Deploy AI Runtime Security Container on AWS
These installation steps show you how to install locally into a Minikube cluster. Instructions are also valid for Kubernetes provided by Docker Desktop and a full-fledged Kubernetes cluster. Running locally with Minikube introduces extra latency due to the prompt injection classification model. Latency is not present in a full-fledged Kubernetes cluster.
Before deploying Model Scanner, make sure you understand:
Select your operating system to view installation instructions.
macOS
Windows
Ubuntu
-
Open a terminal and create an environment variable file with Quay credentials. Use the following examples. Replace
%QUAY_USERNAME%and%QUAY_PASSWORD%with actual values.- For Quay credentials and other requirements, see Resource Requirements.
Special characters will require wrapping the value in a string.
-
Load the environment variables into your shell.
Select your deployment type to view instructions.
Hybrid
Disconnected
A Hybrid deployment sends metadata to the HiddenLayer AI Security Platform. See Hybrid and Disconnected Deployments for information about each deployment type.
-
Create a file named
.env.local.-
Use the comments in the example to find configurations for your deployment needs.
-
File changes to note:
- For the EU region, uncomment
hl_region=eu. - Replace
<license>with your Runtime Security license. - Replace
<client id>and<client secret>with your HiddenLayer API key and secret. - Replace
<aws_access_key>and<aws_access_secret>with information for your AWS instance.
- For the EU region, uncomment
-
For other policy configuration environment variables, see Runtime Security Configuration.
-
Make sure Docker Desktop is running.
-
Run the following command to login to the HiddenLayer Quay repository.
-
Run the Runtime Security container.
Health Check
To check that the proxy is up and running, open a new terminal and use the following command to ping the health monitor.
Generate Manifest
To write the generated manifest to a file (manifest.yml), open a terminal and run the following command.
- You must run the Runtime Security installer before generating a manifest.
- Change
latestto the Runtime Security version that you use.