Files
compute/SECURITY.md
T
Karti Tripathi 91a47fb42c
ci / rust (push) Successful in 2m26s
Lumbridge Compute
Governed compute for unified-memory AI hardware — the machines where CPU and
GPU share one pool and there is no separate VRAM allocation to bounce off.
Over-commit that pool and the box thrashes and wedges, SSH and ping included,
before the OOM killer gets a turn.

Compute does not run inference. It supervises the servers that do:

- Admission control. A model starts only if committed + requested + margin
  fits the budget. The refusal is the feature.
- A 1 Hz watchdog on MemAvailable that stops the newest model before thrash.
- Scenes: named sets of models activated as one transactional unit, with
  pre-flight validation and rollback to the previously active Scene on
  failure. Scenes reference model ids, never weight paths or commands, so a
  Scene obtained from elsewhere cannot introduce code.
- Process ownership bound to (boot_id, pid, start_time_ticks, pgid == pid),
  so a reused PID can never be group-killed.
- A protocol-transparent TCP gateway, so clients keep one address while model
  runtimes move behind it.
- An MCP server, so agents drive the node as tools rather than as a CLI.

One binary, six direct dependencies, no async runtime outside the MCP surface.

Published from the internal monorepo with a fresh history. The private
development tree keeps its own history; nothing here carries it.
2026-08-03 16:22:21 -07:00

1.1 KiB

Security policy

Report vulnerabilities privately to security@karti.ai before opening a public issue. Expect an acknowledgement within a few days.

Scope you should assume

Compute is a node-local supervisor, and two properties are deliberate rather than oversights — know them before you deploy it:

  • The gateway has no authentication and no TLS. The shipped systemd unit binds 127.0.0.1. Anything that widens that bind publishes every model on the node; put a reverse proxy or an overlay network in front instead.
  • The model registry is trusted local configuration. Launch commands live only in the registry, never in a Scene, so a Scene obtained from elsewhere cannot introduce code. Treat the registry itself as you would a systemd unit.

Lumbridge Compute treats model registries as trusted local configuration and scenes/eval suites as potentially untrusted shared data. Shared manifests reference vetted ids and must never execute embedded shell commands. Downloads must be checksum-verified before promotion into the trusted registry. Secrets belong in environment or OS-managed secret stores, never manifests, logs, or result artifacts.