Skip to content

Tag: security

All the articles with the tag "security".

Prompt Injection vs Your Coding Agent

Prompt Injection vs Your Coding Agent

Prompt-level defenses against injection are probabilistic and lose to a patient attacker. Here's the capability-level design that holds, with working configs.

Stop Handing CI Jobs Root on Your Box

Stop Handing CI Jobs Root on Your Box

Self-hosted GitHub Actions, Forgejo, and GitLab runners can hand a forked pull request root on your box. Here is the isolation ladder that actually stops it.

CrowdSec Across a Home Lab: One Brain

CrowdSec Across a Home Lab: One Brain

One central CrowdSec LAPI, remote log-parsing agents, and bouncers on every box, so an SSH brute-force on one server gets blocked everywhere else too.

Docker MCP Toolkit: Trust the Sandbox?

Docker MCP Toolkit: Trust the Sandbox?

Docker MCP Toolkit sandboxes AI agent tools in containers. Here's exactly what that isolation stops, where it silently breaks, and how to configure it safely.

NetAlertX MCP: One Token, Twelve Tools

NetAlertX MCP: One Token, Twelve Tools

NetAlertX v26.9.0 ships a built-in MCP server with 12 tools. Learn how to wire it into Claude Code, what it exposes, and when to use Home Assistant instead.

Skeleton Key MCP vs One Token Per Box

Skeleton Key MCP vs One Token Per Box

Skeleton Key MCP swaps four narrow homelab tokens for one Vaultwarden vault and one OAuth consent flow. Here is what that buys you, and what it risks.

Proxmox MCP: Read-Only Beats Root

Proxmox MCP: Read-Only Beats Root

Two Proxmox MCP servers can query your cluster over chat, but the real safety boundary is a scoped PVEAuditor API token, not a config permission flag.

Komodo MCP vs the Docker Socket

Komodo MCP vs the Docker Socket

Komodo's community MCP server beats mounting the Docker socket or handing an AI agent SSH: scoped auth, per-tool RBAC, and confirmation before deletes.

IPv6 Dual-Stack: The Hard Parts

IPv6 Dual-Stack: The Hard Parts

Dual-stack IPv6 for home labs: DHCPv6-PD delegation, stable addressing past SLAAC privacy extensions, real nftables firewall rules, and Docker IPv6 done right.

Tinyauth vs Pocket ID vs Authelia

Tinyauth vs Pocket ID vs Authelia

Tinyauth vs Pocket ID vs Authelia compared for home labs: setup cost, forward-auth support, real OIDC, passkeys, 2FA, and when to move up to Authentik.

20 Unix Users, 20 Rootless Dockers

20 Unix Users, 20 Rootless Dockers

One host, 20 Unix users, 20 rootless Docker daemons. The isolation model that beats a single shared daemon, plus the trade-offs nobody tells you about.

GrapheneOS for the Curious

GrapheneOS for the Curious

· Updated:

GrapheneOS hardens Android on Pixels. The web installer, re-locking the bootloader, sandboxed Google Play, banking app attestation, and what actually breaks.