AI Security On Gke

Defensive, defense-in-depth security for AI/LLM workloads on Kubernetes and GKE — at the bar of a security engineer for an AI platform. Use when threat-modeling or hardening LLM inference, RAG, or agentic apps; designing prompt-injection / jailbreak / PII / toxicity filtering (Model Armor, Llama Guard, NeMo Guardrails, Guardrails-AI); sandboxing untrusted tool/code execution (gVisor/GKE Sandbox, Kata/microVMs, seccomp, AppArmor); runtime threat detection (GKE Security Posture, Container Threat Detection, Falco); admission control & policy (Pod Security Admission, Gatekeeper, Kyverno); image & model supply-chain (Binary Authorization, Sigstore/SLSA, safetensors vs pickle, dataset integrity); identity, secrets, and egress control (Workload Identity Federation, Secret Manager, NetworkPolicy, private clusters, Confidential GKE). Maps the OWASP LLM Top 10 to concrete controls.

sanjeevrg89 Updated

File contents

sanjeevrg89/arete/tree/main/skills/ai-security-on-gke commit bb38b30851

Frequently asked questions

npx skillmds@latest add sanjeevrg89/ai-security-on-gke