SREday

Site Reliability, DevOps and Cloud

October 2, 2026 San Francisco, CA, USA

1
Day
16+
Speakers
2
Tracks
100+
Attendees

Running Untrusted Agents in Production

Larsen Cundric
SpaceXAI
Abstract

Giving an AI agent the ability to execute code changes the infrastructure it needs. When I was working at Browser Use, that meant rethinking where agents ran, which credentials they could access, and how their work survived a process dying. I'll walk through the architecture we built: isolated agent runtimes, scoped access through a control plane, and state stored outside the worker. Then I'll cover what still went wrong, including a failed state restore that was mistaken for a fresh session and allowed blank state to replace valid conversation history. We'll look at the recovery changes that followed and the operational tradeoffs we encountered moving between runtimes. The talk draws on publicly documented Browser Use work. Attendees will leave with practical lessons for isolating untrusted workloads, distinguishing missing state from unavailable storage, and deciding which parts of an agent platform they need to operate themselves.

Bio

Larsen Cundric works on Grok at SpaceXAI. Previously, he was a founding engineer at Browser Use, where he worked on browser agent infrastructure, sandboxing, and control planes. He writes about the architecture and operational tradeoffs behind running agents in production.

Sponsors & Partners

Want to become a sponsor? Get in touch!
Let's talk!
We'll email you and share prospectuses for relevant events.
We'd like to (one or more)
Pick at least one
Conferences (one or more)
Pick at least one
Regions (one or more)
Pick at least one
Budget
Pick one