Repository navigation
Add Secure Agent Workspace pattern docs - #734
Conversation
Co-Authored-By: Claude
|
Hi @sauagarwa. Thanks for your PR. I'm waiting for a validatedpatterns member to verify that this patch is reasonable to test. If it is, they should reply with Tip We noticed you've done this a few times! Consider joining the org to skip this step and gain Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
🤖 Mon Oct 05 16:01:42 - The preview is ready at: |
dminnear-rh
left a comment
There was a problem hiding this comment.
Using the Request Changes in the review just to make sure nobody else merges this.
PR is good to go but we are awaiting review/approval from Nvidia to include them as a partner
laubai
left a comment
There was a problem hiding this comment.
Added a number of review comments; I'd recommend making these changes prior to this content being merged so that they can be approved by the partner before they're published on the site.
- About and architecture: reword per review (Operators capitalized,
workspace contents as a list, template image instead of golden image,
no anthropomorphism or passive voice, GitOps product URL, descriptive
alt text for the architecture figure).
- Getting started: restructured prerequisites, one API key line,
replaceable values in the clone command and token URL, an example for
TARGET_BRANCH/TARGET_ORIGIN, `\->` menu arrows, and an example prompt
that shows the egress policy denying a request, with the sandbox log.
- Cluster sizing: requirement-style headings, {AWS}, clearer sizing text.
- Ideas for customization: clearer provider profile and binaries
wording, custom-inference steps, a WARNING for upgrading to a new
OpenShell release series, renamed options section.
- Troubleshooting: section headings one level down and every section in
symptom / cause / resolution form.
- Architecture diagram: drop the Flow key, which the page text repeats.
Co-Authored-By: Claude
dminnear-rh
left a comment
There was a problem hiding this comment.
@laubai everything looks good from my end. Nvidia has approved so if you are happy with resolution to your comments please merge
laubai
left a comment
There was a problem hiding this comment.
Looks good; approving to merge.
Adds documentation for the Secure Agent Workspace pattern
(https://github.com/validatedpatterns-sandbox/secure-agent-workspace) as a sandbox-tier pattern.
The pattern gives each user an isolated AI agent workspace in their own OpenShift Virtualization VM, running NVIDIA OpenShell and OpenClaw agents with Keycloak OIDC sign-in, a governed sandbox policy, and API keys kept in Vault.
Pages
_index.adoc– overview and architecture (diagram, numbered flows, shared services, per-user workspace, default profile)getting-started.adoc– prerequisites, preparation, deployment, verification, accessing a workspacecluster-sizing.adoc– bare-metal requirement, per-component resources, example cluster, storage, model servingideas-for-customization.adoc– users, SAW-BOM profiles, model provider, governance policy, OpenShell upgradestroubleshooting.adoc– VM scheduling, installer, sandbox, interceptor, egress, CLI, web UI, Argo CDAlso added
modules/secure-agent-workspace-about.adoc,modules/secure-agent-workspace-architecture.adocmodules/secure-agent-workspace/metadata-secure-agent-workspace.adocstatic/images/secure-agent-workspace/saw-architecture.{png,svg}Notes