Least-Privilege for AI: Authorizing Agents and MCP Tools with A... Luc Chmielowski & Nina Polshakova
About this talk
This talk explores the integration of agentgateway and Kyverno in the context of AI agents, particularly focusing on the need for least-privilege authorization models as these agents transition to autonomous roles within complex systems. The speakers, Luc Chmielowski from Nirmata and Nina Polshakova from Solo.io, discuss how agentgateway, powered by kgateway, supports the Model Context Protocol (MCP) and works with CNCF policy engines like Kyverno to enforce governance. They demonstrate how Kyverno policies evaluate MCP traffic to prevent unauthorized access and privilege escalation, ensure isolation in namespaces and tenants, and link Kubernetes actions to real user identities. The session emphasizes how leveraging Kubernetes, OIDC lookups, and RBAC can enable Platform and Security teams to maintain continuous compliance for AI workloads while implementing cloud-native best practices.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32