Skip to main content

531 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

What the MCP 2026-07-28 Spec Broke: Your Server's Auth Fix Checklist
·Dora Noda·10 min

What the MCP 2026-07-28 Spec Broke: Your Server's Auth Fix Checklist

The MCP 2026-07-28 spec turned every remote server into a formal OAuth 2.1 resource server, and working servers now fail closed. Here is the six-item fix checklist: metadata endpoint, 401 pointer, audience enforcement, issuer validation, and the DCR-to-CIMD plan.

Model Context Protocol
security
identity
AI agents
+1
12,520 Exposed MCP Servers: A 7-Point Auth Checklist for Shipping a Deploy-Capable MCP Server
·Dora Noda·12 min

12,520 Exposed MCP Servers: A 7-Point Auth Checklist for Shipping a Deploy-Capable MCP Server

Censys found 12,520 MCP servers on the public internet and independent studies put 40% of remote servers at no authentication at all. Here is the seven-default auth checklist that keeps a deploy-capable MCP server out of the next scan.

Model Context Protocol
security
AI agents
self-hosting
Mooring: a Security-First PaaS in One Binary — and What Breaks When You Need a Second Server
·Dora Noda·12 min

Mooring: a Security-First PaaS in One Binary — and What Breaks When You Need a Second Server

Mooring packs a secure-by-default PaaS into one 12 MB binary — no Swarm, no Kubernetes. This capability-by-capability comparison with Coolify, Dokploy, and Cluster API fleets shows exactly what breaks when one server stops being enough.

PaaS
self-hosting
security
infrastructure
Railway Skips the Post-Merge Rebuild: Promote the Exact Preview Image to Production With BuildKit Digests
·Dora Noda·10 min

Railway Skips the Post-Merge Rebuild: Promote the Exact Preview Image to Production With BuildKit Digests

Railway's Skipped Builds deploys the already-tested PR image to production instead of rebuilding after merge. A self-hosted version of the same trick: commit-to-digest provenance, BuildKit cache policy, and digest-pinned deploys.

PaaS
self-hosting
developer tools
security
Render Killed the Pasted AWS Key. Your Self-Hosted PaaS Is Now on the Clock.
·Dora Noda·9 min

Render Killed the Pasted AWS Key. Your Self-Hosted PaaS Is Now on the Clock.

Render's July 2026 OIDC releases made keyless auth to AWS, Anthropic, and OpenAI a GA platform feature. Here's the trust-chain machinery behind it and the two concrete paths — cluster-issuer federation or SPIFFE/SPIRE — for matching it on machines you own.

security
identity
PaaS
self-hosting
+1
Keyless Signing Won: What Rekor v2 and cosign v3 Mean for Verifying Every Image at Admission
·Dora Noda·12 min

Keyless Signing Won: What Rekor v2 and cosign v3 Mean for Verifying Every Image at Admission

Rekor v2, cosign v3, and Open Component Model's breaking 2026 releases made keyless signing the default. What identity-based provenance means for verifying every container image at admission — and where the guarantees stop.

security
Kubernetes
self-hosting
PaaS
+1
Sprites Meet MCP: How Fly.io Built Agent-Safe Sandboxed Deployment Environments
·Dora Noda·12 min

Sprites Meet MCP: How Fly.io Built Agent-Safe Sandboxed Deployment Environments

Fly.io's Sprites now speak MCP: agents get persistent Firecracker microVMs with 300ms checkpoints through sprites.dev/mcp. Here is the six-primitive checklist for agent-safe sandboxes, how E2B, Daytona, Modal, and Vercel compare, and what it takes to build the same on owned hardware.

AI agents
Model Context Protocol
self-hosting
security
Java 27 Is GA: G1 Everywhere, Quantum-Safe TLS, and Goodbye Intel Macs — Your Buildpack TODO List
·Dora Noda·10 min

Java 27 Is GA: G1 Everywhere, Quantum-Safe TLS, and Goodbye Intel Macs — Your Buildpack TODO List

Java 27 turned on G1, compact object headers, and hybrid post-quantum TLS by default while ending Intel Mac maintenance. Here is what each change means for a self-hosted PaaS Java buildpack, with container memory math and a build-fleet checklist.

self-hosting
PaaS
engineering
security
+1
MCP Memory Servers: What Persistent Memory-as-a-Tool Means for a Deploy Agent That Forgets Every Session
·Dora Noda·9 min

MCP Memory Servers: What Persistent Memory-as-a-Tool Means for a Deploy Agent That Forgets Every Session

MCP memory servers give deploy agents persistent memory any client can share — last good deploys, environment preferences, and incident fixes recalled by retrieval instead of replayed history. The catch: multi-tenant isolation and poisoned-memory attacks that turn one bad fact into a standing prompt injection.

Model Context Protocol
AI agents
security
self-hosting
Showing 73–81 of 531 posts