AI agents are the new power users — with API keys, tool access, and no device screen. Give each one a scoped identity instead of the keys to the kingdom.
A .env file with production keys, baked into an agent container. The blast radius of one leak is everything.
Nobody can answer "what can this agent touch?" — because the honest answer is "the whole VPC".
When an agent gets talked into fetching a URL it shouldn't, the network is the last line of defense. Make it a real one.
Each agent runs as its own tailnet node with its own short-lived auth key. No shared secrets.
This agent may reach the model gateway and the docs index. Nothing else — enforced at the network layer.
Approved model endpoints only. A prompt-injected fetch to an arbitrary domain fails closed.
Every connection logged: which agent, which destination, when, for how long. Incident response starts with facts.
Agents reach models only through an internal gateway that adds auth, rate limits, and logging. Direct model egress is blocked.
MCP tool servers listen only on the tailnet. Agents discover and call them over AmneziaWG-encrypted connections.
Agents request sensitive datasets; the data plane checks a human-approved grant before the bytes move.