18 Repos
Enforcement of resource isolation and access control via shared workspace permissions.
Distinct from Access Control: Distinct from Access Control: specifically targets the isolation of multi-tenant workspaces in a collaborative design environment.
Explore 18 awesome GitHub repositories matching security & cryptography · Workspace Isolation. Refine with filters or upvote what's useful.
Deepagents is an LLM agent orchestration platform and stateful application server designed for deploying and managing AI agents built with computational graphs. It provides a containerized runtime environment that handles agent execution, state persistence, and the versioning of AI assistants. The platform distinguishes itself through deep integration with the Model Context Protocol, allowing agents to function as servers that expose tools and capabilities to external clients. It features a sophisticated observability suite for capturing execution traces, performing LLM-based evaluations agai
Implements trust boundaries and access control to isolate users and resources within separate workspaces.
Kitematic is a graphical user interface for managing and running Docker containers on desktop operating systems. It serves as a visual Docker management tool and API client that translates user interface interactions into REST API calls to control the Docker daemon without requiring the command line. The application is built as a cross-platform Electron desktop application, utilizing a Chromium-based shell to provide a consistent administrative interface across Mac and Windows. The software covers the full container lifecycle, including the creation, configuration, and monitoring of containe
Runs individual sessions in micro-virtual machines to isolate network and filesystem access for increased security.
Meshery is a service mesh management plane and cloud native infrastructure orchestrator. It provides a visual design-as-code environment for modeling microservices and infrastructure components through declarative blueprints, functioning as a centralized platform for designing, deploying, and managing service mesh infrastructure. The platform is distinguished by its ability to translate visual designs into active deployments and its use of gRPC-based adapters to integrate with diverse infrastructure providers. It features a multi-tenant architecture that manages shared workspaces and role-bas
Enforces resource isolation and access control through workspace permissions and credential encryption.
Noi is an AI-powered web browser designed to organize AI prompts and manage parallel browsing workspaces. It serves as a local-first browsing environment that stores history and settings on the local device for privacy and offline access. The browser distinguishes itself through a command line interface that allows users to trigger application actions and manage environments from external tools. It also includes a system for storing and organizing reusable AI prompt templates to streamline chat-based productivity. The platform provides multi-workspace organization, enabling side-by-side wind
Provides dedicated workspace isolation per session to manage multiple browsing contexts without interference.
Oumi is a comprehensive large language model development platform designed for synthesizing data, fine-tuning models, and running performance evaluations. It serves as a unified environment for the entire model lifecycle, encompassing a training and fine-tuning suite, an evaluation framework, and tools for synthetic data generation and model distillation. The platform is distinguished by its iterative, failure-driven synthesis approach, which analyzes model weaknesses during evaluation to generate targeted training data. It utilizes an LLM-based judge framework to programmatically score respo
Provides isolated project environments with role-based access control to group datasets, models, and evaluators.
RedisInsight is a graphical user interface and management tool for browsing, analyzing, and administering Redis databases. It provides a visual environment for exploring key-value data structures, managing database instances, and performing data analysis across different operating systems and deployments. The tool distinguishes itself by providing dedicated visual managers for complex operations, including a vector database manager for configuring embeddings and similarity searches, a query workbench for executing raw commands and Lua scripts, and a performance monitoring dashboard for tracki
Allows multiple teams to operate on one platform through scoped authentication and independent observability.
This project is an LLM coding agent orchestrator and AI software engineering platform designed to manage fleets of agents that autonomously solve issues, handle pull requests, and fix CI failures. It functions as an agentic CI/CD automator and parallel workflow manager, coordinating the end-to-end development lifecycle from initial ticket tracking to final code merging. The system is distinguished by its modular plugin framework and isolated worktree management, which allow multiple agents to work on separate coding tasks simultaneously without file system conflicts. It utilizes role-based mo
Ensures agent session isolation using tmux windows or child processes to prevent cross-task interference.
🔥 基于大模型和 RAG 的智能问数系统,对话式数据分析神器。Text-to-SQL Generation via LLMs using RAG.
Enforces data access boundaries by partitioning resources and query results at the workspace level.
Materialize is a streaming SQL database that continuously ingests live data from sources such as Kafka, Redpanda, PostgreSQL, and MySQL, and incrementally maintains materialized views. It provides a PostgreSQL-compatible query engine that accepts standard SQL over the PostgreSQL wire protocol, enabling any existing SQL client or BI tool to query real-time data. The system also includes a Model Context Protocol (MCP) server that exposes live materialized view data to AI agents, providing fresh context without polling. Materialize distinguishes itself through its ability to offer configurable c
Selects the consistency guarantee for a session or transaction, balancing freshness against query latency.
Voilà is a tool that converts Jupyter notebooks into standalone interactive web applications. It renders notebook cells as HTML web components, preserving live widgets while stripping source code by default, and gives each viewer a dedicated Jupyter kernel for isolated widget state and callback execution. The project runs as a Jupyter server extension, reusing existing server infrastructure for notebook serving and authentication. It supports directory-based notebook hosting, serving all notebooks in a folder as a browsable collection of web applications from a single command. Voilà also prov
Provides each dashboard viewer with a dedicated Jupyter kernel for isolated widget state and execution.
AgentOps is an observability platform and developer toolkit for monitoring the execution, performance, and reliability of autonomous agents powered by large language models. It serves as a system for tracking AI agent behavior, debugging complex workflows, and benchmarking model performance. The platform is distinguished by its ability to visualize multi-agent workflows through execution path graphing and session replays. It provides specific tools for calculating financial spend across various language model providers and supports a self-hosted observability stack for users who require full
Provides a scalable API and dashboard system that supports multi-tenant observability.
Mimir ist eine Multi-Tenant-Zeitreihendatenbank und ein verteilter Metrik-Speicher für skalierbare Telemetrie. Es dient als Prometheus-kompatibles Backend und bietet Langzeitspeicherung sowie eine skalierbare Abfrage-Engine für massive Mengen an Zeitreihendaten. Das System ist für Multi-Tenant-Observability konzipiert und isoliert Telemetriedaten sowie Ressourcenlimits für unabhängige Teams oder Organisationen innerhalb eines einzigen Clusters. Es gewährleistet hohe Verfügbarkeit und Langlebigkeit durch Sharding und Replikation von Daten über einen verteilten Cluster hinweg und nutzt Objektspeicher zur Persistenz, um externe Datenbankabhängigkeiten zu eliminieren. Das Projekt deckt weitreichende Fähigkeiten ab, einschließlich globaler Metrik-Aggregation für regionsübergreifende Analysen und verteilter Abfrageausführung mittels Parallelisierung und Caching. Es integriert zudem Observability-Tools wie föderiertes Alerting, synthetisches Monitoring und KI-gestützte Incident-Resolution-Workflows zur Beschleunigung der Fehlerbehebung. Administrative Kontrollen umfassen Tenant-Ressourcenquoten, benutzerbezogene Ressourcen-Overrides und Shuffle-Sharding für Workload-Isolierung.
Provides isolated monitoring and observability environments for different teams within a shared cluster.
Youtu Agent is an open-source framework for building, running, and evaluating autonomous agents powered by large language models. It provides the core infrastructure for creating agents that follow reasoning loops, use toolkits, and coordinate with other agents to solve complex tasks, all managed through YAML-driven configuration files. The framework distinguishes itself through its support for multi-agent orchestration, where a planner agent decomposes tasks and coordinates specialized worker agents, and through its integration with the Model Context Protocol for connecting to external toolk
Provide a dedicated workspace directory per session where an agent can read, write, and edit files without cross-task interference.
gptme ist ein autonomer KI-Agenten-Server und ein Framework, das für lokale Systemautomatisierung, Softwareentwicklung und Codeausführung entwickelt wurde. Es arbeitet als lokale Ausführungs-Engine, die es Sprachmodellen ermöglicht, Shell-Befehle auszuführen, lokale Dateien zu ändern und mit dem Betriebssystem zu interagieren. Das Projekt fungiert als Client für das Model Context Protocol und integriert sich in externe Server, um Agentenfunktionen mit standardisierten Tools und Datenquellen zu erweitern. Es verfügt über ein providerunabhängiges Routing-System, um Aufgaben über mehrere proprietäre Cloud-APIs und lokale KI-Backends hinweg zu orchestrieren. Das System umfasst Funktionen für Headless-Browser-Automatisierung, visuelle Inhaltsanalyse und symbolbasierte Codeanalyse zur Kartierung von Codebasen. Um Sicherheit zu gewährleisten, implementiert es Human-in-the-Loop-Leitplanken, die eine Benutzerbestätigung erfordern, bevor sensible Systemänderungen ausgeführt oder Datei-Patches finalisiert werden. Die Anwendung kann als eigenständige Desktop-Binärdatei oder über Docker-Containerisierung bereitgestellt werden.
Assigns dedicated local directories and persistent states to agents to manage long-term goals independently.
Azure Machine Learning Notebooks is a cloud-based environment for developing and executing interactive Jupyter notebooks within a managed machine learning workspace. It provides managed machine learning compute through cloud-based workstations and containerized environments pre-configured with GPU drivers and kernels for high-performance model training. The project functions as a distributed GPU training platform and an ML experiment tracking system to monitor training metrics and version data assets. It also serves as an MLOps pipeline orchestrator for automating modular workflows and a mode
Creates controlled cloud workspaces with role-based access to data sources and compute resources.
OpenSquilla ist ein LLM-Agent-Orchestration-Framework zur Koordination mehrstufiger KI-Workflows und Tool-Ausführungen mittels gerichteter azyklischer Graphen. Es fungiert als zentrales System zur Verwaltung spezialisierter Skill-Pakete und zur Ausführung komplexer Reasoning-Sequenzen. Das Projekt zeichnet sich durch ein Routing-Gateway aus, das Aufgaben basierend auf Komplexität, Kosten und Performance an verschiedene KI-Anbieter weiterleitet. Es nutzt ein mehrstufiges KI-Gedächtnissystem, das Arbeits-, episodisches und semantisches Wissen mittels lokaler Embeddings und SQLite organisiert, sowie eine sichere Ausführungsumgebung (Sandbox), die Agent-generierten Code über risikobasierte Berechtigungsprofile isoliert. Die Plattform deckt ein breites Spektrum an Funktionen ab, einschließlich Multi-Channel-Deployment für Web- und Messaging-Plattformen, automatisierter Aufgabenplanung via Cron und einer Model Context Protocol-Bridge zur Anbindung externer Tools. Zudem bietet sie umfassende Monitoring- und Observability-Tools zur Verfolgung von Token-Kosten, zum Auditing von Laufzeitentscheidungen und zur Verwaltung eines Katalogs wiederverwendbarer Skills. Das System enthält CLI-Utilities für die Workspace-Initialisierung und das Skill-Lifecycle-Management.
Deno AI Agent restricts file and shell operations to specific local directories to ensure execution safety.
Video analyzer is a toolkit that processes video files through computer vision and automatic speech recognition to produce structured JSON data and natural language summaries. The system extracts visual frames, samples key moments based on pixel differences, and transcribes soundtrack audio into written text to generate comprehensive descriptions across chronological timelines. The software coordinates sequential processing stages that combine frame-by-frame visual analysis with audio transcripts using local or cloud AI models. It supports adaptive and uniform frame sampling, hardware-accele
Isolates temporary working directories per upload and cleans up stored session files after processing.
Tempest is an orchestration platform designed for the execution and management of autonomous coding agents. It provides a framework for running multiple agents in parallel, coordinating their workflows, and maintaining persistent session states through a centralized management interface. The platform distinguishes itself through its focus on secure, isolated execution and intelligent context management. Each agent operates within a dedicated sandbox, utilizing ephemeral file systems and database copies to perform tasks without impacting production environments. To optimize performance and red
Isolates each agent session within a dedicated file system worktree to prevent unauthorized access and cross-task interference.