vastai-security-basics
Installation
SKILL.md
Vast.ai Renter Security Boundary
Overview
A Vast.ai renter controls credentials and workload configuration but does not own the physical host. Apply least privilege, prefer verified datacenters for sensitive data, encrypt critical material, and assume destroyed local storage is not a substitute for external recovery.
Prerequisites
- Data classification and decision on whether shared marketplace hardware is permitted
- Scoped API-key and dedicated SSH-key owners
- Approved image provenance, secret injection, network exposure, and checkpoint controls
Instructions
Step 1: Constrain the control plane
Create named scoped keys with only needed permission categories and endpoint constraints. Separate human, CI, monitoring, and deployment identities.