Skip to main content

531 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

External Secrets Operator Won the Kubernetes Secrets War: A Self-Hosted PaaS Playbook
·Dora Noda·8 min

External Secrets Operator Won the Kubernetes Secrets War: A Self-Hosted PaaS Playbook

ESO passed 45M downloads and GA'd its v1 APIs, making it the default sync layer between external secret stores and Kubernetes. Here is the concrete buy-vs-cost case for adopting it as a fleet add-on — tenant-scoped stores, rotation semantics, and what it still doesn't solve.

Kubernetes
PaaS
self-hosting
security
Five Surprising Ingress-NGINX Behaviors to Audit Before Migrating to Gateway API
·Dora Noda·9 min

Five Surprising Ingress-NGINX Behaviors to Audit Before Migrating to Gateway API

Ingress-NGINX retired in March 2026, and a clean converter run is not a correct migration. Audit these five behaviors — regex quirks, vanishing redirects, and untranslatable annotations — before flipping traffic to Gateway API routes.

Kubernetes
migration
self-hosting
security
MCP Lock-In Moves Up the Stack: Why Your Infrastructure MCP Server Belongs on Your Own Fleet
·Dora Noda·10 min

MCP Lock-In Moves Up the Stack: Why Your Infrastructure MCP Server Belongs on Your Own Fleet

MCP passed 10,000 public servers and 97M monthly downloads under foundation governance — but lock-in moved to registries, client defaults, and trust signals. Why teams running deploy-capable infrastructure servers should self-host the server, the catalog, and the registry surface.

Model Context Protocol
AI agents
self-hosting
security
The Agent Wrote the Release Notes. Next It Ships the Release: What ReleasePad's Changelog MCP Server Teaches Deploy-Tool Design
·Dora Noda·10 min

The Agent Wrote the Release Notes. Next It Ships the Release: What ReleasePad's Changelog MCP Server Teaches Deploy-Tool Design

ReleasePad's September 2026 MCP server lets agents draft, publish, and measure changelogs with drafts-by-default and read-only scopes. Its tool catalog is a worked template for deploy-server design — separate the point of no return, make reads plentiful, and enforce gates server-side.

Model Context Protocol
AI agents
developer tools
security
Shadow AI in the Pipeline: What to Audit From Laptop to Kubernetes Before Unvetted AI Becomes a Supply-Chain Bridge
·Dora Noda·13 min

Shadow AI in the Pipeline: What to Audit From Laptop to Kubernetes Before Unvetted AI Becomes a Supply-Chain Bridge

Unmanaged AI tools now sit at every stage from developer laptop to production cluster. A stage-by-stage audit of what to check and which open-source controls clamp each risk on a build fleet you own.

security
AI agents
Kubernetes
self-hosting
SSH Into a Throwaway Instance: Render's Ephemeral Shell and the New Bar for PaaS Debug Access
·Dora Noda·10 min

SSH Into a Throwaway Instance: Render's Ephemeral Shell and the New Bar for PaaS Debug Access

Render's June 2026 ephemeral SSH instances plus shell-session audit events define what tenant debug access should look like. Here is how to match it on a self-hosted PaaS with same-digest debug pods, session-scoped RBAC, and an explicit call on session recording.

Kubernetes
PaaS
self-hosting
security
Approximated vs DIY: The Real Cost of Point-an-A-Record-and-We-Handle-SSL on a Cluster-API Fleet
·Dora Noda·12 min

Approximated vs DIY: The Real Cost of Point-an-A-Record-and-We-Handle-SSL on a Cluster-API Fleet

Approximated charges $0.20 per domain per month — or $199+/month self-hosted — to automate custom domains and SSL. Here is what the same ACME-plus-DNS pipeline costs to build into a Cluster-API fleet you already run, with the crossover math at 100, 1,000, and 10,000 domains.

self-hosting
PaaS
cost-optimization
security
Zero-CVE Buildpacks Are Here: What BellSoft's Hardened Paketo Builder Means for a Git-Push PaaS
·Dora Noda·10 min

Zero-CVE Buildpacks Are Here: What BellSoft's Hardened Paketo Builder Means for a Git-Push PaaS

BellSoft's hardened Paketo builder promises zero-CVE images, 24-hour patching, signed builds, and automatic SBOMs with no workflow change. Here is what a git-push PaaS actually gains, what stays its problem, and how to evaluate the swap in an afternoon.

self-hosting
security
PaaS
guide
Detectify Turned Its Scanner Into an Agent Tool: What 'Call the Scanner Like a Test Runner' Means for Your Deploy Pipeline
·Dora Noda·10 min

Detectify Turned Its Scanner Into an Agent Tool: What 'Call the Scanner Like a Test Runner' Means for Your Deploy Pipeline

Detectify's May 2026 MCP Server hands security findings to coding agents as structured tasks with validation scans. How the Find & Fix loop works, what a scan phase between build and promote looks like for a git-push PaaS, and what stays human.

Model Context Protocol
AI agents
security
self-hosting
+1
Showing 28–36 of 531 posts