<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bucket Notifications on SILO</title><link>https://silo.pgsty.com/tags/bucket-notifications/</link><description>Recent content in Bucket Notifications on SILO</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 05 Aug 2026 07:48:52 +0800</lastBuildDate><atom:link href="https://silo.pgsty.com/tags/bucket-notifications/index.xml" rel="self" type="application/rss+xml"/><item><title>The Parser Knew, the Schema Didn't: Config Keys That Could Take Every Notification Down</title><link>https://silo.pgsty.com/blog/security/notify-keyspace-registration/</link><pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate><guid>https://silo.pgsty.com/blog/security/notify-keyspace-registration/</guid><description>&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Fixed on the local &lt;code&gt;pgsty/minio&lt;/code&gt; branch as &lt;code&gt;162ded343&lt;/code&gt;, &lt;strong&gt;unreleased&lt;/strong&gt;
&lt;strong&gt;Classification:&lt;/strong&gt; Configuration-schema consistency and availability, &lt;strong&gt;not a vulnerability&lt;/strong&gt;; includes one defensive hardening (credential values no longer echoed in validation errors)
&lt;strong&gt;Affected scope:&lt;/strong&gt; &lt;code&gt;notify_nats&lt;/code&gt; JWT/NKey/TLS-handshake-first options, &lt;code&gt;notify_amqp&lt;/code&gt; &lt;code&gt;immediate&lt;/code&gt;, and any pre-2020 config migrated with an enabled NATS target — whose failure then silences &lt;strong&gt;every&lt;/strong&gt; notification backend
&lt;strong&gt;Tracking:&lt;/strong&gt; &lt;code&gt;pgsty/minio&lt;/code&gt; issue #39&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This article names two unfixed availability defects in neighbouring code (the Postgres/MySQL migration writes, and &lt;code&gt;kvFields&lt;/code&gt; typo folding). Neither is exploitable — both break the operator&amp;rsquo;s own configuration, loudly or not at all — and both are already named in the committed audit test&amp;rsquo;s allowlist. Publication needs no hold beyond the release itself.&lt;/p&gt;</description></item></channel></rss>