91a47fb42c
ci / rust (push) Successful in 2m26s
Governed compute for unified-memory AI hardware — the machines where CPU and GPU share one pool and there is no separate VRAM allocation to bounce off. Over-commit that pool and the box thrashes and wedges, SSH and ping included, before the OOM killer gets a turn. Compute does not run inference. It supervises the servers that do: - Admission control. A model starts only if committed + requested + margin fits the budget. The refusal is the feature. - A 1 Hz watchdog on MemAvailable that stops the newest model before thrash. - Scenes: named sets of models activated as one transactional unit, with pre-flight validation and rollback to the previously active Scene on failure. Scenes reference model ids, never weight paths or commands, so a Scene obtained from elsewhere cannot introduce code. - Process ownership bound to (boot_id, pid, start_time_ticks, pgid == pid), so a reused PID can never be group-killed. - A protocol-transparent TCP gateway, so clients keep one address while model runtimes move behind it. - An MCP server, so agents drive the node as tools rather than as a CLI. One binary, six direct dependencies, no async runtime outside the MCP surface. Published from the internal monorepo with a fresh history. The private development tree keeps its own history; nothing here carries it.
23 lines
1.1 KiB
Markdown
23 lines
1.1 KiB
Markdown
# Security policy
|
|
|
|
Report vulnerabilities privately to **security@karti.ai** before opening a
|
|
public issue. Expect an acknowledgement within a few days.
|
|
|
|
## Scope you should assume
|
|
|
|
Compute is a node-local supervisor, and two properties are deliberate rather
|
|
than oversights — know them before you deploy it:
|
|
|
|
- **The gateway has no authentication and no TLS.** The shipped systemd unit
|
|
binds `127.0.0.1`. Anything that widens that bind publishes every model on the
|
|
node; put a reverse proxy or an overlay network in front instead.
|
|
- **The model registry is trusted local configuration.** Launch commands live
|
|
only in the registry, never in a Scene, so a Scene obtained from elsewhere
|
|
cannot introduce code. Treat the registry itself as you would a systemd unit.
|
|
|
|
Lumbridge Compute treats model registries as trusted local configuration and scenes/eval suites
|
|
as potentially untrusted shared data. Shared manifests reference vetted ids and
|
|
must never execute embedded shell commands. Downloads must be checksum-verified
|
|
before promotion into the trusted registry. Secrets belong in environment or
|
|
OS-managed secret stores, never manifests, logs, or result artifacts.
|