Session

Kyverno, OPA, and the Policy Layer Your AI Agents Don't Know They Need

AI agents are getting `kubectl apply` privileges - that should terrify you. Today's agentic systems can generate & deploy K8s resources — scaling deployments, creating namespaces, modifying network policies — with the confidence of a junior engineer at the speed of a shell script.

The CNCF already solved policy enforcement for humans and CI pipelines. Kyverno validates and mutates resources at admission time. OPA Gatekeeper enforces constraints across clusters. CEL-based policies in ValidatingAdmissionPolicy provide native K8s guardrails without external controllers.

This talk demos a prod architecture where AI agents operate under the same policy-as-code regime as every other actor in the cluster. We'll share Kyverno policies that specifically constrain agent-generated resources, how OPA Rego policies can encode organizational intent that agents cannot override, and how admission control becomes the trust boundary.

Your agents will make mistakes, but your policies don't have to.

Cortney Nickerson

Head of Community at Nirmata

Donostia / San Sebastián, Spain

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top