Kubernetes Production Isolation #126
JakobStadlhuber
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
In addition to the described security mechanism in the llm-sandbox documentation, there are necessary mechanisms to have a secure environment when running workloads.
Disable all network access (reduce the risk of DDoS or connecting to a local db for example):
Having a Service Account with Role and/ or ClusterRoles with Bindings to reduce what llm-sandbox can do with the Kubernetes API:
And one of the most important one is to protect the kernel with an issolation like gVisor or Kata
Do you have any other security or hardining mechanism or is this setup good? should we also document this in the project?
Beta Was this translation helpful? Give feedback.
All reactions