532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Gateway API v1.5's ListenerSet Just Solved Multi-Tenant Custom Domains — Here's the RBAC Layout That Replaces Your Ingress Hacks
Gateway API v1.5's ListenerSet lets tenants self-serve custom domains on a shared Gateway without cluster-wide write access — here's the actual YAML, precedence rules, and RBAC layout that makes it safe, not just self-service.

Ingress NGINX Is Officially Dead: The Gateway API Migration a Self-Hosted PaaS Can't Skip
Ingress-nginx went EOL on March 24, 2026 with no more CVE fixes ever. Here's the head-to-head on the two sanctioned exits — Traefik as a drop-in stopgap vs. migrating straight to Gateway API's Gateway/HTTPRoute model — plus the before/after YAML a self-hosted PaaS's routing layer should generate.

Kubernetes 1.36's User Namespaces Go GA: The hostUsers: false Default Every Multi-Tenant PaaS Should Ship
Kubernetes 1.36 graduated User Namespaces to GA — here's the exact node-image, subuid, and admission-policy recipe to make hostUsers: false the cluster-wide default for every tenant pod, plus the shared-kernel limitation it doesn't fix.

Let's Encrypt's 6-Day Certificates Are GA: The Renewal Math Your PaaS's ACME Automation Needs to Survive It
Let's Encrypt's 6-day certificates are live and 45-day defaults are coming by 2028 — the renewal-frequency math, the real rate-limit bottleneck (your DNS provider, not Let's Encrypt), and what a self-hosted PaaS's ACME automation needs to change first.

MCP Server Cards Won't Advertise Your Tools — Here's What They Actually Do
A draft MCP proposal lets servers publish machine-readable metadata at a .well-known URL — but the real schema deliberately leaves out tool names, and that omission changes what publishing one actually buys a self-hosted platform.

Ephemeral Preview Environments on Kubernetes: A Namespace-Per-PR Recipe for a Git-Push PaaS
A working ArgoCD ApplicationSet recipe for namespace-per-PR previews, what it actually costs in cluster resources at 10 vs 50 concurrent PRs, and the quota/network-policy/TTL guardrails that keep a busy repo from starving a shared cluster.

Short-Lived Credentials for AI Agents on Kubernetes: Designing Out the Long-Lived-Secret Failure Mode
Why plain Kubernetes Secrets are the failure mode behind 2026's AI-agent credential incidents, and the concrete Vault/CSI/MCP architecture that replaces them with short-lived, per-task tokens.

What You See Is What You Sign: Inside Ethereum's Plan to Kill the $1.5B Blind-Signing Problem
The Ethereum Foundation's Clear Signing standard (ERC-7730) wants to end blind signing — the UX flaw behind the $1.5B Bybit hack and years of wallet-drainer phishing. Here's how it works, what it can't fix, and why it matters for builders.

Q1 2026 Crypto Security Report: How the $1.5B Bybit Hack Signals a New Era of Infrastructure Attacks
Q1 2026 saw $2 billion in crypto losses as attackers abandoned smart contract exploits for supply chain attacks, social engineering, and DNS hijacks. The $1.5B Bybit breach and $286M Drift Protocol hack reveal a new threat model requiring full-stack security beyond Solidity auditing.