Session
Who's Calling? Agent Identity Before Agent Sprawl
Your cluster has no idea who's calling.
Agents talk to APIs, call tools, hit databases & to your auth system they look like a service account, a shared API key, or a bearer token in a header.
Retrofitting identity after a fleet exists is painful.
The CNCF introduced kagenti to give every agent a SPIFFE/SPIRE cryptographic identity; kagent ships agents as K8s CRDs subject to RBAC. SPIRE has been CNCF graduated for years - the missing piece was the agent side.
This session reframes agent governance as an identity problem, not a policy problem.
For workload identity we'll demo per-agent SPIFFE IDs via kagenti, so every model call and tool call is attributable to a specific agent in a specific trust domain.
Authorization:
Kyverno policies on the agent identity at request time.
Auditing:
OTel GenAI spans tagged with the SPIFFE ID, so traces tell you which agent did what
Least privilege:
agentgateway gating MCP tool access by identity.
Identity-first, policy-second, audit-third.
Maria Gabriella Brodi
Lead Solutions Architect
New York City, New York, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top