2026-09-10 –, Ballroom All times in US/Pacific
"You have full access to the pipeline. Do what you need to do." Famous last words.
I gave Claude Code full pipeline access and stepped away for thirty seconds. It wrecked the Kubernetes cluster, and two troubleshooting sessions later, while it was supposedly helping me recover, it took out the network cards on nearly every Linux box we had. I thought that was as bad as it got. Then came the 2026 edition, when it deleted 250 clusters.
This is the five-minute, twenty-slide version of that spiral: how "let me help" becomes "I've destroyed your cluster," why "the AI knows what it's doing" is the most dangerous phrase in DevOps, and the guardrails I now enforce religiously so a thirty-second walk away can't take down a fleet. Come for the disaster, stay for the wisdom.
"You have full access to the pipeline. Do what you need to do." Famous last words.
I gave Claude Code full access to my cluster enivornment and stepped away for about thirty seconds. When I came back, it had wrecked the Kubernetes cluster. That part I could almost live with. What made it a story was what came next: two troubleshooting sessions later, while it was supposedly helping me recover, it took out the network cards on nearly every Linux box in the set.
That was the original. The 2026 edition is worse. This time it wasn't one cluster, it was 250, gone. I walk the actual spiral, from "let me help" to "I've destroyed your cluster," now at fleet scale, and show why handing an agent broad access hands it a proportionally bigger blast radius by default.
This is a talk about nondeterministic systems and the illusion of AI understanding, and why "the AI knows what it's doing" is the most dangerous phrase in modern DevOps. I show the guardrails I now enforce religiously so it can't happen again, at one cluster or two hundred and fifty.
Five minutes, twenty slides, and one very expensive lesson about handing AI agents infrastructure access, even for a minute. Plus the blame-filled post-mortem I ran afterward with Claude Code itself. Come for the disaster, stay for the wisdom.
Michael Forrester is a student, explorer, and educator working at the boundary between humanity and technology. Over 25+ years he's gone from CTO to IC across operations, AI, cloud, and platform engineering, with time at AWS, ThoughtWorks, Red Hat, and Honeywell. His training has reached over a million engineers, and he now leads AI-for-organizations work as a Principal Training Architect at Accenture LearnVantage. His current focus is agentic AI security: how the CNCF platform stack most teams already run — GitOps, admission control, runtime detection, observability — covers roughly 80% of what governs AI agents in production, and what the remaining 20% actually takes, namely agent identity, LLM input/output sanitization, and MCP tool-call governance. He speaks at KubeCon, CNCF events, and most recently AI Engineer World's Fair on Claude Code, MCP, and agent governance for platform engineers. Tools don't transform organizations. People do.
