Kubernetes adoption is growing rapidly, but so are complexity and security risks.

Platform teams are tasked with keeping clusters secure and observable while navigating a skills gap. At KubeCon + CloudNativeCon North America, The New Stack spoke with Ratan Tipirneni, President and CEO of Tigera, about the future of Kubernetes security, AI-driven operations, and emerging trends in enterprise networking. The highlights from that discussion are summarized below.
Portions of this article are adapted from a recorded interview between The New Stack’s Heather Joslin and Tigera CEO Ratan Tipirneni. You can watch the full conversation on The New Stack’s YouTube channel. Watch the full interview here
How Can Teams Better Manage the Kubernetes Blast Radius and Skills Gap?
Tipirneni emphasizes the importance of controlling risk in Kubernetes clusters. “You want to be able to microsegment your workloads so that if you do come under an attack, you can actually limit the blast radius,” he says.
Egress traffic is another area of concern. According to Tipirneni, identifying what leaves the cluster is critical for security and compliance. Platform engineers are often navigating complex configurations without decades of networking experience.
“Calico AI is a great mechanism to help them understand some of the nuances and intricacies of how to troubleshoot these things without having to get a PhD in networking,” Tipirneni explains.
How Does Calico AI Simplify Kubernetes Operations Through Conversation?
Tigera’s new Calico AI aims to make cluster operations more approachable. Users can ask questions like “What ports are open?” or “Are network policies preventing service connectivity?” and receive actionable guidance.
Tipirneni frames it as a response to growing operational complexity. “Our solution is rich, but it can also be very comprehensive and a little intimidating to use. We figured out a mechanism using AI to simplify the user experience, allowing users to chat with the solution and unlock more value,” he says.
Why Does Support for Istio Ambient Mode Matter for Unified Kubernetes Security?
Tigera is also incorporating Istio Ambient Mode to provide a single point of control from network layer three to application layer seven. This approach allows teams to combine L3 flow logs with L7 service logs, improving visibility and troubleshooting.
Tipirneni highlights that customer demand drove this integration. “Many of our customers really want a single vendor to manage all the solutions so they are not dealing with multiple vendors,” he says.
Istio Ambient Mode used with Calico also offers flexible encryption options, including WireGuard and mTLS, depending on customer requirements.
What Challenges Do AI Agents Introduce for Kubernetes Security?
The conversation turned toward the future of AI in enterprise operations. Tipirneni notes that autonomous AI agents are becoming more common, offering new capabilities but also new challenges.”Agents are autonomous and non-deterministic. You cannot predict which agents are going to talk to other agents or what actions they will take. This presents a complex problem for security, monitoring, and observability,” he says.
Despite the risks, Tipirneni sees enormous opportunity. “We should lean in and do this. We are experimenting internally by building agents to automate functions from marketing to engineering. We are seeing an explosion of ideas.”
Why Are Enterprises Accelerating VM to Kubernetes Migrations?
Tipirneni notes that many enterprises migrating from VMs to Kubernetes are discovering a gap: VM environments often included sophisticated, assumption-laden networking capabilities, and organizations now expect comparable functionality for those workloads once they move into Kubernetes.
“KubeVirt is a powerful mechanism to migrate most of these VMs,” he explains, “but there is still a big gap in networking for those workloads. We are making big investments to solve these problems.”
What Comes Next for Kubernetes Security and AI-driven Operations?
The Kubernetes ecosystem is evolving quickly. Calico AI promises to simplify security operations, Istio Ambient Mode provides application (L7) traffic control and encryption, and emerging trends like AI agents and VM migrations are reshaping enterprise operations.
Together, these innovations signal a shift toward more unified, intelligent platforms that reduce complexity and help teams operate Kubernetes environments with far greater agility and confidence.
Ready to Go Deeper on Istio Ambient Mode, Calico AI and Kubernetes Security?
Take the next step and explore the full set of announcements from this year’s KubeCon + CloudNativeCon NA 2025.
