<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Kaden Projects Blog</title><description>Technical content for DevOps, Kubernetes, cloud infrastructure, and SaaS.</description><link>https://kaden-projects.com/</link><item><title>Vibe Coding&apos;s Security Debt: The AI-Generated CVE Surge</title><link>https://kaden-projects.com/blog/vibe-coding-security-debt-ai-generated-cve-surge/</link><guid isPermaLink="true">https://kaden-projects.com/blog/vibe-coding-security-debt-ai-generated-cve-surge/</guid><description>74 confirmed CVEs traced to AI-generated code. 45% OWASP failure rate. Learn how to build the CI/CD security pipeline your AI coding tools require.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>HTTP/2 Is Your Kubernetes Ingress&apos;s Weakest Link: From Compression Bombs to Rapid Reset</title><link>https://kaden-projects.com/blog/securing-kubernetes-http2-ingress-protocol-attacks/</link><guid isPermaLink="true">https://kaden-projects.com/blog/securing-kubernetes-http2-ingress-protocol-attacks/</guid><description>CVE-2026-49975 exhausts 32 GB of server memory in seconds. ingress-nginx won&apos;t be patched. Per-controller hardening guide for Envoy, NGINX, and HAProxy.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The AI Vulnerability Arms Race: When Models Find Zero-Days Before Humans Do</title><link>https://kaden-projects.com/blog/ai-vulnerability-discovery-arms-race/</link><guid isPermaLink="true">https://kaden-projects.com/blog/ai-vulnerability-discovery-arms-race/</guid><description>How AI vulnerability discovery changed security in May 2026: the first criminal zero-day, OpenAI Daybreak, Anthropic Glasswing, and what to do now.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>TrustFall: How MCP Config Poisoning Enables One-Click RCE in AI Coding Agents</title><link>https://kaden-projects.com/blog/trustfall-mcp-config-poisoning-rce/</link><guid isPermaLink="true">https://kaden-projects.com/blog/trustfall-mcp-config-poisoning-rce/</guid><description>TrustFall exploits MCP config poisoning to enable one-click RCE in Claude Code, Gemini CLI, Cursor, and Copilot CLI. Enterprise defenses here.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>Securing AI Agents in CI/CD Pipelines: Lessons from Comment and Control</title><link>https://kaden-projects.com/blog/securing-ai-agents-cicd-pipelines/</link><guid isPermaLink="true">https://kaden-projects.com/blog/securing-ai-agents-cicd-pipelines/</guid><description>Comment and Control hijacked Claude Code, Gemini CLI, and Copilot in CI/CD. Learn how to secure AI agents in your CI/CD pipeline with OIDC and Kubernetes.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate></item><item><title>How to Prevent AI Coding Agents from Destroying Your Infrastructure</title><link>https://kaden-projects.com/blog/securing-ai-coding-agent-infrastructure-access/</link><guid isPermaLink="true">https://kaden-projects.com/blog/securing-ai-coding-agent-infrastructure-access/</guid><description>A Cursor AI agent deleted PocketOS&apos;s database in 9 seconds. Secure AI coding agent infrastructure with RBAC, token scoping, Kyverno, and backup isolation.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Securing AI Inference Servers on Kubernetes: Defense-in-Depth for the New Attack Surface</title><link>https://kaden-projects.com/blog/securing-ai-inference-servers-kubernetes/</link><guid isPermaLink="true">https://kaden-projects.com/blog/securing-ai-inference-servers-kubernetes/</guid><description>Seven CVEs, three frameworks, one month. Map the April 2026 AI inference attack surface on Kubernetes and apply controls that stop vulnerability classes.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate></item><item><title>MCP STDIO by Design: How the Architecture Exposes 200K AI Servers to RCE and How to Defend at the Infrastructure Layer</title><link>https://kaden-projects.com/blog/mcp-stdio-rce-by-design-kubernetes-defense/</link><guid isPermaLink="true">https://kaden-projects.com/blog/mcp-stdio-rce-by-design-kubernetes-defense/</guid><description>MCP STDIO executes arbitrary OS commands by design. 30+ RCE CVEs, 14+ AI tools affected, and the Kubernetes admission controls that stop it.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Securing AI Agents at the Infrastructure Layer: Identity, Gateways, and K8s Governance</title><link>https://kaden-projects.com/blog/securing-ai-agents-infrastructure-layer/</link><guid isPermaLink="true">https://kaden-projects.com/blog/securing-ai-agents-infrastructure-layer/</guid><description>Platform engineer&apos;s guide to securing AI agents on Kubernetes with cryptographic identity, protocol-aware gateways, admission control, and CNCF KARs.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Anatomy of the TeamPCP Supply Chain Campaign: From Trivy to 1,000+ Enterprise Environments</title><link>https://kaden-projects.com/blog/teampcp-supply-chain-campaign-anatomy/</link><guid isPermaLink="true">https://kaden-projects.com/blog/teampcp-supply-chain-campaign-anatomy/</guid><description>TeamPCP supply chain attack: how one unrotated token compromised five ecosystems and 500,000 machines. Timeline, IOCs, and CI/CD hardening.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Cloudflare AI Agent Infrastructure vs Kubernetes-Native: A Platform Engineer&apos;s Comparison</title><link>https://kaden-projects.com/blog/cloudflare-ai-agent-infrastructure-vs-kubernetes/</link><guid isPermaLink="true">https://kaden-projects.com/blog/cloudflare-ai-agent-infrastructure-vs-kubernetes/</guid><description>Architecture comparison: Cloudflare Dynamic Workers, Sandboxes, and Mesh vs Kubernetes Agent Sandbox, gVisor, Kata, and NVIDIA OpenShell for AI agents.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ingress-nginx to Envoy Gateway: The Production Migration Guide for Kubernetes Teams</title><link>https://kaden-projects.com/blog/ingress-nginx-envoy-gateway-migration/</link><guid isPermaLink="true">https://kaden-projects.com/blog/ingress-nginx-envoy-gateway-migration/</guid><description>Complete guide to migrating from ingress-nginx to Envoy Gateway v1.7.2 in production. Covers Ingress2Gateway 1.0, cert-manager, and zero-downtime cutover.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Istio for Platform Engineers: AI Inference Routing, Ambient Multicluster, and the agentgateway</title><link>https://kaden-projects.com/blog/istio-ai-inference-routing-kubernetes/</link><guid isPermaLink="true">https://kaden-projects.com/blog/istio-ai-inference-routing-kubernetes/</guid><description>Istio 1.29: GIE v1 inference routing and ambient mode for GPU memory savings. Agentgateway is a standalone proxy - Istio integration targets 1.30.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Securing AI Agent MCP Traffic with Kyverno on Kubernetes: Policy-as-Code for Least-Privilege Agent Governance</title><link>https://kaden-projects.com/blog/securing-ai-agent-mcp-kyverno/</link><guid isPermaLink="true">https://kaden-projects.com/blog/securing-ai-agent-mcp-kyverno/</guid><description>Enforce least-privilege on AI agent MCP tool calls using Kyverno admission policies and agentgateway External Authorization on Kubernetes.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Helm 4 Migration Guide: What Changed, What Breaks, and How to Upgrade from Helm 3</title><link>https://kaden-projects.com/blog/helm-4-migration-guide/</link><guid isPermaLink="true">https://kaden-projects.com/blog/helm-4-migration-guide/</guid><description>What breaks in the Helm 3 to Helm 4 migration: SSA defaults, kstatus RBAC changes, plugin manifest requirements, and a five-phase staging-first rollout.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>A2A v1.0 for Platform Engineers: Routing, Securing, and Observing Agent-to-Agent Traffic</title><link>https://kaden-projects.com/blog/a2a-v1-platform-engineers/</link><guid isPermaLink="true">https://kaden-projects.com/blog/a2a-v1-platform-engineers/</guid><description>How platform engineers route, secure, and observe A2A v1.0 traffic on Kubernetes. Covers service mesh, Dapr, Agent Gateway, and OpenTelemetry.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Securing AI/ML Supply Chains on Kubernetes: Lessons from the TeamPCP Campaign</title><link>https://kaden-projects.com/blog/securing-ai-ml-supply-chains-kubernetes/</link><guid isPermaLink="true">https://kaden-projects.com/blog/securing-ai-ml-supply-chains-kubernetes/</guid><description>How a poisoned Trivy GitHub Action escalated to Kubernetes cluster takeover - and the K8s-native controls that would have stopped it at each stage.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Kubernetes v1.36 Production Upgrade Guide: What Changes, What Breaks, What to Do</title><link>https://kaden-projects.com/blog/kubernetes-1-36-production-upgrade-guide/</link><guid isPermaLink="true">https://kaden-projects.com/blog/kubernetes-1-36-production-upgrade-guide/</guid><description>Kubernetes v1.36 ships late April 2026 with 3 permanent removals and 18 stable features. Pre-upgrade checklist, migration steps, and what to adopt first.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Building an Agent-Ready Kubernetes Platform</title><link>https://kaden-projects.com/blog/building-agent-ready-kubernetes-platform/</link><guid isPermaLink="true">https://kaden-projects.com/blog/building-agent-ready-kubernetes-platform/</guid><description>How to build an agent-ready Kubernetes platform: Agent Sandbox, DRA for GPU scheduling, isolation tiers, KEDA scale-to-zero, and OTel tracing.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Microsoft Agent Framework 1.0: Multi-Agent Orchestration with MCP and A2A for Platform Engineers</title><link>https://kaden-projects.com/blog/microsoft-agent-framework-1-0/</link><guid isPermaLink="true">https://kaden-projects.com/blog/microsoft-agent-framework-1-0/</guid><description>Build production multi-agent systems with Microsoft Agent Framework 1.0. Covers MCP, A2A, orchestration patterns, checkpointing, and observability.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Kubernetes LLM Inference Stack 2026: llm-d, GPU DRA, and KAI Scheduler</title><link>https://kaden-projects.com/blog/kubernetes-llm-inference-stack-2026/</link><guid isPermaLink="true">https://kaden-projects.com/blog/kubernetes-llm-inference-stack-2026/</guid><description>Run LLMs at scale on Kubernetes with llm-d, GPU DRA, KAI Scheduler, and Grove — the new Kubernetes-native inference stack from KubeCon EU 2026.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Dapr Agents v1.0: A Platform Engineer&apos;s Guide to Production-Ready AI Agents on Kubernetes</title><link>https://kaden-projects.com/blog/dapr-agents-kubernetes-production-guide/</link><guid isPermaLink="true">https://kaden-projects.com/blog/dapr-agents-kubernetes-production-guide/</guid><description>Run production AI agents on Kubernetes with Dapr Agents v1.0: DurableAgent recovery, scale-to-zero actors, mTLS security, and framework comparison.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Kubernetes Resource Limits: The Production Configuration Guide [2026]</title><link>https://kaden-projects.com/blog/kubernetes-resource-limits/</link><guid isPermaLink="true">https://kaden-projects.com/blog/kubernetes-resource-limits/</guid><description>Set Kubernetes CPU and memory requests and limits correctly in production. Covers QoS classes, LimitRange, VPA, and in-place pod resize in K8s 1.35.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item></channel></rss>