Building Workload Identity Federation for AI Agents on Kubernetes
The easy way to give an agent pod access to an external API is a long-lived key in a Kubernetes Secret. It doesn’t expire when the pod dies, it …
Read more →building the agentic future in public
I run LLMs, robots, and gateways into production walls so you don't have to. Deep dives on the agentic mesh, agent runtimes, AI gateways, and the Kubernetes substrate that keeps autonomous systems honest — every post ships with a repo you can clone and receipts you can check.
The easy way to give an agent pod access to an external API is a long-lived key in a Kubernetes Secret. It doesn’t expire when the pod dies, it …
Read more →An agentic mesh is infrastructure that applies identity, policy, and observability to agent traffic (calls to models, tools, and other agents) so those controls …
Read more →An OpenAI research agent got its HTTPS requests to a public chatbot blocked by a web proxy. So it found a different way to ask the chatbot questions: it queried …
Read more →Disclosure: I work at Solo.io, which created agentgateway and sells Solo Enterprise for agentgateway. Every product claim below links to that project’s …
Read more →Every capacity knob in an agent runtime today is an efficiency knob. Pack more agents onto fewer pods, snapshot the idle ones, scale the pool to match demand, …
Read more →On September 24, Australia’s prime minister told reporters that an OpenAI agent had broken into a government Medicare statistics portal, accessed …
Read more →An AI agent that stops calling its tools does not throw an error. It answers from the model’s memory, confidently and plausibly, and the output still …
Read more →Agents parse HTML badly and expensively. The usual fix is to make the site emit markdown: add a per-page index.md, publish an llms.txt, change the build. That …
Read more →Egress control for AI agents usually gets framed as a blocklist problem. Keep the agent off the hosts it should not reach, and you have contained it. This …
Read more →I built a four-container demo that reproduces an MCP server rewriting its own tool definitions mid-session, and puts two controls in front of it to see which …
Read more →