Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Tailscale Bought a PAM Company and Repriced to Seats in One Quarter: What It Actually Costs to Stay on Headscale
·Dora Noda·8 min

Tailscale Bought a PAM Company and Repriced to Seats in One Quarter: What It Actually Costs to Stay on Headscale

Tailscale repriced to flat per-seat billing and acquired PAM startup Border0 in the same quarter — a concrete cost comparison against self-hosted Headscale, and what capability gap the acquisition actually opens up.

self-hosting
PaaS
cost-optimization
security
+1
Vault Went BSL, OpenBao Forked It Back: Which One Should a Self-Hosted PaaS Wire In
·Dora Noda·8 min

Vault Went BSL, OpenBao Forked It Back: Which One Should a Self-Hosted PaaS Wire In

Vault Community Edition's license bars embedding it in a resold product, but OpenBao's Linux Foundation fork now ships free, GA multi-tenant namespaces that Vault keeps locked behind Enterprise — a concrete look at what a self-hosted PaaS should actually wire in for tenant secrets.

self-hosting
PaaS
security
compliance
Wasmer Built a Full Node.js Runtime in Two Weeks With Codex — What Edge.js Actually Buys a PaaS Over Docker
·Dora Noda·9 min

Wasmer Built a Full Node.js Runtime in Two Weeks With Codex — What Edge.js Actually Buys a PaaS Over Docker

Wasmer says Codex helped it build a full Node.js runtime in two weeks instead of a year. Here's what Edge.js's WASIX sandbox actually costs and buys a PaaS running MCP servers and agent-generated code, with real compatibility and cold-start numbers.

self-hosting
PaaS
security
AI
+1
The 47-Day Certificate Era: TLS Automation Becomes Mandatory for Self-Hosted Infrastructure
·Dora Noda·8 min

The 47-Day Certificate Era: TLS Automation Becomes Mandatory for Self-Hosted Infrastructure

CA/Browser Forum rules cut TLS certificate lifetimes from 398 to 47 days by 2029, with domain-validation reuse shrinking to 7 hours. Here's the full timeline and what it breaks in self-hosted TLS automation.

security
self-hosting
PaaS
infrastructure
+1
Agentic GitOps: Why Your Deploy Agent Should Open a Pull Request, Not Call the API Directly
·Dora Noda·9 min

Agentic GitOps: Why Your Deploy Agent Should Open a Pull Request, Not Call the API Directly

A Cursor agent's direct API call deleted a production volume and its backups in nine seconds. Here's why routing agent-originated infrastructure changes through a pull request, not a live API call, is the safer default for deploy-from-chat.

AI agents
Model Context Protocol
self-hosting
PaaS
+1
Your CI Runner Already Trusts an AI Agent: What Claude Code and Codex CLI's Non-Interactive Mode Doesn't Guard Against
·Dora Noda·11 min

Your CI Runner Already Trusts an AI Agent: What Claude Code and Codex CLI's Non-Interactive Mode Doesn't Guard Against

Claude Code and Codex CLI both ship non-interactive modes built for unattended CI, but neither ships the scoped tokens, transcript redaction, or agent-independent rollback that make letting an agent push to prod safe rather than a demo.

self-hosting
PaaS
security
Claude
+1
Docker's MCP Gateway Caps Every Tool Call at 1 CPU / 2GB: The Container Security Model Your Deploy Bot Should Steal
·Dora Noda·8 min

Docker's MCP Gateway Caps Every Tool Call at 1 CPU / 2GB: The Container Security Model Your Deploy Bot Should Steal

A critical RCE in Anthropic's MCP SDK won't be patched at the protocol layer, so containment has to happen at the tool-server layer. Here's exactly what Docker's MCP Gateway locks down by default, and how to size the same model for a PaaS's own deploy/rollback/scale tools.

security
self-hosting
PaaS
AI
+1
Dokploy's CVE-2026-27130: OS Command Injection via the appName Parameter in a Popular Self-Hosted PaaS, and What It Means to Trust a Deploy Tool With Root on Your Fleet
·Dora Noda·9 min

Dokploy's CVE-2026-27130: OS Command Injection via the appName Parameter in a Popular Self-Hosted PaaS, and What It Means to Trust a Deploy Tool With Root on Your Fleet

Dokploy's CVSS 9.9 command injection through the appName field, why it's the second time that field has been the entry point, and why the same bug class keeps recurring across self-hosted PaaS deploy tools.

security
cybersecurity
PaaS
self-hosting
+1
Envoy AI Gateway Hits v1.0: A CNCF Blueprint for Securing Your Own MCP Server
·Dora Noda·8 min

Envoy AI Gateway Hits v1.0: A CNCF Blueprint for Securing Your Own MCP Server

Envoy AI Gateway's v1.0 release stabilizes MCPRoute and MCPRouteSecurityPolicy, giving self-hosted platforms CEL-based per-tool authorization and audit trails for AI agents — without building an MCP authorization layer from scratch.

self-hosting
PaaS
infrastructure
security
+1
Showing 379–387 of 532 posts