DEV Community

Hyelzor
Hyelzor

Posted on

Building a K8s-Native AI Governance Platform with OPA and ML-BOM

Building a K8s-Native AI Governance Platform with OPA and ML-BOM

AI workloads on Kubernetes are exploding. But governance? That's a mess.

We have models running in production, shadow AI workloads we don't know about, and zero visibility into who deployed what. Compliance teams are panicking. Security teams are overwhelmed.

That's why I built Project-Aegis.

๐ŸŽฏ Project-Aegis is an open-source, Kubernetes-native AI governance platform that discovers, scans, and enforces policies on AI/ML workloads in real-time.

๐Ÿ”— GitHub: github.com/Hyelzor/Project-Aegis


๐Ÿ”ฅ The Problem: AI Governance is Broken

Here's what I kept running into:

ยท Shadow AI โ€” Models deployed without anyone knowing
ยท No audit trail โ€” Who deployed what, and when?
ยท Manual policy enforcement โ€” Good luck applying consistent rules across 50+ clusters
ยท Compliance nightmares โ€” Finance, healthcare, and regulated industries need proof, not promises

Most existing solutions are either:

ยท Cloud-specific (lock-in)
ยท Too heavy (enterprise bloat)
ยท Not designed for Kubernetes-native workflows

I wanted something that works out of the box with Helm, integrates with OPA for policies, and gives me tamper-evident audit logs out of the box.

So I built it.


๐Ÿ—๏ธ Architecture Overview

Here's how Project-Aegis works:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                    Kubernetes Cluster                       โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚  AI Agent   โ”‚  โ”‚  AI Agent   โ”‚  โ”‚    k8s-aibom        โ”‚ โ”‚
โ”‚  โ”‚  (LangChain)โ”‚  โ”‚  (LangChain)โ”‚  โ”‚    Controller       โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ”‚         โ”‚                โ”‚                     โ”‚            โ”‚
โ”‚         โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜            โ”‚
โ”‚                          โ”‚                                  โ”‚
โ”‚                    [WebSocket]                              โ”‚
โ”‚                          โ”‚                                  โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                           โ”‚
                           โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                    Aegis Backend (FastAPI)                  โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚  โ€ข ML-BOM Ingestion  โ€ข Policy Engine (OPA Rego)       โ”‚ โ”‚
โ”‚  โ”‚  โ€ข OpenA2A Scanner   โ€ข Audit Logger (HMAC chain)      โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ”‚                           โ”‚                                  โ”‚
โ”‚                    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”                          โ”‚
โ”‚                    โ”‚ PostgreSQL  โ”‚                          โ”‚
โ”‚                    โ”‚   (16)      โ”‚                          โ”‚
โ”‚                    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                          โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                           โ”‚
                           โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                    React Dashboard                          โ”‚
โ”‚              (Real-time policy visualization)               โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
Enter fullscreen mode Exit fullscreen mode

Tech stack:

ยท Backend: Python 3.11 + FastAPI + SQLAlchemy
ยท Database: PostgreSQL 16
ยท Policy Engine: OPA Rego
ยท Frontend: React 18 + Vite + Tailwind + Recharts
ยท Orchestration: Kubernetes + Helm
ยท Agent SDK: TypeScript 5.x + LangChain wrapper


๐Ÿง  Key Features

1๏ธโƒฃ ML-BOM Discovery & Ingestion

A Kubernetes controller (k8s-aibom) automatically discovers AI models deployed on your clusters and generates ML-BOM (Machine Learning Bill of Materials) documents.

Every model gets tracked โ€” no more shadow AI.

2๏ธโƒฃ OpenA2A Vulnerability Scanning

Every valid ML-BOM triggers an automated OpenA2A scan via webhook. Vulnerabilities are detected before they reach production.

3๏ธโƒฃ Real-Time OPA Policy Enforcement

Policies are written in Rego and enforced in real-time:

# Example: Block vLLM deployments
deny[msg] {
    input.kind == "Deployment"
    input.spec.template.spec.containers[_].image == "vllm/vllm"
    msg = "vLLM deployments are blocked by policy"
}
Enter fullscreen mode Exit fullscreen mode

The policy engine supports three actions:

ยท Block โ€” Prevent the workload from running
ยท Allow โ€” Permit the workload
ยท Mask โ€” Redact sensitive data from logs

4๏ธโƒฃ Tamper-Evident Audit Logs

This is one of my favorite features. Every audit log entry is hashed using HMAC-SHA256 in a chain:

Log 1 โ†’ Hash(Log 1 + Secret)
Log 2 โ†’ Hash(Log 2 + Hash(Log 1 + Secret))
Log 3 โ†’ Hash(Log 3 + Hash(Log 2 + ...))
Enter fullscreen mode Exit fullscreen mode

If someone modifies a log entry, the chain breaks โ€” and you can prove it. Critical for finance, healthcare, and regulated industries.

5๏ธโƒฃ React Dashboard

A clean, real-time dashboard shows:

ยท All ML-BOMs across clusters
ยท Policy violations
ยท Audit trail
ยท Scan results


๐Ÿš€ Getting Started in 5 Minutes

Option 1: Docker Compose (Local Dev)

git clone https://github.com/Hyelzor/Project-Aegis.git
cd Project-Aegis
make docker-up
Enter fullscreen mode Exit fullscreen mode

Option 2: Helm Chart (Kubernetes)

helm repo add aegis https://hyelzor.github.io/Project-Aegis
helm install aegis aegis/aegis
Enter fullscreen mode Exit fullscreen mode

That's it. The dashboard is available at http://localhost:3000.


๐Ÿ“Š Real-World Validation

We recently had users test Aegis on staging clusters. The shadow AI detection caught two orphaned workloads they didn't even know were running.

One user said:

"Helm install was shockingly painless and the OPA policies started blocking my test workload right away, exactly as configured. Wish more k8s tools had audit trails this clean out of the box."

Another added:

"The shadow AI detection caught two orphaned workloads in our staging cluster that I didn't even know were running โ€” which was both reassuring and slightly terrifying."


๐Ÿ”ฎ What's Next?

The platform is production-ready, but here's what I'm thinking about:

ยท More policy templates โ€” Pre-built Rego rules for common AI frameworks
ยท Slack/Email alerts โ€” Real-time notifications for policy violations
ยท Multi-cluster support โ€” Centralized governance across 100+ clusters
ยท CNCF Sandbox โ€” Eventually, I'd love to donate this to the CNCF


๐Ÿ’ฌ Let's Talk

I'd love your feedback on:

  1. The OPA Rego policies โ€” Are they comprehensive enough?
  2. The HMAC audit chain โ€” Any edge cases I missed?
  3. ML-BOM discovery โ€” What models/frameworks should I support next?

Drop a comment below or open an issue on GitHub.

๐Ÿ”— GitHub: github.com/Hyelzor/Project-Aegis
โญ Star it if you find it useful!


Built with โค๏ธ for the Kubernetes and AI community.

Top comments (0)