Loading…
June 9-10, 2026
Bengaluru, India
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for MCP Dev Summit Bengaluru to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration..

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.


Tuesday June 9, 2026 3:20pm - 3:45pm IST
We had 47 runbooks in Confluence. During incidents nobody used them. So I converted them into MCP server tools where an agent picks the right steps based on what it sees in the cluster.
This was working fine until two things went wrong.
One, the MCP server had the same service account as our CI pipeline. Too many permissions. Agent went and listed every secret in the namespace. It wasn't doing anything wrong, just had access it should not have. That's when I understood MCP has no security story for infra tools.
Two, at 3 AM the agent connected two unrelated alerts, restarted the wrong deployment, and a small incident became bigger.
I fixed both. Built OPA policy gates that check every tool call before execution. RBAC is now per tool, not per server. Tokens last five minutes and expire after one action. After the 3 AM incident I added blast-radius checks and human approval for destructive operations.
In the demo I walk through an agent diagnosing a pod failure, clearing policy, running with a scoped token, and logging an audit trail. Then it tries something it should not and gets blocked.
This talk is about what it actually takes to give an agent kubectl access safely.
Speakers
avatar for Koti Vellanki

Koti Vellanki

DevOps Engineer, TransUnion
Senior DevOps Engineer based in Bangalore with over a decade of experience in platform engineering and cloud infrastructure. I work mostly with Kubernetes, observability systems, and CI/CD at scale. Currently building open-source MCP tools that connect AI agents to production infrastructure... Read More →
Tuesday June 9, 2026 3:20pm - 3:45pm IST
Scarlet 2&3
  Security Identity + Trust

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link