Juan Antonio Osorio

Principal Engineer

Ozz is a Principal Engineer at Stacklok based in Helsinki, Finland, with more than two decades of experience at the intersection of security, identity, and cloud infrastructure. Ozz founded the ToolHive project, an open-source platform designed to make deploying MCP servers easy and secure. Prior to his current role, he led security and compliance strategy at Equinix Metal, tackling complex identity problems and contributing to the open-source tools underpinning their stack. At Red Hat, he spent over six years working on security and compliance for OpenShift and Kubernetes, maintaining widely adopted projects including the Compliance Operator and Security Profiles Operator. Ozz's career reflects a consistent focus on making large-scale infrastructure secure by default.

All Articles by Juan Antonio Osorio

March 16, 2026

Your AI agent doesn’t deserve root access

The power of coding agents is inseparable from risk. The question isn’t whether something will go wrong; it’s how far the damage can travel when it does. Here’s what you’ll …

April 24, 2025

No Dockerfile? No problem! Running Node.js and Python MCPs with ToolHive

ToolHive dynamically builds containers for JavaScript and Python-based MCP servers without requiring Dockerfiles.

April 16, 2025

Secure-by-default authorization for MCP servers powered by ToolHive

ToolHive implements authorization using Amazon’s Cedar policy language, enabling fine-grained access to MCP servers with attribute-based rules.

April 14, 2025

Getting authentication right is critical to running MCP servers

Learn how ToolHive uses OIDC for authentication while separating it from authorization to support user authentication via SSO and service auth in Kubernetes.

April 09, 2025

ToolHive: Making MCP servers easy, secure, and fun

Introducing ToolHive, an open source project that makes MCP servers easy to discover, consistent to install, and secure by default.