Loading…
18-19 June
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon India 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in India Standard Time (UTC+5:30)To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Type: Security clear filter
arrow_back View All Dates
Friday, June 19
 

12:40pm IST

Zero Trust for Autonomous Agents: Isolating AI Workloads on Kubernetes - Kanagalingam Senthalan, WSO2
Friday June 19, 2026 12:40pm - 1:10pm IST
AI Agents are moving from experimental scripts to autonomous "digital employees" creating a new security crisis. Because agents determine their own execution paths, standard security fails. Securing them requires strictly enforcing the 4 Pillars of Governance: Administration, Authentication, Authorization, and Audit at the infrastructure layer.

This talk presents a practical implementation of these pillars using Cell-Based Architecture on Kubernetes. We will demonstrate how to encapsulate agents into governed "Cells" to enforce Zero Trust controls at every critical traffic boundary:
1. User → Agent
2. Agent → Agent
3. Agent → Tool
4. Agent → LLM

We will translate these pillars into real Kubernetes primitives, giving attendees a blueprint to move from "unmanaged bots" to hardened, enterprise-ready workloads. All patterns demonstrated use CNCF-hosted projects and open-source identity primitives leveraging open standards like OIDC and OAuth 2.0.
Speakers
avatar for Kanagalingam Senthalan

Kanagalingam Senthalan

Technical Lead, WSO2
Kanagalingam Senthalan is a core contributor and technical lead for Project Thunder, an open-source identity service designed for cloud-native workloads including AI agents. Previously, he led the Application Identity team for WSO2 Internal Developer Platform, where he embedded security... Read More →
Friday June 19, 2026 12:40pm - 1:10pm IST
205 (Level 2)
  Security
  • Content Experience Level Any

2:30pm IST

How We Stopped a Crypto-mining Attack in Kubernetes Caused by a Next.js RCE - Achanandhi M & Tamil Vanan Karuppannan
Friday June 19, 2026 2:30pm - 3:00pm IST
Modern frameworks help teams move fast, but a single vulnerability can quickly escalate into a serious security incident.

In this talk, we simulate a real-world attack scenario where a publicly disclosed RCE vulnerability in Next.js is exploited to deploy crypto-mining workloads inside a Kubernetes cluster. We demonstrate how an application-level vulnerability can quickly escalate into a cluster-wide threat - and how to prevent it before it does.

We’ll break down how such an attack unfolds, the runtime indicators that can expose it, and why patching the application alone isn’t enough.

We’ll then demonstrate how to stop this class of attack using Falco for runtime threat detection and Kyverno for policy enforcement - detecting malicious activity, blocking misuse, and limiting blast radius.

Finally, we’ll share Kubernetes security best practices including resource limits, workload isolation, security policies, and improved runtime visibility to help teams better secure their clusters.
Speakers
avatar for Tamil Vanan Karuppannan

Tamil Vanan Karuppannan

Principal Engineer
Tamil vanan is a cloud native Tech lead. He is passionate about finding solutions to problems in the cloud native environment.

He works with cloud-native technologies like Kubernetes, multi-cloud and networking. He is a passionate supporter of open source and CNCF and actively participates in it... Read More →
avatar for Achanandhi M

Achanandhi M

Developer Advocate

Friday June 19, 2026 2:30pm - 3:00pm IST
Lotus 1 (Level 3)

4:50pm IST

Zero Trust for Fintech: Building Secure Banking Infrastructure With Cilium - Prasta Maha & Herbert Sianturi, Krom Bank Indonesia
Friday June 19, 2026 4:50pm - 5:20pm IST
In the highly regulated world of banking, "security by default" isn't just a buzzword, but it is a compliance requirement. As financial institutions migrate to Kubernetes, they face a critical challenge: How do you enforce strict network segregation, achieve Zero Trust, and maintain deep observability.

This session explores how to leverage Cilium and eBPF to build a battle-hardened banking infrastructure. We will move beyond standard Kubernetes Network Policies, demonstrating how to implement Layer 7 filtering, transparent encryption, and deep observability in service communications.

Attendees will receive a practical roadmap for:
- Enforcing Zero Trust: Using Cilium Network Policies to restrict traffic based on identity and fqdn, not just IP addresses.
- Achieving Compliance: implementing Transparent Encryption (WireGuard/IPsec) to meet data-in-transit requirements.
- Auditing: Utilizing Hubble for deep visibility into dropped packets and flow logs to satisfy security audits.
Speakers
avatar for Herbert Sianturi

Herbert Sianturi

Senior DevOps Engineer, Krom Bank Indonesia
Herbert Sianturi serves as a Senior DevOps Engineer at Krom Bank Indonesia, where he roles spearheads efforts in enhancing the quality of end-to-end application lifecycle and applying open source platform as a base. With years of expertise in container orchestration and cloud computing... Read More →
avatar for Prasta Maha

Prasta Maha

Senior Devops Engineer, Krom Bank Indonesia
Prasta is passionate about tech, especially Linux, Cloud Computing, DevOps, Data Engineering, Security, and Programming. He also shares his tech experiences and insights on https://medium.com/prastamaha

website: https://prastamaha.dev
Friday June 19, 2026 4:50pm - 5:20pm IST
Lotus 1 (Level 3)
  Security
  • Content Experience Level Any
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Content Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -