Edgecase 2026 Lineup

Catch the full lineup and session details

The Main Track

The technical heart of Edgecase. A full day of talks on Kubernetes, cloud native infrastructure, and everything that keeps modern platforms running — from hands-on deep dives to real-world lessons from engineers in the field.

profile justin

Justin Garrison

Field CTO @ Sidero Labs
Gotta Build 'Em All

10.00 - 10.40, Mainstage

The “starter cluster” has evolved from the simple days of kube-up to powering the largest platforms in the world. Kubernetes is the application interface developers expect, but it doesn’t fit everywhere. Justin has spent years trying to meet that challenge. He’s built some of the smallest and largest clusters in the world using old, new, and custom-built hardware. He’ll share lessons learned from putting Kubernetes into places it wasn’t originally designed to run—and how those experiences are shaping a simpler path forward with Talos Linux.

Justin serves as Field CTO at Sidero Labs and hosts the Fork Around and Find Out podcast. He has been called the Steven Spielberg of Cloud Native and the Bill Nye of tech. His career includes contributions to Oscar-winning films, the Disney+ streaming platform, and Amazon EKS. In his free time, Justin enjoys building modern-retro computers and watching Moana.

ShantanuGattani

Shantanu Gattani

SVP, Product @ Sysdig
The Dashboard is Dead: Agent-Driven Security on the Platforms You're Building

11.00 - 11.40, Mainstage

For over a decade, cloud security has been a dashboard discipline. That assumption is breaking, and not because a vendor decided so.

Like their engineering counterparts, the most AI-mature security teams are rebuilding their workflows around the coding agent as the control surface: from posture and identity to runtime data through MCP, defining policy in natural language, and running end-to-end remediation from signal to merged pull request without opening a UI. Enter: Headless cloud security.

This keynote is a field report on that shift. Attendees will explore what these security teams are building, what holds up in production, where it breaks, and what it takes for a headless security platform to meet AI-mature teams where they already work.

With headless cloud security, the dashboard does not disappear, but it does stop being the destination. Keynote attendees leave with a way to evaluate the same evolution in their own program. 

Shantanu Gattani is the SVP, Product at Sysdig, where he leads the development of cloud security solutions. With over 15 years in the security industry, he has a proven track record of creating and maintaining products that fill necessary market gaps. Before Sysdig, Shantanu held senior product management roles at Tenable and Accurics, focusing on cloud security and exposure management. 

Constantino Vázquez

Constantino Vázquez

Head of Systems Engineering @ OpenNebula Systems
 
Elastic Kubernetes Needs a Home: Why Infrastructure Is Key

11.40 - 12.15, Mainstage

How OpenNebula helps platform teams deliver elastic, multi-tenant, multi-cluster Kubernetes environments with sovereignty, simplicity, and cost efficiency.

Head of Systems Engineering at OpenNebula Systems, leading engineering strategy, with deep expertise in cloud computing and software architecture.

WilliamRizzo

William Rizzo

Global Field CTO @ Mirantis + Kairos Maintainer
Inference at the far Edge. Running LLMs on Immutable Disconnected K8s Nodes

13.30 - 14.05, Mainstage

Most inference scenarios assume a datacenter: gigawatts of power, fat pipes, and an operator who can SSH into any node. The edge breaks all three. You're serving models on hardware in a factory floor, retail site, vehicle or remote facility, the link drops for hours at a time, and "just patch the node" means dispatching a human. 
This talk shows how an immutable, image-based operating system turns those constraints into guarantees. We'll walk through serving an LLM on read-only edge nodes: packaging model + runtime + GPU drivers into atomically-updated images, doing A/B upgrades and rollbacks with no remote shell, and keeping inference healthy across disconnected fleets. 
You'll leave with a concrete reference architecture, the failure modes we hit in production across several nodes and sites, and an honest account of where edge inference still hurts. Built entirely on CNCF and open source projects.

William is a CNCF Ambassador and Linkerd Ambassador currently working at Mirantis as Global Field CTO. He’s focused on helping customers designing, building, and running their initiatives on Edge, AI and Platform Engineering. He wore many hats in the IT world, Engineering, Pre-Post sales, Product Owner and Consulting. from HPC, Storage to Distributed Systems. 
William enjoys volunteering in several Cloud Native groups and organizing the KCD Netherlands events.

Merijn Keppel

Merijn Keppel

Principal Consultant @TrueFullstaq
It's Super Effective! The Automation Behind Immutable Edge Kubernetes with Talos + Zarf

14.05 - 14.40, Mainstage

Earlier this year at KubeCon EU, a wild live demo appeared: we deployed and upgraded a Talos Kubernetes cluster in a completely air-gapped environment using Zarf, going from bare metal to a running cluster with zero internet connectivity, then upgrading it live on stage. Critical hit, crowd loved it. What we didn't get to show was the training montage behind the scenes: everything that had to go right to make that "magic" actually work.

This time, I'm revealing the moveset. In this session, I'll break down the real automation driving that demo, including how Talos Linux gives you a rock-solid, predictable OS built specifically for Kubernetes, and how Zarf bundles the OS, Kubernetes itself, and your applications into a single portable package you can deploy anywhere. I'll dig into the tooling that evolved "spin up a cluster with zero connectivity" from a flashy one-off into something repeatable and reliable, and where TrueFullstaq is taking this "magic" component next. 

Merijn is Principal Consultant at TrueFullstaq, focused on declarative infrastructure such as NixOS, Talos Linux, and Zarf, with a particular interest in reproducibility challenges in disconnected and air-gapped systems.

Rick Brouwer

Rick Brouwer

Practice Lead OPS @ DUO
Autoscaling with KEDA: From Metrics to Machine Learning

15.15 - 15.55, Mainstage
(A duo talk with Harke Wijnsma)

What if your applications could scale themselves, intelligently, automatically, and ahead of demand? 

In this session, we explore the world of event-driven autoscaling with KEDA: starting from the fundamentals and building all the way up to predictive autoscaling powered by Machine Learning. Whether you're just getting started with autoscaling or looking to push beyond traditional reactive approaches, this talk has something for you. 

Rick brings over 20 years of IT experience to the stage. Currently serving as Practice Lead OPS at DUO, part of the Dutch Ministry of Education, Culture and Science, he is also an active KEDA maintainer, one of the people who helps shape the project itself. He brings technical insight straight from the source.

HarkeWijnsma

Harke Wijnsma

Practice Lead OPS @ DUO
Autoscaling with KEDA: From Metrics to Machine Learning

15.15 - 15.55, Mainstage
(A duo talk with Rick Brouwer)

What if your applications could scale themselves, intelligently, automatically, and ahead of demand? 

In this session, we explore the world of event-driven autoscaling with KEDA: starting from the fundamentals and building all the way up to predictive autoscaling powered by Machine Learning. Whether you're just getting started with autoscaling or looking to push beyond traditional reactive approaches, this talk has something for you. 

Harke Wijnsma brings extensive IT experience to the table. As a Practice Lead OPS at DUO, he spent many years within DUO's Observability and Analytics team, giving him deep, hands-on knowledge of Machine Learning, metrics, and data. That background makes him perfect to talk about how deep observability and metrics expertise lays the foundation for truly intelligent autoscaling

KrisBudde

Kris Budde

Product Owner @ STACKIT Edge Cloud
Get Your Platform Bootstrapped on Edge

15.55 - 16.30, Mainstage
(A duo talk with Fabian Schmitt)

Building a platform sounds right until every team builds its own. At one of the world’s largest retailers, one platform didn’t fit all, but many siloed platforms did not scale. Different products, constraints, and experience levels drove divergence.

In this talk, we show how we addressed this by building an Open Source Platform Framework not as a rigid product, but as a shared foundation. It allows teams to own their platforms while sharing common practices, from standard cloud setups to 15,000+ edge locations.

I’m an infrastructure enthusiast turned Product Owner, with a deep background in SRE, virtualization, and Kubernetes. Today, I drive the product strategy for STACKIT Edge Cloud at Schwarz Digits, building the next generation of edge infrastructure management for modern cloud-native applications

FabianSchmitt

Fabian Schmitt

Platform Engineer @ Schwarz Digits Cloud
Get Your Platform Bootstrapped on Edge

15.55 - 16.30, Mainstage
(A duo talk with Kris Budde)

Building a platform sounds right until every team builds its own. At one of the world’s largest retailers, one platform didn’t fit all, but many siloed platforms did not scale. Different products, constraints, and experience levels drove divergence.

In this talk, we show how we addressed this by building an Open Source Platform Framework not as a rigid product, but as a shared foundation. It allows teams to own their platforms while sharing common practices, from standard cloud setups to 15,000+ edge locations.

I've been passionate about cloud-native tech for nearly 10 years, working in various DevOps and Platform Engineering roles along the way. Right now, I'm a team member and maintainer of the open-source tool 'kubara'—it started internally at Schwarz Digits and launched publicly in March 2026.

Edgecase partners

The Cloud Native Security Track

The Cloud Native Security Track by Sysdig and TrueFullstaq is for engineers who don't treat security as a separate discipline, but simply as part of the job. Talks on securing Kubernetes and cloud native platforms in practice: from runtime security to tackling vulnerabilities, without slowing down your platform.

Marcel Claassen

Marcel Claassen

Principal Solutions Engineer @ Sysdig
Gerrit Learns Cloud Native Security - The Final Exam

13.30 - 14.00, Security stage

Gerrit Tamboer called himself the LeBron James of vibe coding. Then his colleagues hacked his app in under 20 minutes. So he called Marcel Claassen from Sysdig and asked him to fix that. Publicly.

Three sessions later - it's exam time. Marcel tests Gerrit live on stage. Threat recognition. Attack chains. Defense. The audience plays along. Gerrit passes? Gerrit gets a certificate. You all leave with a limited edition LCNS trucker hat. 

Marcel Claassen is a Principal Solutions Engineer at Sysdig specializing in cloud and container cybersecurity. He is known for his focus on threat detection and has more than 20 years of experience in the IT and Security field. Currently holding a position at Sysdig, a company focused on cloud-native security, and actively contributing to open-source projects such as Falco and Stratoshark. In his spare time, he also manages home automation projects within his home-based K3S cluster. 

GerritTamboer

Gerrit Tamboer

Chief Evangelist @ TrueFullstaq
Gerrit Learns Cloud Native Security - The Final Exam

13.30 - 14.00, Security stage

Gerrit Tamboer called himself the LeBron James of vibe coding. Then his colleagues hacked his app in under 20 minutes. So he called Marcel Claassen from Sysdig and asked him to fix that. Publicly.

Three sessions later - it's exam time. Marcel tests Gerrit live on stage. Threat recognition. Attack chains. Defense. The audience plays along. Gerrit passes? Gerrit gets a certificate. You all leave with a limited edition LCNS trucker hat. 

Gerrit Tamboer, Chief Evangelist at TrueFullstaq, CNCF Ambassador and co-founder of (formerly) Fullstaq, brings a strong technical background to his leadership role. With extensive experience in Kubernetes implementations, Gerrit has transitioned from hands-on technical work to strategic oversight, now focusing on spreadsheets and presentations.

Alessandro Loprete

Alessandro Lo Prete

Threat Detection Engineer @ Sysdig
Prompt and Pillage: How an AI Operator Ran a Full Ransomware Campaign on Cloud Infrastructure

14.05 - 14.40, Security stage

In 2026, the Sysdig Threat Research Team started observing an AI operator targeting popular AI infrastructure with a fully agentic ransomware campaign. We call it JADEPUFFER, and it is the clearest case we have of what an autonomous attacker does to the infrastructure you run every day.

In this talk, we'll show how agentic threat actors are changing the security landscape. We'll walk through the intrusion the way it happened, from CVE exploitation to ransomware deployment, and see how JADEPUFFER recovered from its own failures and ran dozens of operations a minute in parallel, faster than any human could keep up with. Finally, we'll look at how this shifts the security baseline that defenders and builders have to meet, given how easily a campaign like this can now be automated.

You will leave with the anatomy of an agentic intrusion and a clearer sense of what is changing, and what is not. The tooling is new and getting cheaper, but the doors it walked through are the same ones we have always been responsible for closing. 

Alessandro Lo Prete is a Threat Detection Engineer at the Sysdig Threat Research Team, specializing in cloud security and Linux runtime detection.  His current research explores integrating AI into defensive detection workflows and detecting agentic threats. Previously, he collaborated with the European Space Agency (ESA) on time-series anomaly detection for Delay Tolerant Networks as part of his MSc thesis. 

Danielle Wagemakers

Daniëlle Wagemakers

Lead Cybersecurity Technology Specialist @ Sogeti
You're the Security Team Now: How Platform Teams Are Taking on Cloud Security

15.15 - 15.55, Security stage

Somewhere in the last few years, platform teams became security teams. They run the admission controllers, patch the base images, own the pipeline everything ships through, and now review the code AI agents write. Most never applied for the job.

This panel brings engineering and security leaders from large enterprises on stage to compare notes on how that shift is going: which open source security tools earned a permanent place in their stacks, what changed in how they secure running workloads once AI coding agents started committing to production, where they draw the line between platform work and security work, and how they keep shipping fast while the security surface grows.  

You'll hear how teams like yours split the work today, and what they would change if they were starting over. 

Daniëlle is a Lead Cybersecurity Technology Specialist, at Sogeti. There, she specializes in threat modeling, coaches teams through their threat modeling journeys and security in DevOps, and advocates for the responsible use of GenAI. You might also recognize Daniëlle from her other roles: she is on the organizing team of WICCON, one of the Digitale Dolle Minas, and is a speaker at various events on threat modeling, inclusion, and consent. If she's not doing any of that, she's probably in a theater somewhere enjoying a musical. 

Saeid Ashian

Saeid Ashian

Principal Platform Enablement Engineer @ Saxo Bank
You're the Security Team Now: How Platform Teams Are Taking on Cloud Security

15.15 - 15.55, Security stage

Somewhere in the last few years, platform teams became security teams. They run the admission controllers, patch the base images, own the pipeline everything ships through, and now review the code AI agents write. Most never applied for the job.

This panel brings engineering and security leaders from large enterprises on stage to compare notes on how that shift is going: which open source security tools earned a permanent place in their stacks, what changed in how they secure running workloads once AI coding agents started committing to production, where they draw the line between platform work and security work, and how they keep shipping fast while the security surface grows.  

You'll hear how teams like yours split the work today, and what they would change if they were starting over. 

Saeid Ashian is a Principal Platform Enablement Engineer at Saxo Bank, working with Kubernetes, automation, DevOps and secure software delivery. He focuses on platform guardrails that help engineering teams ship faster while keeping security, traceability and control built into the delivery path. Saeid is also a Kubestronaut and is passionate about making cloud native platforms safer and easier for developers to use. 

Marcel Claassen

Marcel Claassen

Principal Solutions Engineer @ Sysdig
Machine-Speed Attack, Machine-Speed Defense: Falco-Powered Threat Detection vs. an AI Attacker

15.55 - 16.25, Security stage

Agentic attacks run end to end with no human at the keyboard, and a defense that waits for someone to read an alert has already been lost.

In this session, Marcel replays one of these attacks live against a real cluster and lets Falco-powered threat detection answer at the same speed. You'll watch the eBPF event stream show what the kernel sees, detection rules fire as the intrusion unfolds, alerts land in the channels your team already pages on, and automated responses kill the compromised workload before a human could have read the message. This is the same engine behind Sysdig Secure's runtime detection, hardened by a decade of community engineering and production use at more than 9,000 organizations.

You'll leave knowing what Falco catches against the newest class of attacker, and what it looks like to respond at the speed the attack demands. 

Marcel Claassen is a Principal Solutions Engineer at Sysdig specializing in cloud and container cybersecurity. He is known for his focus on threat detection and has more than 20 years of experience in the IT and Security field. Currently holding a position at Sysdig, a company focused on cloud-native security, and actively contributing to open-source projects such as Falco and Stratoshark. In his spare time, he also manages home automation projects within his home-based K3S cluster. 

Gotta catch your ticket

Join the search for everything cloud native has to offer. Secure your spot at Edgecase 2026.  
September 24, Gooiland, Hilversum.

More about Edgecase and this year's theme.