Governed compute for unified-memory AI hardware — machines where CPU and GPU share one pool and there is no separate VRAM allocation to bounce off. Over-commit that pool and the box thrashes and wedges, SSH and ping included, before the OOM killer gets a turn. Compute does not run inference. It supervises the servers that do: admission control against both a declared budget and what the machine actually has free, a 1 Hz watchdog that stops the newest model before thrash, Scenes activated as one transactional unit with rollback, process ownership bound to (boot_id, pid, start_time_ticks, pgid) so a reused PID can never be group-killed, a protocol-transparent gateway, an MCP server, and a read-only HTTP API for dashboards. Registry footprints in this release are measured on a live node rather than estimated. One binary, six direct dependencies. Apache-2.0. Generated by scripts/publish-compute.sh, which refuses to publish a tree it cannot prove clean.
This commit is contained in:
+10
@@ -0,0 +1,10 @@
|
||||
# Security policy
|
||||
|
||||
Please report vulnerabilities privately to the maintainers before opening a
|
||||
public issue.
|
||||
|
||||
Lumbridge Compute treats model registries as trusted local configuration and scenes/eval suites
|
||||
as potentially untrusted shared data. Shared manifests reference vetted ids and
|
||||
must never execute embedded shell commands. Downloads must be checksum-verified
|
||||
before promotion into the trusted registry. Secrets belong in environment or
|
||||
OS-managed secret stores, never manifests, logs, or result artifacts.
|
||||
Reference in New Issue
Block a user