Skip to main content

531 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Railway Patches Your Postgres When a CVE Lands — What Vendor-Side Patching Costs vs. Patching It Yourself
·Dora Noda·10 min

Railway Patches Your Postgres When a CVE Lands — What Vendor-Side Patching Costs vs. Patching It Yourself

Railway now patches your Postgres when a CVE lands — but the restart still happens on their schedule, not yours. A side-by-side runbook comparison with patching Postgres you own via CloudNativePG, worked through the 28-CVE August 2026 release, with a verdict for three tenant profiles.

migration
self-hosting
Kubernetes
security
Render Lets You Repoint Production With One Click. Who Vouched for the Bytes?
·Dora Noda·8 min

Render Lets You Repoint Production With One Click. Who Vouched for the Bytes?

Render's May 2026 dashboard swaps any service's backing repo or image with one click and an automatic deploy. The convenience is real, but without digest pins, signature checks, or a change ceremony, the audit trail vouches for the click — not the bytes.

security
PaaS
self-hosting
Rotate the Database Password Without Shipping a Rebuild: A No-Redeploy Secrets Playbook for Git-Push Platforms
·Dora Noda·11 min

Rotate the Database Password Without Shipping a Rebuild: A No-Redeploy Secrets Playbook for Git-Push Platforms

Self-hosted git-push platforms bake secrets into deploys, so every password rotation ships a rebuild. A playbook for decoupling them: projected Secret volumes, a reload sidecar, and the overlap ordering that keeps Postgres readers connected throughout.

self-hosting
PaaS
Kubernetes
security
+1
Wildcard TLS on Autopilot: How Every Tenant Subdomain Gets a Trusted Cert in Under 90 Seconds
·Dora Noda·9 min

Wildcard TLS on Autopilot: How Every Tenant Subdomain Gets a Trusted Cert in Under 90 Seconds

Every tenant subdomain on a PaaS needs a trusted certificate at deploy time. Here is how one wildcard cert, cert-manager's DNS-01 solver, and Let's Encrypt deliver it in under 90 seconds — and why per-tenant certs hit rate limits first.

self-hosting
PaaS
Kubernetes
security
Coolify's 11 Critical CVEs and the Single-Maintainer Security Bill
·Dora Noda·9 min

Coolify's 11 Critical CVEs and the Single-Maintainer Security Bill

Coolify disclosed 11 critical flaws in January 2026 — seven scored CVSS 10.0 — and four more in July. What the CVE record, the rolling-beta patch train, and a three-person team mean for anyone running production behind the popular self-hosted PaaS.

self-hosting
PaaS
security
infrastructure
Flatcar vs Talos vs bootc: Picking the Immutable Node OS for a CAPH-Provisioned Hetzner Fleet
·Dora Noda·12 min

Flatcar vs Talos vs bootc: Picking the Immutable Node OS for a CAPH-Provisioned Hetzner Fleet

Flatcar, Talos, and bootc compared as the immutable node OS for a Cluster API fleet on Hetzner: image pipelines, update and reboot semantics, CAPH integration maturity, and which one a cost-sized team should standardize on first.

Kubernetes
self-hosting
infrastructure
security
gVisor vs Kata vs Firecracker: Picking Sandbox Isolation for an Agent Layer on Shared Nodes
·Dora Noda·13 min

gVisor vs Kata vs Firecracker: Picking Sandbox Isolation for an Agent Layer on Shared Nodes

An agent sandbox on a node shared with paying tenants must survive hostile model-generated code. This concrete comparison of gVisor, Kata Containers, and Firecracker covers cold starts, memory per sandbox, and blast-radius containment — plus a decision rule for self-hosted fleets.

AI
security
infrastructure
self-hosting
+1
Kubernetes v1.37 Finally Lets You noexec a Volume Mount: Closing the 9-Year-Old Hole in readOnlyRootFilesystem
·Dora Noda·8 min

Kubernetes v1.37 Finally Lets You noexec a Volume Mount: Closing the 9-Year-Old Hole in readOnlyRootFilesystem

Kubernetes v1.37 adds alpha bindMountOptions and emptyDir mode fields that finally let operators mount volumes noexec and stop emptyDir from defaulting to 0777. What the two knobs block, and the gate rollout checklist for multi-tenant fleets.

Kubernetes
security
self-hosting
PaaS
An AI Agent Found a WireGuard Bug in GKE: A Blueprint for Agent-Led Triage on Your Own Fleet
·Dora Noda·11 min

An AI Agent Found a WireGuard Bug in GKE: A Blueprint for Agent-Led Triage on Your Own Fleet

Lovable's agent surfaced a crash-looping GKE networking daemon buried in millions of log lines; humans did everything after. The honest agent-vs-human split from that incident, plus a trust-boundary matrix for giving a triage agent read-only cluster access on your own fleet.

AI agents
Kubernetes
self-hosting
security
Showing 64–72 of 531 posts