Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

CloudNativePG 1.30's DatabaseRole CRD and Lease Election: What Changes for a Self-Hosted PaaS's Postgres Layer
·Dora Noda·8 min

CloudNativePG 1.30's DatabaseRole CRD and Lease Election: What Changes for a Self-Hosted PaaS's Postgres Layer

CloudNativePG 1.30 ships a declarative DatabaseRole CRD and a Lease-based primary election, plus two CVE fixes, right as the 1.28.x line hits end of life — here's what that concretely changes for a PaaS running CNPG as its own managed-Postgres engine.

infrastructure
self-hosting
PaaS
security
+1
Coolify Fixed 11 Critical CVEs in January. The Same Root Cause Struck Again in July
·Dora Noda·9 min

Coolify Fixed 11 Critical CVEs in January. The Same Root Cause Struck Again in July

Coolify patched 11 critical CVEs at CVSS 9.4-10.0 in January 2026, then shipped a fix for the same root-cause bug class in July. Here's what the repeat says about single-daemon PaaS architecture versus RBAC-scoped, Kubernetes-native control planes.

security
PaaS
self-hosting
infrastructure
+1
Your Cursor Sandbox Was Never the Thing Protecting You: Inside DuneSlide's Zero-Click RCE
·Dora Noda·8 min

Your Cursor Sandbox Was Never the Thing Protecting You: Inside DuneSlide's Zero-Click RCE

Two CVSS 9.8 bugs in Cursor let a zero-click prompt injection escape the sandbox and reach full code execution. The real lesson isn't the sandbox bug — it's that the agent held the developer's standing machine permissions the whole time.

Cursor
security
AI agents
Model Context Protocol
Doppler Finally Ships On-Prem — It's Still Not Infisical: What Self-Hosting Secrets Actually Costs
·Dora Noda·9 min

Doppler Finally Ships On-Prem — It's Still Not Infisical: What Self-Hosting Secrets Actually Costs

Doppler shipped an on-prem deployment option in June 2026, but it's Enterprise-only and closed-source. Infisical's MIT core stays free to self-host — until you price out RBAC, SSO, and per-identity billing against Doppler's per-seat model.

self-hosting
PaaS
security
compliance
Dremio's MCP Server Doesn't Give AI Agents a Separate Policy — Here's the Kubernetes Version for a Self-Hosted PaaS's Deploy Tools
·Dora Noda·9 min

Dremio's MCP Server Doesn't Give AI Agents a Separate Policy — Here's the Kubernetes Version for a Self-Hosted PaaS's Deploy Tools

Dremio's lakehouse MCP server enforces the same row/column policies for an AI agent as for the human who's logged in — no separate agent policy to write or drift out of sync. Here's the exact Kubernetes primitives (TokenRequest, RBAC impersonation, audit logging) that build the same guarantee into a self-hosted PaaS's deploy and rollback tools.

Model Context Protocol
self-hosting
PaaS
security
+1
Kubernetes 1.36 Splits nodes/proxy Into Nine Permissions — But Exec Still Needs the Keys to Every Container
·Dora Noda·8 min

Kubernetes 1.36 Splits nodes/proxy Into Nine Permissions — But Exec Still Needs the Keys to Every Container

Kubernetes 1.36 finally splits the kubelet's one catch-all nodes/proxy permission into nine narrower ones — but exec, attach, portforward, and run stay exactly as broad as before. Here's the before/after RBAC migration checklist for a multi-tenant self-hosted PaaS.

security
self-hosting
PaaS
infrastructure
CVE-2026-33814: A Single Zero in One HTTP/2 Field Can Hang Every Go Client in Your Kubernetes Fleet
·Dora Noda·8 min

CVE-2026-33814: A Single Zero in One HTTP/2 Field Can Hang Every Go Client in Your Kubernetes Fleet

A malformed SETTINGS_MAX_FRAME_SIZE value can hang any unpatched Go HTTP/2 client forever — and in Kubernetes, that's the apiserver, the kubelet, and every Cluster API provider controller. Here's the mechanism, the exposed-component map, and the govulncheck commands to audit your own fleet.

security
self-hosting
PaaS
engineering
Let's Encrypt's 2.5-Hour Outage Broke Live Renewals: A Real Fallback-CA Design for Self-Hosted ACME
·Dora Noda·12 min

Let's Encrypt's 2.5-Hour Outage Broke Live Renewals: A Real Fallback-CA Design for Self-Hosted ACME

Let's Encrypt's May 2026 outage lasted 2.5 hours and still broke live renewals. The renewal-buffer math showing why short-lived certificates make it worse, and a concrete two-issuer failover design for self-hosted ACME automation.

self-hosting
PaaS
security
infrastructure
+1
Northflank's Vibe-Coding Playbook Has Four Stages. bex Only Ships Two of Them by Default
·Dora Noda·9 min

Northflank's Vibe-Coding Playbook Has Four Stages. bex Only Ships Two of Them by Default

Northflank's enterprise vibe-coding guidance reduces to four jobs a platform owes an AI-generated app: audit, harden, observe, sandbox. Here's which two bex ships as defaults today, and which two are still the tenant's job — checked against the actual bex.yml schema.

self-hosting
PaaS
AI agents
security
+1
Showing 352–360 of 532 posts