531 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Railway Patches Your Postgres When a CVE Lands — What Vendor-Side Patching Costs vs. Patching It Yourself
Railway now patches your Postgres when a CVE lands — but the restart still happens on their schedule, not yours. A side-by-side runbook comparison with patching Postgres you own via CloudNativePG, worked through the 28-CVE August 2026 release, with a verdict for three tenant profiles.

Render Lets You Repoint Production With One Click. Who Vouched for the Bytes?
Render's May 2026 dashboard swaps any service's backing repo or image with one click and an automatic deploy. The convenience is real, but without digest pins, signature checks, or a change ceremony, the audit trail vouches for the click — not the bytes.

Rotate the Database Password Without Shipping a Rebuild: A No-Redeploy Secrets Playbook for Git-Push Platforms
Self-hosted git-push platforms bake secrets into deploys, so every password rotation ships a rebuild. A playbook for decoupling them: projected Secret volumes, a reload sidecar, and the overlap ordering that keeps Postgres readers connected throughout.

Wildcard TLS on Autopilot: How Every Tenant Subdomain Gets a Trusted Cert in Under 90 Seconds
Every tenant subdomain on a PaaS needs a trusted certificate at deploy time. Here is how one wildcard cert, cert-manager's DNS-01 solver, and Let's Encrypt deliver it in under 90 seconds — and why per-tenant certs hit rate limits first.

Coolify's 11 Critical CVEs and the Single-Maintainer Security Bill
Coolify disclosed 11 critical flaws in January 2026 — seven scored CVSS 10.0 — and four more in July. What the CVE record, the rolling-beta patch train, and a three-person team mean for anyone running production behind the popular self-hosted PaaS.

Flatcar vs Talos vs bootc: Picking the Immutable Node OS for a CAPH-Provisioned Hetzner Fleet
Flatcar, Talos, and bootc compared as the immutable node OS for a Cluster API fleet on Hetzner: image pipelines, update and reboot semantics, CAPH integration maturity, and which one a cost-sized team should standardize on first.

gVisor vs Kata vs Firecracker: Picking Sandbox Isolation for an Agent Layer on Shared Nodes
An agent sandbox on a node shared with paying tenants must survive hostile model-generated code. This concrete comparison of gVisor, Kata Containers, and Firecracker covers cold starts, memory per sandbox, and blast-radius containment — plus a decision rule for self-hosted fleets.

Kubernetes v1.37 Finally Lets You noexec a Volume Mount: Closing the 9-Year-Old Hole in readOnlyRootFilesystem
Kubernetes v1.37 adds alpha bindMountOptions and emptyDir mode fields that finally let operators mount volumes noexec and stop emptyDir from defaulting to 0777. What the two knobs block, and the gate rollout checklist for multi-tenant fleets.

An AI Agent Found a WireGuard Bug in GKE: A Blueprint for Agent-Led Triage on Your Own Fleet
Lovable's agent surfaced a crash-looping GKE networking daemon buried in millions of log lines; humans did everything after. The honest agent-vs-human split from that incident, plus a trust-boundary matrix for giving a triage agent read-only cluster access on your own fleet.