intermediatePart 7
Firewall an agent container so it can reach one API and nothing else
· 21 min read
+
0/10
🎯 Skill path0/10 earned
Hardening self-hosted AI infra
- 1Lock down Docker networks
- 2Run containers as non-root
- 3Identity in front of every port
- 4Membership, not just an account
- 5An identity for the agent, not a key
- 6A tool server that checks who is asking
- 7Where the agent can go, not just what it can call
- 8Move the daemon off root
- 9Run the model's own code without trusting it
- 🏆A scope per tool, and a refusal clients can act on
Agent orchestration part 4 split a toolbox so the scheduler could not issue refunds. Part 5 gave the agent an identity at the gateway. Part 6 put a JWT verifier in front of the tools server so it refuses anonymous callers.
Every one of those controls what the agent may call. Not one of them controls where the agent may go.
That distinction is the whole of this post. Exfiltration does not need a tool. It needs a socket.
