# Nirmata

Unified Governance for Agentic Era

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Beyond the Merge: Enforcing Policy Before the Terraform Apply

DevFeed: [Beyond the Merge: Enforcing Policy Before the Terraform Apply](<https://devfeed.tech/articles/beyond-the-merge-enforcing-policy-before-the-terraform-apply-17660.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/09/03/beyond-the-merge-enforcing-policy-before-the-terraform-apply/>)

Author: Sachin Agarwal

Published: 2026-09-03T17:25:32Z

Content type: article

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [iac-security](<https://devfeed.tech/topics/iac-security.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [ci](<https://devfeed.tech/tags/ci.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [other](<https://devfeed.tech/tags/other.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

The article describes using Nirmata Control and its nctl CLI to evaluate Terraform plans against policy-as-code rules before deployment. It presents pre-apply CI checks for detecting infrastructure misconfigurations, including unrestricted ingress, missing S3 public-access blocking, wildcard IAM resources, and missing VPC deployment.

### Source excerpt

Run Terraform security scanning on the plan, not the live account. nctl checks 4 critical misconfigs in CI, with exceptions scoped to one resource.

## Introducing OttoFlow: AI Workflows for Kubernetes

DevFeed: [Introducing OttoFlow: AI Workflows for Kubernetes](<https://devfeed.tech/articles/introducing-ottoflow-ai-workflows-for-kubernetes-17659.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/26/introducing-ottoflow-ai-workflows-for-kubernetes/>)

Author: Shreyas Mocherla

Published: 2026-08-26T18:34:15Z

Content type: release

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [declarative](<https://devfeed.tech/tags/declarative.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [llm](<https://devfeed.tech/tags/llm.md>), [nothing](<https://devfeed.tech/tags/nothing.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [product](<https://devfeed.tech/tags/product.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Nirmata introduces OttoFlow, an open-source system for building AI workflows on Kubernetes. It represents workflows as custom resources with typed DAG steps and limits AI to selected parts of the operations process, aiming to combine deterministic, reviewable automation with model-based reasoning.

### Source excerpt

AI workflows for Kubernetes, without handing an agent your kubeconfig. OttoFlow makes a workflow a custom resource: typed DAG steps, AI only where it counts.

## Closing the Governance Gap in Nutanix Kubernetes Platform Environments

DevFeed: [Closing the Governance Gap in Nutanix Kubernetes Platform Environments](<https://devfeed.tech/articles/closing-the-governance-gap-in-nutanix-kubernetes-platform-environments-17658.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/24/kyverno-on-nutanix-closing-the-governance-gap-in-nutanix-kubernetes-platform-environments/>)

Author: Sachin Agarwal

Published: 2026-08-24T18:04:51Z

Content type: article

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [nutanix](<https://devfeed.tech/topics/nutanix.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>)

Tags: [build](<https://devfeed.tech/tags/build.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [governance](<https://devfeed.tech/tags/governance.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [nutanix](<https://devfeed.tech/tags/nutanix.md>), [other](<https://devfeed.tech/tags/other.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [upgrades](<https://devfeed.tech/tags/upgrades.md>)

### AI overview

Nirmata Enterprise for Kyverno is certified to run on Nutanix Kubernetes Platform through the Nutanix Cloud Platform. The article explains how installing it from the NKP Partner Catalog integrates policy governance, enforcement, and upgrades into the platform without a separate pipeline.

### Source excerpt

Kyverno on Nutanix Kubernetes Platform is now certified. Install Nirmata Enterprise for Kyverno from the NKP Partner Catalog, no separate pipeline.

## Okta Cross App Access (XAA / ID-JAG) in Nirmata AIControls: standards-based authorization for AI agents

DevFeed: [Okta Cross App Access (XAA / ID-JAG) in Nirmata AIControls: standards-based authorization for AI agents](<https://devfeed.tech/articles/okta-cross-app-access-xaa-id-jag-in-nirmata-aicontrols-standards-based-authorization-for-ai-agents-17657.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/18/okta-cross-app-access-xaa-id-jag/>)

Author: Ritesh Patel

Published: 2026-08-19T00:24:40Z

Content type: article

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [cross-app-access](<https://devfeed.tech/topics/cross-app-access.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [cross-app-access](<https://devfeed.tech/tags/cross-app-access.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [llm](<https://devfeed.tech/tags/llm.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [okta](<https://devfeed.tech/tags/okta.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

The article explains how Nirmata AIControls supports Okta Cross App Access and the ID-JAG authorization profile for AI agents. It describes token exchanges performed on behalf of agents, administrator-controlled app-to-app access, policy checks, budgets, and audit records for delegated MCP and LLM calls.

### Source excerpt

AIControls now performs the ID-JAG token exchanges on your agents' behalf -- so agents need no protocol code -- and policy-checks, budgets, and attributes every delegated MCP and LLM call to the human it acts for. ID-JAG answers may this agent act for this user? AIControls answers what... The post Okta Cross App Access (XAA / ID-JAG) in Nirmata AIControls: standards-based authorization for AI agents first appeared on Nirmata.

## Introducing Nirmata Runtime for Kyverno: Kernel-Level Enforcement for AI Workloads

DevFeed: [Introducing Nirmata Runtime for Kyverno: Kernel-Level Enforcement for AI Workloads](<https://devfeed.tech/articles/introducing-nirmata-runtime-for-kyverno-kernel-level-enforcement-for-ai-workloads-17656.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/16/introducing-nirmata-runtime-for-kyverno-kernel-level-enforcement-for-ai-workloads/>)

Author: Jim Bugwadia

Published: 2026-08-17T01:27:43Z

Content type: release

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [Security](<https://devfeed.tech/topics/security.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [policy](<https://devfeed.tech/tags/policy.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Nirmata introduces Nirmata Runtime for Kyverno, which extends workload controls beyond admission-time configuration checks by enforcing selected runtime behaviors in the kernel. The article describes BPF-LSM and cgroup-scoped eBPF enforcement for process execution, file access, network egress, and application protocols, plus DNS observation and reporting.

### Source excerpt

Nirmata created Kyverno and donated it to the CNCF in 2020. Kyverno is now a graduated CNCF project and is widely used for enforcing and automating configuration security and best practices. However, admission control answers one question: does this spec look right? It cannot... The post Introducing Nirmata Runtime for Kyverno: Kernel-Level Enforcement for AI Workloads first appeared on Nirmata.

## Introducing the Remediator Agent: Turning Kyverno Policy Violations into Pull Requests, Automatically.

DevFeed: [Introducing the Remediator Agent: Turning Kyverno Policy Violations into Pull Requests, Automatically.](<https://devfeed.tech/articles/introducing-the-remediator-agent-turning-kyverno-policy-violations-into-pull-requests-automatically-17655.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/14/introducing-the-remediator-agent-turning-kyverno-policy-violations-into-pull-requests-automatically/>)

Author: Akhil Chandran

Published: 2026-08-14T11:29:37Z

Content type: article

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [argocd](<https://devfeed.tech/topics/argocd.md>), [flux](<https://devfeed.tech/topics/flux.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [argocd](<https://devfeed.tech/tags/argocd.md>), [flux](<https://devfeed.tech/tags/flux.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [other](<https://devfeed.tech/tags/other.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>)

### AI overview

Nirmata's Remediator Agent is designed to automate remediation of Kyverno policy violations within an existing GitOps workflow. It traces violations to their Git sources, proposes deterministic or LLM-generated fixes, commits changes, opens pull requests for review, and relies on ArgoCD or Flux CD to sync approved changes back to Kubernetes.

### Source excerpt

Kyverno detects Kubernetes policy violations. Nirmata's Remediator Agent turns them into reviewed pull requests within your existing GitOps workflow.

## Nirmata's Cloud Agents Audited a 40-Cluster Kubernetes Fleet, and recovered 40% of the Cost

DevFeed: [Nirmata's Cloud Agents Audited a 40-Cluster Kubernetes Fleet, and recovered 40% of the Cost](<https://devfeed.tech/articles/nirmata-s-cloud-agents-audited-a-40-cluster-kubernetes-fleet-and-recovered-40-of-the-cost-17654.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/12/how-nirmata-saved-40-in-kuberbnetes-cloud-cost/>)

Author: Anubhav Sharma

Published: 2026-08-12T20:52:35Z

Content type: article

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [clusters](<https://devfeed.tech/tags/clusters.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [compute](<https://devfeed.tech/tags/compute.md>), [cost-savings](<https://devfeed.tech/tags/cost-savings.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [policy-management](<https://devfeed.tech/tags/policy-management.md>), [resource](<https://devfeed.tech/tags/resource.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

Nirmata describes applying its Cost Analyzer and Resource Hygiene Cloud Agents across an enterprise customer's 40-cluster production Kubernetes fleet. The scans identified a roughly $107,000 monthly compute baseline and about 50% recoverable through right-sizing before stale-resource cleanup, while revealing recurring sources of waste and governance gaps.

### Source excerpt

Nirmata's Cloud Agents Audited a 40-Cluster Kubernetes Fleet, and recovered 40% of the Cost Most Kubernetes Cost overruns don't come from one singularly bad decision. They come from dozens of reasonable ones -- made independently, by different teams, at different times -- that... The post Nirmata's Cloud Agents Audited a 40-Cluster Kubernetes Fleet, and recovered 40% of the Cost first appeared on Nirmata.

## AI governance gaps leave developer and agent access to AI tools insufficiently controlled

DevFeed: [AI governance gaps leave developer and agent access to AI tools insufficiently controlled](<https://devfeed.tech/articles/the-ai-innovation-security-paradox-17653.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/04/ai-innovation-security-paradox/>)

Author: Anubhav Sharma

Published: 2026-08-05T01:56:41Z

Content type: opinion

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [ai-governance](<https://devfeed.tech/topics/ai-governance.md>), [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [developer-productivity](<https://devfeed.tech/topics/developer-productivity.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [llms](<https://devfeed.tech/tags/llms.md>), [policy-management](<https://devfeed.tech/tags/policy-management.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

The article presents aggregated responses from security leaders about AI governance in fast-moving engineering organizations. It identifies gaps in centralized access control, policy enforcement, session auditing, real-time visibility, and protection against exposing permissions or environment variables to LLMs.

### Source excerpt

Three Questions We Asked About AI Governance -- And What the Answers Reveal Over the past few months, we've been having the same conversation on repeat with security leaders about AI at fast-moving engineering organizations. Different companies, different tech stacks, same three questions -- and,... The post The AI Innovation-Security Paradox first appeared on Nirmata.

## The AI Gateway Buyer's Guide: Beyond Routing and Tool Visibility

DevFeed: [The AI Gateway Buyer's Guide: Beyond Routing and Tool Visibility](<https://devfeed.tech/articles/the-ai-gateway-buyer-s-guide-beyond-routing-and-tool-visibility-17652.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/02/the-ai-gateway-buyers-guide/>)

Author: Ritesh Patel

Published: 2026-08-02T16:58:40Z

Content type: opinion

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Model Routing](<https://devfeed.tech/topics/model-routing.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-gateway](<https://devfeed.tech/tags/ai-gateway.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cost-optimization](<https://devfeed.tech/tags/cost-optimization.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [latency](<https://devfeed.tech/tags/latency.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [routing](<https://devfeed.tech/tags/routing.md>)

### AI overview

This opinion article argues that AI gateways should not be treated as governance systems merely because they provide model routing and tool-call visibility. Routing can optimize cost and latency, while monitoring can show which tools or MCP servers were used, but governance requires deciding whether an agent action is permitted for a specific agent, with specific arguments, at a specific time.

### Source excerpt

Over the past year, nearly every engineering org I talk to has reached the same milestone: AI agents are no longer a demo. They're calling real tools, against real systems, with real consequences. And nearly every one of those orgs has reached for the same... The post The AI Gateway Buyer's Guide: Beyond Routing and Tool Visibility first appeared on Nirmata.

## Critical Kyverno Vulnerability -- CVE-2026-54523

DevFeed: [Critical Kyverno Vulnerability -- CVE-2026-54523](<https://devfeed.tech/articles/critical-kyverno-vulnerability-cve-2026-54523-17651.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/07/28/critical-kyverno-vulnerability-cve-2026-54523/>)

Author: Anubhav Sharma

Published: 2026-07-29T01:08:41Z

Content type: news

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [admission-controller](<https://devfeed.tech/tags/admission-controller.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-ecosystem](<https://devfeed.tech/tags/cloud-native-ecosystem.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [cve](<https://devfeed.tech/tags/cve.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [nctl-ai](<https://devfeed.tech/tags/nctl-ai.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [policy-management](<https://devfeed.tech/tags/policy-management.md>), [release](<https://devfeed.tech/tags/release.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article reports CVE-2026-54523, a critical Kyverno vulnerability affecting versions 1.18.0 and 1.18.1. A tenant able to create a NamespacedMutatingPolicy could bypass namespace isolation and generate resources in other namespaces, potentially enabling cluster-wide privilege escalation. Kyverno 1.18.2 patches the vulnerability.

### Source excerpt

Critical Kyverno Vulnerability -- CVE-2026-54523 On July 13, 2026, a critical vulnerability was disclosed in Kyverno, the Kubernetes-native policy engine used broadly across the cloud native ecosystem for policy-as-code enforcement. The vulnerability, tracked as CVE-2026-54523 (GHSA-79gf-7frw-68m9), allows a tenant with permission to create a NamespacedMutatingPolicy... The post Critical Kyverno Vulnerability -- CVE-2026-54523 first appeared on Nirmata.