[{"data":1,"prerenderedAt":27},["ShallowReactive",2],{"blog-tag-en-zero-trust":3},[4,16],{"path":5,"title":6,"description":7,"date":8,"tags":9},"\u002Fblog\u002Fen\u002Fai-agent-authentication-kubernetes-keycloak-spiffe","Don't Hand AI Agents the Keys. A Keyless Design for Authenticating MCP Servers on Kubernetes","Handing AI agents static API keys is an operating model that eventually breaks down. This article explains why static secrets hit a wall when running MCP servers on Kubernetes, and how Keycloak combined with SPIFFE\u002FSPIRE enables a 'keyless' authentication design.","2026-08-18",[10,11,12,13,14,15],"k3s","kubernetes","ai-agent","mcp","keycloak","zero-trust",{"path":17,"title":18,"description":19,"date":20,"tags":21},"\u002Fblog\u002Fen\u002Fkubernetes-network-policies-security","Zero Trust Security with Kubernetes Network Policies: A Practical Guide","Implement zero trust networking in Kubernetes with Network Policies. From Default Deny to Cilium and Calico advanced policies with real YAML examples.","2026-05-27",[11,22,15,23,24,25,26],"network-policy","security","cilium","calico","networking",1787649525060]