MODULE 8 · DAY 2
Securing & Governing AI Workloads
Harden and ship the crew, the open source way
Gourav Shah · School of DevOps & AI · Hands-on
M8·01
What you'll learn
Six controls that make the agent safe to ship.
M8·02
An agent is a security surface
Four unguarded exposures, untrusted by default.
M8·03
1 · The analogy: ingredients label, health inspection, tamper seal
M8·04
Three things every shipped product needs
Ship AI like a ready meal: label, check, seal.
M8·05
2 · The supply chain pipeline
M8·06
3 · The SBOM: ingredients label for your image
M8·07
The supply-chain pipeline
Every image passes through this before it deploys.
M8·08
4 · Vulnerability scanning: two scanners disagree — that is a feature
M8·09
Two scanners disagree, that's the point
Different feeds, different CVEs: triage, don't average.
M8·10
5 · Signing: the tamper-evident seal
M8·11
Cosign: the tamper-evident seal
Key-based locally, keyless OIDC in CI.
M8·12
6 · Sandboxing agent, tool, and generated code
M8·13
Sandbox: a box with no blast radius
Run untrusted code once, then throw the box away.
M8·14
7 · Hardening the container image
M8·15
Hardening the agent image
The agent image needs a small attack surface too.
M8·16
8 · Guardrails and evaluation
M8·17
Guardrails at the model boundary
Guardrails protect what goes in and comes out.
M8·18
A lightweight eval proves the guardrails work
A few labeled cases in CI catch regressions.
M8·19
9 · Governance without a vendor
M8·20
Governance without a vendor
Four documented answers, enforced in YAML.
M8·21
SHIP IT SAFELY
Trust is a pipeline, not a promise
In the lab: run the tools, prove isolation.
Head to Module 8 · Lab. · Gourav Shah · School of DevOps & AI
M8·22