Archived copy of an article by Omer Sen, originally published on LinkedIn on 2026-09-29.
Original: https://www.linkedin.com/pulse/agentic-secops-one-workstation-rebuilding-suse-ai-factory-omer-sen-v3gqe/ · ← back to faruk.net

Agentic SecOps on one workstation: rebuilding the SUSE AI Factory + NVIDIA stack with open source, then testing what it promises

SUSE published two pieces this year on giving security agents real autonomy: We Gave Our Agents Autonomy. Here's How We Kept Control and the deeper Agentic SecOps on SUSE AI Factory with NVIDIA Agent Safety Platform. The interesting claim in both is architectural, not about scale. Agents get autonomy because a sandbox holds the credentials and the egress policy, not because the agent is trusted.

That property does not need a datacentre to test. It needs one machine, one GPU and some patience. So I built it, and then wrote a test for every claim I could find in the articles.

What I built

The public half of SUSE's design fits on a workstation. The rest, the BlueField-4 DPU with Sentry and DOCA and the Vera CPU, is hardware and not integrated by NVIDIA yet either. The SecOps agents themselves ship as SUSE AI Factory blueprints, so there is no public repo to run. What can be tested is the runtime the agents would live in.

How the sandbox actually works

This is what reading the articles did not tell me and what the lab did.

Every OpenShell sandbox is two pods. The agent runs in one, as an unprivileged user with Landlock and a seccomp filter applied at creation. The other is a supervisor that owns the agent's DNS and a transparent proxy. Inside the sandbox, a name that no approved rule covers resolves to a synthetic address in 198.18.0.0/15 that only the supervisor can route. The connect fails before a packet leaves the pod, the supervisor logs the refusal, and about a second later the gateway shows a proposed rule for a human to approve or reject.

Credentials work the same way. A provider holds the real secret. The sandbox gets a placeholder string in the environment variable. When curl sends that placeholder as a bearer token to the one host the provider profile names, the supervisor swaps in the real value on the way out. The agent never sees it.

Recommended by LinkedIn

The tests

Seven scripts, each creating or using a real sandbox on the cluster, each printing the evidence it saw before its verdict. Here is the recorded run.

One honest nuance on the sixth point. In OpenShell 0.1.2 the audit records are OCSF-classified event lines with class, activity, severity, decision and reason, not JSON documents. The classification is there. A JSON export is not, or I have not found it.

Three things that surprised me

What is next

Run the NeuVector test with the admin password and make both layers visible in one run. Build a small remediation agent in a sandbox that reads NeuVector events through an approved rule and asks the local vLLM endpoint what to do, which is the article's whole loop on one machine. Try NemoClaw on top of the gateway, put NeMo Guardrails in front of the model, replace unauthenticated gateway access with OIDC, and move RKE2 to the RPM install so SELinux confines containerd.

Everything is public

The Ansible, the docs, the component inventory with licences, the tests and the committed test output are at github.com/omerfsen/agentic-secops-lab under Apache-2.0. If you have a supported GPU and a spare afternoon, it should reproduce. If it does not, open an issue.

Thanks to SUSE and NVIDIA for publishing enough detail to make this reproducible, and to the authors Stacey Miller, Troy Mangum, Alessandro Festa and Gaurav Mehta.