AI Intuition
Avsnitt

Google Agentic Architect - Subconcept 4.1: Cryptographic Network Perimeters & Access Control

Dela

Detail the zero-trust infrastructure required to secure enterprise agent runtimes. Explain how to establish VPC Service Controls (VPC-SC) to create cryptographic network perimeters enclosing models, databases, and buckets to prevent data exfiltration. Discuss the Principle of Least Privilege regarding IAM roles: explain why agents must run under downscoped identity-level service accounts (e.g., roles/aiplatform.user) rather than default project-level permissions. Finally, detail downscoped token delegation (RFC 8693 Context Propagation) to ensure database tools execute under the calling user's identity rather than a high-privilege system account.

Podden och tillhörande omslagsbild på den här sidan tillhör Dan Sarmiento. Innehållet i podden är skapat av Dan Sarmiento och inte av, eller tillsammans med, Poddtoppen.