<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel>
<title>Moatline blog</title><link>https://moatline.dev/blog/</link>
<description>Security and operations for self-hosted apps</description>
<atom:link href="https://moatline.dev/feed.xml" rel="self" type="application/rss+xml"/>
<item><title>Why a renamed Payload field can delete your data — and how to catch it in the pull request</title><link>https://moatline.dev/blog/payload-migration-deleted-data</link><guid>https://moatline.dev/blog/payload-migration-deleted-data</guid><pubDate>Tue, 06 Oct 2026 08:00:00 GMT</pubDate><description>Payload's Postgres adapter turns schema changes into Drizzle migrations. A renamed field or collection can become DROP COLUMN or DROP TABLE. How it happens, the two setup mistakes behind most incidents, and how to catch destructive migrations before they run.</description></item>
<item><title>Backups that stopped weeks ago: how to know your Dokploy and Coolify backups actually ran</title><link>https://moatline.dev/blog/silent-backup-failures</link><guid>https://moatline.dev/blog/silent-backup-failures</guid><pubDate>Mon, 05 Oct 2026 08:00:00 GMT</pubDate><description>Scheduled backups on self-hosted platforms can stop without a notification. Why it happens, what 'backup succeeded' does not tell you, and a dead man's switch that tells you when a backup did not run.</description></item>
<item><title>Is your Dokploy or Coolify vulnerable? Checking the platform itself against its advisories</title><link>https://moatline.dev/blog/paas-vulnerabilities</link><guid>https://moatline.dev/blog/paas-vulnerabilities</guid><pubDate>Sun, 04 Oct 2026 08:00:00 GMT</pubDate><description>The platform that deploys your apps has root on your servers and its own security advisories — dozens of them. How to check the version you run against them, and why the platform is the one component that cannot vouch for itself.</description></item>
<item><title>CVE-2025-29927: why self-hosted Next.js was affected and Vercel was not</title><link>https://moatline.dev/blog/nextjs-middleware-bypass-self-hosted</link><guid>https://moatline.dev/blog/nextjs-middleware-bypass-self-hosted</guid><pubDate>Sat, 03 Oct 2026 08:00:00 GMT</pubDate><description>The Next.js middleware bypass let anyone skip middleware — and the authentication in it — with one request header. Who was affected, which versions fix it, and what it teaches about running Next.js yourself.</description></item>
</channel></rss>
