platformengineering platformengineering/openchoreo conference wso2
The Evolution of Platform Engineering
Lakmal Warusawithana, WSO2Con North America 2026
[!video]- The Evolution of Platform Engineering β From Developer Platforms to AI-Native Platforms
Tldr
Traditionally, Internal Developer Platforms (IDPs) brought self-service, standardization, and βgolden pathsβ on top of Kubernetes. We are now entering a new era where platform engineering must evolve into AI-Native Platforms. Instead of merely automating and streamlining delivery, modern platforms act as intelligent systems that learn from telemetry, build dynamic Context Graphs, and empower autonomous AI agents to actively participate in operations (e.g., triage, root-cause analysis, and cost optimization) within strict corporate guardrails.
1. The Paradigm Shift: Reimagining the Platform
The core thesis of the talk outlines a rapid evolution in how software systems are built, delivered, and operated. The platform is transitioning from a βhuman-only self-service portalβ to a collaborative workspace shared by both human developers and autonomous AI agents.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β THE AI-NATIVE PLATFORM SHIFT β
ββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββ€
β Traditional IDPs β AI-Native IDPs β
ββββββββββββββββββββββββββββΌββββββββββββββββββββββββββββββ€
β β’ Developer-only β β’ Developers + AI Agents β
β β’ Imperative Self-Serv. β β’ Unified Control Plane β
β β’ Bolted-on AI Tools β β’ AI as a Core Primitive β
ββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββ
The Three Key Transitions
- Developer-Only Developers + Agents: AI agents are no longer just writing code in isolated IDEs; they are executing workloads, triggering CI/CD, managing infrastructure, and responding to telemetry at machine speed. They are now first-class consumers of the platform.
- Self-Service Unified Control Plane: A single control plane must govern, manage, and scale workflows for both humans (using UIs/CLIs) and agents (using APIs and Model Context Protocol (MCP)) using the same security boundaries and platform guardrails.
- Bolted-on AI AI as a Platform Primitive: Instead of wrapping old platforms in conversational wrappers, modern developer platforms integrate MCP servers, skill sets, and built-in agents directly into the platform fabric.
2. OpenChoreo: A Case Study in AI-Ready Platforms
Lakmal references OpenChoreo to demonstrate how these architectural concepts are built in practice. OpenChoreo Overview is built on a decoupled, multi-plane architecture.
OpenChoreo Overview > Multi-Plane Architecture Overview
Built-in Platform Agents
OpenChoreo features specialized, autonomous operational agents:
- SRE Agent: Automatically ingests logs, metrics, and traces from the observability plane to perform Root Cause Analysis (RCA) during incident windows.
- FinOps Agent: Powered by
OpenCost. Tracks budget thresholds, dynamically analyzes resource waste, and recommends rightsizing optimization metrics.


3. The Power of the βContext Graphβ
For AI agents to be effective, they cannot work with raw, isolated logs or disconnected metrics. Raw telemetry leads to hallucinations, high token usage, and wrong conclusions.
Raw Metrics/Logs ββ(Transform)ββ> Context Graph ββ> Grounded Reasoning (AI Agent)
What is a Context Graph?
An AI-native platform continuously parses data from code repositories, CI/CD pipelines, runtime infrastructure, and distributed traces, structuring them into a graph of real-world relationships.
When an incident occurs:
Traditional search: Search logs for
500 Error.Context-aware reasoning: The agent knows that Component A relies on Database B, which had a CPU spike immediately after Deployment V1.1.2 was pushed by User X.
4. Operationalizing the Model Context Protocol (MCP)
A major focus of the talk is how platforms expose resources to LLMs safely. OpenChoreo exposes MCP Servers directly from its system planes, giving LLM-based assistants clean contracts for tools and data.
OpenChoreoβs Native MCP Servers
- Control Plane MCP Server (90 tools):
- Allows agents to manage resources, trigger pipelines, create components, and build workloads.
- Example Prompt:
"Deploy my React app on OpenChoreo using this repository link..."
- Observer MCP Server (9 tools):
- Exposes endpoints like
query_component_logs,query_resource_metrics,query_traces, andquery_alerts. - Example Prompt:
"My checkout service has been slow since yesterday morning. Can you analyze what's going on?"
- Exposes endpoints like
5. Security, Identity, and Governance
Allowing autonomous AI agents to interact with live developer platforms introduces major security risks. WSO2 addresses this via two core security layers:
WSO2 Agent ID
- Agent-First Identity: AI agents are treated as distinct, first-class directory entities (not disguised human users) under a Zero-Trust architecture.
- SCIM2 Extensions: Extends standard user provisioning protocols to lifecycle-manage agents.
- User-Delegated Consent: Intercepts actions to verify human-in-the-loop approval before executing high-risk tasks.
The WSO2 MCP Gateway
Acting as a mediation layer between MCP clients (like Claude Desktop or VS Code Copilot) and backend systems, the gateway handles:
- OAuth 2.1 Governance for tool-level access controls.
- AI Guardrails (PII masking, prompt validation, schema validation).
- Token-Based Rate Limiting to keep LLM costs predictable.
ββββββββββββββ βββββββββββββββ ββββββββββββββ βββββββββββββββ
β AI Client β ββ> β MCP Gateway β ββ> β Agent ID β ββ> β MCP Server β
β (VS Code) β β (WSO2 APIM)β β(Auth Check)β β(OpenChoreo) β
ββββββββββββββ βββββββββββββββ ββββββββββββββ βββββββββββββββ
6. OpenChoreo v1.1 - Key Updates
Announced during the conference, OpenChoreo v1.1 implements several AI-native capabilities:
- Agent Sandbox Module: Provides secure, sandboxed runtimes (utilizing kernel/container boundaries) so custom agents can run code safely.
- Cilium & eBPF Integration: Offers raw eBPF networking telemetry and visualizations mapped straight onto platform service topologies.
- Advanced ABAC/RBAC: Introduces CEL-based conditional policies, restricting agent operations based on dynamic environment contexts.