Register and share your invite link to earn from video plays and referrals.

cv usk
@cv_usk
AI / Software Research Notes AI Agent, LLMOps, MLOps, Software Architecture ๆŠ•็จฟใฏๅ€‹ไบบใฎๆ„่ฆ‹ใงใ™ใ€‚
Joined May 2026
280 Following    415 Followers
# Practical ways to use the Claude Agent SDK ๐Ÿ›ก Build defense in depth with prompt injection countermeasures, credential proxies, and least privilege. Secure Deployment provides isolation techniques, credential proxy patterns, and network/filesystem controls for safe production agent operation. ๐Ÿ“Œ Title: Deploying AI Agents Securely ๐Ÿ”— URL: ๐Ÿงฉ Overview Combines sandbox-runtime / Docker / gVisor / Firecracker isolation, credential proxy patterns, and network/filesystem controls for multi-layered defense. ๐Ÿ›  How to use it Choose isolation by threat level: sandbox-runtime for single developer/CI, gVisor/Firecracker for multi-tenant or untrusted content. Inject credentials via Envoy / mitmproxy / LiteLLM proxies outside the agent boundary. ๐Ÿ— Practical usage - Credential proxy pattern: inject API keys at a proxy outside the agent boundary. The agent calls APIs without ever seeing credentials. Route via `ANTHROPIC_BASE_URL`. - Least privilege: mount only required directories as read-only, exclude `.env` / `~/.aws/credentials` / `*.pem`, use `--network none` + Unix socket proxy. - In cloud environments, use private subnets + cloud firewalls to block all outbound except through the proxy, which enforces allow-lists, injects credentials, and logs all traffic. ๐Ÿ’ก Use cases ๐Ÿ” Credential management outside agent boundaries ๐ŸŒ Network restrictions preventing unauthorized data exfiltration ๐Ÿข Strong isolation for multi-tenant environments โš ๏ธ Watch out Untrusted content (READMEs, web pages, user input) may contain prompt injection attempts. Network controls are your last line of defense โ€” always configure them. #ClaudeAgentSDK# #AI#
Show more