Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Thursday September 17, 2026 15:45 - 16:10 CEST
We hand coding agents our workspace, our keys, and a shell, then walk away while they run code generated at runtime from untrusted input: files in the repo, docs fetched off the web, output from MCP servers nobody audited. The obvious fix is isolation: give every agent its own kernel. So we start there, running Claude Code, Codex, and others inside sub-second, hardware-isolated microVMs (libkrun/KVM), where even root in the guest is stuck behind the hypervisor's MMU boundary, not just a shared-kernel namespace.

But isolation on its own isn't enough. An isolated agent can still read the .env beside your code, exfiltrate it, wreck your workspace, or abuse a tool you never vetted. So we add defenses, live, one layer at a time: copy-on-write workspace snapshots with a per-file review gate, non-overridable secret exclusions, a DNS-aware egress firewall, a hardened Wolfi guest (custom Go PID 1, dropped capabilities, seccomp, no-new-privs), and an MCP proxy with Cedar authorization profiles. We finish on the attack surface most tools forget: the security tool's own config.

It's all Apache-2.0. The lesson carries to any agent you run: isolation is the floor, not the ceiling.
Speakers
avatar for Juan A. Osorio

Juan A. Osorio

Principal Engineer, Stacklok Inc.
Juan Antonio "Ozz" Osorio is a Mexican software engineer living in Finland. His background spans security for OpenStack, Kubernetes, and bare metal environments. Currently at Stacklok, he founded the ToolHive project and has been building MCP infrastructure, including supply chain... Read More →
Thursday September 17, 2026 15:45 - 16:10 CEST
G102 + G103 (Level 1)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link