Session
The Unmanaged Node: Policy and Audit for AI Coding Agents
AI coding agents run on developer machines with full credentials. They execute shell commands, install packages, read every file in the project, and call external APIs. Your platform has network policy, workload identity, scoped secrets, and an audit trail — none of it reaches that machine. A public archive of 58 sourced incidents shows what goes wrong: deleted volumes, dropped production databases, leaked .env files, malicious packages installed on request. How do you put these agents back under policy?
This talk shows a practical approach, built on the observation that everything an agent does that you can't see leaves the machine over HTTP. That's where the control belongs. I'll show how an intercepting proxy enforces allow/deny rules per container rather than globally, why the client-supplied Host header can't drive that decision, when the filter should fail open and when it must fail closed, and how a bypass in our own policy parser was caught in review.
The same proxy produces the evidence. Every request lands in a local SQLite database with its host, source container, filter mode, block reason, and token spend, with credentials redacted before the write. I'll demonstrate the whole thing live using VibePod, an open source implementation.
Harald Nezbeda
Python Technical Lead
Klagenfurt am Wörthersee, Austria
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top