Nikolai Norman Andersen

Nikolai Norman Andersen

CTO at Variant Oslo

Oslo, Norway

Actions

Nikolai specializes in how processes and technology work together to enable continuous delivery of solutions. He is always searching for ways to deliver fast without compromising quality. He loves problems related to distributed systems, automation and infrastructure, but shines when focusing on developer experience and deployment pipelines.

Area of Expertise

  • Information & Communications Technology

Topics

  • DevOps
  • Cloud & Infrastructure
  • Programming
  • Privacy
  • Software Development

How to Keep Secrets from your Agent

Agents are taking your job, but can you at least keep your secrets? The last thing we want is agents and LLMs reading our secret values into context and sending them to someone else's computer. In this talk I will get into how to safely store secrets in git using encryption and how we can let our agents use these secrets without seeing them.

I will introduce you to SOPS, key management and practical patterns like stdin-based handoff that let agents use secrets without dragging the plaintext into prompts, logs, chats or onto remote servers. There are some caveats, make sure you come and learn what they are!

Lightning Talks Wednesday

Talk 1: Look ma, no hands! - How to program without using your hands - Peder Voldnes Langdal

Have you ever wondered how to answer an email, surf online, or even program without using your hands?

Probably not, but did you just become a bit curious? Due to a juicy inflammation in my elbow I had to find the answers to these questions, and now I want to show you what I learnt. I will show you voice commands, voice coding and eye tracking, and use these to create a simple little web app on stage. You do not need to know programming to enjoy this talk.

P.S: This text is written without a mouse and keyboard.

————————

Talk 2: How to Manage your Ducks: Being a More Sustainable You - Amy Kapernick

Ever feel like everything's a struggle? Like you're constantly overwhelmed by life? While we can endure it and pull through, this is hardly sustainable. Sometimes, it's just too ducking hard.

We've all been there. Thankfully, there are simple things you can do to not only reduce the stress factors, but sometimes eliminate them altogether.

Join me to learn about setting (and sticking) to your boundaries, identifying which worries help and which ones harm, and most importantly, how to manage your ducks. These are personally vetted, tried and tested steps for being a more sustainable you.

————————

Talk 3: Death to Test Environments - Nikolai Norman Andersen

A validated, stable and usable environment to execute test scenarios and replicate bugs, or a wasteful effort that will never be able to replicate production data or usage patterns? Have the use of test environments gone to far, or are we just doing it wrong? Let's have a look at some normal ways of utilizing test environments and some changes we can do to get more value out of them. Maybe we'll decide we don't need one at all!

————————

Talk 4: Betting the company on Clojure - Erik Assum

When Erik Bakstad and Magnulf Pilskog founded Ardoq in 2013, they decided to use Clojure to implement the backend, and Javascript for the frontend. Now almost 10 years later, Ardoq is a successful scale up with over 200 employees. In this lightning talk we'll examine the reasons for choosing Clojure, and how those decisions turned out. We will also compare our experiences working both in working in the code base and how easy it has been to hire new employees.

Secure Computing and Privacy By Design

This talk is about secure computing, data protection and privacy-by-design from a developer standpoint. By the end you'll have practical insights on how to build privacy-focused systems that keep user data safe, and you'll be able to navigate some of the complexities of legal compliance. You'll learn the essentials of encryption and security, and take your first step towards becoming a privacy-by-design champion!

I'll show encryption techniques for data at rest and in transit. How to manage encryption keys and risks involved. How to utilize anonymization and pseudonymization. How GDPR and other regulations shape system design. How to securely share secrets and data with applications and with the rest of the team. We'll also explore use cases of secure computing and secure enclaves for improved data security.

Death to Test Environments

A validated, stable and usable environment to execute test scenarios and replicate bugs, or a wasteful effort that will never be able to replicate production data or usage patterns? Have the use of test environments gone to far, or are we just doing it wrong? Let's have a look at some normal ways of utilizing test environments and some changes we can do to get more value out of them. Maybe we'll decide we don't need one at all!

Immutable application deployments with F# Make

Deliver continuously to Azure Web Apps by making your build- and deployment pipeline scalable and testable with F# Make! This presentation will show you how to write build- and deployment-scripts that runs the same on your local machine as when deploying in an Azure Web App! I'll do the following:

- Introduce you to FAKE and how it compares to Cake and PSAKE
- Teach you about Kudu, the engine behind deployments to Azure Web Apps
- Show you how you can free yourself of saving environment specific configuration in tools like Octopus Deploy and VSTS
- Demonstrate migrating Azure SQL databases on deploy, using the Web Apps connection string(s)
- Show how add ARM to this setup, how to approach security and how to automatically smoke test

Why Secrets Belong in Git

Encrypted secrets that is! The audience will learn about tools and techniques that will enable them to version control secrets alongside the code these secrets belong to. Learn how to make them available to agents and LLM tools without bringing them into context. Easily share secrets with new team members and get a full audit log as a bonus. All while following modern security practices.

The session will introduce SOPS and how attendees can use keys stored in secure remote services to encrypt and decrypt files. Access is easily controlled through the same identity providers they use for other services. We will look into how this fits into GitOps practices and how it compares to other common ways of handling secrets in Kubernetes like the External Secrets Operator.

The last thing we want is agents and LLMs reading our secret values into context and sending them to someone else's computer. I will show practical patterns like `sops exec-env`, `sops exec-file` and stdin-based handoff that let agents use secrets without dragging the plaintext into prompts, logs, chats or onto remote servers. The presentation will cover some gotchas to be aware of, but there's no need to be afraid of putting secrets in Git.

Norsk helsenett - Containerkonferansen Sessionize Event

October 2025 Trondheim, Norway

Booster Conference 2025 Sessionize Event

March 2025 Bergen, Norway

Cloud Native Day Oslo 2025 Sessionize Event

March 2025 Oslo, Norway

#HelloStavanger 2024 Sessionize Event

October 2024 Stavanger, Norway

NDC Oslo 2024 Sessionize Event

June 2024 Oslo, Norway

NDC Oslo 2022 Sessionize Event

September 2022 Oslo, Norway

DevOpsDays Oslo 2021 Sessionize Event

November 2021 Oslo, Norway

NDC Oslo 2018 Sessionize Event

June 2018

Nikolai Norman Andersen

CTO at Variant Oslo

Oslo, Norway

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top