Blog

Blog

Engineering deep dives, product updates, and perspectives on SSH security from the Mezite team.

TechnicalSeptember 12, 2026

Do One Thing Well: Why We Don't Parse Database or Kubernetes Protocols

A technical look at the architecture behind rejecting bespoke database and Kubernetes protocol parsing, and why that boundary — not "SSH only" — is what keeps Mezite secure and simple.

Read more
SecurityAugust 14, 2026

The CSP Testing Anti-Pattern: Why You Must Parse the Document

A deep dive into why string-matching your Content-Security-Policy header in tests is dangerous, and how we parse the actual SPA entry document to prevent self-inflicted outages.

Read more
TechnicalAugust 12, 2026

Rejecting the Everything Proxy: Why We Don't Proxy Databases or Kubernetes

A technical look at our deliberate decision to reject database and Kubernetes proxying, and where we draw the line on what Mezite proxies at all.

Read more
TechnicalAugust 1, 2026

Why We Reverted Our AWS Fargate Migration on Mezite Cloud

What a live cross-tenant probe taught us about the difference between per-pod compute isolation and enforceable network boundaries on Amazon EKS.

Read more
TechnicalJuly 15, 2026

Zero Inbound Ports: Inside the Mezite Reverse Tunnel Architecture

A technical exploration of why Mezite agents use reverse tunnels to connect to the control plane, eliminating inbound firewall rules and simplifying cluster deployments.

Read more
TechnicalJuly 1, 2026

The Trade-offs of Pure Go SQLite: Taming Context Cancellation

A technical look at our decision to drop CGO and use a pure Go SQLite driver, and the specific query context cancellation patterns required to keep the system robust.

Read more
SecurityJune 24, 2026

The Hidden Danger of Go's Default HTTP Server: Defending Against Slowloris

Why we mandate ReadHeaderTimeout on all http.Server instantiations in Mezite, and how a one-line oversight can expose your infrastructure to catastrophic resource exhaustion.

Read more
TechnicalJune 20, 2026

Decoupling Audit Logging: Why We Built an Asynchronous Emitter

A deep dive into Mezite's audit logging architecture. Discover how we decouple database writes from the fast path to guarantee low latency and high throughput.

Read more
TechnicalMay 10, 2026

Single-Port Architecture: Multiplexing Protocols with ALPN

A technical deep dive into how we use TLS ALPN to serve HTTPS, gRPC, reverse tunnels, and SSH all over a single port, simplifying deployment and firewall rules.

Read more
TechnicalApril 15, 2026

Why We Choose ECDSA P-256 for SSH Certificate Authorities

A technical look at our decision to standardize on ECDSA P-256 for CA keypairs, focusing on Go's crypto implementation, entropy handling, and ubiquitous compatibility.

Read more
TechnicalApril 10, 2026

Why We Moved SSH Session Recording to the Edge

A technical look at why proxy-based session recording is a flawed architecture for modern infrastructure, and how we implemented node-mode recording at the PTY level in Go.

Read more
AnnouncementsMarch 1, 2026

Introducing Mezite: Self-Hosted SSH Access

Today we are launching Mezite, a self-hosted platform that replaces static SSH keys with certificate-based authentication. Single signed binary, closed source, source-available under enterprise license.

Read more
SecurityFebruary 15, 2026

Why Self-Hosted?

Your SSH access platform holds the keys to every server in your infrastructure. Here is why it should run on your hardware, in your network, under your control.

Read more
TechnicalJanuary 15, 2026

Certificate-Based SSH Authentication Explained

SSH keys have been the default for decades. They are also one of the biggest unmanaged attack surfaces in most organizations. Here is how certificates fix this.

Read more