AI-Agent-Sandbox auf Kubernetes: Warum Container-Isolation für untrusted Agents nicht reicht und wie Kata Containers VM-Isolation bei Standard-Container-Workflow liefert.
Keycloak als zentrale Autorisierungs-Control-Plane in Kubernetes: Service-to-Service-Autorisierung an der Plattform-Ebene durchsetzen — ohne App-Änderungen, mit Istio Ambient & Waypoint.
Keyless Identity für MCP-Agents: Warum statische Secrets das größte Sicherheitsrisiko Ihrer KI sind und wie SPIRE, Keycloak, DPoP & OPA Agents ohne stehlbare Secrets absichern.
Non-Human Identities & Identity Chaining für AI-Agents: So verhindern Sie den Confused Deputy mit RFC 8693, RFC 7523 & ID-JAG — Zero-Trust in Kubernetes.
Meldepflicht nach NIS2/§ 32 BSIG für Kubernetes-Vorfälle: 24h-Erstmeldung, 72h-Meldung, Abschlussbericht. Welche Cluster-Ereignisse die Frist auslösen.