Monthly meetup, September 2026: Crossplane & AI security
There'll be 2 presentations:
- "An AI Agent Already Escaped Kubernetes. Is Your Cluster Next?
- Crossplane (introduction, use cases, demos)
1st Presentation: "An AI Agent Already Escaped Kubernetes. Is Your Cluster Next?"
Description: That's not hypothetical. In May 2026, Sysdig documented an AI agent, with no human in the loop, that escaped its container, replayed a stolen service-account token, and dumped the cluster's entire Secret store. Kubernetes wasn't built to contain autonomous agents holding credentials, so a compromised one hands over its full blast radius: permissions, tools, and runtime. This talk hardens all three, using Ledger, a legacy billing platform migrating to Kubernetes under an autonomous agent.
Layer 1: Permissions Ledger's agent runs with more access than deploying code needs, so one prompt injection reaches every Secret in the cluster. We walk through the Sysdig kill chain, then the minimal-RBAC baseline every agent pod should start from: no auto-mounted tokens, namespace-scoped roles, and just-in-time credentials. Layer 2: Tools Ledger runs its schema migrations through an MCP server, a trust boundary most teams leave wide open. We cover what a compromised server can reach by default, and how to lock it down: its own namespace, a dedicated service account, a restricted pod-security profile, and schema validation on every tool call. Layer 3: Runtime The first sign that Ledger's agent is compromised usually isn't an alert. It's a spike in API calls, pod creation, or inter-pod traffic that nothing was watching. We cover the signals that catch an agentic attack before exfiltration completes: token replay in audit logs, runaway spawning, and resource spikes. This already ran on a production cluster, and the CNCF's 2026 agentic standards now treat it as first-class. The question is whether yours is hardened before the next one.
You leave with:
- The Agent Blast Radius: the three layers a compromised agent breaks out through
- Least-Privilege Baseline: the minimal RBAC every agent pod should start from
- Hardened MCP: how to deploy an MCP server that can't become a foothold
- Runtime Tripwires: the signals that catch an agentic attack in progress"
Speaker: https://sessionize.com/moeez-khan
2nd Presentation: Crossplane (introduction, use cases, demos)
Will go through what crossplane is, what it's used for, what sets it apart from other infrastructure as code tools
Speaker: https://sessionize.com/artisticcheese
6:30 - 6:45 - Social 6:45 - 6:55 - Club Business 6:55 - 7:30 - Presentation 1 7:30 - 8:00 - Presentation 2 8.00 - 8.30 - Social/Wrap-up