Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Railway's December 16 Cryptominer Incident: How Under 10% Infected Workloads Degraded 100% of Regions
·Dora Noda·9 min

Railway's December 16 Cryptominer Incident: How Under 10% Infected Workloads Degraded 100% of Regions

Railway's December 16, 2025 postmortem shows how a Next.js RCE that infected under 10% of workloads still degraded every region — and what CPU-isolation guarantees a shared-compute PaaS needs to keep one tenant's breach from becoming everyone else's incident.

self-hosting
PaaS
security
infrastructure
SafeLine's 20,900-Star Self-Hosted WAF Claims 99.995% Accuracy: What It Actually Buys You Over Cloudflare
·Dora Noda·10 min

SafeLine's 20,900-Star Self-Hosted WAF Claims 99.995% Accuracy: What It Actually Buys You Over Cloudflare

SafeLine's self-hosted WAF claims 99.995% accuracy against SQL injection and DDoS traffic — here's the real cost comparison against Cloudflare, why Hetzner already covers the DDoS part for free, and what a self-hosted PaaS actually gains by shipping one as an ingress default.

security
PaaS
self-hosting
infrastructure
SPIFFE/SPIRE for AI Agents: Cryptographic Workload Identity Instead of Long-Lived Service Account Tokens
·Dora Noda·9 min

SPIFFE/SPIRE for AI Agents: Cryptographic Workload Identity Instead of Long-Lived Service Account Tokens

A hands-on look at issuing an AI deploy-agent a cryptographic identity distinct from a human's with SPIFFE/SPIRE — and the honest operational cost next to the Vault/External-Secrets-Operator setup most self-hosted platforms already run.

security
self-hosting
PaaS
AI agents
+1
Talos Linux's No-Shell Design Barely Scratched by CVE-2026-31431
·Dora Noda·9 min

Talos Linux's No-Shell Design Barely Scratched by CVE-2026-31431

A 732-byte exploit roots most major Linux distros — here's exactly why Sidero Labs says it barely touches Talos Linux, backed by the binary counts and CVE benchmarks that make the claim checkable.

security
self-hosting
PaaS
infrastructure
Vercel Made DDoS Traffic Free in May 2026 — So Why Did a Site Still Get Billed $231.71 for an Attack in June?
·Dora Noda·9 min

Vercel Made DDoS Traffic Free in May 2026 — So Why Did a Site Still Get Billed $231.71 for an Attack in June?

Vercel made firewall-blocked DDoS traffic free on May 18, 2026 — but a customer still got hit with a $231.71 bill for a June attack. Here's the exact carve-out in Vercel's policy that still leaves teams exposed, and what changes on owned hardware.

self-hosting
PaaS
cost-optimization
security
Coolify Shipped an MCP Server. It Still Can't Deploy Your App.
·Dora Noda·9 min

Coolify Shipped an MCP Server. It Still Can't Deploy Your App.

Coolify's official MCP server is strictly read-only — the write-capable 'AI deploys your app' story everyone cites comes from a third-party wrapper holding your API token. Here's the concrete tool-by-tool split, why it matters, and where bex's own MCP server stands on the same line.

PaaS
self-hosting
Model Context Protocol
AI agents
+1
One DV Certificate Per Tenant Domain vs Wildcard TLS: The Multi-Tenant Pattern a Self-Hosted PaaS Actually Needs
·Dora Noda·9 min

One DV Certificate Per Tenant Domain vs Wildcard TLS: The Multi-Tenant Pattern a Self-Hosted PaaS Actually Needs

Wildcard TLS stops covering anything the moment a tenant brings their own domain. Here's the concrete cert-manager and acme.sh architecture — bind-time issuance, renewal fan-out, and offboarding revocation — that replaces it, with the Let's Encrypt rate limits and 45-day certificate timeline that make it non-negotiable.

self-hosting
PaaS
security
infrastructure
+1
Self-Hosted Kubernetes Installs Don't Stall on Kubernetes — They Stall on Your Registry, Network, and Approval Chain
·Dora Noda·9 min

Self-Hosted Kubernetes Installs Don't Stall on Kubernetes — They Stall on Your Registry, Network, and Approval Chain

Fairwinds' CTO named the real reason self-hosted Kubernetes installs drag on for months — and it's rarely Kubernetes. Here's what that means for any Cluster-API PaaS that might one day sell into a customer's own infrastructure.

self-hosting
PaaS
infrastructure
security
Kata Containers vs gVisor: A RuntimeClass Decision Framework for Multi-Tenant Kubernetes
·Dora Noda·8 min

Kata Containers vs gVisor: A RuntimeClass Decision Framework for Multi-Tenant Kubernetes

runC's 2025-2026 escape vulnerabilities settled the question of whether untrusted multi-tenant workloads need stronger isolation. This is the decision framework for which one, per workload, actually pays off.

self-hosting
PaaS
security
infrastructure
+1
Showing 361–369 of 532 posts