Agent Identity & Security
How does Catalyst handle agent identity in air-gapped environments for zero-trust?
Catalyst runs fully in your air-gapped cluster, using local workload identity via mTLS without external dependencies. Agent identities are managed through Dapr’s built-in certificate authority, which you can integrate with your internal PKI. Tool authorization policies are stored locally. No internet access is needed for identity or policy enforcement, preserving zero-trust in isolated networks.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Agent Identity & Security
What is a workload identity for an AI agent and why can't I just use a shared API key?
Explains workload identity for AI agents and the security limits of shared API keys in production.
- Agent Identity & Security
How does Catalyst assign a workload identity to an agent runner like LangGraph or CrewAI?
Describes how Catalyst injects workload identities into framework-agnostic agent runners.
- Agent Identity & Security
What security problems do shared API keys cause when multiple agents run in production?
Lists security problems from shared API keys in multi-agent production environments.