532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Tailscale Bought a PAM Company and Repriced to Seats in One Quarter: What It Actually Costs to Stay on Headscale
Tailscale repriced to flat per-seat billing and acquired PAM startup Border0 in the same quarter — a concrete cost comparison against self-hosted Headscale, and what capability gap the acquisition actually opens up.

Vault Went BSL, OpenBao Forked It Back: Which One Should a Self-Hosted PaaS Wire In
Vault Community Edition's license bars embedding it in a resold product, but OpenBao's Linux Foundation fork now ships free, GA multi-tenant namespaces that Vault keeps locked behind Enterprise — a concrete look at what a self-hosted PaaS should actually wire in for tenant secrets.

Wasmer Built a Full Node.js Runtime in Two Weeks With Codex — What Edge.js Actually Buys a PaaS Over Docker
Wasmer says Codex helped it build a full Node.js runtime in two weeks instead of a year. Here's what Edge.js's WASIX sandbox actually costs and buys a PaaS running MCP servers and agent-generated code, with real compatibility and cold-start numbers.

The 47-Day Certificate Era: TLS Automation Becomes Mandatory for Self-Hosted Infrastructure
CA/Browser Forum rules cut TLS certificate lifetimes from 398 to 47 days by 2029, with domain-validation reuse shrinking to 7 hours. Here's the full timeline and what it breaks in self-hosted TLS automation.

Agentic GitOps: Why Your Deploy Agent Should Open a Pull Request, Not Call the API Directly
A Cursor agent's direct API call deleted a production volume and its backups in nine seconds. Here's why routing agent-originated infrastructure changes through a pull request, not a live API call, is the safer default for deploy-from-chat.

Your CI Runner Already Trusts an AI Agent: What Claude Code and Codex CLI's Non-Interactive Mode Doesn't Guard Against
Claude Code and Codex CLI both ship non-interactive modes built for unattended CI, but neither ships the scoped tokens, transcript redaction, or agent-independent rollback that make letting an agent push to prod safe rather than a demo.

Docker's MCP Gateway Caps Every Tool Call at 1 CPU / 2GB: The Container Security Model Your Deploy Bot Should Steal
A critical RCE in Anthropic's MCP SDK won't be patched at the protocol layer, so containment has to happen at the tool-server layer. Here's exactly what Docker's MCP Gateway locks down by default, and how to size the same model for a PaaS's own deploy/rollback/scale tools.

Dokploy's CVE-2026-27130: OS Command Injection via the appName Parameter in a Popular Self-Hosted PaaS, and What It Means to Trust a Deploy Tool With Root on Your Fleet
Dokploy's CVSS 9.9 command injection through the appName field, why it's the second time that field has been the entry point, and why the same bug class keeps recurring across self-hosted PaaS deploy tools.

Envoy AI Gateway Hits v1.0: A CNCF Blueprint for Securing Your Own MCP Server
Envoy AI Gateway's v1.0 release stabilizes MCPRoute and MCPRouteSecurityPolicy, giving self-hosted platforms CEL-based per-tool authorization and audit trails for AI agents — without building an MCP authorization layer from scratch.