Kubernetes Operator based on the open-source container vulnerability scanner Trivy.
-
Updated
Jun 20, 2025 - Python
Kubernetes Operator based on the open-source container vulnerability scanner Trivy.
A hands-on lab toolkit for container security, from CIS-benchmark fundamentals to architectural trust governance. 12 production-grade labs covering image hardening, signing, supply chain attestation, admission control, and runtime debugging. Designed around reproducible, production-oriented container security scenarios.
Policy-as-code admission for Python modules and dependencies. Inspect before execution, enforce runtime and supply-chain policies, and produce evidence-backed ADMIT/DENY decisions.
Self-hosted model routing gateway and agent control plane for OpenAI, Anthropic, Gemini and A2A agents behind one OpenAI-compatible API, protocol-first. MCP server security, governed tools, prompt enhancement, virtual-key budgets, cache, observability, audit chain and agent governance. Zero-key local first run; public preview.
In-process Tokio task supervisor: one job per key with queue/replace/reject admission, retries, graceful shutdown, and reliable final outcomes
Real-time serving of full-duplex interaction models: per-tick deadline scheduling + KV-budget admission control. Systems research.
Drop-in OpenAI- and Ollama-compatible LLM gateway that learns each backend's latency online and routes vLLM / SGLang / TGI / Ollama with SLO-aware admission. No engine patches.
TokenSched 给 Claude Code 的 token 预算装上了一个 CPU 调度器:它按子任务期望值预分配预算、预测超支,并在 5 小时窗口耗尽前自动把低价值工作降级到 Haiku 或抢占——把硬截断变成可调度的软退让。
A focused async bulkhead for Java that limits in-flight work and makes overload visible.
C++17 + CUDA orchestrator for running multiple LLM agents on one constrained GPU. `lmxd` daemon does NVML-seeded admission control to stop llama.cpp OOM crashes; `LayerStreamer` + `PinnedHostPool` show 22–32% wall-clock savings via double-buffered `cudaMemcpyAsync` on two CUDA streams. KV-swap helper included.
OnionGuard is an open-source, sovereign, self-hosted admission-control engine designed specifically for the threat model of anonymous services.
Open-source, self-hosted virtual waiting room for websites and apps. FIFO admission, operator dashboard, and a Docker-based local Preview. Apache-2.0.
Admission control for human approvers — pressure-aware queueing, delegation, and auto-approval, governed by an LLM agent and validated by a deterministic policy engine.
Chaosify is a Kubernetes security testing CLI that proves your admission controls, RBAC policies, network segmentation, and runtime detection actually work by running targeted tests against a live cluster and producing structured evidence.
Shared lifecycle admission protocol and reference policy kernel for DeepSeek Harness subagents.
LLM admission control with concurrency and in-flight token budgeting for predictable performance under contention.
Kubernetes hardening lab — real kind cluster, Pod Security Admission + Kyverno, real kube-bench CIS score
Give an AI agent the keys to a real Kubernetes platform and watch it burn, then turn on the CNCF and agent-specific guardrails that stop it. Hands-on security workshop from AI Engineer World's Fair 2026.
QoS admission control and capacity intelligence for finite AI inference capacity
Reference admission rails for agent execution evidence: four policy engines, each declaring per obligation what it enforces, approximates, or cannot reach.
To associate your repository with the admission-control topic, visit your repo's landing page and select "manage topics."