Two days, built for engineers.
Sessions, keynotes, and breaks across every stage. Released day by day as the lineup locks in.
Where to be, and when.
- 10:30 – 11:15SeattleNo Framework, No Server: Making AI Agents Collaborate in One TerminalAI Engineering & DataLech Kalinowski
- 10:30 – 11:15CupertinoSecuring AI Agents on Kubernetes: Identity, Sandboxes, and Policy EnforcementAI Engineering & DataRoland Huß
- 10:30 – 11:15Los GatosHow will we prompt AGI? A History of Harness Hacks.AI Engineering & DataIvan Charapanau
- 11:30 – 12:15Los GatosSame Bug Twice: What Happens When AI Writes Your Code And Your TestsSoftware Architecture & Engineering ExcellenceMourjo Sen
- 11:30 – 12:15SeattleAgents Propose, Git DisposesCloud, DevOps & Platform EngineeringJaroslaw Gajewski
- 11:30 – 12:15CupertinoAI Tokenomics: Principles for Cost-Efficient GenAIAI Engineering & DataGrzegorz Wasilewski
- 12:30 – 14:00Silicon ValleyPrivate AI with Docker and UpCloudCloud, DevOps & Platform EngineeringPaweł Piwosz
- 12:30 – 13:15RedmondTerraform, day 1001Cloud, DevOps & Platform EngineeringPiotr Trębacz
- 12:30 – 13:15Palo AltoI packaged my application in a container image, and now what?Cloud, DevOps & Platform EngineeringAurélie Vache
- 13:30 – 14:15Cupertino(MCP Security) - How Your Friendly MCP Tool Might Betray YouCybersecurityDaniel Ostrovsky
- 13:30 – 14:15Palo AltoBeyond Coding Assistants: Orchestrating the Entire SDLCAI Engineering & DataIllia Slepau
- 13:30 – 14:15RedmondFrom GenAI Training to Production. Lessons learned from Building AI Agents for Financial Services ClientsAI Engineering & DataAnna Żółtańska
- 14:30 – 15:15CupertinoAgents are easy, enterprises are where they breakAI Engineering & DataKonrad Bujak
- 14:30 – 15:15Palo AltoSourcecode translation as a step in Legacy ModernizationSoftware Architecture & Engineering ExcellenceLeszek Włodarski
- 14:30 – 15:15Los GatosDesign Systems That Explain ThemselvesSoftware Architecture & Engineering ExcellenceSzymon Chudy
- 15:30 – 16:15CupertinoBuilding the next generation of AI developer toolsAI Engineering & DataKrzysztof Cieślak
- 15:30 – 16:15Los GatosPlatforms That Don't Suck - Creating tools that teams might actually loveCloud, DevOps & Platform EngineeringKarolina Ochlik
- 15:30 – 17:00Silicon ValleySecuring AI Agents with Fine Grained AuthorizationCybersecuritySohan Maheshwar
- 16:00 – 16:45Palo AltoMFA? Game over! Watch your protection collapse – liveCybersecurityChristoph Menzel
- 16:30 – 17:15CupertinoGitHub Actions moves to CosmosDB: data migration at internet scaleSoftware Architecture & Engineering ExcellenceBassem Dghaidi
- 16:30 – 17:15Los GatosForensic DDD: Reverse-Engineering the Domain Your Legacy System Never DocumentedSoftware Architecture & Engineering ExcellenceRaj Navakoti
- 16:30 – 17:15RedmondAgile isn't dead, you're just doing it wrongEngineering careersKarolina Ochlik
Securing AI Agents on Kubernetes: Identity, Sandboxes, and Policy Enforcement
Roland Huß
AI agents call external APIs, access databases, and execute code on behalf of users. With the Model Context Protocol (MCP) becoming the standard for how agents discover and invoke tools, every MCP tool call is a security boundary crossing. The agent holds the user's intent, the MCP server holds the capability. The question is: who decides what the agent is allowed to ask for? This talk covers three operational patterns for securing agentic MCP interactions on Kubernetes. Workload identity with SPIFFE gives each agent a cryptographic identity without shared secrets, so MCP servers know exactly which agent is calling. Token exchange for delegated access lets agents act on behalf of users without holding their credentials: the agent presents its own identity, the platform issues a scoped token that the MCP server can verify and constrain. Kernel-enforced sandboxing with NVIDIA's OpenShell wraps the agent in per-binary network policies and L7 HTTP/MCP traffic inspection, so even a compromised agent cannot reach MCP servers it was not granted access to. Walk away knowing how to secure the MCP tool chain from agent identity to server-side verification, and why most agent deployments get this wrong.
Save your seat before it fills.
Early pricing runs while the programme is still being finalised.