Session

Secure Sandboxing on GKE with Go and MCP

As cloud ecosystems scale, platform teams face a critical challenge: giving developers frictionless access to infrastructure without compromising security, accumulating idle cloud costs, or missing the shift toward agentic workflows.

This workshop walks through building a secure, automated Internal Developer Platform on Google Kubernetes Engine — a FastAPI control plane and a Go-based provisioning engine that dynamically generates isolated Terraform workspaces.

We'll cover three pillars: zero-trust security using GKE Agent Sandbox (gVisor) for strict container isolation and network segmentation on multi-tenant, untrusted workloads; sustainable compute via GitOps, Axion (ARM-based) scheduling, and TTL-based automated teardowns; and frictionless developer experience by exposing the Go provisioning engine as a Model Context Protocol (MCP) server, so an AI agent can securely query infrastructure state.

Live demos include a 10-second onboarding flow, an attempted sandbox jailbreak (and gVisor blocking it), a zero-waste teardown, and a closing demo where an AI agent generates a live security-posture overview via MCP.

Godfrey Ogembo

Software Engineer & Community Builder

Kisumu, Kenya

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top