532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

CloudNativePG 1.30's DatabaseRole CRD and Lease Election: What Changes for a Self-Hosted PaaS's Postgres Layer
CloudNativePG 1.30 ships a declarative DatabaseRole CRD and a Lease-based primary election, plus two CVE fixes, right as the 1.28.x line hits end of life — here's what that concretely changes for a PaaS running CNPG as its own managed-Postgres engine.

Coolify Fixed 11 Critical CVEs in January. The Same Root Cause Struck Again in July
Coolify patched 11 critical CVEs at CVSS 9.4-10.0 in January 2026, then shipped a fix for the same root-cause bug class in July. Here's what the repeat says about single-daemon PaaS architecture versus RBAC-scoped, Kubernetes-native control planes.

Your Cursor Sandbox Was Never the Thing Protecting You: Inside DuneSlide's Zero-Click RCE
Two CVSS 9.8 bugs in Cursor let a zero-click prompt injection escape the sandbox and reach full code execution. The real lesson isn't the sandbox bug — it's that the agent held the developer's standing machine permissions the whole time.

Doppler Finally Ships On-Prem — It's Still Not Infisical: What Self-Hosting Secrets Actually Costs
Doppler shipped an on-prem deployment option in June 2026, but it's Enterprise-only and closed-source. Infisical's MIT core stays free to self-host — until you price out RBAC, SSO, and per-identity billing against Doppler's per-seat model.

Dremio's MCP Server Doesn't Give AI Agents a Separate Policy — Here's the Kubernetes Version for a Self-Hosted PaaS's Deploy Tools
Dremio's lakehouse MCP server enforces the same row/column policies for an AI agent as for the human who's logged in — no separate agent policy to write or drift out of sync. Here's the exact Kubernetes primitives (TokenRequest, RBAC impersonation, audit logging) that build the same guarantee into a self-hosted PaaS's deploy and rollback tools.

Kubernetes 1.36 Splits nodes/proxy Into Nine Permissions — But Exec Still Needs the Keys to Every Container
Kubernetes 1.36 finally splits the kubelet's one catch-all nodes/proxy permission into nine narrower ones — but exec, attach, portforward, and run stay exactly as broad as before. Here's the before/after RBAC migration checklist for a multi-tenant self-hosted PaaS.

CVE-2026-33814: A Single Zero in One HTTP/2 Field Can Hang Every Go Client in Your Kubernetes Fleet
A malformed SETTINGS_MAX_FRAME_SIZE value can hang any unpatched Go HTTP/2 client forever — and in Kubernetes, that's the apiserver, the kubelet, and every Cluster API provider controller. Here's the mechanism, the exposed-component map, and the govulncheck commands to audit your own fleet.

Let's Encrypt's 2.5-Hour Outage Broke Live Renewals: A Real Fallback-CA Design for Self-Hosted ACME
Let's Encrypt's May 2026 outage lasted 2.5 hours and still broke live renewals. The renewal-buffer math showing why short-lived certificates make it worse, and a concrete two-issuer failover design for self-hosted ACME automation.

Northflank's Vibe-Coding Playbook Has Four Stages. bex Only Ships Two of Them by Default
Northflank's enterprise vibe-coding guidance reduces to four jobs a platform owes an AI-generated app: audit, harden, observe, sandbox. Here's which two bex ships as defaults today, and which two are still the tenant's job — checked against the actual bex.yml schema.