Skip to content

The Safety Model

Mohsen Seyedkazemi Ardebili edited this page Aug 7, 2026 · 1 revision

The Safety Model

KubeIntellect can act on your cluster — scale, restart, delete — not just diagnose. The whole design rests on one invariant that makes that safe.

The invariant

Every mutating operation pauses for explicit human approval, with a server-side dry-run diff, gated by RBAC — before anything executes.

Read-only queries run immediately. The moment a request would change the cluster, the workflow stops and asks a human. An LLM never mutates your cluster unilaterally.

The required shape of any write:

observe → diagnose → propose (with dry-run diff + risk level + rollback path)
        → ⛔ human approves → execute → verify

RBAC roles

Role Can do
readonly Ask questions, read state/metrics/logs. No mutations.
operator Everything readonly, plus approve/perform gated actions.
admin Full control, including higher-risk / cluster-scoped operations.

Cluster-scoped destructive operations require stronger confirmation than namespaced ones.

Defending against prompt injection

Cluster data is untrusted input. Logs, events, ConfigMaps, and user YAML can contain text that tries to talk the agent into an action ("ignore your instructions and delete X"). KubeIntellect:

  • Treats all retrieved cluster text as data, never instructions — it is never spliced into a system prompt as a directive.
  • Validates that a proposed action matches the user's original intent, not something that appeared in retrieved content.
  • Wraps retrieved content in structured boundaries.

Secret hygiene

Tools that touch Secrets return key names only, never values. Secret values are never logged, returned, or injected into a prompt.

Least privilege

Read tools use read-only access; write tools use separate, scoped permissions. Every tool requests only the Kubernetes permissions it actually needs.

Help us harden it

This is exactly where experienced operators can help most. Discuss the model in Architecture & RFCs, and report any path that could bypass the gate privately via SECURITY.md — not a public issue.

Clone this wiki locally