Teach Agents When Not To Act: Practicing Agentic DevOps

October 07, 2026 03:39

Like most engineers, I have trusted automation a little more than I should have. Once, an auto-fix bot found a race condition in a CI pipeline and "fixed" it by removing the lock. The deadlock that followed reached production and woke people up at 2 a.m. The bot did what I asked. I had not told it what it was allowed to do. That is the gap this talk explores. A coding assistant suggests changes. An agent changes state. It can scan code, create issues, edit files, open pull requests, and clean up after itself. Once a tool can act on a repository, prompts are no longer casual instructions. They become part of the delivery boundary. In this live demo, I will build an Agentic DevOps workflow where intent defines the outcome, policy defines the agent's authority, and human review handles the cases where the agent should not act alone. We will turn "find bugs and fix them" into a safer workflow using severity, complexity, and confidence scoring. A conservative policy lets low-risk fixes move automatically. Risky changes become needs-review items. A developer can still approve the agent to continue, but the default is bounded action, not blind automation. The goal is not a CI bot that always acts. The goal is a CI agent that reads the policy, understands its limits, and knows when not to act.

Views:
11
Download:

speaker

Kamesh Sampath

kameshsampath

An Author, Consultant and Developer Advocate; Kamesh is Product Manager for Managed and Developer Services at Red Hat.

more decks of the speaker