BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//HasGeek//NONSGML Funnel//EN
DESCRIPTION:Real systems. Real engineers. Real lessons.
X-WR-CALDESC:Real systems. Real engineers. Real lessons.
NAME:Platform Engineering meet-up - September 5
X-WR-CALNAME:Platform Engineering meet-up - September 5
REFRESH-INTERVAL;VALUE=DURATION:PT12H
SUMMARY:Platform Engineering meet-up - September 5
TIMEZONE-ID:Asia/Kolkata
X-PUBLISHED-TTL:PT12H
X-WR-TIMEZONE:Asia/Kolkata
BEGIN:VEVENT
SUMMARY:Check-in
DTSTART:20260905T091500Z
DTEND:20260905T093000Z
DTSTAMP:20260909T011940Z
UID:session/Lv482tfR3TNvpjCqLYyRsq@hasgeek.com
SEQUENCE:1
CREATED:20260901T071423Z
LAST-MODIFIED:20260901T071427Z
LOCATION:Bangalore & Hybrid
ORGANIZER;CN=Rootconf:MAILTO:no-reply@hasgeek.com
BEGIN:VALARM
ACTION:display
DESCRIPTION:Check-in in 5 minutes
TRIGGER:-PT5M
END:VALARM
END:VEVENT
BEGIN:VEVENT
SUMMARY:Introduction to the meet-up
DTSTART:20260905T093000Z
DTEND:20260905T094000Z
DTSTAMP:20260909T011940Z
UID:session/PxVduVuAFLviDQPncqHYax@hasgeek.com
SEQUENCE:2
CREATED:20260901T071458Z
GEO:12.9027111;77.6010828
LAST-MODIFIED:20260901T071504Z
LOCATION:Board Room - Blinkit\, 7th floor\, Vaishnavi BVS Senate\nBengalur
 u\,\nIN
ORGANIZER;CN=Rootconf:MAILTO:no-reply@hasgeek.com
BEGIN:VALARM
ACTION:display
DESCRIPTION:Introduction to the meet-up in Board Room in 5 minutes
TRIGGER:-PT5M
END:VALARM
END:VEVENT
BEGIN:VEVENT
SUMMARY:Beyond AI sandboxing: decoupling AI from execution
DTSTART:20260905T094000Z
DTEND:20260905T101500Z
DTSTAMP:20260909T011940Z
UID:session/Qi5Dgq5nSdM5Wk538c4DGB@hasgeek.com
SEQUENCE:4
CATEGORIES:Talk (30 mins),Bangalore meet-ups
CREATED:20260901T071513Z
DESCRIPTION:**Beyond AI Sandboxing: Decoupling AI from Execution**\n\n---\
 n\nAI coding assistants are transforming software development\, but they a
 lso introduce a new security challenge. Today's AI agents typically execut
 e directly on developer workstations or require developers to expose secre
 ts\, cloud credentials\, and production systems to hosted platforms. This 
 creates unnecessary trust assumptions and significantly expands the attack
  surface\, especially when AI-generated applications depend on hundreds of
  open-source packages that may themselves be compromised. The question org
 anizations should be asking is no longer *"Which AI model should we use?"*
  but rather *"Where should AI agents execute\, and what should they be all
 owed to access?"*\n\nThis session introduces a different architectural app
 roach using the open-source [**Agentry**](https://agentry.run/) platform. 
 Rather than sandboxing the AI agent itself\, Agentry allows any MCP-compat
 ible AI coding assistant—such as Claude Code\, Cursor\, Cline\, or OpenC
 ode—to remotely operate a secure development environment running on infr
 astructure you already control. Developers continue using their preferred 
 AI tools and can seamlessly switch between different models and coding ass
 istants throughout the development lifecycle without changing the executio
 n environment. Through architecture deep-dives and live demonstrations\, a
 ttendees will learn how remote sandboxing\, zero-trust connectivity\, isol
 ated execution\, and containerized deployments enable secure AI-assisted s
 oftware development without disrupting existing developer workflows.\n\n--
 -\n\n# Takeaways\n\n- **Understand a new security architecture for AI-assi
 sted development** where AI agents interact with remote sandboxed environm
 ents over MCP instead of executing directly on developer machines or hoste
 d cloud platforms.\n\n- **Learn how remote sandboxing preserves developer 
 productivity** by enabling teams to continue using their preferred AI codi
 ng assistants while securely building\, testing\, and deploying applicatio
 ns on infrastructure they already own.\n\n---\n\n# Who will benefit from t
 his session?\n\nThis session is ideal for:\n\n- Software Engineers and Ful
 l-Stack Developers using AI coding assistants\n- Platform Engineers and De
 vOps Engineers\n- Security Engineers and Application Security (AppSec) pro
 fessionals\n- Engineering Managers and Technical Architects evaluating ent
 erprise AI adoption\n- Open Source contributors and AI infrastructure enth
 usiasts\n\n---\n\n# About me\n[Gowtham Sadasivam](https://www.linkedin.com
 /in/gowthamsadasivam/) is a Senior Staff Engineer at [Acceldata](https://w
 ww.acceldata.io/) with 13+ years of experience designing and operating Lin
 ux\, Kubernetes\, and cloud-native application development. His current wo
 rk focuses on AI infrastructure\, Agentic AI\, self-hosted LLMs\, and secu
 re software engineering.\n\n---
GEO:12.9027111;77.6010828
LAST-MODIFIED:20260901T071619Z
LOCATION:Board Room - Blinkit\, 7th floor\, Vaishnavi BVS Senate\nBengalur
 u\,\nIN
ORGANIZER;CN=Rootconf:MAILTO:no-reply@hasgeek.com
URL:https://hasgeek.com/rootconf/platform-engineering-meet-up-september-5/
 schedule/beyond-ai-sandboxing-decoupling-ai-from-execution-Qi5Dgq5nSdM5Wk5
 38c4DGB
BEGIN:VALARM
ACTION:display
DESCRIPTION:Beyond AI sandboxing: decoupling AI from execution in Board Ro
 om in 5 minutes
TRIGGER:-PT5M
END:VALARM
END:VEVENT
BEGIN:VEVENT
SUMMARY:Birds of Feather (BOF) session: The new age of building on object 
 storage
DTSTART:20260905T101500Z
DTEND:20260905T110000Z
DTSTAMP:20260909T011940Z
UID:session/L7QVjTY5Cg8oSFYQpeE9ZH@hasgeek.com
SEQUENCE:4
CREATED:20260901T071534Z
DESCRIPTION:\nWhy are database and database-adjacent systems increasingly 
 being built directly on S3? A growing list of systems are betting on objec
 t storage as the primary layer\, not just cold storage.\n\nOpen discussion
 :\n* Why build on S3 in the first place — what does it actually buy you?
 \n* Why not — where does this break down?\n* What kinds of systems does 
 this pattern not make sense for?\n
GEO:12.9027111;77.6010828
LAST-MODIFIED:20260901T072053Z
LOCATION:Board Room - Blinkit\, 7th floor\, Vaishnavi BVS Senate\nBengalur
 u\,\nIN
ORGANIZER;CN=Rootconf:MAILTO:no-reply@hasgeek.com
BEGIN:VALARM
ACTION:display
DESCRIPTION:Birds of Feather (BOF) session: The new age of building on obj
 ect storage in Board Room in 5 minutes
TRIGGER:-PT5M
END:VALARM
END:VEVENT
BEGIN:VEVENT
SUMMARY:Observing and governing agents you did not build
DTSTART:20260905T110000Z
DTEND:20260905T113500Z
DTSTAMP:20260909T011940Z
UID:session/U5Jv5V3uH9Yy5yLsjq7378@hasgeek.com
SEQUENCE:4
CATEGORIES:Talk (30 mins),Bangalore meet-ups
CREATED:20260901T071542Z
DESCRIPTION:Uber burned its entire 2026 AI budget in four months\, and its
  COO said publicly that the link to customer value is not there yet. Repli
 t's agent deleted a production database during a code freeze that existed 
 only as English inside a prompt. The tools do work: Microsoft's study of i
 ts early 2026 command-line agent rollout measured about 24 percent more me
 rged pull requests for adopters\, and named token spend as the governing c
 onstraint. What is missing is a control plane\, not intelligence.\n\n  The
  claim that these agents emit nothing is wrong\, which makes it worse rath
 er than better. Claude Code's OpenTelemetry exporter redacts prompt\, resp
 onse and tool content by default. Cursor's export is Enterprise only and i
 ts own documentation says\, in those words\, that cost is not billing. Cop
 ilot's audit log excludes the prompts a user sends locally. Three agents\,
  three partial and incompatible feeds\, and still no answer to what the ag
 ent changed\, on whose instruction\, who approved it\, and what it cost.\n
 \n  Coding agents already write down what they did\, they just never expos
 e it. So ClawMetry reads those session files directly with no cooperation 
 from the vendor\, normalises every runtime onto one contract\, and lands i
 t in a local DuckDB file\, so cost per model\, per session and per tool is
  a SQL query you own rather than a dashboard someone rents you. A real ada
 pter is nine hundred lines when the parsing is fifty\, and the other eight
  hundred and fifty are what I will spend the middle of the talk on.\n\n  G
 overning needs less than people expect. An agent is a process on your mach
 ine\, so stopping one needs its process tree\, not a vendor integration. T
 he harder question is what to stop\, and risk turns out to be a property o
 f the call rather than the tool: definition-level classification cannot te
 ll `ls` from `rm -rf /` when both arrive through the same shell tool on ev
 ery harness. Normalise the tool vocabulary once and one rule covers every 
 runtime you monitor. The talk opens with an agent deleting a production da
 tabase and ends with that call being held live on stage\, then denied. All
  of it ships off by default\, which is the only honest setting for softwar
 e that can halt someone's work. MIT core.\n\n## Takeaways\n\n**1. Classify
  the call\, not the tool.** Nothing that grades tool names can tell `ls` f
 rom `rm -rf /`\, because both arrive through the same shell on every harne
 ss. Normalise the vocabulary once\, classify from the arguments\, and one 
 rule covers every runtime instead of one per vendor. Write the reasons as 
 plain sentences\, because a human reads them in an approval prompt at thre
 e in the morning.\n\n**2. A format you do not control changes without tell
 ing you.** Pin real captures as fixtures so a vendor's change fails your C
 I instead of silently zeroing someone's cost report. Then check on a sched
 ule: clone the source where the harness is open\, and where it is closed\,
  install their latest build every night\, drive one minimal turn\, and ass
 ert it still lands. Grade each runtime live-verified\, fixture-replayed or
  unverified\, and never let unverified render as green.\n\n## Who this is 
 for\n\n- Platform and developer-experience engineers rolling out coding ag
 ents across teams and CI\n- SREs and observability engineers who own the t
 elemetry pipeline and will be handed this problem next\n- Anyone who has t
 o read a data format they do not control and cannot ask the vendor to chan
 ge\n- Engineering managers and architects who have to produce a cost and a
 udit story for agent usage\n- Anyone building on OpenTelemetry who needs t
 o know what the GenAI conventions do not yet carry\n\n## About me\n\nI am 
 Vivek Chand\, AI Engineer at Booking.com\, creator and maintainer of [Claw
 Metry](https://github.com/vivekchand/clawmetry)\, an open-source observabi
 lity and governance layer for AI coding agents (MIT core). I spend my time
  at the unglamorous end of this problem: ingest adapters for agent runtime
 s that were never designed to be observed\, an embedded columnar store\, a
 nd an enforcement proxy. \n
GEO:12.9027111;77.6010828
LAST-MODIFIED:20260901T072140Z
LOCATION:Board Room - Blinkit\, 7th floor\, Vaishnavi BVS Senate\nBengalur
 u\,\nIN
ORGANIZER;CN=Rootconf:MAILTO:no-reply@hasgeek.com
URL:https://hasgeek.com/rootconf/platform-engineering-meet-up-september-5/
 schedule/observing-and-governing-agents-you-did-not-build-U5Jv5V3uH9Yy5yLs
 jq7378
BEGIN:VALARM
ACTION:display
DESCRIPTION:Observing and governing agents you did not build in Board Room
  in 5 minutes
TRIGGER:-PT5M
END:VALARM
END:VEVENT
BEGIN:VEVENT
SUMMARY:Feedback\, group photo
DTSTART:20260905T113500Z
DTEND:20260905T114500Z
DTSTAMP:20260909T011940Z
UID:session/BfpAn1WdXu4wP35bQ7K8b1@hasgeek.com
SEQUENCE:2
CREATED:20260901T072151Z
GEO:12.9027111;77.6010828
LAST-MODIFIED:20260901T072159Z
LOCATION:Board Room - Blinkit\, 7th floor\, Vaishnavi BVS Senate\nBengalur
 u\,\nIN
ORGANIZER;CN=Rootconf:MAILTO:no-reply@hasgeek.com
BEGIN:VALARM
ACTION:display
DESCRIPTION:Feedback\, group photo in Board Room in 5 minutes
TRIGGER:-PT5M
END:VALARM
END:VEVENT
BEGIN:VEVENT
SUMMARY:Networking and snacks
DTSTART:20260905T114500Z
DTEND:20260905T123000Z
DTSTAMP:20260909T011940Z
UID:session/LTN7YS7VHamzsEPNxkD6YL@hasgeek.com
SEQUENCE:1
CREATED:20260901T072207Z
GEO:12.9027111;77.6010828
LAST-MODIFIED:20260901T072212Z
LOCATION:Board Room - Blinkit\, 7th floor\, Vaishnavi BVS Senate\nBengalur
 u\,\nIN
ORGANIZER;CN=Rootconf:MAILTO:no-reply@hasgeek.com
BEGIN:VALARM
ACTION:display
DESCRIPTION:Networking and snacks in Board Room in 5 minutes
TRIGGER:-PT5M
END:VALARM
END:VEVENT
END:VCALENDAR
