Перейти к содержимому

S02 E09 - SPIFFE Identity for AI Agents on Kubernetes

Buoyant

0:00 / 0:00

S02 E09 - SPIFFE Identity for AI Agents on Kubernetes

62 просмотра · 6 дней назад
Buoyant
1,46 тыс. подписчиков
62 просмотра · 6 дней назад
Long-lived secrets keep leaking, and AI agents are about to make it worse. Matt Barker, the engineer who built cert-manager and later ran secure workload access at CyberArk, joins the show to explain why SPIFFE, the workload identity standard, is having a moment because of agentic AI. Barker walks through why SPIFFE replaces long-lived secrets with short-lived, cryptographically backed workload identities and how AI agents are well-positioned to easily adopt it. He and William get into where SPIFFE stops (it proves workload identity, not delegated human intent), what Barker is building at BoltMCP to translate APIs into things agents can efficiently use via Model Context Protocol (MCP) with fine-grained context authorization, and why it matters. They also cover Barker’s takes on AI adoption and why Kubernetes stays the likely foundation for agentic infrastructure. FIND AND FOLLOW US ON: ✦ Spotify: https://open.spotify.com/show/4LLTNjM... ✦ Apple Music: https://podcasts.apple.com/us/podcast... TAKEAWAYS: ✓ Why SPIFFE replaces long-lived secrets with short-lived, cryptographically backed workload identities (SVIDs) built on X.509 PKI ✓ Why AI agents are easier to secure with SPIFFE than existing applications, since they don't require a retroactive rework ✓ Where SPIFFE's job ends and human-delegated authorization (OAuth-based on-behalf-of flows) begins ✓ Why Matt Barker sees Kubernetes remaining the default foundation for agentic AI infrastructure, even as consumption shifts to abstracted platforms ✓ Why CISOs are under pressure to greenlight AI agent adoption before the security tradeoffs are fully worked out Read the blog post at: www.buoyant.io/ai-kubernetes-episode/spiffe-identity-for-ai-agents-on-kubernetes