[{"data":1,"prerenderedAt":24},["ShallowReactive",2],{"blog-tag-en-ai-agent":3},[4,16],{"path":5,"title":6,"description":7,"date":8,"tags":9},"\u002Fblog\u002Fen\u002Fai-agent-authentication-kubernetes-keycloak-spiffe","Don't Hand AI Agents the Keys. A Keyless Design for Authenticating MCP Servers on Kubernetes","Handing AI agents static API keys is an operating model that eventually breaks down. This article explains why static secrets hit a wall when running MCP servers on Kubernetes, and how Keycloak combined with SPIFFE\u002FSPIRE enables a 'keyless' authentication design.","2026-08-18",[10,11,12,13,14,15],"k3s","kubernetes","ai-agent","mcp","keycloak","zero-trust",{"path":17,"title":18,"description":19,"date":20,"tags":21},"\u002Fblog\u002Fen\u002Fai-agent-sandbox-kata-containers-kubernetes","AI Agent Code Isn't a \"Trusted Product\" Anymore. Kubernetes Sandbox Design Has an Answer","Code generated and executed by AI agents can no longer be treated as a trusted, reviewed product. This article explains the limits of container isolation and why Kata Containers' microVM isolation is becoming essential when designing AI agent sandboxes on Kubernetes.","2026-08-08",[10,11,22,12,23],"kata-containers","security",1787649524987]