Sold out
Cloud Native Security Japan

KubeCon + CloudNativeCon Japan Community Day 2026

Capacity: 1
in-person
Event date
Jul 28, 26
09:00 AM - 06:00 PM JST
Location
パシフィコ横浜, Yokohama
About this event

7/28にKubeCon + CloudNativeCon Japanの併催イベントとして開催されるJapan Community Dayにて、 Cloud Native Security Japanはセキュリティに関連したいくつかのセッションをホストします。

他のSIGによってホストされる多数のセッションと共に是非お楽しみください。 皆様のご参加を心よりお待ちしております!

なお、Japan Community Dayの参加には、KubeCon + CloudNativeCon Japanへの参加登録が必要です。 登録は、KubeCon + CloudNaitiveCon公式サイトから実施下さい。 Japan Community Day自体には追加登録費用はございません。

※ X(旧 Twitter)でのイベントに関する投稿も歓迎します。ハッシュタグ:#CNCJ

※ 参加者にはLinux Foundationが定める行動規範に同意いただきます。 https://www.linuxfoundation.jp/code-of-conduct/

Agenda
  1. 1:20 PM - 1:25 PM JST

    Welcome & Introduction: Cloud Native Security Japan

    in-person
    Track 1
    SPEAKERS
  2. 1:25 PM - 1:50 PM JST

    Building Trust in MCP for Agentic AI with Authorization Server Conformance Tests

    in-person
    Track 1

    Recently, Agentic AI has become widespread and collaborates with various external tools to perform tasks. Therefore, governance, such as authentication and authorization, becomes crucial, and MCP, which includes authentication and authorization specifications, has been created. There are authorization servers that claim to be compliant with MCP, but there is no way to verify whether they correctly comply. If implemented incorrectly, this could lead to information leakage through CSRF or replay attacks, making conformance tests to verify compliance with MCP essential. In this session, Michito Okai will introduce conformance tests he developed to verify whether an authorization server complies with the Authorization Code Grant in OAuth 2.1 on which MCP is based. He will also demonstrate how to verify that Keycloak is compliant as an MCP authorization server using these tests. These tests are contributed to the MCP community to help increase trust in MCP within Agentic AI systems.

    Speakers

    Michito Okai

  3. 2:00 PM - 2:25 PM JST

    AI Agent Security: Why GuardRails Alone Are Not Enough

    in-person
    Track 1

    As AI Agents gain access to files, tools, APIs, and operational systems, ensuring their security becomes increasingly important.

    While GuardRails and policy controls help reduce risks, they cannot completely prevent unintended actions or unexpected behavior.

    In this session, we discuss AI Agent Security through three layers:

    GuardRails Risk Management Runtime Security

    We then explore how CNCF technologies such as eBPF and Falco can provide runtime visibility and protection as the final line of defense for AI Agents.

    SPEAKERS
Organizers