

<!DOCTYPE html>

<html lang="en-US">
<head>
  <meta charset="UTF-8">
  <meta http-equiv="X-UA-Compatible" content="IE=Edge">

  <link rel="stylesheet" href="/assets/css/just-the-docs-default.css">

  <link rel="stylesheet" href="/assets/css/just-the-docs-head-nav.css" id="jtd-head-nav-stylesheet">

  <style id="jtd-nav-activation">
  
    .site-nav ul li a {
      background-image: none;
    }

  </style>

  

  
    <script src="/assets/js/vendor/lunr.min.js"></script>
  

  <script src="/assets/js/just-the-docs.js"></script>

  <meta name="viewport" content="width=device-width, initial-scale=1">

  



  <!-- Begin Jekyll SEO tag v2.9.1 -->
<title>LLM Shield | AI guardrails platform — input safety, output validation, and agentic security with multi-tenant policy enforcement.</title>
<meta name="generator" content="Jekyll v4.4.1" />
<meta property="og:title" content="LLM Shield" />
<meta property="og:locale" content="en_US" />
<meta name="description" content="AI guardrails platform — input safety, output validation, and agentic security with multi-tenant policy enforcement." />
<meta name="twitter:description" property="og:description" content="AI guardrails platform — input safety, output validation, and agentic security with multi-tenant policy enforcement." />
<link rel="canonical" href="https://docs.shield.votal.ai/assets/openshift/shield-admin.yaml" />
<meta property="og:url" content="https://docs.shield.votal.ai/assets/openshift/shield-admin.yaml" />
<meta property="og:site_name" content="LLM Shield" />
<meta property="og:type" content="website" />
<meta name="twitter:card" content="summary" />
<meta name="twitter:title" content="LLM Shield" />
<script type="application/ld+json">
{"@context":"https://schema.org","@type":"WebPage","description":"AI guardrails platform — input safety, output validation, and agentic security with multi-tenant policy enforcement.","headline":"LLM Shield","publisher":{"@type":"Organization","logo":{"@type":"ImageObject","url":"https://docs.shield.votal.ai/assets/images/votalai-logo.svg"}},"url":"https://docs.shield.votal.ai/assets/openshift/shield-admin.yaml"}</script>
<!-- End Jekyll SEO tag -->


  

</head>

<body>
  <a class="skip-to-main" href="#main-content">Skip to main content</a>
  <svg xmlns="http://www.w3.org/2000/svg" class="d-none">
  <symbol id="svg-link" viewBox="0 0 24 24">
  <title>Link</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-link">
    <path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path>
  </svg>
</symbol>

  <symbol id="svg-menu" viewBox="0 0 24 24">
  <title>Menu</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-menu">
    <line x1="3" y1="12" x2="21" y2="12"></line><line x1="3" y1="6" x2="21" y2="6"></line><line x1="3" y1="18" x2="21" y2="18"></line>
  </svg>
</symbol>

  <symbol id="svg-arrow-right" viewBox="0 0 24 24">
  <title>Expand</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-chevron-right">
    <polyline points="9 18 15 12 9 6"></polyline>
  </svg>
</symbol>

  <!-- Feather. MIT License: https://github.com/feathericons/feather/blob/master/LICENSE -->
<symbol id="svg-external-link" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-external-link">
  <title id="svg-external-link-title">(external link)</title>
  <path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"></path><polyline points="15 3 21 3 21 9"></polyline><line x1="10" y1="14" x2="21" y2="3"></line>
</symbol>

  
    <symbol id="svg-doc" viewBox="0 0 24 24">
  <title>Document</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-file">
    <path d="M13 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V9z"></path><polyline points="13 2 13 9 20 9"></polyline>
  </svg>
</symbol>

    <symbol id="svg-search" viewBox="0 0 24 24">
  <title>Search</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="feather feather-search">
    <circle cx="11" cy="11" r="8"></circle><line x1="21" y1="21" x2="16.65" y2="16.65"></line>
  </svg>
</symbol>

  
  
    <!-- Bootstrap Icons. MIT License: https://github.com/twbs/icons/blob/main/LICENSE.md -->
<symbol id="svg-copy" viewBox="0 0 16 16">
  <title>Copy</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="currentColor" class="bi bi-clipboard" viewBox="0 0 16 16">
    <path d="M4 1.5H3a2 2 0 0 0-2 2V14a2 2 0 0 0 2 2h10a2 2 0 0 0 2-2V3.5a2 2 0 0 0-2-2h-1v1h1a1 1 0 0 1 1 1V14a1 1 0 0 1-1 1H3a1 1 0 0 1-1-1V3.5a1 1 0 0 1 1-1h1v-1z"/>
    <path d="M9.5 1a.5.5 0 0 1 .5.5v1a.5.5 0 0 1-.5.5h-3a.5.5 0 0 1-.5-.5v-1a.5.5 0 0 1 .5-.5h3zm-3-1A1.5 1.5 0 0 0 5 1.5v1A1.5 1.5 0 0 0 6.5 4h3A1.5 1.5 0 0 0 11 2.5v-1A1.5 1.5 0 0 0 9.5 0h-3z"/>
  </svg>
</symbol>
<symbol id="svg-copied" viewBox="0 0 16 16">
  <title>Copied</title>
  <svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" fill="currentColor" class="bi bi-clipboard-check-fill" viewBox="0 0 16 16">
    <path d="M6.5 0A1.5 1.5 0 0 0 5 1.5v1A1.5 1.5 0 0 0 6.5 4h3A1.5 1.5 0 0 0 11 2.5v-1A1.5 1.5 0 0 0 9.5 0h-3Zm3 1a.5.5 0 0 1 .5.5v1a.5.5 0 0 1-.5.5h-3a.5.5 0 0 1-.5-.5v-1a.5.5 0 0 1 .5-.5h3Z"/>
    <path d="M4 1.5H3a2 2 0 0 0-2 2V14a2 2 0 0 0 2 2h10a2 2 0 0 0 2-2V3.5a2 2 0 0 0-2-2h-1v1A2.5 2.5 0 0 1 9.5 5h-3A2.5 2.5 0 0 1 4 2.5v-1Zm6.854 7.354-3 3a.5.5 0 0 1-.708 0l-1.5-1.5a.5.5 0 0 1 .708-.708L7.5 10.793l2.646-2.647a.5.5 0 0 1 .708.708Z"/>
  </svg>
</symbol>

  
</svg>

  
    <header class="side-bar">
  <div class="site-header">
    <a href="/" class="site-title lh-tight">
  <div class="site-logo" role="img" aria-label="LLM Shield"></div>

</a>
    <button id="menu-button" class="site-button btn-reset" aria-label="Menu" aria-expanded="false">
      <svg viewBox="0 0 24 24" class="icon" aria-hidden="true"><use xlink:href="#svg-menu"></use></svg>
    </button>
  </div>

  <nav aria-label="Main" id="site-nav" class="site-nav"><ul class="nav-list"><li class="nav-category" aria-hidden="true">Get Started</li><li class="nav-list-item">
          <a href="/" class="nav-list-link">Overview</a>
        </li><li class="nav-list-item">
          <a href="/quickstart/" class="nav-list-link">Quickstart</a>
        </li><li class="nav-list-item">
          <a href="/faq/" class="nav-list-link">FAQ</a>
        </li><li class="nav-list-item">
          <a href="/glossary/" class="nav-list-link">Glossary</a>
        </li><li class="nav-category" aria-hidden="true">Guardrails & Policies</li><li class="nav-list-item">
          <a href="/guardrails/" class="nav-list-link">Guardrails Catalog</a>
        </li><li class="nav-list-item">
          <a href="/agentic-guardrails-guide/" class="nav-list-link">Agentic Guardrails</a>
        </li><li class="nav-list-item">
          <a href="/non-human-identity/" class="nav-list-link">Non-Human Identity (NHI)</a>
        </li><li class="nav-list-item">
          <a href="/agent-identity-architecture/" class="nav-list-link">Agentic Identity Architecture</a>
        </li><li class="nav-list-item">
          <a href="/rbac/" class="nav-list-link">Role-Based Access (RBAC)</a>
        </li><li class="nav-list-item">
          <a href="/tool-data-policies/" class="nav-list-link">Tool Data Policies</a>
        </li><li class="nav-list-item">
          <a href="/cross-app-flow-control/" class="nav-list-link">Cross-App Flow Control</a>
        </li><li class="nav-list-item">
          <a href="/infra-guardrails/" class="nav-list-link">Infrastructure Guardrails</a>
        </li><li class="nav-list-item">
          <a href="/hitl-approvals/" class="nav-list-link">Human-in-the-Loop Approvals</a>
        </li><li class="nav-list-item">
          <a href="/prevent-secret-leakage/" class="nav-list-link">Secret Vault</a>
        </li><li class="nav-list-item">
          <a href="/sigma-policies/" class="nav-list-link">Sigma Policies & ASIM Telemetry</a>
        </li><li class="nav-list-item">
          <a href="/policy-lifecycle/" class="nav-list-link">Policy Lifecycle</a>
        </li><li class="nav-list-item">
          <a href="/aibom/" class="nav-list-link">AI Bill of Materials</a>
        </li><li class="nav-list-item">
          <a href="/compliance-mapping/" class="nav-list-link">Compliance Mapping</a>
        </li><li class="nav-category" aria-hidden="true">Develop</li><li class="nav-list-item">
          <a href="/developer-guide-mcp/" class="nav-list-link">Developer Guide — MCP & APIs</a>
        </li><li class="nav-list-item">
          <a href="/api-reference/" class="nav-list-link">API Reference</a>
        </li><li class="nav-list-item">
          <a href="/api-explorer/" class="nav-list-link">API Explorer</a>
        </li><li class="nav-list-item">
          <a href="/connect-your-ide/" class="nav-list-link">Connect to Your IDE</a>
        </li><li class="nav-list-item">
          <a href="/mcp-e2e-lab/" class="nav-list-link">MCP End-to-End Lab</a>
        </li><li class="nav-list-item">
          <a href="/mcp-gateway/" class="nav-list-link">MCP Gateway</a>
        </li><li class="nav-list-item">
          <a href="/openshell-sandbox/" class="nav-list-link">Agent Sandbox (OpenShell)</a>
        </li><li class="nav-list-item">
          <a href="/integration-guide/" class="nav-list-link">Integrations</a>
        </li><li class="nav-category" aria-hidden="true">Deploy & Operate</li><li class="nav-list-item">
          <a href="/installation-guide/" class="nav-list-link">Installation</a>
        </li><li class="nav-list-item">
          <a href="/deployment-guide/" class="nav-list-link">Deployment (MCP Servers)</a>
        </li><li class="nav-list-item">
          <a href="/on-premises-deployment-guide/" class="nav-list-link">On-Premises</a>
        </li><li class="nav-list-item">
          <a href="/workload-identity-bundle/" class="nav-list-link">Workload Identity (SPIRE)</a>
        </li><li class="nav-list-item">
          <a href="/multi-tenant-architecture/" class="nav-list-link">Multi-Tenant Architecture</a>
        </li><li class="nav-list-item">
          <a href="/architecture-diagram/" class="nav-list-link">Architecture</a>
        </li><li class="nav-list-item">
          <a href="/agent-run-tracing/" class="nav-list-link">Agent Run Tracing</a>
        </li><li class="nav-list-item">
          <a href="/agent-governance/" class="nav-list-link">Agent Governance</a>
        </li><li class="nav-list-item">
          <a href="/enterprise-features/" class="nav-list-link">Enterprise Features</a>
        </li><li class="nav-category" aria-hidden="true">Rafay Integration</li><li class="nav-list-item">
          <a href="/partners/rafay/" class="nav-list-link">Overview</a>
        </li><li class="nav-list-item">
          <a href="/partners/rafay/integration/" class="nav-list-link">Integration Guide</a>
        </li><li class="nav-list-item">
          <a href="/partners/rafay/admin/" class="nav-list-link">Admin & Tenant Creation</a>
        </li><li class="nav-list-item">
          <a href="/partners/rafay/customers/" class="nav-list-link">For Customers</a>
        </li></ul></nav>
<div class="d-md-block d-none site-footer">
  
  
    This site uses <a href="https://github.com/just-the-docs/just-the-docs">Just the Docs</a>, a documentation theme for Jekyll.
  
  </div>
</header>

  
  <div class="main" id="top">
    <div id="main-header" class="main-header">
  
    

<div class="search" role="search">
  <div class="search-input-wrap">
    <input type="text" id="search-input" class="search-input" tabindex="0" placeholder="Search LLM Shield" autocomplete="off">
    <label for="search-input" class="search-label">
      <span class="sr-only">Search LLM Shield</span>
      <svg viewBox="0 0 24 24" class="search-icon" aria-hidden="true"><use xlink:href="#svg-search"></use></svg>
    </label>
  </div>
  <div id="search-results" class="search-results"></div>
</div>

  
  
  
    <nav aria-label="Auxiliary" class="aux-nav">
  <ul class="aux-nav-list">
    
      <li class="aux-nav-list-item">
        <a href="https://github.com/sundi133/llm-shield" class="site-button"
          
          target="_blank" rel="noopener noreferrer"
          
        >
          View on GitHub
        </a>
      </li>
    
  </ul>
</nav>

  
</div>

    <div class="main-content-wrap">
      
      <div id="main-content" class="main-content">
        <main>
          
            <h# Secret — create manually BEFORE applying this file:
#   oc create secret generic shield-admin-secrets \
#     --from-literal=UPSTASH_REDIS_REST_URL=http://srh:8079 \
#     --from-literal=UPSTASH_REDIS_REST_TOKEN=your-token \
#     --from-literal=SHIELD_ADMIN_KEY=your-admin-key \
#     --from-literal=PLAYGROUND_LLM_BASE_URL=https://your-litellm-proxy/v1 \
#     --from-literal=PLAYGROUND_LLM_MASTER_KEY=sk-your-key \
#     --from-literal=PLAYGROUND_LLM_MODEL=moonshotai/kimi-k2.5 \
#     --from-literal=PLAYGROUND_SHIELD_ENDPOINT=https://your-shield-server \
#     --from-literal=PLAYGROUND_SHIELD_TOKEN=your-shield-token \
#     -n sundi133-dev

---
# Deployment
apiVersion: apps/v1
kind: Deployment
metadata:
  name: shield-admin

  labels:
    app: shield-admin
    app.kubernetes.io/part-of: llm-shield
spec:
  replicas: 1
  selector:
    matchLabels:
      app: shield-admin
  strategy:
    type: RollingUpdate
    rollingUpdate:
      maxUnavailable: 0
      maxSurge: 1
  template:
    metadata:
      labels:
        app: shield-admin
        app.kubernetes.io/part-of: llm-shield
    spec:
      initContainers:
        - name: init-permissions
          image: busybox:latest
          command: ["sh", "-c", "mkdir -p /app/data /app/log"]
          resources:
            requests:
              cpu: 50m
              memory: 32Mi
            limits:
              cpu: 100m
              memory: 64Mi
          volumeMounts:
            - name: storage-data
              mountPath: /app/data
            - name: logs
              mountPath: /app/log
      containers:
        - name: shield-admin
          image: docker.io/sundi133/llm-shield-admin:latest
          imagePullPolicy: Always
          ports:
            - containerPort: 8080
              protocol: TCP
          env:
            - name: AUDIT_LOGGING_ENABLED
              value: "true"
            - name: SHIELD_MAX_MODEL_LEN
              value: "16384"
            - name: AUDIT_DB_PATH
              value: /app/data/audit.db
            - name: NO_PROXY
              value: "localhost,127.0.0.1,127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.svc,.cluster.local,redis"
            - name: no_proxy
              value: "localhost,127.0.0.1,127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.svc,.cluster.local,redis"
          envFrom:
            - secretRef:
                name: shield-admin-secrets
          resources:
            requests:
              cpu: 250m
              memory: 256Mi
            limits:
              cpu: "1"
              memory: 512Mi
          livenessProbe:
            httpGet:
              path: /health
              port: 8080
            initialDelaySeconds: 10
            periodSeconds: 15
            timeoutSeconds: 5
            failureThreshold: 3
          readinessProbe:
            httpGet:
              path: /health
              port: 8080
            initialDelaySeconds: 5
            periodSeconds: 10
            timeoutSeconds: 3
            failureThreshold: 2
          securityContext:
            allowPrivilegeEscalation: false
            capabilities:
              drop:
                - ALL
          volumeMounts:
            - name: tmp
              mountPath: /tmp
            - name: storage-data
              mountPath: /app/data
            - name: logs
              mountPath: /app/log
            - name: reports
              mountPath: /app/report
            - name: guardrail-reports
              mountPath: /app/reports
      volumes:
        - name: tmp
          emptyDir: {}
        - name: storage-data
          emptyDir:
            sizeLimit: 500Mi
        - name: logs
          emptyDir:
            sizeLimit: 500Mi
        - name: reports
          emptyDir:
            sizeLimit: 1Gi
        - name: guardrail-reports
          emptyDir:
            sizeLimit: 1Gi

---
# Service
apiVersion: v1
kind: Service
metadata:
  name: shield-admin

  labels:
    app: shield-admin
    app.kubernetes.io/part-of: llm-shield
spec:
  selector:
    app: shield-admin
  ports:
    - port: 8080
      targetPort: 8080
      protocol: TCP
      name: http
  type: ClusterIP

---
# Route — exposes the admin portal externally with TLS
apiVersion: route.openshift.io/v1
kind: Route
metadata:
  name: shield-admin

  labels:
    app: shield-admin
    app.kubernetes.io/part-of: llm-shield
spec:
  to:
    kind: Service
    name: shield-admin
    weight: 100
  port:
    targetPort: http
  tls:
    termination: edge
    insecureEdgeTerminationPolicy: Redirect
  wildcardPolicy: None

---
# HorizontalPodAutoscaler
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
  name: shield-admin

  labels:
    app: shield-admin
spec:
  scaleTargetRef:
    apiVersion: apps/v1
    kind: Deployment
    name: shield-admin
  minReplicas: 1
  maxReplicas: 6
  metrics:
    - type: Resource
      resource:
        name: cpu
        target:
          type: Utilization
          averageUtilization: 70
    - type: Resource
      resource:
        name: memory
        target:
          type: Utilization
          averageUtilization: 80

---
# NetworkPolicy — only allow traffic from OpenShift router and within namespace
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: shield-admin-ingress

  labels:
    app: shield-admin
spec:
  podSelector:
    matchLabels:
      app: shield-admin
  policyTypes:
    - Ingress
  ingress:
    - from:
        # Allow from OpenShift router (ingress controller)
        - namespaceSelector:
            matchLabels:
              network.openshift.io/policy-group: ingress
        # Allow from pods in same namespace (e.g., shield workers)
        - podSelector: {}
      ports:
        - port: 8080
          protocol: TCP

          

          
            
          
        </main>
        
<hr>
<footer>
  
    <p><a href="#top" id="back-to-top">Back to top</a></p>
  

  

  <div class="d-md-none mt-4 fs-2">
    
    
      This site uses <a href="https://github.com/just-the-docs/just-the-docs">Just the Docs</a>, a documentation theme for Jekyll.
    
  </div>
</footer>

      </div>
    </div>
    
      

<div class="search-overlay"></div>

    
  </div>

  
    





<script type="module">
  
  import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@10.9.0/dist/mermaid.esm.min.mjs';
  

  var config = {}
;
  mermaid.initialize(config);
  mermaid.run({
    querySelector: '.language-mermaid',
  });
</script>



  
</body>
</html>

