At KubeCon + CloudNativeCon 2025 in Atlanta, the panel of experts - Kate Goldenring of Fermyon Technologies, Idit Levine of Solo.io, Shaun O'Meara of Mirantis, Sean O'Dell of Dynatrace and James Harmison of Red Hat - explored whether the cloud native era has evolved into an AI native era — and what that shift means for infrastructure, security and development practices. Jonathan Bryce of the CNCF argued that true AI-native systems depend on robust inference layers, which have been overshadowed by the hype around chatbots and agents. As organizations push AI to the edge and demand faster, more personalized experiences, Fermyon’s Kate Goldenring highlighted WebAssembly as a way to bundle and securely deploy models directly to GPU-equipped hardware, reducing latency while adding sandboxed security.
Dynatrace’s Sean O’Dell noted that AI dramatically increases observability needs: integrating LLM-based intelligence adds value but also expands the challenge of filtering massive data streams to understand user behavior. Meanwhile, Mirantis CTO Shaun O’Meara emphasized a return to deeper infrastructure awareness. Unlike abstracted cloud native workloads, AI workloads running on GPUs require careful attention to hardware performance, orchestration, and energy constraints. Managing power-hungry data centers efficiently, he argued, will be a defining challenge of the AI native era.
Learn more from The New Stack about evolving cloud native ecosystem to an AI native era
Cloud Native and AI: Why Open Source Needs Standards Like MCP
A Decade of Cloud Native: From CNCF, to the Pandemic, to AI
Crossing the AI Chasm: Lessons From the Early Days of Cloud
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
The agentic AI space faces challenges around secure, governed connectivity between agents, tools, large language models, and microservices. To address this, Solo.io developed two open-source projects: Kagent and Agentgateway. While Kagent, donated to the Cloud Native Computing Foundation, helps scale AI agents, it lacks a secure way to mediate communication between agents and tools. Enter Agentgateway, donated to the Linux Foundation, which provides governance, observability, and security for agent-to-agent and agent-to-tool traffic. Written in Rust, it supports protocols like MCP and A2A and integrates with Kubernetes Gateway API and inference gateways.
Lin Sun, Solo.io’s head of open source, explained that Agentgateway allows developers to control which tools agents can access—offering flexibility to expose only tested or approved tools. This enables fine-grained policy enforcement and resilience in agent communication, similar to how service meshes manage microservice traffic. Agentgateway ensures secure and selective tool exposure, supporting scalable and secure agent ecosystems. Major players like AWS and Microsoft are also engaging in its development.
Learn more from The New Stack about the latest in open source projects like Agentgateway:
Learn more from The New Stack about the latest in open source projects like Agentgateway:
Why Tech Giants Are Backing the New Agentgateway Project
AI Agents Are Creating a New Security Nightmare for Enterprises and Startups
Five Steps to Build AI Agents that Actually Deliver Business Results
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
Nina Polshakova is a software engineer at Solo.io, where she's worked on Istio and API Gateway projects. She's been part of the Kubernetes release team since v1.27 and is currently serving as the Release Lead for v1.33.
Do you have something cool to share? Some questions? Let us know:
- web: kubernetespodcast.com
- mail: kubernetespodcast@google.com
- twitter: @kubernetespod
- bluesky: @kubernetespodcast.com
News of the week 229 new things Google announced at Next 25
MCO: Multi-Cluster Orchestrator
Golden Kubestronaut
Cloud Native Platform Engineering Associate
The kube-scheduler-simulator
K0s and k0smotron are now CNCF Sandbox projects
Links from the interview Nina Polshakova
Kubernetes Deprecation Policy
Kubernetes Dev Google Group
solo.io
Istio
API Gateway (General concept, linking to K8s Gateway API)
Kubernetes Release Team
GitHub
Istio revisions
Working in Public by Nadia Eghbal (Link to publisher's site about the book)
Kubernetes Maintainers Read Mean Comments (KubeCon EU 2024)
Kubernetes 1.33 release blog (Link to release announcement blog)
Kubernetes Enhancement Proposals (KEPs)
Sidecar Containers
Multiple Service CIDR support (KEP link)
Dynamic Resource Allocation (DRA)
DRA support for partitioned devices (KEP link)
DRA device taints and tolerations (KEP link)
DRA: Prioritized Alternatives in Device Requests (KEP link)
Kubernetes 1.33 sneak peak (Link to pre-release highlights)
EndpointSlices API
Kubernetes Gateway API
node.status.nodeInfo.kubeProxyVersion is a lie (issue)
KEP-4004: Deprecate the kubeProxyVersion field of v1.Node #4005 (KEP link)
Kubelet
Removal: Host network support for Windows pods (KEP link)
Containerd
SIG Windows
HostProcess Containers (Windows)
Removal: KEP-5040: Disable git_repo volume driver (KEP link)
User Namespaces (Beta, Enabled by Default)
CRI-O
Runc
In-place Resource Resize for Pods (Link to the alpha announcement, but now beta)
Vertical Pod Autoscaler (VPA)
KEP-5080: Ordered Namespace Deletion
PyTorch
Linkerd
Terry Pratchett's Discworld series
Tiffany Aching series
Guards! Guards!
Going Postal
Kubernetes Slack
New Contributor Orientation
Solo.io provides API gateway, service mesh, and internal developer portal solutions.
Follow Solo.io on X or LinkedIn or dig into the docs.
Want to brush up on RAG? Our Guide to AI walks you through the concept and includes a practical example. Or check out one expert’s practical tips for RAG on our blog.
Connect with Keith on LinkedIn.
Shoutout to Stack Overflow user MrSimpleMind: their helpful answer to the question – How to run jq from gitbash in windows? – has been viewed by more than 213,000 people and won a Populist badge.
See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
At Cloud Native Security Con, we sat down with Solo.io's Marino Wijay and Jim Barton, who discussed how service mesh technologies have matured, especially now with the removal of sidecars in Ambient Mesh that it developed with Google.
Ambient Mesh is "a new proxy architecture that, according to the Solo.io site, "moves the proxy to the node level for mTLS and identity. It also allows a policy-enforcement policy to manage Layer 7 security filters and policies.
A sidecar is a mini-proxy, a mini-firewall, like an all-in-one router, said Wijay, who does developer relations and advocacy for Solo. A sidecar receives instructions from an upstream control plane.
"Now, one of the things that we started to realize with different workloads and different patterns of communication is that not all these workloads need a sidecar or can take advantage of the sidecar," Wijay said. "Some better operate without the sidecar."
Ambient Mesh reflects the maturity of service mesh and the difference between day one and day two operations, said Barton, a field engineer with Solo.
"Day one operations are a lot about understanding concepts, enabling developers, initial configurations, that sort of thing," Barton said. "The community is really much more focused and Ambient Mesh is a good example of this on day two concerns. How do I scale this? How do I make it perform in large environments? How can I expand this across clusters, clusters in multiple zones in multiple regions, that sort of thing? Those are the kinds of initiatives that we're really seeing come to the forefront at this point."
With the maturity of service mesh comes the users. In the context of security, that means the developer security operations person, Barton said. It's not the developer's job to connect services. Their job is to build out the services.
"It's up to the platform operator, or DevSecOps engineers to create that, that fundamental plane or foundation for where you can deploy your services, and then provide the security on top of it," Barton said.
The engineers then have to configure it and think it through. "How do I know who's doing what and who's talking to who, so that I can start forming my zero trust posture?," Barton said.
Idit Levine’s tech journey originated in an unexpected place: a basketball court. As a seventh grader in Israel, playing in hoops tournaments definitely sparked her competitive side.
“I was basically going to compete with all my international friends for two minutes without parents, without anything,” Levine said. “I think it made me who I am today. It’s really giving you a lot of confidence to teach you how to handle situations … stay calm and still focus.”
Developing that calm and focus proved an asset during Levine’s subsequent career in professional basketball in Israel, and when she later started her own company. In this episode of The Tech Founder Odyssey podcast series, Levine, founder and CEO of Solo.io, an application networking company with a $1 billion valuation, shared her startup story.
The conversation was co-hosted by Colleen Coll and Heather Joslyn of The New Stack
After finishing school and service in the Israeli Army, Levine was still unsure of what she wanted to do. She noticed her brother and sister’s fascination with computers. Soon enough, she recalled, “I picked up a book to teach myself how to program.”
It was only a matter of time before she found her true love: the cloud native ecosystem. “It's so dynamic, there's always something new coming. So it's not boring, right? You can assess it, and it's very innovative.”
Moving from one startup company to the next, then on to bigger companies including Dell EMC where she was chief technology officer of the cloud management division, Levine was happy seeking experiences that challenged her technically. “And at one point, I said to myself, maybe I should stop looking and create one.”
Learning How to Pitch
Winning support for Solo.io demanded that the former hoops player acquire an unfamiliar skill: how to pitch. Levine’s company started in her current home of Boston, and she found raising money in that environment more of a challenge than it would be in, say, Silicon Valley.
It was difficult to get an introduction without a connection, she said: “I didn't understand what pitches even were but I learned how … to tell the story. That helped out a lot.”
Founding Solo.io was not about coming up with an idea to solve a problem at first. “The main thing at Solo.io, and I think this is the biggest point, is that it's a place for amazing technologists, to deal with technology, and, beyond the top of innovation, figure out how to change the world, honestly,” said Levine.
Even when the focus is software, she believes it’s eventually always about people. “You need to understand what's driving them and make sure that they're there, they are happy. And this is true in your own company. But this is also [true] in the ecosystem in general.”
Levine credits the company’s success with its ability to establish amazing relationships with customers – Solo.io has a renewal rate of 98.9% – using a very different customer engagement model that is similar to users in the open source community. “We’re working together to build the product.”
Throughout her journey, she has carried the idea of a team: in her early beginnings in basketball, in how she established a “no politics” office culture, and even in the way she involves her family with Solo.io.
As for the ever-elusive work/life balance, Levine called herself a workaholic, but suggested that her journey has prepared her for it: “I trained really well. Chaos is a part of my personal life.”
She elaborated, “I think that one way to do this is to basically bring the company to [my] personal life. My family was really involved from the beginning and my daughter chose the logos. They’re all very knowledgeable and part of it.”
What do you do next when you have over 150 patents to your name? Write a book, of course! Lin Sun is a Senior Technical Staff Member and Master Inventor at IBM, where she has spent the past 14 years doing software engineering in areas including cloud and open technologies. She has worked on the Istio service mesh since 2017, and is on the Istio steering and technical oversight committees. Lin joins Adam and Craig to discuss invention, making Istio easier to use, and how being a mother has impacted both.
Do you have something cool to share? Some questions? Let us know:
web: kubernetespodcast.com
mail: kubernetespodcast@google.com
twitter: @kubernetespod
Chatter of the week Snow in Seattle
News of the week Tanka, from Grafana Hacker News commentary
Jsonnet
ksonnet archived
Configula, from Brendan Burns Caligula, from Rome
Falco moves to the CNCF incubator Falco's biggest hit, Rock Me Amadeus
CKAD is now valid for 3 years
Contour 1.1.0
Getting serious about open-source security by Dan Lorenc Episode 39, with Dan Lorenc
Designing and Building HA Kubernetes on Bare-Metal
AKS Latency and performance/availability issues due to IO saturation and throttling under load
Kubernetes Networking Demystified by Karen Bruner at StackRox
How to Give Developers Access to Kubernetes During Development by Daniel Thiry How to deal with computing resource cost for Kubernetes-based development
Key metrics for monitoring Istio from Datadog
Deploying multiple Istio Ingress Gateways by Peter Jausovec
Big Prometheus by Clay Smith from Monitoring Monitoring
Breaking Changes in Helm 3 (and How to Fix Them) by Jack Morris
Security advantages of pull-based CD pipelines by Alex Kaskasoli
Zero touch authentication on Kubernetes by Peter Wilcsinszky at BanzaiCloud
Vault replication across multiple datacenters on Kubernetes by Nandor Kracser
OpenStack's Complicated Kubernetes Relationship by Mike Vizard of ContainerJournal
Kubernetes 1.15 security changes in GKE
KubeCon + CloudNativeCon NA 2019 Transparency Report
Zendesk case study
Links from the interview IBM Master Inventor
Lin's patents
Her favorites: Analyzing email content to determine potential intended recipients
Ensuring a desired distribution of content in a multimedia document for different demographic groups utilizing demographic information
Istio announcement blog and GlueCon talk from 2017
Lin at the IBM Cloud CTO Office IBM Research
IBM Cloud, formerly known as Bluemix
Bluemix Service Proxy
Amalgam8
Envoy
Istio 1.1, the "9 months" release The Sidecar resource, which lets you scope which services are known by a given sidecar to reduce resource usage
Release cadence
Istio 1.4
Mutual TLS
New 1.4 features: Auto-mutual TLS
client-go library
istioctl analyze
Requirement to declare containerPort removed in 1.3, automatic protocol selection added
User Experience working group istioctl add-to-mesh
istioctl describe-pod
istioctl install
Steering committee
Technical oversight committee
istiod Istio as an Example of When Not to Do Microservices by Christian Posta
Minion cluster mode
Istio Explained, by Lin and Dan Berg
kui and iter8
Lin Sun on Twitter
Solo.io was founded in 2017 by this week's guest, Idit Levine. She talks to Craig and Adam about API gateways, service meshes, and lots of project names with two O's in them.
Do you have something cool to share? Some questions? Let us know:
web: kubernetespodcast.com
mail: kubernetespodcast@google.com
twitter: @kubernetespod
Chatter of the week Casa Battlo
Picasso Museum
Dali Museum and Theatre in Figueres
MoPOP in Seattle The "Beaker Sane" t-shirt
A bottle of Sortilege whisky Gifted to us by Francois LeMessier
Shared with the community at KubeCon
News of the week Announcing SMI SMI Spec website
CNAB and Virtual Kubelet updates from Microsoft
Banzai Cloud Kafka Operator
Razee: multi-cloud CD from IBM
Couchbase Autonomous Kubernetes Operator 1.2
Rio, a MicroPaaS from Rancher Labs
Atlassian Software for Kubernetes from Praqma
Kyma goes 1.0
Intuit win the CNCF End User Award
CapitalOne make their Kubernetes platform available
Links from the interview Solo.io
Gloo Envoy Proxy
SuperGloo
SMI
GlooShot
Service Mesh Hub
Flagger by Weaveworks
Chaos Debugging talk from KubeCon EU; discussing Loop
Knative Using Gloo in Knative
Idit Levine on Twitter