Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

The Kubernetes CSI Driver Bug That Turns a Tenant's subDir Into a Delete Weapon
·Dora Noda·9 min

The Kubernetes CSI Driver Bug That Turns a Tenant's subDir Into a Delete Weapon

CVE-2026-3864 and CVE-2026-3865 let a crafted subDir value in a PersistentVolume escape onto the shared NFS or SMB export it's mounted from. Here's the exact mechanism, who can actually trigger it on a self-hosted PaaS, and the audit checklist that closes it.

security
self-hosting
PaaS
infrastructure
Kubernetes 1.36's Fine-Grained Kubelet Authorization Is GA — Here's Exactly What It Doesn't Fix
·Dora Noda·8 min

Kubernetes 1.36's Fine-Grained Kubelet Authorization Is GA — Here's Exactly What It Doesn't Fix

Kubernetes 1.36 splits kubelet API permissions out of the all-or-nothing nodes/proxy grant — but exec, attach, and portforward stay bundled together by design, so tenant kubectl exec access is exactly as risky as before.

security
self-hosting
PaaS
infrastructure
+1
User Namespaces Are GA in Kubernetes 1.36: Exactly What It Buys You (and What It Doesn't) for Multi-Tenant and AI-Agent Nodes
·Dora Noda·11 min

User Namespaces Are GA in Kubernetes 1.36: Exactly What It Buys You (and What It Doesn't) for Multi-Tenant and AI-Agent Nodes

Kubernetes 1.36 makes User Namespaces GA — a near-free identity remap that neutralizes four real container-escape CVEs, but stops short of the kernel-level isolation AI agents running untrusted code still need.

security
self-hosting
PaaS
infrastructure
+1
Let's Encrypt's DNS-PERSIST-01: One TXT Record Replaces Every Renewal for Multi-Tenant TLS
·Dora Noda·8 min

Let's Encrypt's DNS-PERSIST-01: One TXT Record Replaces Every Renewal for Multi-Tenant TLS

A new Let's Encrypt challenge type lets a tenant authorize a platform's ACME account once instead of on every renewal — here's the record format, the security tradeoff, and what it changes for a self-hosted PaaS issuing certs at fleet scale.

self-hosting
PaaS
Domain
security
+1
MCP's Enterprise-Managed Authorization Goes Stable: What the ID-JAG Grant Fixes and What It Doesn't
·Dora Noda·8 min

MCP's Enterprise-Managed Authorization Goes Stable: What the ID-JAG Grant Fixes and What It Doesn't

MCP's Enterprise-Managed Authorization extension went stable in June 2026, killing per-server OAuth consent screens via a new ID-JAG grant flow — but it only governs connections, not individual tool calls, leaving per-action authorization for agent deploy/rollback tools squarely up to the platform.

Model Context Protocol
AI agents
self-hosting
security
MCP Goes Vendor-Neutral: What the Linux Foundation Handoff Actually Buys Down
·Dora Noda·8 min

MCP Goes Vendor-Neutral: What the Linux Foundation Handoff Actually Buys Down

Anthropic handed MCP's governance to a new Linux Foundation body, and the protocol's biggest breaking change yet ships in three weeks. Here's what actually changed, what didn't, and what it means for a platform betting on MCP as its agent interface.

Model Context Protocol
AI agents
governance
self-hosting
+1
Metal3 Enters CNCF Incubation: What the Bare-Metal Provisioning Layer Actually Changes for a Cluster API Fleet Not Already Running It
·Dora Noda·8 min

Metal3 Enters CNCF Incubation: What the Bare-Metal Provisioning Layer Actually Changes for a Cluster API Fleet Not Already Running It

Metal3 just became a CNCF incubating project, but the badge only matters to a Cluster API fleet the day its hardware stops living behind a single vendor's API. Here's the concrete Redfish/IPMI-vs-Hetzner-API line that decides when to adopt it.

self-hosting
PaaS
infrastructure
engineering
+1
The Trust Gradient Is Broken: Why AI Deploy Agents Need Revocable Capabilities, Not Permission Levels
·Dora Noda·11 min

The Trust Gradient Is Broken: Why AI Deploy Agents Need Revocable Capabilities, Not Permission Levels

A Cursor agent used a stray API token to delete a production Railway volume. New research shows why permission tiers like read-only or full-auto can't stop that — and what a capability that expires actually buys you.

AI
security
self-hosting
PaaS
Switching to crun Won't Save You From runc's Masked-Path Escape Bug — Here's What Actually Will
·Dora Noda·8 min

Switching to crun Won't Save You From runc's Masked-Path Escape Bug — Here's What Actually Will

Three runc CVEs disclosed in November 2025 share one root cause, and crun's own coordinated patch proves switching runtimes doesn't dodge it. Here's the concrete patch checklist self-hosted Kubernetes fleets actually need to run.

security
self-hosting
PaaS
infrastructure
Showing 370–378 of 532 posts