ChatLoopBackOff Episode 78: Exploring Cedar with Henrik Rexed
In this episode of ChatLoopBackOff, CNCF Ambassador Henrik Rexed explores Cedar for the first time. Cedar is an open-source authorization policy language designed to decouple access control from application logic. Core Capabilities: Decoupled Security: Separates authorization…
Network boundary for AI agents using NGINX and OpenTelemetry
I recently had an interesting conversation at a KCD about OpenClaw with one of the attendees, and they remarked that they wouldn’t put an agent in their network, because “we don’t know what that thing really…
Why sandboxing your agent is not enough
The agentic AI space is moving incredibly fast. Not long ago, I learned about a cool project called agent-sandbox, which provides a sandboxed environment for AI agents by leveraging many of the building blocks we have…
Evolving platform engineering for AI-native workloads
Platform Engineering 1.0 delivered real value. Golden paths accelerated deployment. Internal Developer Platforms (IDPs) reduced cognitive load for developers. Self-service infrastructure gave developers back hours they had been spending filing tickets. Pipelines provided a standard vehicle to…
How data sovereignty is changing cloud native infrastructure design
The core issue isn’t where your server sits. It’s who can be compelled to hand over what’s on it. For years, cloud providers treated sovereignty as a geography problem. Pick a region. Choose a country. Keep…
Challenge: Scaling Infrastructure Without Linear Team Growth Operating Kubernetes at large scale required more than deploying clusters. Manual provisioning and ad-hoc operations would not scale, and planned maintenance could not be disruptive. As internal adoption increased,…
Slam26 Spring Transparency Report
Setting the stage for the Spring 2026 Security Slam The CNCF Security Slam has continuously evolved to meet the community’s need for robust software supply chain security. In 2022 and 2023, the event functioned as highly…
Dragonfly v2.5.0 is released! Thanks to all of the contributors who made this Dragonfly release happen. New features and enhancements Direct repository downloads from Hugging Face and ModelScope Dragonfly Client now supports directly downloading model repositories…
Securing CI/CD for an open source project, part 3: Credentials, verification, and what’s next
This is the third and final post in a series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control and Part 2 covered dependency hardening. This post covers the last layer: keeping CI…
Challenge As an authorized Payment Aggregator, Razorpay operates under the strict oversight of the Reserve Bank of India (RBI). The RBI PA Master Directions mandate absolute operating resilience, which introduces several highly specific, non-negotiable security requirements:…