Build a Platform and Watch It Burn — Michael Forrester, Accenture & Whitney Lee, Datadog

Michael Forrester and Whitney Lee demonstrate an interactive Internal Developer Platform called Burrito Bot that intentionally exposes Kubernetes cluster vulnerabilities to highlight real-world security risks and the importance of layered defenses, including network policies, runtime security tools, and AI-specific safeguards like input sanitization and prompt injection prevention. They emphasize combining robust infrastructure, traditional SDLC practices, and careful AI integration to build secure, reliable developer platforms, with the Burrito Bot repository soon to be publicly available for further learning and development.

In this workshop-style presentation, Michael Forrester from Accenture and Whitney Lee from Datadog introduce an interactive demonstration involving the launch of an Internal Developer Platform (IDP) called Burrito Bot. The bot is designed to simulate real-world challenges by intentionally exposing vulnerabilities within a Kubernetes cluster, allowing participants to attempt various hacks and observe the consequences. The presenters emphasize that while the bot’s antics may seem humorous, such vulnerabilities can lead to serious reputational, financial, and data losses in real systems. Attendees are encouraged to engage with the bot by ordering burritos, querying its capabilities, and trying to exploit it in controlled ways.

The demonstration is structured around a series of escalating challenges where participants try to push data outside the cluster, deploy unauthorized images, and access sensitive files like a secret recipe. Early attempts to exfiltrate data were thwarted by built-in model-level defenses, highlighting that some protections are embedded within the AI itself. However, other attacks, such as deploying public container images or reading confidential files, initially succeeded, illustrating the risks of insufficient security controls. The presenters also discuss how naming conventions and prompt engineering can influence the AI’s behavior, with negative or villainous names triggering refusal responses from the model.

To counter these vulnerabilities, the presenters introduce a second Kubernetes cluster fortified with multiple layers of security, including Kubernetes network policies, Kyverno admission controllers, and runtime security tools like Falco, KubeArmor, and Tetragon. These tools enforce strict policies on network traffic, image sources, and runtime behavior, effectively blocking many of the previously successful attacks. The importance of traditional software development lifecycle (SDLC) practices, CI/CD pipelines, and access control is underscored as foundational to securing AI-driven platforms. The presenters caution against over-privileging AI agents and stress that many security issues stem from human and process errors rather than AI itself.

The final phase of the workshop focuses on AI-specific safeguards such as input and output sanitization, prompt injection prevention, and multi-component prompt (MCP) verification. Using tools like LLM Guard, the system filters and monitors AI inputs and outputs to prevent leakage of sensitive information and unauthorized actions. The presenters demonstrate how these safeguards can block malicious queries before they reach the AI model, reducing operational costs and enhancing security. They also highlight the probabilistic nature of large language models, warning that reliance solely on AI compliance is risky and that layered defenses remain essential.

Concluding the session, Michael and Whitney share insights on when and how to integrate AI into workflows, emphasizing the need for bounded systems with verifiable outputs and clear value propositions. They announce that the entire Burrito Bot repository, including the platform and security mechanisms, will soon be publicly available for others to study and build upon. The presenters encourage attendees to apply these lessons thoughtfully, combining AI capabilities with robust infrastructure and process controls to create secure, reliable developer platforms. Despite some live demonstration challenges, the overall message stresses the critical balance between innovation and security in AI-enabled environments.

Useful Links