
SIG Node Meeting for 2026-05-05
Source: YouTube · Kubernetes · published May 5, 2026 · 56:14
This SIGN Node meeting discusses proposed improvements to Kubernetes for agent sandbox workloads, specifically per-pod limits and Landlock support, drawing from collaboration between Red Hat and Nvidia on the Open Shell project 0:03.
Key Takeaways:
• Red Hat has been evaluating Nvidia's Open Shell agent sandbox tool to identify areas where Kubernetes can better support such workloads 0:16.
• Two improvements emerged: implementing a per-pod limit and adding eventual Landlock support, both proposed by Mnol 0:34.
• The speaker's team is actively exploring implementation approaches for both proposals and is seeking community feedback on the designs 0:42.
The session serves as an early design discussion to align the community on these security and resource isolation enhancements for agent sandbox use cases in Kubernetes.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hey everyone, welcome to the SIGN Node meeting on May 5th uh 2026. Um I'm going to start us off today with a couple of improvements. So um folks at Red Hat have been looking, it's actually agent sandbox, I think maybe isn't the correct term. It is an agent sandbox um tool, open shell that's been worked on by Nvidia and um Red Hat has been looking at that um and finding ways that we can sort of improve Kubernetes use cases for it. Um and there were two ideas that came of it. They're proposed by Mnol to me and sort of um and then my team is sort of looking at them and the two of them uh are a per pod limit and then eventual landlock support. And I wanted to talk through sort of the way that I was imagining both those how both of those could happen and gather feedback. So I'll start with the …