infrabroker
面向AI代理的基础设施访问代理——SSH和Kubernetes。每次操作由独立签名者生成的临时凭据;模型永远不会接触到。支持MCP stdio / HTTP+OIDC。
Infrastructure access broker for AI agents — SSH & Kubernetes. Per-operation ephemeral credentials minted by a separate signer; the model never touches one. MCP stdio / HTTP+OIDC.
怎么安装
暂无统一安装命令,请查看仓库 README。
简介
infrabroker **Infrastructure access broker for AI agents — SSH & Kubernetes. The model never touches a credential.** *(formerly ssh-broker)* The agent requests an *action* — run a command on a host, query or change a cluster. infrabroker checks it against policy, executes it with a credential minted for that single operation — an **ephemeral, scope-limited SSH certificate** from its own CA, or a **short-lived bound ServiceAccount token** — and returns **only the output**. Keys, certificates and tokens live in the broker's memory and are discarded after the call: nothing enters the model's cont…
推荐参考
信息
- 协议
- GPL-3.0
- 语言
- Go
- GitHub 星标
- 10
- 月下载
- –
- 最近更新
- 2026-09-22
- 创建于
- 2026-06-03
基础安全检查
- 检查结果
- curated 收录但无 npm 包/安装命令
- 收录来源
- curated:punkpeye/awesome-mcp-servers
- 主题标签
- ai-agents, golang, kubernetes, mcp, mcp-server, prompt-injection, security, ssh, ssh-certificates, zero-trust