TCP-Talks: Keep the Raccoons Out: Service Mesh, MCP, and Securing Agentic Workloads.

TCP-Talks: Keep the Raccoons Out: Service Mesh, MCP, and Securing Agentic Workloads.

Author: Justin Brodley, Jonathan Baker, Ryan Lucas and Matt Kohn | Cloud Computing & AI News May 5, 2026 Duration: 38:05

Keep the Raccoons Out: Service Mesh, MCP, and Securing Agentic Workloads

With William Morgan, CEO of Buoyant and creator of Linkerd

Linkerd just turned 10, so we brought on the person who built it and coined the term “service mesh” in the first place. William Morgan joins Jonathan and Justin to talk about where service mesh came from, where it’s going, and the very specific kind of chaos that agentic AI is about to unleash on anyone who owns a Kubernetes cluster. The short version: lock your doors, because the raccoons are coming.

“Our job is basically to make Linkerd as boring as possible.”

William traces Linkerd’s origins back to Twitter’s infrastructure work between 2010 and 2014, when a Ruby on Rails monolith turned into a sprawling distributed system — the same problems we have today, just a different decade. As the fifth project ever to join the CNCF, Linkerd has had a front-row seat to the ecosystem’s evolution, and William explains why his actual goal these days is to make it as boring as humanly possible: the kind of dependable infrastructure layer you can trust to still be around in another 90 years. That’s also why he’s not adding AI to Linkerd — an infrastructure layer has to be fast, lightweight, and predictable, and generative AI is the opposite of all three.

“At some point your agentic workload is going to figure out how to delete the production database. And it’s going to try it.”

The heart of the conversation is what the AI wave means for the platform teams who own the clusters. Developers just got an army of AI assistants, and that has real consequences for CI/CD, code quality, and blast radius. William digs into the boundary problem — agentic workloads are untrusted but need access to your most important systems — and why zero trust has suddenly stopped being optional now that the code hitting your database no longer clears peer review and a security committee. Along the way they get into cache-aware routing that can take a 13-second inference call down to one, the still-unsolved mess of agentic identity, and why we keep anthropomorphizing these tools and letting our guard down.

“If you don’t use Linkerd, your data system will be overrun by raccoons.”

Finally, they turn to MCP — building a catalog of MCP servers, detecting tool calls, and adding DLP-style protection in front of the services an agent never sees. But William’s real point is that MCP is something of a red herring for a much older problem: uncontrolled access to your APIs. Whatever protocol you use, once an unconstrained workload is loose in your environment, you need an immune system to keep it in check.

Links and resources:

  • Linkerd:

Every week, the team behind The Cloud Pod gathers to sift through the constant stream of announcements from AWS, Azure, and Google Cloud. Hosts Justin Brodley, Jonathan Baker, Ryan Lucas, and Matt Kohn bring their combined expertise to the table, translating complex platform updates and new service launches into practical insights. This isn't just a headline recap; it's a detailed analysis meant for engineers, architects, and tech leaders who need to understand the "why" and "how" behind the news. You'll hear them debate the real-world implications of the latest AI tooling, unpack FinOps strategies for managing costs, and track the evolving competitive landscape between the major providers. The conversation is grounded in years of hands-on experience, offering a perspective that goes beyond the press releases. Tuning into this weekly podcast provides a consistent, informed checkpoint for anyone whose work depends on the cloud. It’s a direct line to understanding the innovations and shifts that are actively reshaping how businesses build and scale technology, all from one of the most enduring voices in the space.
Author: Language: en-us Episodes: 50

The Cloud Pod | Weekly AI & Cloud News on AWS, Azure & GCP
Podcast Episodes
341: AWS Layoffs: Scaling Down Instead of Scaling Out [not-audio_url] [/not-audio_url]

Duration: 1:13:29
Welcome to episode 341 of The Cloud Pod, where the forecast is always cloudy! Matt & Ryan are picking up Justin’s slack this week while he’s traveling for work, but don’t worry, because they have plenty of news! We’re ta…
340: Azure releases a new SQL AI Assistant… Jimmy Droptables [not-audio_url] [/not-audio_url]

Duration: 1:13:07
Welcome to episode 340 of The Cloud Pod, where the forecast is always cloudy! It’s a full house (eventually) with Justin, Jonathan, Ryan, and Matt all on board for today’s episode. We’ve got a lot of announcements, from…
338: T5Gemma Says “AI’ll be Back” [not-audio_url] [/not-audio_url]

Duration: 1:02:00
Welcome to episode 338 of The Cloud Pod, where the forecast is always cloudy! Justin, Ryan, Matt, and Jonathan are in the studio today to bring you all the latest in cloud and AI news, including a bit of a buying spree (…
336: We Were Right (Mostly), 2026: The New Prophecies [not-audio_url] [/not-audio_url]

Duration: 1:08:15
Welcome to episode 335 of The Cloud Pod, where the forecast is always cloudy! Welcome to the first show of 2026, and it’s a full house, too! Justin, Jonathan, Ryan, and Matt are all here to reflect on 2025, plus bring yo…
334: AWS Makes Kubernetes Conversational [not-audio_url] [/not-audio_url]

Duration: 1:28:07
Welcome to episode 334 of The Cloud Pod, where the forecast is always cloudy! This week, we’re bringing you a jam-packed recap of re:Invent! We’ve got all the news, from keynotes to announcements. Whether you were there…
333: The Cloud Pod Goes Nano Banana [not-audio_url] [/not-audio_url]

Duration: 1:02:32
Welcome to episode 333 of The Cloud Pod, where the forecast is always cloudy! Justin, Ryan, and Matt are taking a quick break from re:Invent festivities. They bring you the latest and greatest in Cloud and AI news. This…