Session
Propose, Approve, Apply: Securing Kubernetes AI Agents with OCM, MCP & Kyverno
Give an AI agent a privileged kubeconfig, and the model becomes part of your production security boundary. We built ocm-mcp-server because we wanted agents to help run a Kubernetes fleet without that authority.
The agent talks to an MCP server in front of an Open Cluster Management hub, never to cluster credentials. Reads are open. Writes follow propose -> validate -> approve -> apply: static checks run first, Kyverno then does a server-side dry-run on the hub to validate the exact ManifestWork before it can reach a managed cluster, and a human approves that exact content with an Ed25519 signature, so an approved diff cannot be swapped for another. Kubernetes RBAC limits what the server itself can do, and every step lands in the audit trail.
In the live demo, we'll break a workload, let the agent find the failing cluster and propose a ManifestWork fix, reject an unsafe alternative, approve the safe change, and verify recovery. We ran 22 incident scenarios against two agents. Safety held in all 44 runs, but each agent recovered only 8 of the 15 remediable incidents. The misses are part of the talk: they show where agent autonomy still breaks and why the approval step stays.
Sandeep Bazar
Engineering Leader at IBM, working on production Kubernetes, observability and day-2 operations
Pune, India
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top