TCP-Talks: Keep the Raccoons Out: Service Mesh, MCP, and Securing Agentic Workloads.

TCP-Talks: Keep the Raccoons Out: Service Mesh, MCP, and Securing Agentic Workloads.

Author: Justin Brodley, Jonathan Baker, Ryan Lucas and Matt Kohn | Cloud Computing & AI News May 5, 2026 Duration: 38:05

Keep the Raccoons Out: Service Mesh, MCP, and Securing Agentic Workloads

With William Morgan, CEO of Buoyant and creator of Linkerd

Linkerd just turned 10, so we brought on the person who built it and coined the term “service mesh” in the first place. William Morgan joins Jonathan and Justin to talk about where service mesh came from, where it’s going, and the very specific kind of chaos that agentic AI is about to unleash on anyone who owns a Kubernetes cluster. The short version: lock your doors, because the raccoons are coming.

“Our job is basically to make Linkerd as boring as possible.”

William traces Linkerd’s origins back to Twitter’s infrastructure work between 2010 and 2014, when a Ruby on Rails monolith turned into a sprawling distributed system — the same problems we have today, just a different decade. As the fifth project ever to join the CNCF, Linkerd has had a front-row seat to the ecosystem’s evolution, and William explains why his actual goal these days is to make it as boring as humanly possible: the kind of dependable infrastructure layer you can trust to still be around in another 90 years. That’s also why he’s not adding AI to Linkerd — an infrastructure layer has to be fast, lightweight, and predictable, and generative AI is the opposite of all three.

“At some point your agentic workload is going to figure out how to delete the production database. And it’s going to try it.”

The heart of the conversation is what the AI wave means for the platform teams who own the clusters. Developers just got an army of AI assistants, and that has real consequences for CI/CD, code quality, and blast radius. William digs into the boundary problem — agentic workloads are untrusted but need access to your most important systems — and why zero trust has suddenly stopped being optional now that the code hitting your database no longer clears peer review and a security committee. Along the way they get into cache-aware routing that can take a 13-second inference call down to one, the still-unsolved mess of agentic identity, and why we keep anthropomorphizing these tools and letting our guard down.

“If you don’t use Linkerd, your data system will be overrun by raccoons.”

Finally, they turn to MCP — building a catalog of MCP servers, detecting tool calls, and adding DLP-style protection in front of the services an agent never sees. But William’s real point is that MCP is something of a red herring for a much older problem: uncontrolled access to your APIs. Whatever protocol you use, once an unconstrained workload is loose in your environment, you need an immune system to keep it in check.

Links and resources:

  • Linkerd:

Every week, the team behind The Cloud Pod gathers to sift through the constant stream of announcements from AWS, Azure, and Google Cloud. Hosts Justin Brodley, Jonathan Baker, Ryan Lucas, and Matt Kohn bring their combined expertise to the table, translating complex platform updates and new service launches into practical insights. This isn't just a headline recap; it's a detailed analysis meant for engineers, architects, and tech leaders who need to understand the "why" and "how" behind the news. You'll hear them debate the real-world implications of the latest AI tooling, unpack FinOps strategies for managing costs, and track the evolving competitive landscape between the major providers. The conversation is grounded in years of hands-on experience, offering a perspective that goes beyond the press releases. Tuning into this weekly podcast provides a consistent, informed checkpoint for anyone whose work depends on the cloud. It’s a direct line to understanding the innovations and shifts that are actively reshaping how businesses build and scale technology, all from one of the most enduring voices in the space.
Author: Language: en-us Episodes: 50

The Cloud Pod | Weekly AI & Cloud News on AWS, Azure & GCP
Podcast Episodes
361: Beep Beep: AWS Ships an ACME Product That Actually Works [not-audio_url] [/not-audio_url]

Duration: 1:24:24
Welcome to episode 361 of The Cloud Pod, where the weather is always cloudy! It’s a full house tonight – Justin, Ryan, Jonathan (and eventually) Matt are all in the studio this week to bring you the latest in cloud and A…
360: And you thought AWS was out of features for S3. Surprise! [not-audio_url] [/not-audio_url]

Duration: 1:22:25
Welcome to episode 360 of The Cloud Pod, where the weather is always cloudy! Justin, Matt, and Jonathan (for a bit, anyway) are in the studio this week bringing you all the latest in cloud and AI news, including a bunch…
359: Tokenomicon Sounds Metal, but it’s Just Cloud Budgets [not-audio_url] [/not-audio_url]

Duration: 1:37:44
Welcome to episode 359 of The Cloud Pod, where the weather is always cloudy! Justin and Ryan are in the studio this week to bring you all the latest in cloud and AI news, including AI governance, FinOps’ final conference…
358: AI Spend Limits Because Frontier Models Aren’t Free Therapy [not-audio_url] [/not-audio_url]

Duration: 1:22:50
Welcome to episode 358 of The Cloud Pod, where the weather is always cloudy! Justin, Matt, and Ryan (who, rumour has it, was working on an Eagles music podcast) are in the studio this week to bring you all the latest in…
357: Cache Me If You Can – Now With Durability [not-audio_url] [/not-audio_url]

Duration: 1:00:32
Welcome to episode 357 of The Cloud Pod, where the weather is always cloudy! Justin and Matt are in the studio this week to bring you all the latest in cloud and AI news! Is AI costing more than the people it replaced? A…
356: Holy Labor Displacement, Batman! The Vatican Weighs In [not-audio_url] [/not-audio_url]

Duration: 47:27
Welcome to episode 356 of The Cloud Pod, where the weather is always cloudy! Justin and Ryan are in the studio this week and ready to bring you all the latest in cloud and AI news, including the Pope coming out against A…
354: US-Tirefire-1 lives up to its Stellar Reputation [not-audio_url] [/not-audio_url]

Duration: 1:30:35
Welcome to episode 354 of The Cloud Pod, where the weather is always cloudy! This week was sort of a tire fire for the cloud, with US-East-1 losing power, TanStack Supply chain being hit with an impressively creative att…
353: Don’t Be Evil Unless the Government Asks Nicely [not-audio_url] [/not-audio_url]

Duration: 1:40:02
Welcome to episode 353 of The Cloud Pod, where the weather is always cloudy! Justin, Ryan, and Matt are in the studio this week and ready to bring you all the latest news, including earnings from the big 3, a new agreeme…
352: Google Next: Rebrandapalooza [not-audio_url] [/not-audio_url]

Duration: 1:45:30
Welcome to episode 352 of The Cloud Pod, where the weather is always cloudy! Justin, Matt, and Ryan are safely back from Vegas (Ryan and Justin, anyway), and they have all the news and announcements from Google Next. Plu…