266 posts tagged with "Model Context Protocol"
Content about the Model Context Protocol (MCP)

Rubrik Gave AI Agents the Keys to the Recovery Vault: What a Backup Vendor's Governed MCP Server Teaches Infrastructure Tool Design
Rubrik's September 2026 MCP server gives customer AI agents governed access to backup and recovery state — RBAC parity, blast-radius-gated restores, and auditable tool calls. Here is the five-rule checklist its design implies for any infrastructure MCP surface.

An Agent That Runs a Company Holds the Company's Credentials: 4 Identity Controls Pion's Launch Demands
Andon Labs' Pion hands persistent agents email, phone, and banking to run real businesses. Four controls — per-agent identity, least-privilege credential vending, spending governors, and signed audit trails — must come first, and deploy pipelines already show how.

Your Next Platform User Isn't Human: RBAC and Quotas for AI Agents as Platform Consumers
CNCF's Platform Engineering 2.0 names AI agents as platform consumers with their own access, scope, and governance needs. Here is the concrete design that follows: per-agent identity, least-privilege roles, machine-speed quotas — and why MCP auth must be agent-first from day one.

Backstage Hits CNCF 'Adopt': What Pairing a Software Catalog With an MCP Server Actually Takes
CNCF's Q1 2026 radar put Backstage in 'Adopt' while its agentic-enterprise commentary demands machine-consumable platform interfaces. The official MCP plugin, read-through sync, and four hard parts — auth, writes, refresh, drift — decide whether the pairing holds.

Your AI Agent Has the Keys to Your Servers: What a Coolify MCP Bridge Teaches About Scoping Deploy Authority
A community MCP server turns Coolify into agent-callable deploy tools for about 13 dollars a month — but the agent holds a deploy-level API token with nothing between it and delete. Scoped, audited agent credentials are the missing primitive.

Kubernetes Shipped a Sandbox API for AI Agents: What a Declarative Singleton-Workload Primitive Means for a Deploy-From-Chat PaaS
SIG Apps' Agent Sandbox CRD collapses the hand-rolled StatefulSet-plus-Service-plus-PVC stack into one declarative resource for stateful AI agent runtimes. Here is how the four CRDs work, what the gVisor-vs-Kata choice costs, and which parts a self-hosted platform should adopt now.

MCP's 10,000-Server Problem: Building an Allowlisted, Audited Tool Catalog Before an Agent Can Deploy to Your Fleet
With 10,000+ public MCP servers and most scanned servers needing security review, connecting an agent to a tool is now a governance problem. A tiered, allowlisted tool catalog design — plus a deploy-from-chat walkthrough — for teams running agents against production.

450+ MCP Servers Catalogued and Quality-Scored Daily: What the Ecosystem Census Says About the Tool Sprawl Your Deploy Platform Inherits
A daily census grades 453 MCP servers an average of 16.3 out of 100. Here is what that number means for platform teams, the security gap the score does not cover, and a bless-or-block rubric for governing tenant agent tools.

MCP Bets H2 2026 on Server Cards: What Your Registry-Less Server Must Hand-Roll Today
The July 2026 MCP spec shipped stateless transport and a mandatory server/discover RPC but left pre-connect Server Cards experimental. Here is the concrete manifest, capability advertisement, and trust signaling a registry-less deploy-from-chat server builds today so the eventual card format is a migration, not a rewrite.