World Congress 2026 Europe • Jul 9, 2026 • Session details

No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents

Jaroslaw Gajewski

Are you giving autonomous AI agents direct deployment keys? Prevent runaway automation by treating AI like a junior developer who must propose operational fixes via GitOps pull requests.

Pause
Mute Enter Fullscreen
#1 about 3 min

Real-world risks of autonomous AI agents in production

Unconstrained AI automation causes runaway costs and destructive infrastructure events when given direct access.

#2 about 3 min

Managing autonomous agent trust and cloud permission gaps

Treating AI agents like unpredictable new hires emphasizes the risk of granting overly permissive cloud identities.

#3 about 3 min

Routing agent decisions through standard delivery pipelines

Forcing AI-proposed infrastructure changes through standard CI/CD and review processes prevents dangerous direct executions.

#4 about 3 min

Implementing read-only access and zero trust policies

Restricting autonomous agents to read-only infrastructure permissions ensures all operational changes are safely routed through Git.

#5 about 3 min

Standardizing the infrastructure control plane with Crossplane

Structuring infrastructure as code tools creates a uniform entry point for all control plane modifications proposed by agents.

#6 about 4 min

Leveraging GitOps for AI auditing and instant rollbacks

Git repository history inherently provides compliance-ready audit trails and deterministic rollback capabilities for flawed AI decisions.

#7 about 2 min

Enforcing core security gates for AI agentic workflows

Infrastructure reconciliation, policy as code, and branch protections actively block unauthorized operations and enforce governance.

#8 about 2 min

Walking through an agent-driven GitOps deployment workflow

A conceptual runbook demonstrates an AI generating pull requests while GitOps controls successfully block direct cluster modifications.

#9 about 8 min

Strategies for safely phasing autonomous agents into production

Gradually expanding agent permissions from staging reviews to robust production workloads prevents catastrophic downtime and normalizes on-call operational models.

Matching moments

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann Chris Heilmann +2 · LIVE

1:30 min

Understanding the self-managed nature of GitOps software agents

Roberth Strand · LIVE

2:40 min

Enforcing developer accountability when leveraging AI programming agents

Daniel Siegl · Coffee With Developers

2:34 min

Balancing developer autonomy with the adoption of coding agents

Clemens Wasner Clemens Wasner +4 · World Congress 2026 Europe

2:18 min

Managing security risks introduced by autonomous AI agents

Christian Heilmann Christian Heilmann · World Congress 2025

1:03 min

From read-only models to excessive agency

Alex Olivier Alex Olivier · World Congress 2026 Europe