Session

Autonomous Agents, Bounded Privileges : OpenClaw Reference Architecture for Kubernetes Config Audit

Autonomous agents that act on a user’s behalf introduce identity and authorization risks the cloud native stack cannot adequately mitigate: data exfiltration from overprivileged or compromised agents, lost delegation context as agents cross domains and trust boundaries, and intent drift beyond authorized scope.

This talk presents a reference architecture to mitigate these risks. We use OpenClaw, an open source personal agent scoped with four added identity primitives: AGNTCY Identity Service-issued crypto-attested badges, ID-JAG tokens, declarative policy for fine-grained authorization at trust boundaries, and an end-to-end delegation chain for governance and auditing, in a Kubernetes-native stack.

Case Study: A SecDevOps engineer delegates OpenClaw to run a Kyverno config audit against a KinD workload. OpenClaw detects violations, spawns a scoped sub-agent, exchanges tokens across Keycloak realms, and posts findings to Slack after Cedar/OPA approval through Envoy AI Gateway.

Sri Aradhyula

Principal Software Engineer at Cisco | Building the Autonomous Platform Engineer | Creator of CAIPE

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top