Senior Technical Staff Member, AI Platform | IBM Research SPIFFE Steering Committee member · Co-creator of Tornjak (CNCF)
Building zero-trust identity and platform primitives for cloud-native AI agents.
When AI agents act on behalf of users — committing code, calling APIs, triggering workflows — who holds the identity?
I work on rossoctl (formerly Kagenti): open-source platform primitives for trustworthy AI agents on Kubernetes. It is framework-neutral, built on open standards, and supports A2A and MCP.
My focus is the security and identity layer: SPIFFE/SPIRE workload identity, OAuth 2.0 token exchange (RFC 8693), and transparent sidecar injection — so agent developers never write auth code.
User Agent Token Exchange Target Service
(authorization) ──▶ (SPIFFE identity) ──▶ (RFC 8693) ──▶ (scoped access)
│ │
zero code changes subject preserved → audit trail
The agent holds cryptographic identity. The user holds delegated authorization. The platform enforces policy.
| Project | Role | Description |
|---|---|---|
| rossoctl/rossoctl | Creator & Maintainer | Agentic platform — installer, UI, and docs for running secure AI agents on Kubernetes |
| rossoctl/cortex | Creator & Maintainer | Data plane that mediates agent actions — admission webhook, AuthBridge, client registration |
| rossoctl/operator | Maintainer | Kubernetes operator for deploying and managing the lifecycle of Agents and Tools |
| rossoctl/examples | Creator & Maintainer | Reference agent implementations and demo tools |
| spiffe/tornjak | Co-creator & Maintainer | SPIRE management UI and API layer (CNCF) |
| Kuadrant/mcp-gateway | Contributor | Envoy-based MCP Gateway with Istio and policy attachment integration |
kagenti/*repositories were renamed torossoctl/*— old links redirect.
- Workload Identity — SPIFFE/SPIRE, JWT-SVIDs, attestation, chain-of-trust
- Agent Security — OAuth 2.0 token exchange, subject preservation, scope-based access control
- Agent Attestation — stackable attestors enriching identity with provenance, capabilities, and SBOM verification
- Cloud-Native Infrastructure — Kubernetes admission webhooks, Envoy sidecars, service mesh coexistence
- KubeCon + CloudNativeCon Europe 2026 — When an Agent Acts on Your Behalf, Who Holds the Keys? Cryptographic identity and delegation for cloud-native AI agents
- Full talk list with recordings on mrsabath.github.io
- rossoctl.dev — project site: architecture, docs, blog, and getting-started guides
- Publications & patents — NIST IR 8320B, Red Hat and IBM Research articles, 20 patents
Ask me about: SPIFFE/SPIRE · zero-trust for AI agents · Kubernetes workload identity Contact: mrsabath at gmail.com




