Skip to content

Security Model

André Borchert edited this page Jun 13, 2026 · 7 revisions

Security Model

Purpose

This page describes the evolving security model for OSAI.

Contents

Capability Model

OSAI should use capabilities for resources such as cores, memory arenas, NIC queues, model mappings, Git workspaces, build sandboxes, and deployment hooks.

Agent Permissions

App agents should be read-only by default. Git write access, build/test access, network access, and deployment access must be explicit.

Build and Test Sandboxes

Build and test jobs should run in isolated cells or sandboxes. They should not inherit broad access to production data, credentials, or unrelated repositories.

Administration

Administration should be SSH-only. Password login should be disabled by default. Serial access is for early bring-up and recovery.

Updates and Rollback

Signed updates, patch review, audit logs, and rollback are required for safe code-changing agents.

Secret Rule

Never commit credentials, tokens, private keys, SSH keys, passwords, or benchmark data containing secrets.

Clone this wiki locally