Layer 1: Agent Security
- • Outbound-only communication over TLS 1.3 with certificate pinning
- • Minimal footprint: 50 MB binary, <100 MB RAM, <0.5% CPU average
- • Runs as dedicated service account with whitelisted command scope
- • GPG-signed agent binaries verified at install and update time
Agent (Your VPC) --TLS 1.3--> Control Plane
Firewall Policy:
- Outbound 443 only
- No inbound ports required