Skip to content
Binary file not shown.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added assets/sponsors/b/bsides-philadelphia.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
8 changes: 8 additions & 0 deletions content/events/2026-philadelphia/program/anish-puthuraya.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,11 @@ Title = "We Gave the Agent Production Credentials"
Type = "talk"
Speakers = ["anish-puthuraya"]
+++

Every talk about a risky agent ends the same way. Put it in a container. Give it a scratch branch. Let it break things where breaking things is free.

That answer was not on offer to us. Our agent works on the live data platform behind more than 150 hotels, the one operators open every morning to read their numbers. It can query the warehouse, write a notebook, run a pipeline, open a ticket, and change a production table. We gave it all of that, then spent longer on the brakes than on the capability.

The brakes had to be permissions and process, because walls were never available.

Nothing authenticates with a password. Four access modes exist and none of them share code, because one validator with a mode flag is exactly how a read-only path quietly acquires write access. Every write dry runs inside a transaction and rolls back until a human types confirm. The apply script is deliberately kept off the tool allow list, so the permission prompt fires every single time. It is annoying on purpose.
15 changes: 15 additions & 0 deletions content/events/2026-philadelphia/program/blair-salmon.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
+++
Talk_date = ""
Talk_start_time = ""
Talk_end_time = ""
Title = "Your Post-Mortems Called…. They'd Like a Word With Your Agent."
Type = "talk"
Speakers = ["blair-salmon"]
+++

We are in uncharted territory right now. Agentic development is hurtling at us like the next comet and the pressures of adopting AI are real. Getting it wrong leads to even more work to clean up through code mounting code reviews, AI slop and rework. It’s not a bad day in the office, it’s a bad year.

This talk will dive into detail of two key things to help prevent this. Incident Economics and Post Mortems to understand the types of metrics, signals and data you need to understand about how building in your organization isn’t working.

Taking the next step, then we look at Harness Engineering and the tools/frameworks and ideas that need to surround your AI agents, with this context, to make it work the right way.
Putting these ideas together should help your AI building experience move more towards a nice peaceful vacation, than a chaotic spring break.
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,8 @@ Talk_end_time = ""
Title = "Free Software Isn't Gratis: why companies should treat Open Source as part of their Infrastructure"
Type = "talk"
Speakers = ["christopher-tineo"]
+++
+++

Maintaining an open source project is hard. It requires managing a group of people who are largely working for free to build something that other people profit from, usually distributed across the globe, with limited resources.

The whole time you’re doing this, you’re receiving demands from users and businesses alike for features or bug fixes on a timeline that works for them, not you and your (possibly very limited) group of contributors that you can’t exactly order around, since they aren’t being paid. It’s stressful, and it can be overwhelming. When one of these projects is the victim of an attack that takes advantage of the fact that there are only one or two maintainers, or eventually has to shut down due to rising technical debt and falling contributor numbers, the public blame falls on us, not on the businesses that didn’t offer contributors in time.
2 changes: 2 additions & 0 deletions content/events/2026-philadelphia/program/erica-windisch.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,5 @@ Title = "Workshop: Securely Deploying AI Infrastructure"
Type = "talk"
Speakers = ["erica-windisch"]
+++

The deployment of agentic systems, and their use in development, has brought a radical shift to our industry. These systems are not simply new applications to deploy into existing fleets, but bring fresh operational challenges. We will explore what these systems are, how agentic systems work, how they are changing DevOps, and the new security challenges posed by these systems.
11 changes: 11 additions & 0 deletions content/events/2026-philadelphia/program/imran-haider.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
+++
Talk_date = ""
Talk_start_time = ""
Talk_end_time = ""
Title = "How we slashed costs & emissions 85% for 1 of the UK's biggest charities"
Type = "talk"
Speakers = ["imran-haider"]
+++

We helped one of the UK’s largest charities, Prostate Cancer UK, rebuild their website to align with their sustainability, performance, & cost-efficiency goals.
By moving to SCALE-TO-ZERO Container Apps (which turn off when not in use) we delivered an average of 85% reduction in carbon emissions & hosting costs. The app is now cheaper, greener & future-ready, all without sacrificing developer experience. This is a practical, behind-the-scenes look at the technical decisions & real-world results that came from applying a modern, sustainability driven approach to a high-profile non-profit site.
8 changes: 0 additions & 8 deletions content/events/2026-philadelphia/program/imran-halder.md

This file was deleted.

16 changes: 16 additions & 0 deletions content/events/2026-philadelphia/program/justin-oleary.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
+++
Talk_date = ""
Talk_start_time = ""
Talk_end_time = ""
Title = "The Operator Calls Are Coming From Inside the Namespace"
Type = "talk"
Speakers = ["justin-oleary"]
+++

Kubernetes operators are supposed to make life easier. Give them cloud credentials, point them at your provider, and they'll provision infrastructure for you. Config Connector, ACK, ASO, Crossplane — they all work the same way.

They also all have the same problem.

I spent six months hunting bugs in these operators. Most of them trust user-supplied references without checking if the user should actually have access to what they're referencing. Create a custom resource pointing at someone else's cloud resources, and the operator will happily modify them using its own credentials. Your RBAC says you can only touch your namespace. The operator's service account can touch everything.

This talk covers what I found, how the attacks work, and what to check before you deploy operators in production. No slides full of vendor logos — just patterns I saw across four projects and the guardrails that would've stopped them.
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,6 @@ Talk_end_time = ""
Title = "Engineering Serendipity: Building AI Systems That Don't Converge to Average"
Type = "talk"
Speakers = ["kateri-waltermeyer"]
+++
+++

Modern AI models are optimized to predict the most likely answer—which is exactly why they often produce surprisingly average work. This talk explores how to build AI systems that deliberately resist that tendency. Rather than relying on a single frontier model, we'll treat creativity as a distributed systems problem: assigning specialized cognitive roles to different models, introducing controlled randomness, building feedback loops, and using critique and iteration to evolve ideas instead of accepting the first plausible response. Through a real-world autonomous content pipeline, we'll explore how concepts from DevOps—modularity, orchestration, observability, and resilience—apply just as naturally to creative AI workflows. The result isn't just better content; it's a framework for building AI systems that consistently generate ideas you wouldn't have thought of yourself.
8 changes: 0 additions & 8 deletions content/events/2026-philadelphia/program/mehul-vani.md

This file was deleted.

8 changes: 8 additions & 0 deletions content/events/2026-philadelphia/program/mike-elkins.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
+++
Talk_date = ""
Talk_start_time = ""
Talk_end_time = ""
Title = "The Future of DevOps: From Automation to Trustworthy Autonomy Session"
Type = "talk"
Speakers = ["mike-elkins"]
+++
10 changes: 9 additions & 1 deletion content/events/2026-philadelphia/program/pravalik-medi.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,12 @@ Talk_end_time = ""
Title = "We Cut Our AWS SQL Server Bill by a Third. Here's What Actually Moved the Number"
Type = "talk"
Speakers = ["pravalik-medi"]
+++
+++

We run SQL Server across RDS and EC2, and the bill was growing faster than the workload was. We took about a third off it. Nothing got rewritten, and no application team had to change how they worked.

This is a walkthrough of where the money actually was, ranked by what each change returned. Some of it was obvious in hindsight. One of the larger items we found by accident while looking for something else.

I'll also cover what looked like savings in a spreadsheet and wasn't, including the changes we tried and rolled back. And how we decided what was safe to shrink on a production database, where the cost of guessing wrong is an outage during dinner rush.

You should leave with a way to rank cost levers against risk on your own estate, instead of working down whatever list the cost console puts in front of you.
8 changes: 8 additions & 0 deletions content/events/2026-philadelphia/program/precious-daka.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
+++
Talk_date = ""
Talk_start_time = ""
Talk_end_time = ""
Title = ""

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This talk doesn't have a title. Not a blocker—just raising it. :)

Type = "talk"
Speakers = ["precious-daka"]
+++
8 changes: 8 additions & 0 deletions content/events/2026-philadelphia/program/rahul-sharma.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,11 @@ Title = "Shipping the Agent Was Easy. Keeping It Honest Wasn't."
Type = "talk"
Speakers = ["rahul-sharma"]
+++

We shipped an AI DevOps agent to diagnose infrastructure alerts in weeks. Making its output trustworthy has taken months — and we're still not done.

The agent works. It also confidently told us our database was routing queries incorrectly — a claim we repeated to our vendor and burned a multi-hour escalation on before discovering it was completely fabricated. That same agent, facing a mystery memory spike it couldn't explain, did something different: it said ""I don't know, but this looks like GC."" That honest uncertainty pushed us to build observability we didn't had.

Same agent. Same model. Opposite outcomes. The difference wasn't the AI — it was whether we understood what the agent needed to reason correctly before we acted on what it said. Factual claims now pass through a second, smaller agent that cross-checks documentation before reaching our on-call engineer. Causal hypotheses require a corroborating metric before anyone acts.

Hot take: treat every agent claim as a hypothesis, never a finding.
8 changes: 0 additions & 8 deletions content/events/2026-philadelphia/program/ranjita-shetty.md

This file was deleted.

11 changes: 10 additions & 1 deletion content/events/2026-philadelphia/program/scott-howard.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,13 @@ Talk_end_time = ""
Title = "So Your Coding Is Fast, But Can the Business Keep Up?"
Type = "talk"
Speakers = ["scott-howard"]
+++
+++

AI coding assistants have made writing code faster than almost anyone predicted. But speeding up one stage of a long chain doesn't speed up the chain. It just reveals where the chain was weak all along.

This talk walks through the full business lifecycle that a piece of software actually travels through. Not just code, build, and deploy, but exploring, validating, defining, developing, verifying, deploying, measuring, and learning. At every one of these stages, we'll ask a simple question: has AI actually touched this, or are we just moving faster
into the same old queue?

We'll dig into two places the bottleneck is quietly piling up right now: at the front of the lifecycle in exploring and defining, where turning a vague idea into something a fast team can act on is now the slow part; and in the middle in verifying and deploying, where review, validation, and approval processes built for a slower era can't keep pace with 10x the output.

DevOps has always been about optimizing flow across the whole value stream, not just the flashiest stage. AI is just the first thing to make that imbalance impossible to ignore. Attendees will leave with a new way to think about their own product's lifecycle stage by stage, see where AI has genuinely changed the work versus where it has just added speed to an old queue, and find their next real bottleneck - because it might not be where they think.
22 changes: 22 additions & 0 deletions content/events/2026-philadelphia/program/swetha-rajshree.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,25 @@ Title = "The Deployment Worked. The Release Failed."
Type = "talk"
Speakers = ["swetha-rajshree"]
+++

The pipeline says SUCCESS.

Kubernetes says the pods are healthy.

The deployment dashboard is green.

There's just one problem: customers can't use the feature.

We often treat deployment and release as the same event. They aren't.

In this five-minute Ignite, we'll follow a feature from commit to production and discover why technically successful deployments can still become unsuccessful releases.

Across 20 rapid-fire slides, we'll explore the small engineering practices that separate the two: feature flags, progressive delivery, canary releases, observability, customer-impact metrics, automated rollback, and separating code deployment from feature activation.

The goal isn't another complicated deployment architecture. It's a change in how we think about shipping software.

Deployment asks: "Did the code reach production?"

Release asks: "Did it actually work for our users?"

Those are very different questions—and successful DevOps teams need to answer both.
4 changes: 4 additions & 0 deletions content/events/2026-philadelphia/program/tim-gross.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,7 @@ Title = "Clinical methods in debugging"
Type = "talk"
Speakers = ["tim-gross"]
+++

Our industry has built a culture around incident management, around blameless post-mortems, around observability, around psychological safety. But at the end of the day when production is down, no one in management wants to hear "there's no such thing root cause". We're tasked to solve a problem, and often in a context where there's a gap between our aspirations and the gritty reality of monitoring vendor costs cutting short retention times.

This talk will provide methods for building an accurate model of the problem quickly, and navigate the challenge of leaning on our instincts and expertise without leading ourselves astray with bias. This method forms a clinical loop: starting with symptoms, building hypotheses, and making new observations to prove or disprove those hypotheses. And yes, we'll cover how LLMs play into this model for better and worse.
8 changes: 8 additions & 0 deletions content/events/2026-philadelphia/program/tyler-auerbeck.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,3 +6,11 @@ Title = "Let Me Show You How The World Ends: Using Domain Storytelling to Surviv
Type = "talk"
Speakers = ["tyler-auerbeck"]
+++

If your infrastructure disappeared tomorrow, would you understand how to rebuild it? Not just what needed to be restored or what configuration might need to be reapplied, but what depends on what, which teams need to be engaged, and that one command, run by that one person, that one time, that somehow became the thing standing between you and recovery.

The truth is, creating infrastructure is often the easy part—especially today, when an answer is only a prompt away. The hard part is understanding the story behind it: why things exist, when they need to happen, and how the pieces depend on one another. That story is unique to every environment, and too often only exists in the memories of the people who built it.

By utilizing Domain Storytelling, we can preemptively survive our infrastructure doomsday scenario. Through a collaborative visual exercise, we can identify actors, systems, decisions, and dependencies so that the entire organization can understand how an environment would need to be rebuilt. We’ll also explore how these stories can reveal a team’s gaps in understanding, uncover issues with circular dependencies, and use these conversations to drive changes in the in the architecture and operational practices themselves. Most importantly, these stories become living artifacts that evolve alongside our infrastructure, ensuring that our understanding grows as our environments change.

Because when doomsday arrives, the difference between recovery and rebuilding from scratch is not whether you have a backup. It’s whether your organization knows the story that got you there.
8 changes: 0 additions & 8 deletions content/events/2026-philadelphia/program/yossi-eliaz-2.md

This file was deleted.

8 changes: 0 additions & 8 deletions content/events/2026-philadelphia/program/yossi-eliaz.md

This file was deleted.

11 changes: 0 additions & 11 deletions content/events/2026-philadelphia/registration.md

This file was deleted.

Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
+++
Title = "Ashley Gross"
Title = "Blair Salmon"
Twitter = ""
linkedin = "https://www.linkedin.com/in/theashleygross/"
image = "ashley-gross.png"
linkedin = ""
image = "blair-salmon.png"
type = "speaker"
linktitle = ""

Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
+++
Title = "Mehul Vani"
Title = "Irman Haider"
Twitter = ""
linkedin = ""
image = ""
Expand Down
11 changes: 11 additions & 0 deletions content/events/2026-philadelphia/speakers/justin-oleary.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
+++
Title = "Justin O'leary"
Twitter = ""
linkedin = ""
image = "justin-oleary.jpg"
type = "speaker"
linktitle = ""

+++

Justin O'Leary is a security researcher focused on cloud-native infrastructure vulnerabilities. His work on confused deputy flaws in Kubernetes operators has uncovered privilege escalation paths in Config Connector, AWS Controllers for Kubernetes, Azure Service Operator, and Crossplane. He presented this research at Black Hat USA 2026 and will be speaking at KubeCon NA 2026. By day, he serves as Principal Bioinformatics Engineer at Children's Hospital of Philadelphia.
15 changes: 15 additions & 0 deletions content/events/2026-philadelphia/speakers/mike-elkins.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
+++
Title = "Mike Elkins"
Twitter = ""
linkedin = "https://www.linkedin.com/in/elkinsmike"
image = "mike-elkins.png"
type = "speaker"
linktitle = ""

+++

Michael Elkins is a Sr. Client Solutions Engineer at AHEAD with nearly 30 years of experience working at the intersection of technology, cybersecurity, risk, and resilience. Throughout his career, Michael has helped organizations navigate large-scale transformation—from enterprise architecture and infrastructure modernization to cloud, cybersecurity, AI, and emerging technology risk.

His work has taken him inside some of the most complex and highly regulated environments, where technology decisions have real operational and human consequences. He has advised executives and boards, contributed to cybersecurity frameworks and strategies, and helped organizations rethink how they design systems to withstand disruption.

Michael brings a human-centered perspective to technology, exploring not just how we build and secure systems, but how people, complexity, and technology interact. His talks challenge technology leaders to think beyond tools and architecture—and consider how we build systems, organizations, and teams that become more resilient as the world around them becomes more complex.
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
+++
Title = "Irman Haldeer"
Title = "Precious Daka"
Twitter = ""
linkedin = ""
image = ""
Expand Down
9 changes: 0 additions & 9 deletions content/events/2026-philadelphia/speakers/ranjita-shetty.md

This file was deleted.

4 changes: 3 additions & 1 deletion content/events/2026-philadelphia/speakers/scott-howard.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,4 +6,6 @@ image = ""
type = "speaker"
linktitle = ""

+++
+++

Scott is a Lead Delivery Consultant with Liatrio, focusing on expediting world-class software delivery for enterprises by building advanced platforms powered by AI and open source, while coaching engineering and business teams along the way. With over a decade of experience in tech, Scott has worked as a consultant across a range of industries including Education, FinTech, Retail, Aviation, Life Sciences, and Healthcare, helping organizations modernize their software delivery practices. Prior to consulting, he designed developed applications for Naval and Army automated vehicle defense systems in the defense industry. Scott holds a BS and MS in Computer Science from Rowan University, and when he's not building pipelines, he can be found reading Stephen King, playing guitar, or kayaking the rivers of southern New Jersey where he resides with his wife, dog, and three cats.
Loading
Loading