The New MCP Headers Are a Gift to Gateways
The MCP 2026-07-28 release candidate introduces mandatory Mcp-Method and Mcp-Name headers, cache-control-style ttlMs and cacheScope fields, and standardized W3C Trace Context propagation, enabling gat…
The MCP 2026-07-28 release candidate introduces mandatory Mcp-Method and Mcp-Name headers, cache-control-style ttlMs and cacheScope fields, and standardized W3C Trace Context propagation, enabling gat…
The MCP 2026-07-28 release candidate includes six SEPs that harden the protocol's OAuth layer, addressing issuer validation, credential binding, and client type declaration to fix mix-up attacks preva…
EBPF is useful for observing and sandboxing AI agents because it attaches to the kernel to monitor syscalls—file, process, and network activity—without modifying the agent, according to a technical an…
Tigera's Calico Enterprise platform now supports VMs and containers on Kubernetes with a unified networking and security model, enabling enterprises to migrate VMs to Kubernetes without renumbering IP…
NVIDIA released OpenShell, an open-source (Apache 2.0) secure runtime for AI agents that enforces controls at the environment layer rather than the model or application layer, preventing agents from o…
Six AI agent SDKs—LangGraph, CrewAI, Google ADK, and others—are compared for enterprise Kubernetes deployment, with most being model-agnostic and containerizable for on-premise use, though Anthropic's…
Lynx, a Kubernetes-native control and data plane for agentic AI traffic, launched this week. It provides a registry, gateway, audit, authentication, policy enforcement, and agent sandboxing without re…
Tigera announced Lynx, a unified control plane for Kubernetes-native AI agents, to address security challenges posed by autonomous, non-deterministic AI agents. Lynx authenticates, authorizes, mediate…
A Tigera blog post outlines five architectural principles for evaluating AI agent governance platforms: default-deny, attribute-based policy, zero-trust identity, audit by design, and Kubernetes-nativ…
Tigera has introduced a multi-layer policy framework for securing AI agents, requiring policy enforcement at both the gateway and kernel layers rather than a single point. The gateway layer enforces a…
The Spring 2026 release of Calico introduces unified operations across Kubernetes pods and virtual machines, including KubeVirt Live Migration in Bridge Mode that preserves VM IPs during migration wit…
Enterprises relying on network policies, API gateways, and role-based access control (RBAC) for AI agent accountability face critical gaps, as these tools were designed for deterministic, human-driven…
A McKinsey study found that only one-third of organizations have AI agent governance maturity at level 3 or higher, leaving most companies unable to answer basic accountability questions about their d…
Enterprises are consolidating virtual machine and container platforms onto a single Kubernetes infrastructure using KubeVirt, a CNCF project now in production at NVIDIA, Cloudflare, and ByteDance. The…
Enterprises operating multiple Kubernetes clusters are increasingly connecting them through legacy north-south networking patterns—load balancers, public DNS, and firewall rules—that were not designed…
Enterprises are deploying AI agents across marketing, engineering, customer support, and finance functions, but governance frameworks have not kept pace, creating an accountability gap. According to a…