Open-Source
Pourquoi Caddy tourne comme service hôte installé depuis le dépôt APT officiel signé, et non comme container Podman, sur ma plateforme de services perso. Et pourquoi un runbook administrateur explicite remplace un wrapper automatisé prématuré.
Why Caddy runs as a host service installed from Caddy's signed official APT repository, not as a Podman container, on my personal services platform. And why an explicit administrator runbook replaces a premature automated wrapper.
Greywall's built-in pi profile leaves the agent's persistence vectors writable. Analysis of the gaps (network, inaccurate XDG paths, overly broad allowWrite) and a corrective denyWrite profile, with the limits the sandbox cannot cover on its own.
Le profil pi intégré à Greywall laisse inscriptibles les vecteurs de persistance de l'agent. Analyse des failles (réseau, chemins XDG inexacts, allowWrite trop large) et profil correctif en denyWrite, avec les limites que la sandbox ne couvre pas seule.
La v1.1.0 de pi-secured-setup passe au OWASP AI Agent Security Cheat Sheet. Audit log chaîné par HMAC, détection d'exfiltration bash, rate limiting, scanner d'injection prompt, et 14 advisories Dependabot fermés.
pi-secured-setup v1.1.0 maps against the OWASP AI Agent Security Cheat Sheet. HMAC-chained audit log, bash exfiltration detection, rate limiting, prompt injection scanner, and 14 Dependabot advisories closed.
Interconnecter des trunks SIP d’opérateurs et des IPBX d’entreprise semble simple sur le papier. En pratique, c’est l’un des points de friction les plus coûteux d’une infrastructure VoIP : il faut sécuriser l’IPBX exposé sur Internet, gérer plusieurs opérateurs en parallèle, basculer en cas de panne, normaliser le routage, le tout sans grever le budget avec un SBC propriétaire opaque et fermé.
PK-SBC est une réponse open source à ce problème. Un Session Border Controller construit sur Kamailio, RTP Engine, Redis et PostgreSQL, conçu selon le principe KISS — Keep It Simple, Stupid — et éprouvé en production depuis 2012.
Interconnecting carrier SIP trunks and enterprise IPBXs looks simple on paper. In practice, it is one of the most expensive friction points in a VoIP infrastructure: you have to secure the IPBX exposed to the Internet, juggle several operators in parallel, fail over when one goes down, normalise routing — all without blowing the budget on a closed, opaque proprietary SBC.
PK-SBC is an open source answer to that problem. A Session Border Controller built on Kamailio, RTP Engine, Redis and PostgreSQL, designed along the KISS principle — Keep It Simple, Stupid — and battle-tested in production since 2012.