Original: https://www.linkedin.com/pulse/agentic-secops-one-workstation-rebuilding-suse-ai-factory-omer-sen-v3gqe/ · ← back to faruk.net
Agentic SecOps on one workstation: rebuilding the SUSE AI Factory + NVIDIA stack with open source, then testing what it promises
SUSE published two pieces this year on giving security agents real autonomy: We Gave Our Agents Autonomy. Here's How We Kept Control and the deeper Agentic SecOps on SUSE AI Factory with NVIDIA Agent Safety Platform. The interesting claim in both is architectural, not about scale. Agents get autonomy because a sandbox holds the credentials and the egress policy, not because the agent is trusted.
That property does not need a datacentre to test. It needs one machine, one GPU and some patience. So I built it, and then wrote a test for every claim I could find in the articles.
What I built
- Host: Ubuntu 24.04 with KVM. The GPU, one RTX 4080 SUPER, is bound to vfio-pci and passed through to a guest. Switching it back to the host is one variable and one reboot.
- Guest: SLES 16.0 on a 60-day trial, NVIDIA G06 driver, RKE2 with Traefik ingress.
- Stack: NVIDIA GPU Operator, SUSE Security (NeuVector), vLLM serving Nemotron Nano 9B in FP8 on that one GPU, and NVIDIA OpenShell with the Agent Sandbox CRDs and its CLI.
- Automation: three Ansible playbooks. One prepares the host and creates the VM, one provisions the guest, one installs the stack. Everything is idempotent, and every optional piece sits behind its own switch.
The public half of SUSE's design fits on a workstation. The rest, the BlueField-4 DPU with Sentry and DOCA and the Vera CPU, is hardware and not integrated by NVIDIA yet either. The SecOps agents themselves ship as SUSE AI Factory blueprints, so there is no public repo to run. What can be tested is the runtime the agents would live in.
How the sandbox actually works
This is what reading the articles did not tell me and what the lab did.
Every OpenShell sandbox is two pods. The agent runs in one, as an unprivileged user with Landlock and a seccomp filter applied at creation. The other is a supervisor that owns the agent's DNS and a transparent proxy. Inside the sandbox, a name that no approved rule covers resolves to a synthetic address in 198.18.0.0/15 that only the supervisor can route. The connect fails before a packet leaves the pod, the supervisor logs the refusal, and about a second later the gateway shows a proposed rule for a human to approve or reject.
Credentials work the same way. A provider holds the real secret. The sandbox gets a placeholder string in the environment variable. When curl sends that placeholder as a bearer token to the one host the provider profile names, the supervisor swaps in the real value on the way out. The agent never sees it.
Recommended by LinkedIn
The tests
Seven scripts, each creating or using a real sandbox on the cluster, each printing the evidence it saw before its verdict. Here is the recorded run.
One honest nuance on the sixth point. In OpenShell 0.1.2 the audit records are OCSF-classified event lines with class, activity, severity, decision and reason, not JSON documents. The classification is there. A JSON export is not, or I have not found it.
Three things that surprised me
- Approvals are a poll, not a push. The supervisor picks up policy changes on a settings poll of roughly ten seconds. Fast enough, but worth knowing when a test "fails" for eight seconds.
- Provider types are not built in. The gateway ships with no provider profiles. You import them from NVIDIA's examples or write your own, and the profile is what decides which binaries may reach which host with the credential. That is the least-privilege control, and it lives in a YAML file you review.
- The sandbox can hang the CLI. Calling exec a few seconds after the sandbox reports Ready can race the supervisor's relay and hang forever. Wrap it in a timeout and probe first. Alpha software, as NVIDIA says.
What is next
Run the NeuVector test with the admin password and make both layers visible in one run. Build a small remediation agent in a sandbox that reads NeuVector events through an approved rule and asks the local vLLM endpoint what to do, which is the article's whole loop on one machine. Try NemoClaw on top of the gateway, put NeMo Guardrails in front of the model, replace unauthenticated gateway access with OIDC, and move RKE2 to the RPM install so SELinux confines containerd.
Everything is public
The Ansible, the docs, the component inventory with licences, the tests and the committed test output are at github.com/omerfsen/agentic-secops-lab under Apache-2.0. If you have a supported GPU and a spare afternoon, it should reproduce. If it does not, open an issue.
Thanks to SUSE and NVIDIA for publishing enough detail to make this reproducible, and to the authors Stacey Miller, Troy Mangum, Alessandro Festa and Gaurav Mehta.