Why Caddy runs as a host service installed from Caddy's signed official APT repository, not as a Podman container, on my personal services platform. And why an explicit administrator runbook replaces a premature automated wrapper.
Open-Source
Greywall's built-in pi profile leaves the agent's persistence vectors writable. Analysis of the gaps (network, inaccurate XDG paths, overly broad allowWrite) and a corrective denyWrite profile, with the limits the sandbox cannot cover on its own.
pi-secured-setup v1.1.0 maps against the OWASP AI Agent Security Cheat Sheet. HMAC-chained audit log, bash exfiltration detection, rate limiting, prompt injection scanner, and 14 Dependabot advisories closed.
Interconnecting carrier SIP trunks and enterprise IPBXs looks simple on paper. In practice, it is one of the most expensive friction points in a VoIP infrastructure: you have to secure the IPBX exposed to the Internet, juggle several operators in parallel, fail over when one goes down, normalise routing — all without blowing the budget on a closed, opaque proprietary SBC.
PK-SBC is an open source answer to that problem. A Session Border Controller built on Kamailio, RTP Engine, Redis and PostgreSQL, designed along the KISS principle — Keep It Simple, Stupid — and battle-tested in production since 2012.
