In-VPC Topology & Dual-Plane Enforcement

Execution control at the
system boundary.

How Sabrix isolates model completions from consequential actions, binds approvals to exact parameter digests, injects credentials in-VPC, and records verifiable outcomes on a durable ledger.

Decoupled Traffic Paths
In-VPC Secret Injection
AmbiguousInFlight Ledger
Read integration docs →
IN-VPC RUNTIME BOUNDARY · SPECIFICATION ILLUSTRATIVE TRACE
PATH A · :8080 Model Data Path HTTP/1.1 · SSE
POST /v1/chat/completions → Streaming Redaction + KV-Cache Align
PATH B · :8090 Action Forward Path Forward Proxy
POST api.stripe.com/v1/refunds → Policy Gate + SHA-256 Digest Verification
ADMIN INTERFACE (:9090) · DURABLE LEDGER STATE
action_id: "act_88f2910c"
status:    "AmbiguousInFlight" (HTTP 504)
policy:    "HOLD_FOR_DESTINATION_EVIDENCE"
retry:     "BLOCKED (Prevent duplicate charge)"

IN-VPC EXECUTION TOPOLOGY

Two traffic paths. One administrative control interface.

Sabrix establishes two separate traffic paths inside your private cluster perimeter, backed by an isolated administrative ledger interface. Model reasoning passes through an L7 streaming proxy, while consequential downstream API mutations are guarded by an action execution forward proxy.

TOPOLOGY BOUNDARY SPECIFICATION
Path A: Model Data Path (:8080)
Path B: Action Forward Path (:8090)
Downstream VPC Isolation
CUSTOMER PRIVATE VPC / CLUSTER PERIMETER EXTERNAL / DOWNSTREAM WORKLOAD AI Agent Runtime LangGraph / CrewAI / Custom Host / Kubernetes Pod PATH A: HTTP /v1 SABRIX L7 GATEWAY (:8080) Model Traffic Proxy • Streaming Prompt Compactor • KV-Cache Prefix Alignment Egress over WAN CLOUD PROVIDER LLM Provider OpenAI / Anthropic / Gemini PATH B: FORWARD PROXY ACTION FORWARD PROXY (:8090) Action Interceptor • Pre-Execution Policy Gate • Parameter SHA-256 Digest Verification • In-VPC Credential Injection Guarded Dispatch DOWNSTREAM VPC Internal Systems Production DBs, IAM, Stripe ✓ Zero Direct Unchecked Calls
PATH A · INGRESS Port :8080 · Streaming

Model Traffic Proxy

Intercepts model completion requests on port 8080. Inspects prompts, compacts redundant conversational context, aligns KV-cache prefixes, and forwards to your configured model provider over TLS.

Port :8080 · Streaming reverse proxy · Zero-buffer forwarding
PATH B · ACTION AUTHORITY Port :8090 · Enforced

Action Execution Forward Proxy

Intercepts tool calls, MCP JSON-RPC, and HTTP APIs before execution. Actions within policy proceed automatically. Actions requiring approval pause until authorized by a matching parameter digest.

Port :8090 · In-VPC forward proxy · Controlled credentials
Decoupled Deployment: Supported tool clients can route action traffic through Sabrix (:8090) while retaining their existing model gateway. Deployment requires explicit client routing, identity configuration, and network controls that prevent direct endpoint bypass. Administration and durable ledger records are exposed on isolated port :9090.

EXECUTION LIFECYCLE MECHANICS

Approval binding, credential control, and destination evidence.

01 · INTEGRITY SHA-256 Digest

Cryptographic Approval Binding

Approvals are never broad permission grants. Human decisions bind to a canonical SHA-256 wire digest over target destination, account, and parameters. Any post-approval payload mutation immediately voids the decision.

Canonical parameter digest · Single-use consumption
02 · ISOLATION In-VPC Secret Vault

Controlled Credential Injection

Agents never hold downstream API keys, database passwords, or OAuth bearer tokens. Credentials remain isolated in-VPC and are injected by Sabrix only upon authorized dispatch.

Isolated secrets · Zero agent visibility
03 · DURABILITY Atomic State Store

Durable State & Timeout Preservation

Execution state is persisted through atomic record replacement with file and directory synchronization. When a downstream call times out, the outcome is recorded as AmbiguousInFlight rather than assumed failed.

Atomic record replacement · Directory synchronization
04 · RECONCILIATION Destination Evidence

Destination Evidence & Reconciliation

Rather than blind retries, Sabrix uses supported destination checks or operator investigation to verify external evidence before deciding if another attempt is safe.

Preserved uncertainty · Destination status verification

EVALUATION CONSIDERATIONS

Validate against your production environment.

✓
1. Identify Target Tool Boundaries
Catalog which agent tool paths perform mutations (MCP tools, HTTP endpoints, SQL write connections) vs read-only queries.
✓
2. Configure Policy Limits & Secrets
Define deterministic threshold limits, human escalation tiers, and store downstream credentials inside your private VPC.
✓
3. Confirm Destination Idempotency
Verify that downstream business APIs support idempotency keys and status query endpoints for post-timeout reconciliation.
✓
4. Establish Operator Runbooks
Define standard operating procedures for investigating AmbiguousInFlight ledger events before triggering manual replay.

Discuss your workflow.

Review your agent boundaries, approval policies, and recovery requirements with our systems engineering team.