CNDN 2026/BERGEN/OCT 26–27/120 MIN
Agentic
Cloud
Ops
Practical AI-Driven Kubernetes Operations
From Infrastructure as Code toInfrastructure as Agents. Two hours turning AI agents loose on a live Kubernetes cluster — and figuring out what it actually takes to dare run them in production.
$ git clone https://github.com/leffen/agentic-cloud-ops.git && make preflight # ~10 GB · 15 min · do this at home
This is a hands-on workshop. You need a laptop with Docker, ~10 GB of free disk and 8 GB of free RAM — and you must do the setup at home. Conference Wi-Fi is not a build system.
Agentic vs. GitOps
What is genuinely new, and what is just marketing. A pipeline executes a sequence; GitOps converges on a declared state; an agent runs a loop. Knowing which you want is the skill.
Hands-on experience
Deploy, debug and harden a live cluster with an agent holding kubectl — including the part where it gets it wrong and has to work out why.
Risk management
The guardrails that make this safe: namespace-scoped RBAC, tool-layer flags, and a referee that decides what "healthy" means so the agent cannot mark its own homework.
120 minutes
block width = duration · select a blockLab 2 · Security and hardening
Start from a deliberately insecure workload and a namespace-scoped RBAC ladder. Harden to restricted, then prove the guardrail holds by watching the agent get refused.
Read the block →Is this
for me?
YES, IF
- +you use kubectl regularly
- +you want to watch an agent make real changes to a real cluster
- +you are curious where the limits actually are
- +you are a developer, architect or SRE
PROBABLY NOT, IF
- −you have never seen a Kubernetes manifest
- −you want an overview presentation to sit back for
- −you cannot bring a laptop
- −you expect finished product recommendations
No machine-learning background is needed. None of this is model training.
Prepare before Bergen
A cold bootstrap takes about two minutes on a good connection. Thirty-five of them on conference Wi-Fi takes the whole first block — which is why the prep happens at home, and why this is the only thing we ask of you in advance.
What we actually do
Your first agent
Hand over a task in plain language. Watch it plan, act and verify — then debug a deliberately planted ImagePullBackOff without you touching kubectl.
Lab 2Security and hardening
Harden a deliberately insecure workload to restricted, on a namespace-scoped RBAC ladder. The interesting part is what the agent gets refused.
Lab 3Chaos and recovery
Incident response end to end, demonstrated at the front of the room with you as backseat drivers. We measure the recovery rather than describing it.
Instructors
Lars Effenberger
TODO: role and one-line bio
Lars Søraas
TODO: role and one-line bio