Shadow AI — a pulled image and a --model flag is all it takes to serve a model.
Compliance pull — AI inventory obligations assume you can list what is actually running.
github.com/GoogleCloudPlatform/k8s-aibomProduced in CI, from the artifact you meant to ship. Frozen at the moment of build.
Blind to a hot-swapped HF_MODEL_ID, an edited Deployment, or a digest that was actually pulled.
Generated from live Kubernetes API objects: the args, env, image and digest serving right now.
Every attribute carries evidence pointing at the exact spec field it came from.
github.com/GoogleCloudPlatform/k8s-aibomk8s-aibom-system
Reads the Kubernetes API. Nothing else.
aibom.k8saibom.dev/enabled=true
Inference, agents, RAG, training, eval — vLLM, TGI, Triton, NIM, Dynamo, Ollama, Ray Serve, SGLang, KServe
sha256
Byte-deterministic → GitOps-diffable
github.com/GoogleCloudPlatform/k8s-aibom--model container arg, or an HF_MODEL_ID env var.vllm, from matching the image against a pattern.Each attribute ships with an evidence locator pointing at the exact spec field it came from.
github.com/GoogleCloudPlatform/k8s-aibomModel signature claims are checked against operator-configured trust roots (Sigstore public-good via TUF, self-hosted TUF mirror, or a static trusted-root file for air-gapped clusters) plus Rekor transparency-log inclusion.
verified requires a signer-identity constraint the workload author does not control. A claim can never upgrade itself. Under a public trust root with no identity constraints the verifier reports signature-valid-unconstrained and the tier stays claimed.
verified means a signer the operator trusts signed a statement consistent with this claim. It does not mean the bytes on the accelerator were hashed — the controller has no node access, by design.
Designed in an open review window; substantively amended twice by community review from the model-signing ecosystem.
github.com/GoogleCloudPlatform/k8s-aibom$ kubectl aibom summary -n rc-verify NAMESPACE NAME WORKLOAD WORKLOAD-NAME CATEGORY RUNTIME MODELS CONFIDENCE SIGNED READY rc-verify apps-deployment-goodsig Deployment goodsig inference vllm pkg:npm/sigstore@1.3.0 inferred verified True $ kubectl aibom verify apps-deployment-goodsig -n rc-verify published: e15230d35f8561617f94012d8782ca3cd10591d13968e0adf24e5eb555566a99 computed: e15230d35f8561617f94012d8782ca3cd10591d13968e0adf24e5eb555566a99 OK: document bytes match the published digest model pkg:npm/sigstore@1.3.0: signature verified
kubectl aibom summaryTable of tracked workloads, incl. per-model SIGNED state.kubectl aibom view <name>Decoded ML-BOM for one workload.kubectl aibom verify <name>Recompute sha256 vs the published digest; non-zero exit on mismatch.github.com/GoogleCloudPlatform/k8s-aibomMeasured on live GKE, dual-sampled (metrics-server and kubelet counter deltas), and independently reproduced by NVIDIA on their own cluster (NVIDIA/aicr issue #2310).
github.com/GoogleCloudPlatform/k8s-aibomShips in NVIDIA AI Cluster Runtime as a qualified component since AICR v0.20. Enabled by default in exactly one stock recipe — the GKE H100 inference recipe — and available opt-in on every AICR platform.
github.com/GoogleCloudPlatform/k8s-aibomsha256
Optional sinks: GCS, webhook
Outputs are designed as evidence for EU AI Act Articles 12/50 logging & transparency, NIST AI RMF inventory controls, and ISO/IEC 42001 inventory clauses.
github.com/GoogleCloudPlatform/k8s-aibomhelm install k8s-aibom oci://ghcr.io/googlecloudplatform/charts/k8s-aibom --version 1.5.1 --namespace k8s-aibom-system --create-namespace
kubectl label namespace <ns> aibom.k8saibom.dev/enabled=true
kubectl krew install aibom
Chart is digest-pinned; releases ship provenance and SBOM attestations.
v1.6 train: CronJob coverage, workload-kind allowlist, NIM-operator/LeaderWorkerSet scrapers under design review.
Designed and reviewed in public — contributions welcome.
github.com/GoogleCloudPlatform/k8s-aibom?notes for speaker notes