Policy audit log
Creates and changes to quotas, priorities, fair-share rules, and enforcement mode — with actor and timestamp.
Security
We're designing Ainek for least-privilege access on customer-controlled clusters. Workloads, weights, and datasets stay in your environment. Exact permissions will be documented with design partners before any enforcement.
01 / Posture
Intended model: Ainek authenticates to your cluster API and metrics endpoints with scoped service identity. You own the nodes, the GPU operator, and the data path. We decide and record capacity policy — we do not become where model artifacts live.
02 / Deployment & data
Topology and data categories below are the design we're building toward — so early security conversations stay concrete.
Controllers or agents beside the cluster, scheduler integration points, and local collection of the metrics needed for observe and policy.
Where a hybrid control plane is used: policy API, configuration, and usage state required to operate the product — never your training data plane.
Retention for operational metrics and audit records will be agreed per design-partner deployment — only as long as needed to run and review the system.
03 / Authentication
Target design: admin access and cluster access as distinct identities. Roles stay coarse on purpose.
Operators sign in through your identity provider when configured, or an equivalent secured admin path agreed with partners.
Conceptual roles: Admin (policy and deployment), Team lead (team quotas and views), Viewer (read-only capacity and usage). Finer grants follow your org model.
Cluster API and metrics access via a dedicated service account or equivalent — least privilege, rotatable, scoped to required APIs.
04 / Isolation
Ainek is meant to separate teams in capacity policy. Hardware and runtime isolation remain your cluster’s job.
05 / Audit
We're building for an audit trail from the start. Capacity governance without one is not serious infrastructure.
Creates and changes to quotas, priorities, fair-share rules, and enforcement mode — with actor and timestamp.
Audit events designed to export to your logging or SIEM pipeline in a form your team can ingest.
We do not list certifications we have not completed. Questionnaires and architecture detail are available on request during early access.
06 / Network
Exact ports and CIDRs will be defined per topology with partners. The shape below is the target for a first security conversation.
Cluster API for policy integration; metrics endpoints (or push path) for GPU and scheduler signals; admin API for operators.
Hybrid designs may need controlled egress to Ainek-operated endpoints. Fully in-cluster installs keep that surface minimal or none.
TLS in transit for control-plane and admin traffic. State we persist (configuration, usage, audit) encrypted at rest.
07 / Operations
Control components will be deployed for continuity appropriate to each partner environment. Exact HA topology is part of install design — not a marketing claim.
Intended default: scheduling fail-open under existing Kubernetes or Slurm rules. Enforce-mode behavior documented before anyone enables it.
During private preview, contact is direct by email — not a ticket queue or enterprise support desk.
If security review matters for your evaluation, note it in the form. We'll cover intended topology, permissions, and data categories as part of early access.