Whitney Lee

@whitneylee.com

Doin' it and doin' it and doin' it well https://whitneylee.com/

Lin Sun, co-creator of kagent, joined me at the lightboard to walk through how it works. kagent is a framework to help you make AI agents and run them in Kubernetes declaratively, with YAML. Read the full board notes here: https://gist.github.com/wiggitywhitney/97e3347ddc5c00da2b3c07471a2ac277

A hand-drawn lightboard diagram on a black background, filled with colorful marker text and boxes mapping out how kagent works. Sections include "Before kagent," "kagent config" with a Kubernetes CRD circle, "kagent controller watches," "Agent Sandbox," "Agent Runtimes," "Why run your agent on Kubernetes," "AUTH," and "How do people use kagent," connected by arrows and underlines in pink, yellow, and green.

Lin Sun, CNCF TOC member and kagent co-creator, explains how kagent's Agent custom resource lets you declaratively configure its instructions, model, and MCP tools, all with the same `kubectl apply` workflow Kubernetes users already know. Watch the full ⚡️Enlightning: https://youtu.be/SjiFGqtiZqg

A lightboard illustration on a black background reads "KAGENT — Bringing Agentic AI to Cloud Native" in a hand-drawn box with green, pink, and yellow outlines. To the right, Lin Sun smiles and waves, wearing a black zip-up jacket, with "with guest Lin Sun" written beside her in yellow cursive.

On 🌩️Thunder, Kubescape maintainer Ben Hirschberg shows how the tool catches misconfigurations, then watches runtime behavior with eBPF & turns that into a least-privileged NetworkPolicy proposal. Read the full board notes here: https://gist.github.com/wiggitywhitney/5268e193d49604d7d8a19bb48cd86cfa

A completed lightboard covered in handwritten colored notes about Kubescape. Sections include Before Kubescape, Threats in Kubernetes, Kubescape Can Do a Lot (infrastructure scanning, workload config scanning, RBAC configuration, vulnerability scanning with GRYPE, hardening and remediation proposals), a Glossary of security terms, and the Kubescape User Experience covering CLI, Operator, and GitHub Action.

Kubescape maintainer Ben Hirschberg teaches how Kubescape scans a cluster for security risks. It checks infrastructure, workload, and RBAC configuration against OPA-based policies, then adds vulnerability scanning with Grype and runtime monitoring with eBPF. Watch here: https://youtu.be/z008cHQDA2Q

Thunder episode thumbnail. On the left, Ben Hirschberg, a man with short graying brown hair and a beard, wearing a red shirt, smiling at the camera. On the right, Whitney Lee, a woman with reddish-brown hair, wearing a black top under a red and black plaid flannel shirt, laughing with one hand in her hair. Between them, a black rounded rectangle showing a lightboard covered in handwritten white and teal notes and diagrams. Large yellow bold text reads "What Is Kubescape" and below it "Scanning Kubernetes for Real Security Risks." Yellow and white text at the bottom left reads "with Ben Hirschberg." The Thunder logo (a cloud with a lightning bolt) appears in the top left corner.

Datadog rewrote its AWS Lambda monitoring software from Go to Rust. How much did that cut memory usage? Watch the full Datadog Illuminated episode: https://www.youtube.com/watch?v=r-tDBtxGHeY #Rust #Serverless #AWSLambda #Datadog #DatadogIlluminated

Datadog's serverless monitoring software started in Go. After rewriting it in Rust, how far does AJ Stuyvenberg think the language will spread at Datadog? Watch the full Datadog Illuminated episode: https://www.youtube.com/watch?v=r-tDBtxGHeY #Rust #Serverless #Datadog #DatadogIlluminated

If Datadog's AWS Lambda extension crashes, AWS Lambda shuts down the sandbox, taking the customer's code with it. How does Datadog minimize that risk? Watch the full Datadog Illuminated episode: https://www.youtube.com/watch?v=r-tDBtxGHeY #Rust #Serverless #AWSLambda #Datadog #DatadogIlluminated

Datadog rewrote the software that monitors AWS Lambda functions from Go to Rust. How did that affect cold start time? Watch the full Datadog Illuminated episode: https://www.youtube.com/watch?v=r-tDBtxGHeY #Rust #Serverless #AWSLambda #Datadog #DatadogIlluminated

When breaking a monolith into microservices, why ask countless teams to each migrate their own code when one team can build the tooling to do it for all of them? Watch the full Datadog Illuminated episode: https://youtu.be/6KlZVvLSMJo #Datadog #AI #LLM #Microservices

What happens behind the scenes when your coding agent asks the Datadog MCP server for telemetry? Watch the full Datadog Illuminated episode: https://youtu.be/5PzqNwOTMEc #MCP #MCPServer #Datadog #DatadogIlluminated #AIAgents

Here's the final board from the Datadog Illuminated episode with AJ Stuyvenberg, who explains how his team rewrote Datadog's serverless agent in Rust, and the benefits of doing so! Read the full board notes here: https://gist.github.com/wiggitywhitney/d2084b9dea6074729e9ac09b3d195efe

A lightboard titled "WHY WE REWROTE OUR SERVERLESS AGENT." Three sections: left "The Problem Space" notes that AWS Lambda freezes the CPU between requests and runs code in tiny, isolated sandboxes, while the Datadog Agent was built to be long-running with a 55mb binary and 400ms+ startup, shown with a before/after timeline where startup drops from 400ms to 50ms and the agent continuously flushes data to Datadog during I/O waits. Middle "Why Rewrite?" lists making the agent lighter, eliminating upstream bugs, and switching to Rust for no garbage collection, small binaries, fast startup, and memory safety, with a playful "Suspense" note about more reasons to come. Right "Challenges" notes the team had no Rust knowledge, next to a "Results" box showing startup time improving from 400ms to 50ms, binary size shrinking from 55mb to 7mb, memory reduced by 50%, a 2x reduction in tail latency, and a safe rollout shipping Rust and Go binaries together with failover to the old Go version. Chalk-style text on a dark lightboard.

@ajs.bsky.social, Staff Engineer on Datadog's Serverless team, explains how his team rewrote Datadog's serverless agent from scratch, in a language none of them had ever used in production. Give it a watch! https://www.youtube.com/watch?v=r-tDBtxGHeY

Whitney, a woman with reddish-brown bangs, laughs with both hands on her cheeks on the left. AJ Stuyvenberg, a man with short brown hair and a beard wearing a maroon shirt, smiles on the right. Between them, a lightboard reads "WHY WE REWROTE OUR SERVERLESS AGENT" in large yellow and white pixel-style letters over chalk-style diagram notes about AWS Lambda, binary size reduction, and cold start improvements. "Datadog Illuminated" appears in neon-style lettering in the upper left corner. "with AJ STUYVENBERG" is written at the bottom right.

How do you improve the behavior of AI agents? You make the right thing to do the easy thing to do. Watch the full Datadog Illuminated episode: https://youtu.be/5PzqNwOTMEc #MCP #MCPServer #Datadog #DatadogIlluminated #AIAgents

Did you know an AI agent's performance can degrade from tool overload long before it ever hits a hard limit? Watch the full Datadog Illuminated episode: https://youtu.be/5PzqNwOTMEc #MCP #MCPServer #Datadog #DatadogIlluminated #AIAgents

The client doesn't know or care where the Network Service is running. Read the full board notes here: https://gist.github.com/wiggitywhitney/89348c8553b7ce9b69f091c785343fe1

A lightboard covered in dense handwritten-style text in white and yellow, organized into labeled sections including "Before Network Service Mesh...", "A Network Service is", "Network Service Mesh is", "Use Cases for Network Service Mesh (NSM)", "Network Service Registry", and "Application Service Meshes." Black background with multiple columns of technical notes about K8s networking, Network Service Mesh concepts, and comparisons between application service meshes and NSM.

Ed Warnicke, Distinguished Engineer at Cisco and Network Service Mesh co-founder, explains in this 🌩️Thunder episode why not every workload speaks HTTP, and how NSM connects them at Layer 3 without tying entire systems together. Watch here: https://youtu.be/u9hOPyRVwBs

Whitney Lee on the left, smiling, with long dark hair and a black top. Ed Warnicke on the right, a man with long hair wearing a dark patterned shirt. Between them is a lightboard with large yellow text reading "What Is Network Service Mesh?" and "Workload Connectivity at Layer 3." The Thunder logo appears in the upper left. "With Ed Warnicke" is written in the lower right. Blue lightning bolt decorations appear in the upper corners.

My Datadog Illuminated episode with Reilly Wood, whose team built the Datadog MCP server from scratch, distilled to a single lightboard. Read the full board notes here: https://gist.github.com/wiggitywhitney/f919d9d9e571e8bf6f5fba4a81fcbc55

A lightboard titled "BUILDING AN MCP SERVER." A flowchart shows Datadog Backend to Datadog-hosted MCP Server via HTTP to Agent (labeled "WILDCARD") to User to "SUCCESS = HAPPY USER." Below: "TAMING THE AGENT (+ LLM) = Correctness + Efficiency." Three sections: left "Context Efficiency" (data format: JSON crossed out, replaced by YAML nested / CSV flat / TOON; agent control over context: let agents write SQL queries; good tool descriptions: smart yet succinct), center "no tool sprawl" (default core toolset: logs, metrics, traces; opt-in specialized toolset: synthetics), right "guide the agent" (specialized search docs tool with RAG; good error messages: Actionable; good server-level instructions: ex "use search docs RAG tool"). Chalk-style text on a dark lightboard.

@reillywood.com, Staff Engineer at Datadog, explains how the team built the Datadog MCP server to work reliably when you don't control which agent or LLM will be calling it. 👀 ⬇️ https://youtu.be/5PzqNwOTMEc #Datadog #MCP #MCPServer #AIAgents #DatadogIlluminated

Reilly Wood, a man with dark hair, glasses, and a short beard, smiles on the left side. Whitney, a woman with bright red hair, waves enthusiastically on the right. Between them is a lightboard reading "BUILDING THE DATADOG MCP SERVER" in large yellow and white pixel-style letters. "Datadog Illuminated" appears in neon-style lettering in the upper left corner. "with REILLY WOOD" is written at the bottom left.

When people can touch things they don’t own, conflicts and accidents happen, and the fix is SSO + access control + auditability. That way everyone knows exactly what they’re in charge of. Watch the full 🌩️Thunder episode: https://youtu.be/9meKq_7WwfM

"Because we have this layer in between the people and the infrastructure, we can log all of the interactions that the people have with the infrastructure." Watch the full 🌩️Thunder episode: https://youtu.be/9meKq_7WwfM #Paralus #Kubernetes #RBAC #AccessControl #CloudNative

How do you manage Kubernetes access for 1,000+ developers across many clusters? Watch the full 🌩️Thunder episode: https://youtu.be/9meKq_7WwfM #Paralus #Kubernetes #RBAC #AccessControl #CloudNative

What if your Kubernetes access control tool also became a better developer experience for your whole team? Watch the full 🌩️Thunder episode: https://youtu.be/9meKq_7WwfM #Paralus #Kubernetes #RBAC #AccessControl #CloudNative

If a dev leaves, it is a one-click experience to remove permissions. Read the full board notes here: https://gist.github.com/wiggitywhitney/231881c0fe0203b4b38c81419f0f3f43

A lightboard covered in neon handwritten notes on a dark background. The board is divided into sections with RBAC problems, a center architecture diagram showing PARALUS connecting to Kubernetes clusters, and PARALUS MAIN POINTS. Text and arrows are written in neon marker throughout.

In this episode of 🌩️Thunder, @cloudnativeboy.bsky.social, CNCF Ambassador and host of Cloud Native Podcast, explains how Paralus replaces manual Kubernetes RBAC with centralized SSO, group-based access control, and full kubectl audit trails. Give it a watch! https://youtu.be/9meKq_7WwfM

Two people flank a lightboard. On the left, Saim Safdar, a man with short dark hair wearing a white collared shirt, looks toward the camera with a calm expression. On the right, Whitney, a woman with long brown hair wearing a patterned top, laughs and points at the board. The board displays "WHAT IS Paralus? KUBERNETES ACCESS CONTROL MADE SIMPLE" in large yellow letters with handwritten lightboard notes visible behind. The Thunder show logo appears in the top left corner. Text at the bottom left reads "With SAIM SAFDAR." The background is white with decorative colorful shapes.

Did you know that the owner of a machine can stop your VM at any time, dump the guest memory, and read everything in it? Confidential computing completely changes the relationship between a cloud provider and a client. Watch the full 🌩️Thunder episode: https://youtu.be/WdW-_KU_BfA