Uploaded August 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Securing Non-Human Identities: A Defense-in-Depth Blueprint for AI Agents - Tatsuya Yano, LY Corporation
The rise of AI agents and the MCP is revolutionizing autonomous system interactions. However, it introduces a severe security flaw: the "Confused Deputy" problem. When an AI agent executes tasks on behalf of a human, traditional service-to-service authentication often drops the original user's context, potentially granting the agent excessive permissions to access unauthorized data.
This session, will demystify "Identity Chaining" - a robust architectural pattern designed to solve this critical flaw, and will explore how to seamlessly propagate user intent across microservices and agents using the emerging "ID-JAG" (Identity Assertion JWT Authorization Grant) standard alongside "RFC 8693 Token Exchange."
Drawing from massive-scale web service implementations powering LINE and Yahoo! JAPAN, we showcase a Single Source of Truth (SSoT) design. While IdP-agnostic, we demonstrate unifying CNCF Keycloak (User) with CNCF Athenz (Workload) to build a zero-trust AI architecture.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Securing Non-Human Identities: A Defense-in-Depth Blueprint for AI Agents - Tatsuya Yano, LY Corporation
The rise of AI agents and the MCP is revolutionizing autonomous system interactions. However, it introduces a severe security flaw: the "Confused Deputy" problem. When an AI agent executes tasks on behalf of a human, traditional service-to-service authentication often drops the original user's context, potentially granting the agent excessive permissions to access unauthorized data.
This session, will demystify "Identity Chaining" - a robust architectural pattern designed to solve this critical flaw, and will explore how to seamlessly propagate user intent across microservices and agents using the emerging "ID-JAG" (Identity Assertion JWT Authorization Grant) standard alongside "RFC 8693 Token Exchange."
Drawing from massive-scale web service implementations powering LINE and Yahoo! JAPAN, we showcase a Single Source of Truth (SSoT) design. While IdP-agnostic, we demonstrate unifying CNCF Keycloak (User) with CNCF Athenz (Workload) to build a zero-trust AI architecture.










