Portainer-Command: The Safe Way to Put AI to Work on Your Kubernetes Fleet
No CISO will sign off on an AI agent holding cluster credentials. Portainer-Command is the governance layer that makes "yes" possible. Agents read through time-limited sessions tied to a named person, and every change goes through a GitOps pull request a human approves. Join CPO Nathan Peck for a live demo.
Wednesday 14 October, 2026 | 1:30 PM Pacific / 2:30 PM Mountain / 3:30 PM Central / 4:30 PM Eastern
Thursday 15 October, 2026 | 9:30 AM New Zealand Time
For other timezones, please register and we will send you a link to the recording.
Anyone can point an AI agent at kubectl today. What most teams can't do is get that approved, and for good reason. An agent holding someone's cluster credentials is hard to trace when it gets something wrong and harder to undo.
Portainer-Command is the governance layer between AI agents and Kubernetes. Agents connect over MCP, whether that's Claude, another MCP-compatible client, or a workspace your admins provision inside Portainer. They can read cluster state through sessions that carry a stated reason, expire on a time limit, and map to a named person. They cannot write to the cluster directly. Each agent gets access only to its own environment's manifest folder, and its changes land as pull requests that a human approves before Portainer applies them through GitOps. After the merge, the agent checks the rollout and corrects a failed deployment.
In this session, Nathan Peck, Chief Product Officer at Portainer, will show Portainer-Command on a live environment. Two groups of teams will get the most out of it.
If you haven't started using AI for ops, you'll see the built-in workspace. It needs no setup, comes with a prompt library for real tasks like security audits, image pinning and network policies, and lets you undo every change. The guardrails are what let you begin.
If your engineers are already using AI agents against your clusters, officially or otherwise, you'll see how to bring that under control. The demo covers per-environment rules for what agents can read or propose, namespace restrictions, and a full timeline of AI activity for tracing what happened during an incident. You'll also see one-click revert of any AI change, rollback to a known-good state, and emergency halt that cuts off agents fleet-wide, environment or user level.
One thing to know going in: Portainer-Command assumes GitOps is your source of truth. If you're not there yet, Nathan will cover why Command is a good reason to get there.
Portainer-Command is available now in the Portainer Business add-on catalog. Every registrant will receive our published threat model, which documents the threats and mitigations, to share with your security team.
Speakers
Nathan Peck Chief Product Officer, Portainer
Nathan has spent more than a decade building and operating container platforms in production, across Amazon Elastic Container Service and Kubernetes. He focuses on container orchestration and on using automation to solve real operational problems.
See it run on infrastructure you already operate
We will walk you through the product that maps to your current AI conversation, on a live governed Kubernetes environment.

