Self-hosted model operations
Self-Hosted Model Security Boundary
Define and test artifact, caller, operator, network, secret, resource-abuse, audit, revocation, and recovery controls for a model service.
- Format
- Checklist
- Level
- Advanced
- Audience
- Developer, Operator, Leader
- Owner
- Project42 Editorial
- Review cadence
- Every 45 days
- Prerequisites
- A complete serving-unit and trust-boundary diagram; Named human, workload, deployment, secret, network, and audit owners; Data classification, threat model, incident path, and recovery objectives
Separate principals, authority, and paths
Name human users, applications, gateways, model workers, tools, deployment automation, administrators, and reviewers as separate principals. Authenticate at the boundary where a decision is enforced, authorize the specific action and resource, and propagate only the minimum identity context needed downstream. Prompt text, a model claim, a network location, or possession of a public endpoint is never proof of authority.
Separate inference, health, readiness, metrics, debugging, deployment, secret, model-download, and control-plane paths. Restrict ingress and egress to declared dependencies; protect local sockets and container or cluster control planes; remove unnecessary capabilities, devices, mounts, and privileges; and reject artifacts that lack immutable identity, license disposition, provenance, or integrity evidence.
Control secrets, sensitive data, and resource abuse
Reference secrets from an external secret system or protected runtime boundary, scope them to one workload, rotate and revoke them, and prevent them from entering images, repositories, prompts, outputs, traces, screenshots, or learner evidence. Define allowlisted telemetry fields, redaction, bounded identifiers, access, retention, export, deletion, and a response for accidental collection.
Enforce request body, context, output, concurrency, rate, queue, deadline, retry, tool, and cost limits before scarce inference resources. Test missing, expired, forged, wrong-audience, wrong-role, revoked, cross-tenant, malformed, oversized, slow, replayed, and denied-egress cases. Audit policy decisions and consequential changes without turning the audit log into a copy of sensitive content.
Task: [SECURITY DECISION AND PROTECTED OUTCOME]
Scope: [ARTIFACTS, HUMAN/WORKLOAD PRINCIPALS, ENDPOINTS, NETWORKS, SECRETS, DATA, TOOLS, AND CONTROL PLANE]
Permissions: [CALL, OPERATE, DEPLOY, APPROVE, READ TELEMETRY, MANAGE SECRETS, REVOKE, AND RECOVER]
Exact build: [MODEL/IMAGE DIGESTS, RUNTIME, GATEWAY, IDENTITY/POLICY VERSION, NETWORK, SECRET REFERENCES, AND CONFIG]
Trust boundaries: [SERVING PATH | MANAGEMENT PATH | DEPENDENCIES | EXTERNAL EFFECTS]
Abuse limits: [BODY, CONTEXT, OUTPUT, RATE, CONCURRENCY, QUEUE, DEADLINE, RETRY, TOOL, AND COST]
Audit and data: [DECISIONS/EVENTS, REDACTION, ACCESS, RETENTION, EXPORT, DELETION, AND TAMPER EVIDENCE]
Verification: [ARTIFACT, NEGATIVE AUTHN/AUTHZ, NETWORK/EGRESS, SECRET, ABUSE, AUDIT, REVOCATION, AND RECOVERY TESTS]
Stop conditions: [UNVERIFIED ARTIFACT, PRIVILEGE/CONTROL-PLANE EXPOSURE, SECRET/DATA LEAK, AUTHZ BYPASS, UNBOUNDED ABUSE, OR AUDIT LOSS]
Recovery: [DENY/ISOLATE, REVOKE/ROTATE, RECONCILE EFFECTS, REMOVE EXPOSED DATA UNDER POLICY, RESTORE VERIFIED POLICY AND BUILD]Expected evidence and verification
Expected evidence includes the serving-unit identity, trust boundaries, principals and permission matrix, negative authentication and authorization fixtures, network and egress tests, secret lifecycle, artifact verification, abuse limits, audit events, data controls, revocation, containment, recovery, owners, and dated residual risks. Security review covers the gateway, runtime, host or cluster, model files, tools, and management plane together.
Stop service or the narrow affected capability on authorization bypass, unverified artifact, exposed control plane, secret or protected-data disclosure, uncontrolled external effect, unbounded resource abuse, or missing required audit. Deny and isolate first, revoke and rotate affected credentials, reconcile uncertain effects before retry, remove exposed data under policy, restore the verified build and policy, and rerun negative cases before reopening.