicit call on session recording.

Approximated vs DIY: The Real Cost of Point-an-A-Record-and-We-Handle-SSL on a Cluster-API Fleet
Approximated charges $0.20 per domain per month — or $199+/month self-hosted — to automate custom domains and SSL. Here is what the same ACME-plus-DNS pipeline costs to build into a Cluster-API fleet you already run, with the crossover math at 100, 1,000, and 10,000 domains.

Zero-CVE Buildpacks Are Here: What BellSoft's Hardened Paketo Builder Means for a Git-Push PaaS
BellSoft's hardened Paketo builder promises zero-CVE images, 24-hour patching, signed builds, and automatic SBOMs with no workflow change. Here is what a git-push PaaS actually gains, what stays its problem, and how to evaluate the swap in an afternoon.

Detectify Turned Its Scanner Into an Agent Tool: What 'Call the Scanner Like a Test Runner' Means for Your Deploy Pipeline
Detectify's May 2026 MCP Server hands security findings to coding agents as structured tasks with validation scans. How the Find & Fix loop works, what a scan phase between build and promote looks like for a git-push PaaS, and what stays human.