Upgrade to Pro — share decks privately, control downloads, hide ads and more …

OpenAppa

Avatar for cncf-canada-meetups cncf-canada-meetups
September 27, 2026
4

 OpenAppa

Avatar for cncf-canada-meetups

cncf-canada-meetups

September 27, 2026

Transcript

  1. CNCF MONTRÉAL · SEPT 29, 2026 · LIGHTNING TALK OpenAPPA

    on kagent Deterministic guardrails that don't break agents Joey Orlando · Co-founder, Archestra
  2. CO-FOUNDER AT Archestra 01 Why guardrails are hard 02 OpenAPPA

    in five minutes 03 OpenAPPA on kagent demo We build an open-source AI platform for enterprises, and OpenAPPA. openappa.com · archestra.ai
  3. SIMON WILLISON, JUNE 2025 Co-creator of Django. Coined the term

    “prompt injection” in 2022. The lethal trifecta Give an agent all three, and anyone who can put text in front of it can steal your data. The model can't reliably tell your instructions from theirs. simonwillison.net/2025/Jun/16/the-lethal-t rifecta
  4. THE USUAL FIX Ask another model Auto modes use a

    second LLM to judge each tool call. • It can't follow data across calls • It doesn't see tool outputs • It can be prompt-injected too Best reported judge accuracy: 99.3% · openappa.com
  5. OPENAPPA · AGENTIC PERMISSIONS POLICY ALGEBRA Track the data, not

    the words. Deterministic Outside the loop Doesn't break agents A pure function of the event log. No Checks every tool call before it runs. Every block comes with a remedy second model to fool. Fails closed. plan, not a dead end. “You cannot prompt-inject an algebra.” · Rust core · MIT licensed · openappa.com
  6. ⎈ CNCF SANDBOX · CREATED BY SOLO.IO What is kagent?

    AI agents as Kubernetes resources. You declare them, the controller runs them. • Agent, ModelConfig, RemoteMCPServer CRDs • Each agent is a pod running Google ADK (Python or Go) • Built-in UI, A2A endpoints, MCP tool servers kagent.dev · github.com/kagent-dev/kagent apiVersion: kagent.dev/v1alpha2 kind: Agent metadata: name: incident-scribe spec: type: Declarative declarative: modelConfig: openai-model-config tools: - type: McpServer mcpServer: name: internal-slack kind: RemoteMCPServer - type: McpServer mcpServer: name: github kind: RemoteMCPServer
  7. OPENAPPA × KAGENT One image swap A drop-in agent image

    with the OpenAPPA ADK plugin, plus the runtime chart. • Two env vars per agent to opt in • Python and Go ADK runtimes • Runtime unreachable: every call fails closed
  8. DEMO The public issue is blocked acme/status needs trusted data

    for a public audience. The session has neither. The agent asks for approval. kagent shows its native Approve / Reject card.
  9. Demo · nothing leaked Oncall rejected The call never ran.

    The agent stops and reports it. The work still got done Full incident summary, including "rotate the exposed key". Audit trail appa-runtime logs every block, release and ruling. GitHub: no CREATED.