Self-Hosted Weekly: Week 40, 2026. Gitea 28, Keycloak Agent Tokens, Weekly Ubuntu Kernels

Week 40: Gitea 28 routes Git traffic through an egress proxy, Keycloak 26.8 adds delegated tokens for AI agents, Ubuntu goes to weekly kernels.

Self-Hosted Weekly: Week 40, 2026. Gitea 28, Keycloak Agent Tokens, Weekly Ubuntu Kernels

AI agents got their own tokens in Keycloak this week, Gitea now routes every outbound Git connection through a proxy it controls, and Ubuntu switched to shipping kernels every week. Papermerge, which was 11 days from being archived, found three new maintainers. Here's what mattered.

1. Ubuntu ships kernels weekly now, and the container escape is still open

Canonical announced on September 23 that kernel CVE fixes move to a weekly cadence starting September 28. The old four-week SRU cycle and two-week security cycle merge into overlapping two-week cycles that start a week apart, so a new kernel lands every week. The reason given is the growing number of kernel CVEs, much of it from AI-assisted bug hunting. Admins who can't wait get a sanctioned shortcut: install release candidates from the -proposed pocket before certification finishes.

The first test is the container escape we covered last week. As of this morning, Ubuntu's tracker still lists CVE-2026-80521 as vulnerable on 24.04 LTS and 26.04 LTS. One correction: 22.04 LTS now shows "Not affected", and last week we listed it as vulnerable.

Our take: A weekly kernel only helps if you actually reboot into it. If your hosts run untrusted containers on 24.04 or 26.04, keep them isolated until the fix lands, then schedule the reboot. Don't wait for the next maintenance window.

2. Gitea 28 puts every outbound Git call behind a proxy

Gitea 28.0.0 shipped September 30. The headline change is a breaking one: all Git network operations (mirrors, migrations, pushes to remotes) now go through an internal forward proxy that enforces egress rules. Settings changed with it: ALLOWED_DOMAINS, BLOCKED_DOMAINS and ALLOW_LOCALNETWORKS are deprecated, wildcards in IP addresses and bare * entries are rejected, and in the default lax mode ALLOWED_HOST_LIST no longer restricts public hosts. You need EGRESS_MODE = strict to keep an allowlist exclusive. The release also carries six security fixes, including repository-scoped authorization for team access and keeping cancelled fork pull request runs behind the Actions approval gate.

Our take: This is the right design, since a Git server that mirrors arbitrary URLs is an SSRF waiting to happen. But the lax default quietly widens what an existing allowlist permits. If you run Gitea with a locked-down host list, set strict mode before you upgrade, then read the startup warnings.

3. Keycloak 26.8 gives AI agents delegated tokens

Keycloak 26.8.0 landed October 1. The feature we'll be testing first is token exchange delegation, in preview: a user consents to an agent through a delegation:client:<client-id> scope, and the resulting token carries an act claim naming the agent. A leaked delegation token can't reach the Admin API, even if the client has service account credentials. Also new: SCIM user provisioning and stateless multi-cluster mode (sessions in the database, no external Infinispan) are now fully supported. The old multi-site feature is deprecated.

Our take: Most teams give an agent a service account or a user's own token. Both are bad answers, because the logs can't tell the agent apart from the person. An act claim fixes that at the protocol level. If you run Keycloak and you're wiring agents to internal APIs, this is worth a staging realm today. Custom login themes should check the redesigned identity provider buttons before upgrading.

4. Grafana patches three authorization bugs on four branches

Grafana published three advisories on September 29, fixed in 12.4.12, 13.0.10, 13.1.7 and 13.2.3. The most practical one, CVE-2026-81841 (CVSS 5.3), is a Grafana Enterprise issue: pausing a shared dashboard didn't revoke its token, so anyone with the link could still pull data source configuration, including credentials stored for browser-access data sources. The other two let editors forge file-provisioning provenance on dashboards (5.4) and expose alert rules from restricted folders through the list API (4.3).

Our take: None of these are emergencies, but they share a theme: something you thought you'd turned off is still on. On Enterprise, delete shared dashboards instead of pausing them. Then patch Grafana during the next quiet hour.

5. Ollama 0.35 adds models that answer with probabilities

Ollama v0.35.0, released September 28, adds a /v1/systemone endpoint for decision models. You send context and a question with labelled options. Instead of prose, you get back a choice, a probability for each option, and a confidence score. Two models launch with it: Nimble from Bespoke Labs and Tev1 from Together AI. In Ollama's own example, the whole answer costs one output token.

Our take: Ticket triage and model routing are where people burn a 7B chat model on a one-word answer and then parse it with a regex. A probability you can put a threshold on beats that. If you already route work through Ollama, try it on your noisiest classification job.

6. NocoDB's account-wide MCP skips the Community Edition

NocoDB 2026.09.1 (September 29) lets one MCP connection reach every base you choose, capped at your own role. The MCP server now exposes 199 tools, 50 more than the previous release. The availability table is the fine print: account-wide MCP is marked unavailable in Community Edition. It's available on NocoDB Cloud, including the free plan, and on paid on-prem plans.

Our take: The per-base MCP that self-hosters already have still works, so nothing broke. But the trend is worth noticing: as AI features become the selling point, they're the first thing open-core vendors keep for paid tiers. If you run NocoDB for agents, plan around per-base connections.

7. OpenProject 17.9 moves a paid feature into Community

OpenProject went the other way. Version 17.9.0 (September 30) adds date alerts to the Community edition, so every user gets notified about approaching start and finish dates and overdue work packages. It also fixes four security advisories, including sessions that stayed valid after a password change. 17.9.1 followed on October 1.

Our take: The session fix alone justifies the upgrade, since "change your password" is the first thing anyone does after a suspected compromise. Upgrade OpenProject straight to 17.9.1.

8. Papermerge won't be archived

The 30-day maintainer search we've tracked since September 5 ended early. On September 24, the original author gave maintainer rights to three community contributors, who started by merging pending authorization fixes. One detail from the thread: the open-source code and the commercial cloud version have diverged since May 2026.

Our take: This is a good outcome, and maintainer transitions don't always go this smoothly. If you run Papermerge, watch the repo for the first tagged release under its new maintainers.

What we're watching next week

Ubuntu's first weekly kernels. The new cadence started September 28. The first real test is whether CVE-2026-80521 gets fixed on 24.04 and 26.04 within it.

PostgreSQL 19 RC1 on October 15. The release team set the dates: RC1 on October 15 and GA on October 29, unless testing turns up problems.

LibreChat 0.8.8 in the wild. Released October 1 with agent controls (interrupt, steer, approve tool calls) and experimental scheduled chats. We'll see how the experimental parts hold up on real deployments of LibreChat.

The bottom line

This week's theme was boundaries. Keycloak now distinguishes an agent from the user it acts for. Gitea checks where outbound Git traffic goes. Grafana closed three gaps where an "off" switch didn't actually turn anything off. The tooling for safely giving agents access keeps improving. Turning it on is still up to you.

Thanks for reading ❤️ See you next Friday 👋