Posted on October 8, 2026 by Mauro Morales | CNCF Ambassador In the past few months, I've been hearing different versions of the same question: under what conditions can we safely allow an autonomous system to operate a machine? It comes up when my colleagues discuss how much autonomy we should give our agents. It comes up when people outside the software industry wonder how to secure their OpenClaw or similar installations. And it's my own question when I wonder how much of my Kubernetes cluster my agents should control. Let me be upfront: I don't have the answer.

As with security, the answer depends on the system we're talking about. There is no one-size-fits-all answer in the cloud native ecosystem. But as someone directly involved in the development of an operating system, and who's recently gotten heavily invested in software factories, I'd like to share what I think it should look like at this layer of the cake. By software factory, I mean the machinery that turns a proposed change into a running artifact: source control, review, CI, tests, image builds, signing, release, and deployment.

I know it feels amazing to give an agent root access to a machine and watch all the impressive things it can do. I recently migrated a home service from a MacBook to a Linux box without downtime, and all it took was giving the agent superuser access. But just because it can be done doesn't mean it should be done. Experimentation and production are very different environments, and both come with different expectations. If you give an agent root access and expect a well-written AGENTS. md file to prevent an unrecoverable mistake, you are fooling yourself.

The system, however capable it may be, is still nondeterministic, so you cannot guarantee the outcome. This is not simply about failures. APIs can contain bugs and fail too. It is about reproducibility: knowing what changed and tracking who or what changed it. We should not give agents unrestricted root access to production systems for the same reason we should not give humans unrestricted root access to them. In the traditional Linux paradigm, if an application needed something, such as a library, we installed it on the base system.