Secure VMs for Kubernetes: Hardening Kata containers
A developer used AI agent Astra to cut ~60% of Kata Containers code, releasing a minimal-attack-surface fork for Kubernetes on Firecracker VMs.
The author used OpenAI's Codex CLI running the Astra agent to delete about 60% of Kata Containers code, leaving 13.5k SLOC for the host runtime and 8.1k SLOC for the agent, while preserving x86_64 Kubernetes workload support in Firecracker VMs. The goal was to shrink the attack surface of host-facing code that parses guest RPC data, since Kata opens host-guest channels that base Firecracker does not. Changes were validated on a homelab cluster running untrusted Kubernetes pods; the fork is unaudited and not production-tested. The post cites Artem Dinaburg's August 2026 experiments in which GPT-5.6 Cyber escaped qemu to the Debian host three times as motivation.