Kyverno

Enforcing real time, payload aware governance for the agentic era

Policy-Driven Authorization for AI Agents with Kyverno and AWS AgentCore

Enforcing real-time, payload-aware governance for the agentic era Introduction: From Generation to Action AI agents are no longer just generating responses, they’re taking actions. From invoking APIs to modifying infrastructure, agentic systems now operate directly on production environments. This raises a critical question: How do…

0

From Policy Engine to AI-Native Platform: Introducing Cloud Agents for Infrastructure Governance

PRODUCT LAUNCH  Nirmata’s new Cloud Agents give platform engineers a one-click way to run deterministic, LLM-powered diagnostics directly on their clusters — no scripts, no setup, no surprises. When we launched Nirmata, the goal was straightforward: give teams a better way to govern Kubernetes at…

0

Kubernetes nodes/proxy GET → RCE: how “telemetry” permissions can compromise a cluster

A subtle (and frankly surprising) Kubernetes authorization behavior has resurfaced as a practical cluster-compromise path: an identity granted nodes/proxy access with an HTTP Get can be leveraged to execute commands in Pods across the cluster—effectively turning what many teams treat as “read-only node telemetry access”…

0
Beyond Authentication

Beyond Authentication: How to Implement Strong API Authorization in Kubernetes with Kyverno Authz-Server

The Kubernetes security market, valued at $1.195 billion in 2022, is projected to reach $10.7 billion by 2031 (27.6% CAGR) due to the need for robust authorization. As organizations adopt zero-trust security models, they’re moving from perimeter-based defenses toward granular, identity-aware access control inside the…

0
NVIDIA AI Platforms

How Kyverno Strengthens Security, Compliance, and Reliability Across NVIDIA AI Platforms

What is Kyverno and Why Does NVDIA Use it for GPU Management? Kyverno is a Kubernetes-native policy engine that NVIDIA embeds directly into its AI platform stack—including DGX Cloud, Mission Control, and NeMo microservices—to enforce security, compliance, and operational stability for GPU workloads. Created by…

0