Agent Platform Gateway Control Plane
A production agent platform needs one gateway path where SPIFFE identity binds the caller and four controls ride the same hop: secretless provider keys, per-key …
Read more →21 posts
A production agent platform needs one gateway path where SPIFFE identity binds the caller and four controls ride the same hop: secretless provider keys, per-key …
Read more →They answer different questions. SPIFFE proves which process is calling, without a provisioned secret. OAuth scopes what it may do and, when a human is in the …
Read more →Three replicas of an MCP server, fronted by agentgateway , with no session affinity configured anywhere. A four-call shopping cart session (create cart, add two …
Read more →I spent the last month building small, runnable labs for the ways AI agents break the infrastructure they run on: credentials, egress, audit logs, MCP tool …
Read more →Choose by the controls in the request path, not by model-catalog size. Write down what you must enforce on agent→model and agent→tool traffic: workload …
Read more →The easy way to give an agent pod access to an external API is a long-lived key in a Kubernetes Secret. It doesn’t expire when the pod dies, it …
Read more →An agentic mesh is infrastructure that applies identity, policy, and observability to agent traffic (calls to models, tools, and other agents) so those controls …
Read more →Disclosure: I work at Solo.io, which created agentgateway and sells Solo Enterprise for agentgateway. Every product claim below links to that project’s …
Read more →Egress control for AI agents usually gets framed as a blocklist problem. Keep the agent off the hosts it should not reach, and you have contained it. This …
Read more →I built a four-container demo that reproduces an MCP server rewriting its own tool definitions mid-session, and puts two controls in front of it to see which …
Read more →A conventional web application firewall reads a URL, some headers, and maybe a form body. For agent traffic that is the wrong layer. The interesting content is …
Read more →For about six weeks I’ve had a Pocket recorder stuck to the back of my phone, and it has quietly become the thing I reach for most after the phone itself. …
Read more →An AI agent that calls a model, a tool, or another agent has to prove who it is. Almost every production failure I have written up this month traces back to …
Read more →Almost everything in this series started the same way: a control that everybody agrees is the right control, applied to an agent, quietly not doing the thing …
Read more →Tracking shadow MCP servers across teams is hard because most of them never show up anywhere a platform team looks. Local MCP servers run as child processes of …
Read more →I have some version of this conversation just about every week. A platform team is rolling out MCP across the company, and the plan looks the same every time: …
Read more →How do you keep MCP server instructions out of the trusted system prompt? Isolate them, cap them, bind any cache that stores them to server and caller, and pin …
Read more →kagent v0.10.0 went GA on September 4 . Buried in a long release list is a pair of environment variables that decide whether an agent’s credential works …
Read more →The Model Context Protocol roadmap published on August 22 names agent identity and enterprise-ready security as a priority workstream, with four specific …
Read more →An agent with a policy file that says “you must not delete customer records”, running behind an approval layer that denylists the delete tool, …
Read more →Three companies authenticate against three different identity providers, connect to the same three MCP URLs, and get three completely different products. Acme …
Read more →