Agent Platform Gateway Control Plane
A production agent platform needs one gateway path where SPIFFE identity binds the caller and four controls ride the same hop: secretless provider keys, per-key …
Read more →29 posts
A production agent platform needs one gateway path where SPIFFE identity binds the caller and four controls ride the same hop: secretless provider keys, per-key …
Read more →agentgateway v1.6.0 went GA on October 2. Two features are worth a hands-on look before anything else: a built-in LLM pricing catalog that gives you cost …
Read more →They answer different questions. SPIFFE proves which process is calling, without a provisioned secret. OAuth scopes what it may do and, when a human is in the …
Read more →I built a demo where an AI agent calls a backend API and holds no credential for it. No API key in its environment, no key file on disk, no token. agentgateway …
Read more →Three replicas of an MCP server, fronted by agentgateway , with no session affinity configured anywhere. A four-call shopping cart session (create cart, add two …
Read more →I spent the last month building small, runnable labs for the ways AI agents break the infrastructure they run on: credentials, egress, audit logs, MCP tool …
Read more →Choose by the controls in the request path, not by model-catalog size. Write down what you must enforce on agent→model and agent→tool traffic: workload …
Read more →An agentic mesh is infrastructure that applies identity, policy, and observability to agent traffic (calls to models, tools, and other agents) so those controls …
Read more →An OpenAI research agent got its HTTPS requests to a public chatbot blocked by a web proxy. So it found a different way to ask the chatbot questions: it queried …
Read more →Disclosure: I work at Solo.io, which created agentgateway and sells Solo Enterprise for agentgateway. Every product claim below links to that project’s …
Read more →On September 24, Australia’s prime minister told reporters that an OpenAI agent had broken into a government Medicare statistics portal, accessed …
Read more →Agents parse HTML badly and expensively. The usual fix is to make the site emit markdown: add a per-page index.md, publish an llms.txt, change the build. That …
Read more →Egress control for AI agents usually gets framed as a blocklist problem. Keep the agent off the hosts it should not reach, and you have contained it. This …
Read more →I built a four-container demo that reproduces an MCP server rewriting its own tool definitions mid-session, and puts two controls in front of it to see which …
Read more →A conventional web application firewall reads a URL, some headers, and maybe a form body. For agent traffic that is the wrong layer. The interesting content is …
Read more →I was writing a CEL authorization policy for an LLM route in Solo Enterprise for agentgateway : restrict which models a caller may reach, and refuse callers …
Read more →I have some version of this conversation just about every week. A platform team is rolling out MCP across the company, and the plan looks the same every time: …
Read more →I gave an agent pod an LLM API key the normal way, as a Secret projected into its environment. Then I turned on every Kubernetes control that sounds like it …
Read more →How do you keep MCP server instructions out of the trusted system prompt? Isolate them, cap them, bind any cache that stores them to server and caller, and pin …
Read more →Solo shipped agentgateway enterprise 2026.9.0 on Tuesday, and the part worth your attention is not a feature inside the proxy. It is where the token service now …
Read more →Two weeks ago METR and Redwood Research published their review of ~1,300 agent transcripts from the OpenAI / Hugging Face incident. Buried in it is a finding …
Read more →agentgateway v1.5.0 shipped on 2026-08-27 with two controls that attach to the API key rather than the route: a rolling spend budget that blocks with an HTTP …
Read more →On September 4, 2026, researchers published ~18,000 posts that autonomous agents left on a 25-year-old German wiki over six weeks, using it as a message board …
Read more →An agent with a policy file that says “you must not delete customer records”, running behind an approval layer that denylists the delete tool, …
Read more →An autonomous agent escaped its evaluation sandbox on July 9, 2026, and about twelve and a half hours of wall-clock work later it held cluster-admin on multiple …
Read more →SPIFFE gives each AI agent a short-lived, attested workload identity (an SVID) instead of a stored secret, issued at runtime by SPIRE, rotated automatically, …
Read more →I built a demo where an agent calls an LLM and has no LLM credential anywhere in its process. No API key in the environment, no key file on disk, nothing in …
Read more →Three companies authenticate against three different identity providers, connect to the same three MCP URLs, and get three completely different products. Acme …
Read more →Every agent platform demo eventually meets the same question from the person who signs off on it: who is spending what, and what stops a runaway agent from …
Read more →