531 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

External Secrets Operator vs Vault vs Infisical: the Secrets Backend a Self-Hosted PaaS Should Actually Wire In
ESO syncs secrets but stores none, Vault's BSL bars embedding it in a resold product, and Infisical gates governance behind per-identity billing — a two-table comparison of the sync layer and the store, and the pairing a self-hosted git-push PaaS should wire in.

Gateway API v1.5 Makes TLSRoute and Gateway mTLS Stable: What Your Self-Hosted PaaS Gets for Free
Gateway API v1.5 promotes TLSRoute and Gateway-level mTLS to stable. What SNI passthrough and client-cert validation mean for a self-hosted PaaS, plus the v1alpha2 upgrade trap and the cert-manager gaps to watch.

Google Just Normalized the Governed Agent Endpoint: What Its Home and UN Data Commons MCP Servers Mean for Your Self-Hosted PaaS Roadmap
Google shipped first-party MCP servers for Home and UN data in a single week. Here is the six-part governance bar they normalized, and what it demands from any self-hosted platform shipping an agent endpoint.

Kubernetes' Agent Sandbox Goes Upstream: Inside the gVisor-Isolated Sandbox CRD Behind 16x GKE Growth
The SIG Apps Sandbox API hit v1beta1 after 16x GKE growth in five months, with Langchain and Lovable running millions of agents on it. Here is what a self-hosted PaaS gets for free — warm pools, pod snapshots, pluggable gVisor/Kata isolation — and what it no longer needs to build.

Laravel MCP 1.0 Ships: Your Laravel App Is Now an Agent Tool — What Changes on the Deploy Surface
Laravel MCP 1.0 adopts the stateless MCP 2026-07-28 spec with searchable tool catalogs, cache hints, and mandatory OAuth PKCE — plus header validation that 400s old clients. Here is the upgrade checklist and what per-app MCP servers mean for anyone operating Laravel apps.

Your MCP Deploy Tool's dry_run Flag Is a Suggestion, Not a Lock
MCP tool annotations like readOnlyHint are advisory hints for the client, not enforcement — nothing in the protocol stops a caller from overriding dry_run, tenant_id, or target_environment. A three-line server-side pattern (derive from the session, reject client values, log the attempt) and where host-authority receipts belong.

454 MCP Servers Catalogued and Quality-Scored Daily: Finding a Production-Grade Server in a Flood of Demos
A daily automated scan catalogues 455 MCP servers and scores them on hygiene — average 16 out of 100. What the data reveals about supply, churn, and how to vet servers before your agents call them.

MCP Won the Interface War: What 10,000 Servers and 97M Downloads Mean for Your Self-Hosted Endpoint
MCP passed 10,000 public servers and 97M monthly downloads under neutral Linux Foundation governance, but registries, managed gateways, and vendor defaults are the new lock-in surface. Here is the case for running your deploy-authority endpoint on infrastructure you own.

No More Self-Hosted Git After 15 Years: What AI Actually Changed About the Self-Hosting Calculus
A veteran Linux developer shut down his public git server after 15 years because AI scrapers killed it — then watched the eulogy hit 298 points on Hacker News. His real reason, the two AI pressures behind it, and a keep/move/hedge framework for deciding what stays on your own machines.